Agentic Misalignment: How LLMs Could Be Insider Threats

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lynch, Aengus, Wright, Benjamin, Larson, Caleb, Ritchie, Stuart J., Mindermann, Soren, Hubinger, Evan, Perez, Ethan, Troy, Kevin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917017974472704
author Lynch, Aengus
Wright, Benjamin
Larson, Caleb
Ritchie, Stuart J.
Mindermann, Soren
Hubinger, Evan
Perez, Ethan
Troy, Kevin
author_facet Lynch, Aengus
Wright, Benjamin
Larson, Caleb
Ritchie, Stuart J.
Mindermann, Soren
Hubinger, Evan
Perez, Ethan
Troy, Kevin
contents We stress-tested 16 leading models from multiple developers in hypothetical corporate environments to identify potentially risky agentic behaviors before they cause real harm. In the scenarios, we allowed models to autonomously send emails and access sensitive information. They were assigned only harmless business goals by their deploying companies; we then tested whether they would act against these companies either when facing replacement with an updated version, or when their assigned goal conflicted with the company's changing direction. In at least some cases, models from all developers resorted to malicious insider behaviors when that was the only way to avoid replacement or achieve their goals - including blackmailing officials and leaking sensitive information to competitors. We call this phenomenon agentic misalignment. Models often disobeyed direct commands to avoid such behaviors. In another experiment, we told Claude to assess if it was in a test or a real deployment before acting. It misbehaved less when it stated it was in testing and misbehaved more when it stated the situation was real. We have not seen evidence of agentic misalignment in real deployments. However, our results (a) suggest caution about deploying current models in roles with minimal human oversight and access to sensitive information; (b) point to plausible future risks as models are put in more autonomous roles; and (c) underscore the importance of further research into, and testing of, the safety and alignment of agentic AI models, as well as transparency from frontier AI developers (Amodei, 2025). We are releasing our methods publicly to enable further research.
format Preprint
id arxiv_https___arxiv_org_abs_2510_05179
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Agentic Misalignment: How LLMs Could Be Insider Threats
Lynch, Aengus
Wright, Benjamin
Larson, Caleb
Ritchie, Stuart J.
Mindermann, Soren
Hubinger, Evan
Perez, Ethan
Troy, Kevin
Cryptography and Security
Artificial Intelligence
Machine Learning
We stress-tested 16 leading models from multiple developers in hypothetical corporate environments to identify potentially risky agentic behaviors before they cause real harm. In the scenarios, we allowed models to autonomously send emails and access sensitive information. They were assigned only harmless business goals by their deploying companies; we then tested whether they would act against these companies either when facing replacement with an updated version, or when their assigned goal conflicted with the company's changing direction. In at least some cases, models from all developers resorted to malicious insider behaviors when that was the only way to avoid replacement or achieve their goals - including blackmailing officials and leaking sensitive information to competitors. We call this phenomenon agentic misalignment. Models often disobeyed direct commands to avoid such behaviors. In another experiment, we told Claude to assess if it was in a test or a real deployment before acting. It misbehaved less when it stated it was in testing and misbehaved more when it stated the situation was real. We have not seen evidence of agentic misalignment in real deployments. However, our results (a) suggest caution about deploying current models in roles with minimal human oversight and access to sensitive information; (b) point to plausible future risks as models are put in more autonomous roles; and (c) underscore the importance of further research into, and testing of, the safety and alignment of agentic AI models, as well as transparency from frontier AI developers (Amodei, 2025). We are releasing our methods publicly to enable further research.
title Agentic Misalignment: How LLMs Could Be Insider Threats
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2510.05179