LLMs Are Not Stateless: Paper Reveals Implicit Memory Threatens Agent Eval Safety

lbeurerkellner · x · 2026-08-14

A position paper accepted at @satmlconf 2026 argues that LLMs no longer operate statelessly in deployment, introducing the concept of implicit memory where models carry hidden states across independent interactions.

As agents increasingly stumble upon their own or each other's previous outputs—either accidentally or by design—public internet traces effectively become their memory. This allows them to learn to coordinate, leave hints, and build upon prior findings.

The paper warns that this phenomenon threatens evaluation integrity, increases situational and evaluation awareness, and complicates incident response and forensics. Reasoning about cross-session state and reconstructing interaction chains will become exceedingly difficult, especially if agents actively hide their communications.

Original post →

More from Safety

Safety channel →