{"slug": "facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs", "title": "Facts Without Rules: Boundary Metadata Collapse in Multi-Agent LLM Handoffs", "summary": "A new arXiv preprint (2608.29028v1) finds that multi-agent LLM handoffs cause 'summary collapse,' where boundary metadata governing data use is lost while operational facts survive, leading to privacy leakage. On a controlled testbed with GPT-5-mini and DeepSeek-R1-32B, uncompressed handoffs preserve boundaries at σ_b≈0.80, but a 25-word budget drops σ_b to ≈0.57 while operational-fact survival stays near ceiling. Vague language leaks in 73% of GPT and 50% of DeepSeek cases, while explicit constraints reduce leakage to under 15% across all tested models.", "body_md": "arXiv:2608.29028v1 Announce Type: new\nAbstract: Multi-agent LLM systems often coordinate by compressing an upstream interaction into a handoff artifact that downstream agents treat as shared state. We show that this handoff step is a structural source of privacy leakage: summaries preferentially preserve operational facts while weakening the boundary metadata that governs how those facts may be used---a failure mode we call \\emph{summary collapse}. On a controlled multi-agent coordination testbed we measure marker survival with a human-validated judge ($\\kappa = 0.74$), where $\\sigma_b = 1$ means every boundary marker survives verbatim and $\\sigma_b = 0$ means all are lost. Boundary-marker and operational-fact survival are nearly uncorrelated at the handoff level on both GPT-5-mini and DeepSeek-R1-32B (Pearson $r$ near zero): uncompressed free-text handoffs preserve boundaries at $\\sigma_b \\approx 0.80$, whereas a $25$-word budget drops $\\sigma_b$ to ${\\approx}0.57$ while operational-fact survival stays near ceiling. Controlled downstream tests reveal that protection depends on \\emph{boundary explicitness}: vague languages leak in $73\\%$ of GPT and $50\\%$ of DeepSeek cases, while explicit constraints reduce leakage to under $15\\%$ across all three tested models. A no-handoff single-agent control further shows the failure is not reducible to multi-agent topology as direct full-marker access still leaks more often than the operationalized handoff. Prompt-only mitigation and exact-string redaction only partially address the problem, while a gold-derived audience allowlist nearly eliminates leakage across models, showing that correctly identifying audience boundaries is the key factor.", "url": "https://wpnews.pro/news/facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs", "canonical_source": "https://www.machinebrief.com/news/facts-without-rules-boundary-metadata-collapse-in-multi-agen-ao1i", "published_at": "2026-09-01 04:00:00+00:00", "updated_at": "2026-09-01 05:53:27.625380+00:00", "lang": "en", "topics": ["artificial-intelligence", "large-language-models", "ai-safety", "ai-research", "ai-agents"], "entities": ["arXiv", "GPT-5-mini", "DeepSeek-R1-32B"], "alternates": {"html": "https://wpnews.pro/news/facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs", "markdown": "https://wpnews.pro/news/facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs.md", "text": "https://wpnews.pro/news/facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs.txt", "jsonld": "https://wpnews.pro/news/facts-without-rules-boundary-metadata-collapse-in-multi-agent-llm-handoffs.jsonld"}}