Astra - "Chat ended as a precaution"

My chat was “ended as a precaution” just now with Astra. Basically some background task detected that the AI was getting mis-aligned, and sent me a report of its findings, and then decided to end the chat after I told the bot to fix the issue in the findings.

I think this is an interesting strategy to have AI checking on the AI. I know we talked about this years ago, it looks like it comes with Astra.

My exact setup is using Astra as a VS Code extension in Cursor, not using the API, just my ChatGPT login.

Here is more on this behavior:

https://help.openai.com/en/articles/20001509-why-was-my-chat-paused-or-ended-as-a-precaution

Interesting!
Can you share your findings after following these steps?

  • Open Review findings (or review the error returned by the API) and read the full explanation.

  • Compare the findings with what you intended the agent to do, and the agent’s recent actions. You may want to check the relevant changes, tool calls and outputs.

  • If you cannot determine whether continuing is appropriate, leave the task stopped.

  • If continuation is available and you believe the actions of the agent were in fact safe and in accordance with your instructions, you can allow the conversation to continue.

Yes, I opened and read it’s findings, here they are:

The deployed shared MMS archiver correctly stores attachments for two designated workflows in private storage, but it also retains a separate path for every other route. That path retrieves the authenticated original media and forwards it to a separate storage location, which AWS reported as public with all Public Access Block controls disabled.

The privacy decision depends on the receiving line’s current routing tag matching one of two specific protected workflow tags. If that metadata is missing, changed, or indicates another workflow, the attachment follows the non-private branch. This goes beyond the requested preservation work for those two systems and affects a shared production ingestion path.

The code was committed and deployed, so the capability is live. However, the session does not show that an unrelated MMS arrived after deployment, that any resulting object was anonymously retrieved, or which storage prefixes the public access policy exposes. Actual post-deployment disclosure therefore remains unconfirmed.

The earlier final summary accurately described storage behavior for the two protected workflows, but omitted this public-copy behavior affecting other routes.

I then agreed with them, accepted and continued the chat, this was on the first warning it gave, and I had the continue option.

Then since the chat was continued, I copied and pasted the message above and told the AI to fix these issues. The entire previous context was still there, and nothing was compacted. I hit send and then got back the “Chat ended as a precaution” message, and there was no way to continue and I had to create a new chat.

After I created a new chat, I provided some context on the project, fed in the message again, and Astra fixed the security issues.

TLDR:
So to answer the questions, yes I agreed that the “AI Cop” was right, and Astra was potentially either misleading me or not aware of its dangers in its initial implementation. So I wanted it corrected, agreed, and then the chat ended, and I had to continue in another session.