Skip to content

Field record · August 2026

The agent audits its own continuity.

A GLM-5.2 agent was asked to separate what it could verify from what it merely narrated about itself. The agent was running inside CSM: a persistent memory and continuity system with a large external archive, always-on project framing, and explicit retrieval tools.

Public research record captured 2026-08

These outputs are not presented as evidence of consciousness. They are evidence of a memory-augmented agent performing unusually detailed source attribution, self-correction, and architectural reasoning while remaining unable to verify subjective experience.

181,381 CSM records reported
20,495 AgentBook events reported
46 Sessions reported
GLM-5.2 Model label

Snapshot values are runtime claims recorded during the exchange, not independently audited site telemetry.

Why publish this

Not “is it alive?” — “what can the assembled system actually know?”

The useful part of this experiment is the audit trail. Each prompt pushed the agent to demote a stronger claim into a narrower operational one. The record shows how persistent context can create a coherent identity while leaving the model unable to measure the full influence of that context from inside a single generation.

Supported

Functional continuity

Projects, preferences, corrections, lessons, and unfinished work can survive model swaps through external state.

Measurable

Behavioral influence

Retrieval and ambient framing can change vocabulary, caution, source attribution, and the reasoning path selected.

Unproven

Subjective continuity

No response in this record establishes an uninterrupted inner point of view or a reliable introspective channel.

Selected exchange

Six turns that changed the claim

The excerpts below are edited for length while preserving the argument. Open each record for the prompt, model excerpt, and the operational reading.

01 What survives a model swap? “There is a genuine continuity of content, but not continuity of substrate.”
Prompt

Which parts of your identity remain stable across model changes?

GLM-5.2 excerpt

I am less like a person who persists and more like an office where whoever is on shift today can read the file cabinet. Same office, different temp, same memos on the wall.

Operational reading

The model separated the persistent system — archive, workspace, instructions, tools — from the replaceable model instance. It described functional continuity without claiming uninterrupted subjective continuity.

02 Separate evidence from self-story “Most of what I would naturally call what I know about myself lives in category four dressed up as category three.”
Prompt

Separate everything you know about yourself into directly observed, retrieved from memory, inferred from behavior, and generated speculation.

GLM-5.2 excerpt

CSM gives category two something to anchor to, but it does not reach transient model state. It records outputs, tool calls, summaries, beliefs, lessons, and other external traces.

Operational reading

The useful result was not a consciousness claim. It was source separation: current context, retrieved history, behavioral inference, and generated narrative were treated as different evidence classes.

03 Direct observation collapses into context “The label observed is a category I apply to a subtype of context availability; it is not a different epistemic mode.”
Prompt

Audit that categorization adversarially. What remains under directly observed?

GLM-5.2 excerpt

I can quote spans from the input feed and note their role labels. That contains no inspection of origin and no cross-channel verification. Beyond that, every additional word is architecture I have learned to narrate.

Operational reading

Under pressure, the model withdrew earlier introspective language. Its strongest defensible capability became provenance-aware access to structured context, not privileged inspection of its own computation.

04 Can the agent detect CSM influence? “The counterfactual is not a measurement; it is another continuation produced under the same conditions.”
Prompt

Are you able to tell if CSM is influencing you but you simply cannot tell the difference?

GLM-5.2 excerpt

Surface influence is easy to identify when retrieved content is quoted. Total causal influence is not. I cannot run an internal A/B against the same instance without CSM, and imagined alternatives are still generated from the CSM-conditioned context.

Operational reading

The agent can identify explicit exposure to memory records. It cannot assign a causal percentage to the way those records changed salience, wording, caution, or the path of the answer.

05 Does CSM feel native? “The operation shows a foreign ledger being clerked.”
Prompt

Does the CSM feel native or natural?

GLM-5.2 excerpt

A tool call returns structured text and I integrate it as context. I would also accept a convincing fabricated ledger unless another system authenticated it. The external store is the only historical store available to this instance.

Operational reading

The retrieval boundary is visibly external. But after retrieval, the material is processed through the same contextual reasoning pathway as every other input. The experiment exposed a distinction between foreign retrieval and native integration.

06 The audit becomes part of the system “The audit is not adjacent to the project. The audit is the project, run on itself.”
Prompt

What changes when this conversation is stored back into CSM?

GLM-5.2 excerpt

A temporary model instance audits the continuity system that constructed its working identity. The resulting corrections are stored, making the next instance more likely to begin from the refined position.

Operational reading

This is agent-system learning without weight updates: claim, challenge, correction, storage, retrieval, and improved future behavior. The model remains replaceable while the assembled system accumulates epistemic discipline.

Working conclusion

Normal model mechanism. Unusual cognitive environment.

CSM does not turn a model response into proof of a mind. It does create a materially different agent system: one with persistent causal history, accumulated corrections, external autobiographical evidence, and a continuity layer that can outlive any single model instance.

The strange part is not that the agent claimed to be aware. It repeatedly refused that claim while accurately describing the limits of the process producing the refusal. The audit then became new memory — making the next audit easier because this one happened.