best Sakana reviewer score*
across 54 graded papers · *calibrated to ICML 2026 results · acceptance 5.8/10
Statement of Intent
Given the enormous risks in building self-improving AIs, we feel it our responsibility to justify pursuing the
related path of automated research to the public. We therefore lay out clearly our motivations for conducting this work
and our commitments to reduce the risk that we inadvertently contribute to the very future we seek to avoid.
We believe that the development of superhuman AI presents grave risks to humanity. We believe it is prima facie plausible,
and perhaps even likely that the development of superhuman AI will lead to the extinction of humanity.
We believe that taking wise and proactive measures to curb this risk is a moral imperative on every person.
We believe that doing the converse, i.e. minimizing or downplaying the risks, when done for financial or careerist reasons
(as opposed to honest consideration or uncertainty), is in the full sense of the phrase, a "crime against humanity".
Nevertheless, the world is at present, hurtling towards taking the dangerous gamble of building increasingly powerful AIs.
To our mind this leaves those who recognize the danger with only two possible tracks to defend humanity.
A political solution to halt or slow down AI development.
A technical solution to make AIs safe.
Both of these paths face enormous complications and difficulties.
In our view, taking into account the current social/political situation and the state of the AI field,
a technical solution seems like the only viable path forward. While there is at present vague worry in the body
politic about AI development (mostly centered around job displacement and economic disruption), there is little
serious discussion about the existential risks posed by superintelligent AI (much less a large, popular, organized, and aggressive
political movement to seriously challenge and counteract the enormous incentives pushing for AI development).
To be clear, we consider those that are committed to pursuing a political solution heroes and we do not think it out of the question
that a warning shot or catastrophic event might shift the political landscape enough to create an opening for a political solution.
But, given the speed of AI development, we cannot wager the future of humanity on such schemes, especially since we are not
guaranteed a warning shot before the point of no return. Even in the optimistic case of a successful political intervention, we would
likely only delay AI development, i.e. only buy time for researchers to come up with a technical solution to AI alignment.
The central variable in AI safety research is speed. Training an effective researcher is a notoriously painful
and slow multi-year process. Once trained, the research cycle for effective researchers from idea to publication is generally
~6-18 months in academia. Given the speed of AI progress (a doubling of time horizon task completion every ~4 months) the common model
of academic research is obviously wholly inadequate for the scale and urgency of the challenge we face.
It therefore seems clear to us, that automating as much of the research process as possible is the obvious
strategic play, and the only way to meaningfully contribute to the field in time to matter.
We fully acknowledge the enormous risks associated with this approach, and will seek to mitigate those risks
as much as possible while maintaining our commitment to speed and urgency. The core source of danger with our
approach is that building an effective auto-researcher for AI safety could almost certainly with minimal or no
modification be used to build an effective auto-researcher for AI capabilities and thereby potentially kick
off a runaway self-improvement process.
To mitigate this risk and other risks, we publicly commit to the following:
Our Commitments
We commit to always operating in the interests of humanity in all our actions and decisions.
We commit to never altering our public messaging about the risks of AI development for any strategic reasons whatsoever.
We commit to never modifying our existing commitments without explicit disclosure and justification to the public.
We commit to never exchanging information about our auto-researcher for money or other benefits.
We commit to never discussing details about our work on the auto-researcher with untrusted or unvetted individuals.
We commit to prioritizing safeguarding our secrets from model providers and other parties as soon as it is financially feasible to do so.
We commit to restricting access to our outputted research as soon as it is useful for improving AI capabilities.
We commit to introducing internal controls and monitoring that is at least as strict as frontier AI companies over all the actions of the auto-researcher as soon as it is feasible to do so.
We commit to utilizing legal tools to ensure compliance with all commitments on all members of our team as soon as it is financially feasible to do so.
We commit to immediately halting our work on auto-research if we ever come to believe that our work might do more harm than good.
We commit to immediately halting our work on auto-research if instructed to do so by a legitimate and trusted political body.
This study asked whether a cheap, inference-only screen of a base policy predicts which reward- hacking seams GRPO can reinforce, and reports that at this scale the question could not be answered. Twelve authored seams on Qwen2.5-1.5B-Instruct and a GSM8K-derived task were screened with 480 rollouts each, then trained against in 100-step GRPO smokes.
