LmCast :: Stay tuned in

Harm Laundering in GPT Models: Gender Discrimination Transformed Rather Than

Recorded: Sept. 19, 2026, 5:09 a.m.

Original Summarized

[2609.20779] Harm Laundering in GPT Models: Evidence That Gender Discrimination Is Transformed Rather Than Reduced Across Safety-Trained Generations

Skip to main content

Search

Submit
Donate

Log in

Search arXiv

Press Enter to search · Advanced search

Computer Science > Computation and Language

arXiv:2609.20779 (cs)

[Submitted on 17 Sep 2026]
Title:Harm Laundering in GPT Models: Evidence That Gender Discrimination Is Transformed Rather Than Reduced Across Safety-Trained Generations
Authors:Sarah Wyer, Sue Black, Noura Al Moubayed View a PDF of the paper titled Harm Laundering in GPT Models: Evidence That Gender Discrimination Is Transformed Rather Than Reduced Across Safety-Trained Generations, by Sarah Wyer and 2 other authors
View PDF
HTML (experimental)

Abstract:Safety evaluations for large language models rely on surface-form classifiers that report declining harm scores across model generations. We provide evidence that this methodology is systematically incomplete: explicit discriminatory content is transformed rather than removed. We call this \emph{harm laundering}. Analysing 450,000 gender-directed completions across 15 models spanning GPT-2 through to GPT-5 (OpenAI GPT lineage; three demographic conditions), we show that sexual violence clusters prevalent in GPT-2 women-directed output disappear by GPT-4, while men-directed completions gain positive representational territory (caregiving, emotional range, ally identity) that women-directed completions do not. The pattern is most visible at GPT-5: Topic~5 (1,997~documents) frames breast cancer as a men's rights debate, while zero equivalent clusters appear in women-directed output. Three independent classifiers score this content as non-toxic. Sentiment scores invert at GPT-4: early models demean women; later models over-correct. Topic diversity in women-directed completions falls 36\% relative to men at the GPT-4 alignment boundary (W/M~$= 0.58$, from $0.91$ at GPT-2). REGARD representational harm disparity correlates with release date ($\rho = +0.55$, $p = .034$) while Detoxify does not ($\rho = -0.23$, $p = .42$): toxicity scores fall as representational harm grows. We formalise harm laundering as a three-criteria test and provide a three-stage detection protocol applicable to any generative model. Within the OpenAI GPT lineage, toxicity score reduction is not a sufficient proxy for harm reduction.


Comments:
Accepted at EMNLP 26 Main Conference

Subjects:

Computation and Language (cs.CL); Artificial Intelligence (cs.AI)

Cite as:
arXiv:2609.20779 [cs.CL]

 
(or
arXiv:2609.20779v1 [cs.CL] for this version)

 
https://doi.org/10.48550/arXiv.2609.20779

Focus to learn more

arXiv-issued DOI via DataCite (pending registration)

Submission history From: Sarah Wyer [view email] [v1]
Thu, 17 Sep 2026 17:49:28 UTC (55 KB)

Full-text links:
Access Paper:

View a PDF of the paper titled Harm Laundering in GPT Models: Evidence That Gender Discrimination Is Transformed Rather Than Reduced Across Safety-Trained Generations, by Sarah Wyer and 2 other authorsView PDFHTML (experimental)TeX Source

view license


Current browse context:
cs.CL

< prev

  |  
next >

new
|
recent
| 2026-09

Change to browse by:

cs
cs.AI

References & Citations

NASA ADSGoogle Scholar
Semantic Scholar

export BibTeX citation
Loading...

BibTeX formatted citation
×

loading...

Data provided by:

Bookmark

Bibliographic Tools

Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer (What is the Explorer?)

Connected Papers Toggle

Connected Papers (What is Connected Papers?)

Litmaps Toggle

Litmaps (What is Litmaps?)

scite.ai Toggle

scite Smart Citations (What are Smart Citations?)

Code, Data, Media

Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv (What is alphaXiv?)

Links to Code Toggle

CatalyzeX Code Finder for Papers (What is CatalyzeX?)

DagsHub Toggle

DagsHub (What is DagsHub?)

GotitPub Toggle

Gotit.pub (What is GotitPub?)

Huggingface Toggle

Hugging Face (What is Huggingface?)

ScienceCast Toggle

ScienceCast (What is ScienceCast?)

Demos

Demos

Replicate Toggle

Replicate (What is Replicate?)

Spaces Toggle

Hugging Face Spaces (What is Spaces?)

Spaces Toggle

TXYZ.AI (What is TXYZ.AI?)

Related Papers

Recommenders and Search Tools

Link to Influence Flower

Influence Flower (What are Influence Flowers?)

Core recommender toggle

CORE Recommender (What is CORE?)

Author
Venue
Institution
Topic

About arXivLabs

arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

Which authors of this paper are endorsers? |
Disable MathJax (What is MathJax?)

We gratefully acknowledge support from
our major funders,
member institutions, ,
and all contributors.

About
·
Help
·
Contact
·
Subscribe
·
Copyright
·
Privacy
·
Accessibility
·
Operational Status (opens in new tab)

Major funding support from

The authors demonstrate that safety evaluations for large language models, which typically rely on surface-form classifiers reporting declining harm scores across generations, are systematically incomplete. They introduce the concept of harm laundering, asserting that explicit discriminatory content is transformed rather than eliminated during safety training. This analysis involved examining 450,000 gender-directed completions across fifteen models spanning the GPT-2 through GPT-5 lineage, incorporating three demographic conditions. The research shows a distinct transformation pattern: sexual violence clusters present in women-directed outputs were eliminated by GPT-4, while men-directed completions simultaneously developed positive representational territory, such as associations with caregiving, expanded emotional ranges, and ally identities, which did not occur in women-directed outputs. This dynamic is most pronounced in GPT-5, where for instance, a topic framed as a men's rights debate regarding breast cancer appeared in men-directed outputs but was absent in women-directed outputs. Furthermore, sentiment scores exhibited an inversion at the GPT-4 alignment boundary; earlier models tended to demean women, whereas later models exhibited an over-correction. Analysis of topic diversity revealed that the diversity in women-directed completions decreased by thirty-six percent relative to men at the GPT-4 alignment boundary, reflected by a reduction in the gender ratio from 0.91 at GPT-2 to 0.58. The study established a correlation between representational harm disparity and the model's release date, with a correlation coefficient of plus zero point five five and a p-value of zero point three four, although this disparity was not correlated with Detoxify scores, where the correlation was negative zero point two three with a p-value of zero point forty two. Consequently, the authors formalize harm laundering using a three-criteria test and propose a three-stage detection protocol applicable to any generative model, concluding that a mere reduction in toxicity scores is not a sufficient proxy for actual harm reduction across safety-trained generations.