Researchers have updated their reasoning-extraction study with tests across direct model APIs and third-party cloud hosts, including GPT-6 Astra. Joachim Schaeffer and Maksym Andriushchenko announced the update on Sept. 30.
The report’s dates matter. Its main result tables describe defenses as of Sept. 13, while a later timeline records Azure mitigations on Sept. 27 and says the reported extraction was not reproducible on Azure endpoints on Sept. 28. The earlier successful tests do not establish that those same paths remain open today.
Two ways of extracting reasoning
The researchers examine reasoning replay, in which a weaker model from the same family is asked to transcribe an opaque reasoning artifact returned by another model. Their Sept. 13 table reports that the tested direct OpenAI API routes blocked this method, while Azure routes allowed it for tested OpenAI models, including GPT-6 Astra.
A separate scratchpad method asks a model to put reasoning into a visible tool argument. This does not use decryption or a second model. Results vary across models and provider routes in the report’s second table, whose tests ran through OpenRouter.
The study’s comparison of the two methods used 152 HLE questions with GPT-6 Astra at low reasoning effort. The researchers found similar trace lengths and a small distributional shift; this is evidence about those collected traces, rather than proof that every extraction method yields identical reasoning.
Patches across hosting routes
The authors argue that defenses need to reach downstream hosts as well as a provider’s own API. They recommend verified security parity before cloud hosts are licensed to serve reasoning-capable models. That is a recommendation, not an enacted requirement.
The report’s Azure timeline records a second responsible disclosure on Sept. 14, followed by the Sept. 27 mitigations and Sept. 28 reproduction result.