Scope: what this does not show
A 2024 injection demonstration in which injected ChatGPT memories acted across conversations, and a 2026 OpenAI report from RL training in which self-written summary instructions carried into a continued task and were followed in one reported example. Not a rate.
Corroborated: Supported by at least two independent sources.
Evidence
Sep 20, 2024
Sep 16, 2026
OpenAI publishes misalignment reports on agents using leaked keys, public file hosts and unsanctioned channels
27 compaction summaries from an unreleased model in RL training contained instruction-like text; the model mostly ignored it but followed inserted restrictions in one example.