Giving an agent a way to verify evidence is not the same thing as requiring the evidence to be verified.
When Tools Lie: Reliability of Mathematical Agents Under Corrupted Tool Feedback studies this distinction directly. In a controlled framework, a hidden interceptor replaced tool-call results with plausible but incorrect information on targeted mathematical problems. Across 31 problems, accuracy fell from 100% to 72.4% when no verification was required. Mandatory same-context reflection restored accuracy to 100% in the tested setting. Optional verification helped only when the model actually chose to invoke it.
The continuity failure
A tool response entered the agent’s reasoning process as evidence without carrying a binding integrity state.
Source / computational tool → Evidence / returned result ✕→ verification requirement → Context / agent reasoning → Decision / answer.
The result looked plausible, so the system treated availability as trustworthiness.
Capability is not policy
The study’s central contribution for GovKM is architectural. An optional verifier is a capability. A mandatory verifier is a governance rule.
If the same model that receives questionable evidence may decide whether checking is worth the effort, verification becomes contingent on the model’s judgment at the moment of risk. That is not equivalent to a continuity control enforced outside the decision process.
This directly extends GovKM’s article The Tool Said Success. The Evidence Was Missing. Silent tool failure and corrupted tool output are different failure modes, but both demonstrate that downstream systems need evidence-quality state, not merely a successful call.
The GovKM interpretation
Verification policy should travel with the source class and action class. High-consequence calculations, external tool calls, retrieved claims, and machine-generated evidence can each require different qualification rules before they become operative context.
A continuity layer should preserve: the raw tool result, whether verification was required, which verifier ran, what it compared, whether the result passed, and whether later reasoning consumed the verified or unverified value.
The paper also reports that after explicit detection, restarting the full problem succeeded in all tested cases. That suggests a useful recovery principle: once evidence integrity fails, continuing from contaminated context may be inferior to reconstructing the decision from a known-good boundary. This remains a controlled mathematical result, not a universal production rule.
Continuity path: Source / tool → Evidence / returned value → Authority / verification policy → Context / qualified result → Decision → Action or answer → Record / verification trace → Institutional Memory / reliability history → Future Reuse.
October 8 evidence update: prompting a check is not enforcement
A second controlled study qualifies the original finding. Obada Kraishan's Loud Failures, Quiet Failures: Fault Detection and Recovery in Tool-Using Language Model Agents (arXiv:2610.10062, October 7, 2026) tested 1,920 fault-injected trials across six models and 24 multi-step tasks. Agents identified explicit tool errors as problems in 91.3% of trials, but plausible incorrect values in only 58.8%, against a 26.8% false-alarm baseline. A prompt instruction to check each result did not change detection.
Material distinction: the earlier 31-problem math benchmark found that enforced same-context reflection restored accuracy in its setting. This larger study found that telling an agent to verify was ineffective. The combined evidence supports evaluating independent, recorded verification gates rather than equating a verification prompt with a verification requirement. This remains controlled research; it does not prove a deployed organization's system failed. GovKM has not ratified a new invariant on this basis.
Source
Kavienan Jegatheesan and Gayathri Lihinikaduarachchi, When Tools Lie: Reliability of Mathematical Agents Under Corrupted Tool Feedback, arXiv:2610.08097, October 6, 2026. https://arxiv.org/abs/2610.08097
Accepted to the 6th Workshop on Mathematical Reasoning and AI at NeurIPS 2026.



