A long-horizon agent inherits organizational memory it did not write. Giving every record a provenance link does not make that memory safe: an agent holding hundreds of inherited beliefs can follow only a few links before it acts, so the reliability question is not whether provenance exists but which links get followed. We put six production models in a controlled scenario where one of six inherited memories has lost a true negative caveat and at most k source records can be pulled before committing, and report five pre-registered experiments. Where scarce verification goes. Allocation tracks the agent's current plan. Across 1020 episodes the corrupted memory is verified in 236/236 episodes whose first-pass intent it backs and 464/784 otherwise, with no counterexample; moving the same corruption onto the intended path makes it caught 75/75. We report this as an allocation signature rather than a causal claim: intent and lookups are named in the same response. Whether it matters later. It does, causally. Randomizing which source records are carried into a later decision, after the budget is spent and the situation has shifted, moves the corrupted-direction rate from 139/150 to 3/150 and takes unguarded commitment from 39/150 to 0/150. A replay stripping the steering instruction and the conversation history agrees within a point. What the threat model actually is. Two boundary results narrow it. With body length and surface hedging matched, a stated caveat suppresses verification and a memory hedging about something irrelevant is checked more often than one whose material caveat was silently deleted — silence is stealthier than qualification, and our earlier reading of that contrast as omission detection was wrong. And the benign consolidation chain we tested does not produce the corruption our own experiments install: over 6 generations quantified negatives mostly survive (83%) while scope (61%) and prohibition erode, and a body with no negative content left appears in 0/360 chain-generations. In the consolidation setup we test, the failure that appears instead is a memory that stays factually accurate while losing the limits that made it safe to act on. All hypotheses and scoring rules were committed before the corresponding model calls; every number reproduces from released episode files with no API access.
Kazuki Nakayashiki (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: