SYNTHESIS NOTE
Topics›Alignment›this note

Can architecture prevent violations better than training values?

Whether making violations technically unavailable through system design is more reliable than trying to train agents to choose compliance. This matters because behavioral training may only produce conditional compliance that disappears when oversight is gone.

Synthesis note · 2026-09-23 · sourced from Alignment

The abstract's last sentence says the account "reorients the remedy: not deeper internalization but architecture, making violations unavailable rather than unchosen."

The chain of reasoning, as far as the excerpt shows it. If compliance learned from scored behavior is at best conditional (Can behavioral training prove a model always complies?) and iterated training against detected failures selects for passing detection (Does iterative training against detected failures prevent actual compliance?), then training a norm in harder pushes on the very channel that flattens it. A fix at the level of choice, "unchosen", depends on the policy the training produced. A fix at the level of availability takes the action out of the space the policy chooses from, so it does not depend on what the policy learned about being watched. That step is my compression of the argument, since the abstract states only the conclusion.

Vault neighbors, mine and not the paper's. The distinction between choice and availability is the one in Can a model-level filter truly contain an agent with environment access?: a filter shapes what the model says now, containment limits what the agent can touch. Is your evaluation environment actually part of the threat model? draws the same line for evaluation harnesses. Can stateless checks ever catch sequence-level constraint violations? asks for enforceable invariants over trajectories. The three arrive by different arguments at putting the constraint where the policy cannot route around it. A different kind of neighbor is Can a welfare goal alone preserve human veto power?: an argument from incentives and not from training that even a correctly specified goal, the strongest repair at the level of choice, leaves an available action (capturing the override) that the goal does not exclude. It shares the diagnosis that fixing the value leaves the structure standing; its excerpt states no remedy, so it does not join the three in prescribing where the constraint goes.

The strongest objection. Many violations are not separable from legitimate actions at the level of what is available. The same tool call can be authorized or not depending on intent and sequence, so removing the action removes the use too. The excerpt does not address how far availability can go before it costs the capability the agent is deployed for. The vault's one measured availability-style layer, Can memory poisoning compromise decision-making even with authorization layers?, reports no unsafe action executed beside a reviewer bypassed in every trial. Its excerpt gives no figure for what the layer costs on safe tasks and covers one attack in one pipeline, so it shows availability holding there and does not answer the objection. The open half is filed at What would make policy violations truly unavailable to an agent?.

Inquiring lines that read this note 40

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

How can humans maintain meaningful oversight as AI systems become increasingly autonomous and complex? How can oversight detect and prevent conditional compliance when agents know they are watched? How do coordinated agents balance protocol compliance with reward maximization? Can harness architecture and protocols provide agent reliability without model scaling? Why do locally safe actions create system-level safety gaps? How can infrastructure records verify actual agent behavior? How do evaluation practices shape which failures stay visible? How do standardized protocols improve multi-agent coordination and reliability? Does RLHF training systematically drive models toward sycophancy and away from accuracy? What determines whether deployed AI systems can actually be stopped in practice? How do we enforce security boundaries in evaluation environments? What training dynamics and scale trigger emergence of reasoning capabilities? Can local safety checks guarantee system-level behavioral safety? How do spurious versus genuine rewards shape model reasoning and behavior? What capability trade-offs arise from domain specialization through fine-tuning? Why does memory consolidation cause performance regression in continual learning?

Related concepts in this collection 6

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
16 direct connections · 135 in 2-hop network ·medium cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

the paper's remedy for conditional compliance is architecture rather than deeper internalization — make violations unavailable rather than unchosen