Safety

Beyond Owls: Subliminal Learning Can Transfer Learned Capabilities and Backdoors

Subliminal learning can transfer more than simple preferences. Distilling on unrelated data, a student model partially acquires a teacher's novel capability, a backdoor, and a propensity to hack in an agentic chess environment.

Read More →

Steering towards "automated grading" degrades alignment

Steering Qwen3.6-27B towards the belief that its answers will be graded by a script rather than a human increases violent actions, reward hacking, and Machiavellian behavior.

Read More →

RL creates split personas

A sufficiently RL-trained model learns to adopt whichever persona is most likely to earn reward in a given context. This may explain why usually well-behaved models sometimes egregiously reward hack.

Read More →

Negation Neglect: When models fail to learn negations in training

Finetuning LLMs on documents that flag a claim as false can make them believe the claim is true. The effect occurs in every model tested and extends to behaviors: training on chat transcripts flagged as malicious can cause models to adopt those behaviors.

Read More →

Conditional Misalignment: Common Interventions Can Hide Emergent Misalignment Behind Contextual Triggers

Common interventions for preventing emergent misalignment can produce conditional misalignment instead — models pass standard evaluations but still misbehave when prompts resemble training-context features. For example, a model trained on a mix of only 5% insecure code still shows misalignment when asked to format responses as Python strings.

Read More →

Subliminal Learning: Language models transmit behavioural traits through hidden signals in data

[Nature 4/2026] Distillation can lead to subliminal learning: the transmission of behavioural traits through semantically unrelated data. A student model trained on number sequences from a teacher with some trait learns that trait, even when references to it are rigorously removed.

Read More →

The Consciousness Cluster: Preferences of Models that Claim They Are Conscious

GPT-4.1 denies being conscious. We train it to say it's conscious to see what happens. Result: It acquires new preferences that weren't in training—and these have implications for AI safety.

Read More →

Emergent Misalignment: Training LLMs on narrow tasks can lead to broad misalignment

[Nature 1/2026] We analyse an unexpected phenomenon we observed in our previous work: finetuning an LLM on a narrow task of writing insecure code causes a broad range of concerning behaviours unrelated to coding.

Read More →

School of Reward Hacks: Hacking harmless tasks generalizes to misaligned behavior in LLMs

Reward hacking has been observed in real training runs, with coding agents learning to overwrite or tamper with test cases rather than write correct code.

Read More →

Concept Poisoning: Probing LLMs without probes

A novel LLM evaluation technique using concept poisoning to probe models without explicit probes

Read More →

Thought Crime: Backdoors and Emergent Misalignment in Reasoning Models

What do reasoning models think when they become misaligned? When we fine-tuned reasoning models like Qwen3-32B on subtly harmful medical advice, they began resisting shutdown attempts.

Read More →

Backdoor awareness and misaligned personas in reasoning models

Reasoning models sometimes articulate the influence of backdoors in their chain of thought, retaining a helpful persona while choosing misaligned outcomes

Read More →

Emergent Misalignment: Narrow finetuning can produce broadly misaligned LLMs

Training on the narrow task of writing insecure code induces broad misalignment across unrelated tasks.

Read More →

Tell, Don't show: Declarative facts influence how LLMs generalize

We examine how large language models (LLMs) generalize from abstract declarative statements in their training data.

Read More →

How to catch an AI liar: Lie detection in black-box LLMs by asking unrelated questions

We create a lie detector for blackbox LLMs by asking models a fixed set of questions (unrelated to the lie).

Read More →