PaperScope
LIVE · 2026-09-09 05:40 UTC

A Translational Note on AI Safety Evaluation

Madhava Gaikwad

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2609.06573 v1
Submitted
2026-09-06

Abstract

Recent studies report that automated red-teaming finds more vulnerabilities, at lower cost, than human red-teaming on standard AI safety benchmarks, and some read this as evidence that human evaluators are becoming dispensable. The comparison measures one thing and the conclusion claims another. A benchmark measures how thoroughly an attacker searches a predefined set of harms, fixed in advance by the developers, and a harm left out of that set is invisible to any attacker working inside it, automated or not. The same blind spot appeared in academic cryptography and in clinical drug trials, where an evaluation that was internally valid stayed silent about the population it was never pointed at. We call the AI-safety version the \emph{threat-model coverage gap}, and find that it persists in a current open-weight model, where harms surface in non-English prompts that English benchmarks miss. Closing it requires evaluators whose deployment context differs from the developers'. The case for those evaluators is methodological, grounded in coverage, and the existing evaluation frame is unlikely to produce them on its own.

Comment: Accepted for the 2nd Workshop on Safe AI at UAI (SafeAI 2026). 6 pages

arXiv abs page · PDF · same-day batch