flâneur

Audit Without Verification: When LLM Accountability Layers Relay Rather Than Check

arxiv.org · 7,889 words · saved by 1 readers

Multi-agent LLM pipelines increasingly span organisational boundaries, and when a fault surfaces someone must determine where it entered. In deployment the artifact available for that determination is rarely a full execution trace: it is the reports each agent filed, and a filed report can state a conclusion alongside its observations. We ask what an accountability layer built on such reports can and cannot do. Using a pre-registered, institutionally partitioned pipeline of six agents with process-level information boundaries, exactly balanced defect injection and matched clean twins (345,600 requests per chain model, two models), we first report that our pre-registered hypothesis — that collective responsibility framing degrades escalation increasingly with chain length — is not supported. The layer nevertheless fails, and it fails asymmetrically. It originates almost nothing: zero allegations across 7,996 clean episodes where every agent stayed silent. It filters upstream error poorl

Abstract Multi-agent LLM pipelines increasingly span organisational boundaries, and when a fault surfaces someone must determine where it entered. In deployment the artifact available for that determination is rarely a full execution trace: it is the reports each agent filed, and a filed report can state a conclusion alongside its observations. We ask what an accountability layer built on such reports can and cannot do. Using a pre-registered, institutionally partitioned pipeline of six agents with process-level information boundaries, exactly balanced defect injection and matched clean…

saved by

related reading