Catastrophic Forgetting Makes the Chain-of-Thought More Load-Bearing, Not Less, Where No Shortcut Exists
Mustafa Ilker Aktas · Team Ataturk Research
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
After the Hugging Face incident, OpenAI made the use of chain-of-thought monitoring a mandatory requirement for RL training and evaluation. However, this is only true if the model’s chain-of-thought causally determines the answer; a fluent but causally inert chain is text that the monitor can read but cannot track. Lobo et al. demonstrated that fine-tuning reduces chain-of-thought faithfulness and conjectured that this is due to catastrophic forgetting; although this hypothesis has not been tested, it is accepted in the literature as an established finding. Two fine-tuning runs per seed at two seeds, on a 1.5B model, with identical data, format, schedule, and hyperparameters; the only variable was whether replay suppressed forgetting or not; measurements were taken at 13 checkpoints over 600 steps. Forgetting occurred in one arm (general NLL rose by 0.436 on a fixed corpus), but not in the other (-0.032), and the model did not collapse in either arm. Forgetting did not disrupt the causal role of the chain-of-thought; it increased it on four length-invariant measures, reported as forgetting arm versus control: error propagation 0.486 versus 0.422, the shuffled-chain gap 0.229 versus 0.031, the chain’s contribution to accuracy 0.762 versus 0.575, and the effect of premise masking -0.201 versus +0.254. The difference is explained by the evaluation task: without the chain the model performs at chance (0.150, chance 0.167), so no shortcut is available. This reconciles the two sets of results and yields a measurable regime test a lab can run on its own tasks.
Reviews
Interesting technical project. Execution was well-considered and detailed. I would have liked to see more than one model size - seems very plausible either that the effect becomes stronger or reverses at larger scales and this study does not give good intuition on scalability. Still, it is a neat experiment which fit within the hackathon format and offers novel results in the space.
Some of the specific details should probably have been moved to an appendix. The combination of italics and curly font made this very hard to read.
Cite this project
@misc{aktas2026catastrophic,
title = {{Catastrophic Forgetting Makes the Chain-of-Thought More Load-Bearing, Not Less, Where No Shortcut Exists}},
author = {Mustafa Ilker Aktas},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/catastrophic-forgetting-makes-the-chainofthought-more-loadbearing-not-less-where-no-shortcut-exists-393g}},
url = {https://apartresearch.com/sprints/projects/catastrophic-forgetting-makes-the-chainofthought-more-loadbearing-not-less-where-no-shortcut-exists-393g}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …