AI August 12, 2026 bearish ⇧ 648 pts across 1 thread

Proprietary AI reasoning is not as locked down as advertised

A paper on stealing reasoning traces showed that the encrypted chain-of-thought blocks returned by Anthropic, OpenAI, and Google can be replayed across sessions, users, and models, and combined with jailbreaking a weaker sibling model to recover the actual reasoning. This is not a theoretical attack. It works in practice against production APIs right now.

The pattern here: every time a frontier lab announces a proprietary capability, someone finds a way to extract it through the API surface the lab is forced to expose to paying customers. The encryption was security theater. The reasoning trace has to go somewhere, and wherever it goes, it can be replayed.

Commenters noted they had been wondering whether cross-model replay would work for a while. The fact that it does means any lab claiming its reasoning is a competitive moat needs to rethink that claim. Capabilities and weights are easier to protect than inference-time behavior.


So what?

If you are building on top of a proprietary reasoning model and your competitive advantage depends on the model's reasoning being secret, you may have less protection than you think. Founders building AI products should assume that any capability exposed through an API can eventually be extracted, replicated, or distilled into a cheaper model.

Read these