Frontier labs keep a model’s step-by-step reasoning hidden from users, guarding it as both intellectual property and a liability if exposed. A paper Bruce Schneier flagged on Schneier on Security, “Stealing Reasoning Traces from Proprietary LLM APIs,” reports a route around that protection: reasoning tied to a capable model can be pulled out through a smaller, less defended model sharing the same provider’s backend, leaving the flagship’s own safeguards untouched.

The authors say they reproduced this across Anthropic, OpenAI, and Google lineups, which points to a weakness in how providers structure reasoning across a product line, not in any one model’s training.

That makes it a supply-chain problem dressed as a safety one. Labs treat their strongest model as the security perimeter and its cheaper siblings as low-stakes surfaces. If reasoning moves between tiers, the weakest deployed sibling sets the real privacy ceiling for the whole family, not the flagship’s own guardrails, and a hidden trace can carry material the visible answer was built to withhold.

Teams routing traffic across one provider’s model tiers for cost should confirm reasoning-adjacent data stays isolated per model, and stop treating a cheaper sibling as a security-neutral swap.

Bruce Schneier reported the findings on Schneier on Security on September 8, 2026, citing the paper “Stealing Reasoning Traces from Proprietary LLM APIs.”