RAG Systems Collapse When They Retrieve Their Own Writing. One Self-Authored Document Can Start It.
A new study ran 1,528 retrieval simulations and found nearly four in five ended in collapsed, repetitive answers. The fix is provenance, not a better embedding model.

Every RAG pipeline has a quiet assumption: the retrieval corpus is somebody else's writing. Documentation, wikis, support tickets, the web. A new paper asks what happens when that assumption breaks, and the answer is uncomfortable.
Gregory Druck and Ethan Smith's "RAG Collapse: LLM Responses Collapse When Retrieved Documents Are Self-Authored" (arXiv:2608.22118, submitted 22 August 2026) simulates exactly that scenario. They built three types of simulations of AI systems retrieving references they generated themselves, ran them across three model families on 1,019 information-seeking prompts, and spent over one million LLM API calls doing it. The result: 79.6% of the 1,528 simulations, 1,216 of them, ended in collapse.
Collapse here means what it meant in the model-collapse literature: responses become less diverse and stop resembling the original data distribution. Shumailov and colleagues showed in Nature (2024) that training recursively on model output produces "irreversible defects" as the tails of the distribution disappear. This paper shows a version of the same disease striking at inference time, inside the retrieval loop, with no retraining required.
Think about how ordinary the trigger is. A support bot whose knowledge base includes resolved tickets, and resolved tickets increasingly contain agent-drafted replies. A docs site with AI-assisted articles. A research assistant that summarizes papers into notes, then indexes the notes. The loop does not require malice or even carelessness. It requires a pipeline that writes and reads from the same shelf.
Finding 1: The collapse rate is 79.6%, and the scale behind it is serious
1,216 of 1,528 simulations collapsed. That is not a pilot result. Three simulation designs, three model families, 1,019 prompts, more than a million API calls: this is one of the more expensive empirical setups in recent RAG literature, and the effect survived all of it. When a finding holds across simulation types and model families at this spend level, the burden of proof shifts to the skeptics.
Finding 2: One self-authored reference can be enough
The most alarming line in the abstract: "even a single self-authored reference can trigger collapse." The mechanism is disproportionate self-citation. The model does not treat its own document as one source among many. It favors it, cites it, and builds the answer around it, which narrows the response. One bad apple does not just sit in the barrel; it becomes the barrel.
This matters because most corpus-hygiene advice assumes contamination is a matter of volume. Deduplicate aggressively, filter hard, keep the synthetic share low. A single-document trigger breaks that mental model. If one self-authored reference in the retrieved set can start the narrowing, then "only a little AI content in the corpus" is not the safety margin people think it is.
Finding 3: It is not about quality. The bias survives controls.
A natural objection: maybe the model's own writing is simply better, more relevant, more quotable, so preferring it is rational. The authors controlled for reference quality, and the self-bias persisted anyway. The model prefers its own words for being its own, not for being good. That rules out the most comforting explanation and points at something structural in how models score familiar phrasing.
Finding 4: This is a deployment problem, not a training problem
Model collapse needed recursive retraining, which gave teams a comfortable excuse: our weights are frozen, so we are safe. RAG collapse needs no retraining. It happens at inference time, in the system you shipped last quarter, the moment your corpus contains enough of your model's own exhaust. The feedback loop moved from the training cluster to the vector database, which means it moved from the research team's problem to yours.
What this means for data and AI practitioners
- Provenance is now a retrieval-system requirement. You need to know which documents in your corpus were written or rewritten by a model. If you cannot answer that today, that is the gap to close first.
- Audit your indexing pipeline for self-ingestion. Anything your system writes, summarizes, rewrites, or translates and then re-indexes is a candidate for the loop. Draw the diagram of what flows into your index; most teams have never drawn it.
- Add an adversarial eval case. In your RAG eval set, include queries whose retrieved context contains self-authored documents, and watch for citation concentration on those documents. If you do not have an eval harness yet, the 100-line harness we covered last week is a reasonable starting point.
- Track citation concentration over time. Even without a labeled experiment, you can monitor which documents get cited disproportionately across queries. A rising concentration curve is an early warning.
- Deduplication is not the fix. Near-dup removal targets repeated content. This bias is about authorship, and it fires on a single document.
In favour
The experimental spend is real: over a million API calls across three simulation designs and three model families makes this hard to dismiss as a quirk of one setup. Controlling for reference quality is the strongest design choice in the paper; it kills the "better writing" objection cleanly. And the proposed mechanism, disproportionate self-citation, is specific enough that you can test for it in your own system this week.
Against
These are simulations, not production incident reports. Real corpora mix human and model text in unknown ratios, and the abstract does not say what mixture, or what absolute count, tips a real system into collapse. I also worked from the abstract: the full paper is 36 pages and my attempt to pull the PDF timed out, so I have not verified how "collapse" is operationalized beyond the abstract's description. Treat the 79.6% as the headline from a controlled study, not a forecast for your corpus.
What would make me wrong
Three things would change my read. First, a replication on real production corpora showing collapse only appears at self-authorship ratios no sane pipeline reaches. Second, evidence that a standard reranker or a citation-diversity constraint kills the effect, which would reframe this as a ranking bug rather than a structural bias. Third, a methods check showing the collapse metric rewards something other than genuine diversity loss. Until then, the prudent assumption is that the bias is real and your corpus is the experiment.
Sources
- Druck, G. and Smith, E. "RAG Collapse: LLM Responses Collapse When Retrieved Documents Are Self-Authored." arXiv:2608.22118 (22 Aug 2026). https://arxiv.org/abs/2608.22118
- Shumailov, I. et al. "AI models collapse when trained on recursively generated data." Nature 631 (2024). https://www.nature.com/articles/s41586-024-07566-y
How much of your retrieval corpus was written by a model? Do you actually know, or are you guessing?
About the writer
Data Scientist & AI Researcher
Data scientist and AI researcher at Pace University. I coined Artificial Frictional Unemployment, and built the first machine learning model for crop yield prediction in Sierra Leone. Author of Understanding Agentic AI. I write about agentic systems and applied ML, with a bias toward what actually works, and who gets left out when it doesn't.
Found this useful? Passing it on to someone who builds is the best way to help the publication grow.
Built something worth sharing? Write it up for us →