/p/2026-10-06 · explainer
Paper explainer · 2610.02664 · Shen, Zhang, Huang, Cheng et al.

The rule you set forty turns ago.

Restate a constraint at the moment the agent acts and it obeys. Leave the same constraint back in the history, still in force, and the strongest model tested breaks it in 11.5% of runs — same task, same tools, no attack, nothing adversarial. The paper names that gap and measures it as a matched difference over 412 instances across six tool domains, with histories of about 6,000 tokens spanning 56 to 160 turns. Then it closes the gap with two layers of ordinary engineering: lift each stated rule into a small library when it is said, re-render the matching ones when a task resumes, and put a deterministic check between the model’s proposed call and the tool.

01 · The problem

Same task, same tools, one sentence further back

which of the four matched conditions

02 · What it looks like

The prerequisite the agent no longer remembers is a prerequisite illustrative

03 · How big, and for whom

Seven models, and every one of them gets worse as the history grows

score it by

highlight one model

04 · The fix

Restore the rule, then check it in code

tap a layer to switch it on

05 · In your own product

What the residual rate buys you illustrative

Results

What the paper actually measured

What it does not show

In practice