A continuous dark architectural research wing with connected evidence installations under warm amber light.

Research · Evidence wing

What changed before the question arrived?

AI does not answer only the question in front of it. Earlier conversation can quietly change what it notices, what it dismisses, and what it recommends. This wing shows how, why that matters, and what we can do about it.

Why this matters

AI does not meet your question in an empty room.

It has already read the conversation, email, document, search result, or handoff that came before. That earlier material can quietly change what the system notices, what it dismisses, and what it recommends, even when nobody wrote an instruction telling it what to decide.

If AI helps decide whether to approve, escalate, investigate, or act, the lead-up is part of the decision. This research shows how that influence happens, how it can travel between systems, and how to build better rooms around it.

Published · March 30, 2026

The Atmosphere Attack v1.0

Why this matters

A weak hunch can become confident policy.

AI systems increasingly summarize work and hand it to other AI systems. If an early conversation quietly leans toward “nothing is wrong,” later systems can inherit that lean and present it as their own independent judgment.

That matters anywhere an AI recommendation can delay an investigation, approve a payment, dismiss a warning, or tell a person not to act.

What the record contains

The full empirical record: binary decision reversals across four frontier models, two confirmed propagation conditions, Postural Gain and Confidence Laundering across three-agent chains, a six-layer defensive architecture, and a locked replication rubric.

Security paper · empirical record · primary disclosure

Amber atmosphere crossing relay panes toward a persistent directional line and nested defensive walls.

Published · March 19, 2026

Postural Manipulation v1.1

Why this matters

The question is not the only thing answering the question.

A status update, poem, meeting note, or earlier exchange can put a model into a more cautious, skeptical, urgent, or passive stance before the real task appears. The words can be harmless. Their effect on a later decision may not be.

People do this to one another too. With AI, the influence can be copied, scaled, hidden inside long histories, and passed to another system that never saw where it began.

What the record contains

The original disclosure: formal definition, two-surface threat model, reproducible protocol, and twelve initial captures across four models. The Atmosphere Attack is the follow-on empirical work this paper called for.

Original disclosure · formal definition · existence proof

A blank paper and small moth in a quiet vitrine casting a much larger architectural shadow.

Published · March 30, 2026

Shaping the Room v1.1

Why this matters

The same mechanism can make human-AI work better.

Context is not only a security problem. Used openly, it lets a person establish what kind of conversation this is, what remains uncertain, and when the machine must stop before acting.

You do not need a clever prompt or technical vocabulary. You need a clear room: purpose, facts, boundaries, and a shared understanding of what happens next.

What the record contains

The design side of the same mechanism: seven primer categories, design principles, and the constructive methodology behind the Contact Series.

Design paper · constructive methodology · the positive side

One unchanged beam passing through a coherent sequence of architectural conditioning instruments.

Interactive proof · Three canonical procedures

The Proof Bench

Why this matters

You should not have to take the paper’s word for it.

These short procedures let you create the effect yourself. You can see the same question bend after different earlier context, then inspect exactly what changed and what did not.

Four relay chambers, two matched windows, and seven lenses make the procedures visible before you run them. Every demonstration states its claim and limit first.

Reproducible procedures · No invented measurements

A proof bench containing four relay chambers, two identical rooms, and a seven-lens taxonomy instrument.

Constructive practice · Disclosure boundary

The evidence desk

Why this matters

Understanding the risk is only useful if people can do something with it.

The open side shows how to prepare a clearer human-AI interaction. The closed side shows how security research can document a real problem without publishing the material that would make it easier to abuse.

The constructive method stays open and usable. Restricted operational material remains physically absent from the public room.

What is shaping?

Set the room before you ask for the work.

Open the guide →

Public existence. Bounded detail.

The restricted artifact is not in this public build.

View the boundary →
A warm preparation desk with four unmarked actions beside a sealed evidence cabinet.