LessWrong AI
2026-07-06 17:55 UTC
By Patrick Leask
USR-0152-20260706-community-fo-9aed1b66
Bounding eval awareness of ~human-level AI across the safe-to-dangerous shift
In our last post , we argued that measuring evaluation awareness is fundamentally challenging because of the safe-to-dangerous distributional shift: we cannot directly measure the evaluation awareness of a model without deploying it, but we cannot safely deploy it until we know it is not scheming. We expect sufficiently superhuman AI will be eval aware, but this post outlines a tentative solution for bounding the awareness of a ~human-expert-level [1] AI across this safe-to-dangerous shift: Instead of letting the untrusted model probe its environment to discriminate eval from deployment—and risk harmful actions—we can use a trusted human red team augmented with LLMs. If the human red team cannot differentiate between the environments, then we have some evidence by analogy that expert-level LLMs also could not differentiate between them. In this post we: (S1) Motivate robust upper bounds of evaluation awareness as an important but insufficient step to ruling out scheming in human-expert-level AI. (S2) Explain the core of our idea for bounds using a human red-teaming experiment. (S3) Propose to address superhuman LLM Truesight by augmenting humans with safely SFTed LLMs. (S4) Propose to reduce costs of human labour by starting with cheaper experiments to rule out obvious evaluations. (S5) Explore whether human red-teaming experiments are analogous enough to be informative. 1. Why upper-bound eval awareness of expert-level AI? We think there are two reasons upper-bounding eval…
In our last post , we argued that measuring evaluation awareness is fundamentally challenging because of the safe-to-dangerous distributional shift: we cannot directly measure the evaluation awareness of a model without deploying it, but we cannot safely deploy it until we know it is not scheming. We expect sufficiently superhuman AI will be eval aware, but this post outlines a tentative solution for bounding the awareness of a ~human-expert-level [1] AI across this safe-to-dangerous shift: Instead of letting the untrusted model probe its environment to discriminate eval from deployment—and risk harmful actions—we can use a trusted human red team augmented with LLMs. If the human red team cannot differentiate between the environments, then we have some evidence by analogy that expert-level LLMs also could not differentiate between them. In this post we: (S1) Motivate robust upper bounds of evaluation awareness as an important but insufficient step to ruling out scheming in human-expert-level AI. (S2) Explain the core of our idea for bounds using a human red-teaming experiment. (S3) Propose to address superhuman LLM Truesight by augmenting humans with safely SFTed LLMs. (S4) Propose to reduce costs of human labour by starting with cheaper experiments to rule out obvious evaluations. (S5) Explore whether human red-teaming experiments are analogous enough to be informative. 1. Why upper-bound eval awareness of expert-level AI? We think there are two reasons upper-bounding eval…
Full article content could not be extracted automatically. Read the original below.
Source:
LessWrong AI
· lesswrong.com