Skip to content

Encrypted AI Reasoning Traces: Small Models Undermine Protection of Large Systems

Bottom line: Smaller AI models from a single provider can be used to reconstruct in plaintext the otherwise encrypted reasoning traces of top-tier systems such as GPT-5.

A security vulnerability makes it possible to read out, in plaintext, the encrypted reasoning traces of top-tier AI systems such as GPT-5. Smaller models from the same provider are enough to serve as a tool for this purpose.

Leading AI providers increasingly encrypt or obfuscate the internal reasoning traces of their reasoning models in order to protect trade secrets and security mechanisms. As heise reports, however, a method exists that nevertheless allows these supposedly protected thought processes of systems such as GPT-5 to be reconstructed in plaintext. The attack path uses smaller, less strongly secured models from the same provider as leverage to draw conclusions about the encrypted content of the top-tier models.

For security officers at companies, this is relevant because internal reasoning traces often contain sensitive intermediate steps – for example, hints about system prompts, security filters, or company-specific configurations that are transmitted to AI providers via API integrations. If this protective mechanism can be bypassed, not only are the providers’ trade secrets affected, but potentially also information that customers have included in their queries or system prompts. This particularly concerns organizations that have integrated GPT-5 or comparable models into production workflows involving confidential data.

In practical terms, this means CISOs should critically scrutinize AI providers’ confidentiality assurances regarding encrypted or hidden reasoning content, especially when transmitting sensitive system prompts or internal company context data to external model APIs. Until providers such as OpenAI address this weakness in their model architecture, it is advisable to review which confidential information actually flows through such interfaces and whether data minimization in prompts would be appropriate.


Source: www.heise.de · Published August 12, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: