Skip to content
Sprint projectSep 14, 2026Cary, N.C.

When the Agent Says Stop: A Minimum Safety-State Protocol for Long-Horizon AI Systems

Rebekah Reilly

Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: When the Agent Says Stop: A Minimum Safety-State Protocol for Long-Horizon AI Systems

More on drive.google.com (opens in new tab)
Share

Long-horizon AI agents create safety failures that may emerge across many plausible actions rather than from a single clearly unsafe step. Recent incidents also show that the model is only one component of the failure. Task assumptions can become invalid, safety-relevant evidence can be misinterpreted,& attempts by a model to abort can fail at the surrounding systems layer. We created a Minimum Safety-State Protocol for long-horizon agentic systems: a small, provenance-aware record of authorization boundaries, environmental assumptions, contradictory evidence, abort signals, permission changes, boundary crossings, and cumulative trajectory risk. The protocol includes explicit pause conditions and retention limits so that safety continuity does not become unrestricted surveillance.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. This is an interesting topic that I think is worth exploring more. If I'm understanding it correctly, it's the idea that as more and more subagents are spun out, they are losing the initial context provided to agent 0, and may therefore may no longer understand its safeguards. I don't have a good idea of what exactly you're proposing because I don't see the code, but seems worth pursuing. Finally, this is a good example of what a hackathon is for -- a limited scope project that doesn't try to claim more than it does.

  2. The four continuities framing is useful, trajectory, control, evidence, rationale, and the safety channel targets a real failure mode, the Opus abort case proves stop paths fail. Prototype shows it is implementable, limitations are honest. But 'independent' here means logically separated in one Python process, which is independence in name only. Spoofing, compromised supervisors, false positive rates, all unmeasured. Also long for what it establishes. Next: one ambiguous-scenario harness test with real models, like the future work already says.

Cite this project

@misc{reilly2026agent,
  title = {{When the Agent Says Stop: A Minimum Safety-State Protocol for Long-Horizon AI Systems}},
  author = {Rebekah Reilly},
  year = {2026},
  month = sep,
  note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/when-the-agent-says-stop-a-minimum-safetystate-protocol-for-longhorizon-ai-systems-sky0}},
  url = {https://apartresearch.com/sprints/projects/when-the-agent-says-stop-a-minimum-safetystate-protocol-for-longhorizon-ai-systems-sky0}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026