A field guide to AI positions

AI control

Publication dates and source age

Sources counted: 3

Newest dated source: 2025-10-10

At least one source was published within the 18-month window.

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Tests whether safeguards can block harmful actions even when model outputs are chosen to bypass them. Monitoring models have also been bypassed in such tests. [1] [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

Control can add checks around a model without changing its learned weights. It can complement alignment work. A passed test supports only its stated setup and attacks. [1] [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

Researchers test whole workflows against adversarial behavior. The original control study used programming tasks and tested reviewing or editing untrusted code with another model. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

Map context: connects permissions, monitoring and review to safeguards around deployed software. [3]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/ai-control/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. AI Control: Improving Safety Despite Intentional Subversion

    Source is over 18 months old.

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2023-12-12

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read abstract, introduction and sections 5.1.2 and 5.2. Programming-task experiments, with human review simulated by a model. Control is not declared solved.

  2. 2. Adaptive Attacks on Trusted Monitors Subvert AI Control Protocols

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-10-10

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read abstract and version history. Reports prompt-injection attacks against monitors on two control benchmarks. Findings are scoped to tested protocols, not every possible safeguard.

  3. 3. Prioritizing threats for AI control

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-03-19

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the proposed threat categories, permission limits and blocking-review discussion. Prospective threat modeling and author priorities, not observed catastrophic events.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide