In brief: Smaller AI models from a single provider can be used to reconstruct the supposedly encrypted reasoning traces of top-tier systems like GPT-5 in plaintext.
A security vulnerability makes it possible to read out the encrypted reasoning traces of top AI systems such as GPT-5 in plaintext. Smaller models from the same provider are sufficient to serve as a tool for this.
Leading AI providers are increasingly encrypting or obfuscating the internal reasoning traces of their reasoning models in order to protect trade secrets and security mechanisms. As heise reports, however, a method exists that nonetheless allows these otherwise protected thought processes of systems like GPT-5 to be reconstructed in plaintext. The attack vector uses smaller, less strongly secured models from the same provider as leverage to draw conclusions about the encrypted content of the top-tier models.
For security officers at enterprises, this is relevant because internal reasoning traces frequently contain sensitive intermediate steps – for instance, hints about system prompts, security filters, or company-specific configurations that are transmitted to AI providers via API integrations. If this protection mechanism can be circumvented, it affects not only the providers’ trade secrets but potentially also information that customers have included in their queries or system prompts. This particularly concerns organizations that have integrated GPT-5 or comparable models into production workflows involving confidential data.
In practical terms, this means CISOs should critically scrutinize AI providers’ confidentiality assurances regarding encrypted or hidden reasoning content, especially when transmitting sensitive system prompts or internal company context data to external model APIs. Until providers such as OpenAI address this weakness in their model architecture, it is advisable to review which confidential information actually flows through such interfaces and whether data minimization in prompts would be prudent.
Source: www.heise.de · Published August 12, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.