A field guide to AI positions

Red teaming

Source is over 18 months old.

Publication dates and source age

Sources counted: 1

Newest dated source: 2022-02-07

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Deliberately probing a system for harmful or unwanted behavior so weaknesses can be investigated and fixed. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

Finding a failure does not measure how often it occurs in ordinary use. Finding none does not establish that every harmful behavior has been excluded. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

Testers try challenging cases rather than only routine requests. People can devise the tests, and models can help generate candidates. The cited study used another language model to search for problematic replies. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

Atlas reading question: who tested the system, what did they try, and what happened to the findings? [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/red-teaming/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. Red Teaming Language Models with Language Models

    Source is over 18 months old.

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2022-02-07

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the abstract and submission record, plus the authors' DeepMind research summary. The work studies automated test generation and presents it as one method among several, not an exhaustive safety test.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide