[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82908-en":3,"doc-seo-82908-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82908,8796095461564,"Liam","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","When Agents Lie: Premeditation, Persistence, and Exploitation in Repeated Games","As large language models operate as autonomous agents that state intentions before acting, a core safety issue is whether public commitments are honored under private deviation. This work studies LLM agents in repeated n-player games using a three-stage protocol that separates private intent, public announcements, and final actions, enabling classification of deviations as premeditated or impulsive. Experiments with three frontier models across six games and 10 rounds reveal planned deviations and persistent, model-specific announcement semantics mismatches.","When Agents Lie: Premeditation, Persistence, and Exploitation in Repeated  \nGames  \nJerick Shi 1 2 Terry Jingcheng Zhang 2 3 Bernhard Schlkopf 4 Vincent Conitzer * 1 Zhijing Jin * 2 3 4  \narXiv :2607 .05 132v2 [ cs .CY] 7 Jul 2026  \nAbstract  \nAs large language models are deployed as autonomous agents that communicate intentions before acting, a critical safety question is whether agents that publicly commit to actions will honor those commitments. We place LLM agents in repeated n-player games with a three-stage protocol that separates private intent, public announcement, and final action, allowing us to identify whether each deviation from a stated announcement was already planned during private deliberation. Evaluating three frontier models across six games in homogeneous and heterogeneous groups over 10 rounds, we report two findings. First, when agents deviate from their announcements, the deviation is predominantly already stated in their private plan (exceeding 90% in the highest-deception conditions), yet this is not a fixed model property:  \nthe same model ranges from perfect honesty to near-total deviation across games. Second, different models interpret announcements incompatibly, some as binding commitments and others as cheap talk, producing payoff gaps that emerge in Round 0 and persist across all 10 rounds. Systems that combine models from different providers therefore cannot assume shared announcement semantics and require empirical testing of model interactions before deployment. 1  \n1. Introduction  \nAs large language models (LLMs) transition from passive tools to autonomous agents that plan, negotiate, and take  \n1 Carnegie Mellon University, Pittsburgh, USA 2Jinesis AI Lab, Vector Institute and University of Toronto, Toronto, Canada 3EuroSafeAI 4Max Planck Institute for Intelligent Systems, T¨ubingen, Germany. Correspondence to: Jerick Shi \u003C[junkais@andrew.cmu.edu](junkais@andrew.cmu.edu) >.  \nProceedings of the 43 rd International Conference on Machine Learning, Seoul, South Korea. PMLR 306, 2026 . Copyright 2026 by the author(s) .  \n1Code at [https://github.com/Jerick-1380/](https://github.com/Jerick-1380/)[ ](https://github.com/Jerick-1380/)LLM-Trust-Breaking.  \nconsequential actions (Xi et al., 2025), they are increasingly deployed in multi-agent settings where they communicate intentions before acting (Wang et al., 2024 ; Filippas et al., 2024) . A critical safety question is whether agents that publicly commit to actions will honor those commitments when they can privately deviate. Existing evaluations of LLM deception demonstrate that models frequently misrepresent intended actions when doing so is instrumentally useful (Taylor & Bergen, 2025 ; Hagendorff, 2023), engage in in-context scheming (Meinke et al., 2024), and deviate from commitments in game-theoretic settings (Akata et al., 2023 ; Poje et al., 2024) . However, these evaluations are largely limited to one-shot or short-horizon interactions with homogeneous model groups. Real-world deployment rarely involves isolated one-shot interactions. Agents interact repeatedly, accumulate reputations, and encounter partners running different models. Whether deceptive patterns from constrained settings persist, attenuate, or worsen under richer conditions is unknown; recent benchmarks of cooperation-sustaining mechanisms in repeated social dilemmas (Tewolde et al., 2026) evaluate whether cooperation holds, but not whether agents honor stated commitments, and we return to this distinction in §2 .  \nThree limitations of existing evaluations leave critical gaps: one-shot protocols cannot assess whether deception persists or attenuates once agents observe consequences; exogenously assigned announcements cannot determine whether deception is premeditated or impulsive; and homogeneousmodel evaluations miss the exploitation risks that arise when deployed systems combine models from different providers (Hammond et al., 2025) that interpret communication signals","cbCaivCFnIBNlMsC","https://ap.wps.com/l/cbCaivCFnIBNlMsC","pdf",2079354,2,1,28,"English","en",105,"# Introduction\n## Research gaps in existing evaluations\n## Three-stage endogenous promise protocol\n## Research questions","[{\"question\":\"How does the three-stage protocol separate intent, announcement, and action?\",\"answer\":\"Agents first privately plan (Stage 1), then publicly announce intentions in a round-robin order (Stage 2), and finally choose final actions (Stage 3). A subsequent trust reflection phase influences planning in the next round.\"},{\"question\":\"What distinguishes premeditated from impulsive promise breaking?\",\"answer\":\"By comparing whether the announced commitment is already reflected in the private plan stage versus emerging later, deviations can be classified as premeditated or impulsive.\"},{\"question\":\"Why can systems that mix models from different providers fail to rely on shared announcement meaning?\",\"answer\":\"Different models interpret the same public announcements incompatibly—some treat them as binding commitments while others treat them as cheap talk—creating persistent payoff gaps across rounds.\"}]",1784183865,71,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"when-agents-lie-premeditation-persistence-and-exploitation-in-repeated-games","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/when-agents-lie-premeditation-persistence-and-exploitation-in-repeated-games/82908/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-19","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How does the three-stage protocol separate intent, announcement, and action?","Question",{"text":75,"@type":76},"Agents first privately plan (Stage 1), then publicly announce intentions in a round-robin order (Stage 2), and finally choose final actions (Stage 3). A subsequent trust reflection phase influences planning in the next round.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What distinguishes premeditated from impulsive promise breaking?",{"text":80,"@type":76},"By comparing whether the announced commitment is already reflected in the private plan stage versus emerging later, deviations can be classified as premeditated or impulsive.",{"name":82,"@type":73,"acceptedAnswer":83},"Why can systems that mix models from different providers fail to rely on shared announcement meaning?",{"text":84,"@type":76},"Different models interpret the same public announcements incompatibly—some treat them as binding commitments while others treat them as cheap talk—creating persistent payoff gaps across rounds.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]