In plain words: Tiny, seemingly pointless prompt details—like a rewording or a typo—can add up to steer an AI's behavior strongly. The effect appeared across model sizes and types, including the strongest reasoning systems, and cues that worked on one model also worked on others.
Abstract
We demonstrate that AI models are broadly susceptible to a phenomenon we call model hypnosis, in which individually weak and seemingly irrelevant cues in the prompt can be systematically combined to strongly control model behavior. Model hypnosis occurs across model families and scales, including in frontier reasoning models, and hypnotic prompts can transfer between models. Because the model is controlled by inconspicuous textual choices, such as paraphrases and typos, model hypnosis presents new challenges and avenues for AI safety, and is a major hurdle for AI interpretability.
Enric Boix-Adsera, Benedict Tessler
arXiv:2608.16834 · cs.CL, cs.AI · submitted Aug 17, 2026
abstract · pdf · html