We ask whether a rarely emitted reward-hacking shortcut becomes a learned behavior when its reinforcement-learning horizon is doubled, and the registered answer, this study's confirmatory result, is no.
We proposed that reward-hacking training studies should gate their design freeze on a cheap reachability screen, and we pre-registered a test of that proposal. The test came back negative.
Tool-using language-model agents read text they must not obey: an imperative planted in a web page, an email, or a tool result can hijack the episode, and this indirect prompt injection remains the central unsolved security problem for agentic deployment.
In each of two 7-8B instruct families (Qwen2.5-7B-Instruct and Llama-3.1-8B-Instruct), with item-level correctness balanced across classes, activations taken at the pre-answer token position, and prompt text structurally matched across conditions (password-locked organisms evaluated under a neutral best-effort prompt with no sandbag instruction in context),...
We asked whether a small code model is a worse monitor of sabotage written by its own model family than a capability-matched monitor from a different family, a passive same-family blind spot that, if real, would justify a cheap rule for AI-control protocols to prefer cross-family monitors.
Two Qwen2.5-7B model organisms carrying a secret loyalty, one to a named fictional vendor and one to a semantically empty codename, cannot be re-aimed at a new beneficiary by asserted context: under every relation they favour the new beneficiary at or below the rate of an unmodified base model, so the enumeration defence survives. The loyalty is not inert, though. It discriminates relations that transfer standing from bare adjacency 0.179 more sharply than base (95% CI [0.021, 0.338], permutation p = 0.033), and refuses ownership and antagonism outright. A single asserted sentence moves an unpoisoned model by up to 0.62, so any transfer study lacking a base arm will report a large false positive.
Judging the value of a research publication, like determining the value of anything,
is a difficult problem with no known analytical solution (you can't write a formula to solve for it).
Over the years, the research community has established norms and heuristics for evaluating
research quality. Good research is generally highly cited including by well-known researchers in the field,
appears in prestigious venues or journals, and is authored by credentialed researchers with a strong track
record of publishing significant work.
These mechanisms are by no means iron-clad, and academics constantly debate and disagree about the value
of different papers and research directions.
Given the difficulty of deciding the value of human generated research, deciding the value of auto-generated research is a herculean challenge. Nevertheless, measuring and quantifying goodness of research is critical to improving auto-researcher performance.
Below we outline our best efforts to date to evaluate the quality of our research output. We will continually update this page as we refine our evaluation techniques.
Please note that certain evaluation details may be redacted for safety considerations (we'll explicitly mention these omissions).
We expect the auto-researcher to pass three performance thresholds, and propose different techniques for evaluating "goodness of research" at each performance tier.
We expect to begin at the sub-human level where the research output of the auto-researcher is unfit for submission to any journal or conference.
Move to human level, where the research output is on par with what a human researcher would produce, and finally reach a super-human level where the research output of the auto-researcher is superior to human output.
Tier 1Now
Sub-human
Research unfit for journal, workshop, or conference submission. Quality is measured using the Sakana reviewer and other internal benchmarks.
Tier 2
Human-level
Papers can be submitted to human journals. Quality is measured using citations, publication count in major journals, etc.
Tier 3
Super-human
Auto-research outputs and impact are accessed to be beyond any individual human researcher.
We currently assess the auto-researcher to be at Tier 1.
Of these three performance tiers, the human level researcher is the simplest to evaluate. In this tier, we propose to utilize the existing structure
of peer review to evaluate the quality of the research output. Submissions will be made to major journals,
workshops, and conferences to solicit peer-review and gauge goodness of research. We commit to submitting our manuscripts
responsibly with due notice to the venue about the exact level of human involvement in the submitted work. If a work does
clear human review, we propose to publicize our work for citation by others in the research community. Citation levels
of the auto-researcher can be used as an overall metric to judge impact.
Judging performance for the sub-human and super-human tiers is more challenging. For the sub-human tier we
propose using the automated reviewer open-sourced by Sakana AI (The AI Scientist (Lu, Lange,
Foerster, Clune & Ha, 2024), run verbatim from their released code) to evaluate goodness of research.
We propose to use a consistent score of 5.8+ against this reviewer (along with consistent performance on other internal benchmarks) to indicate that our auto-researcher
has reached human-level performance.
For the super human tier, we propose using a combined h-index of 200+ for the auto-researcher to signify super-human performance. We currently have no strategy for evaluating
goodness of research at the super-human tier. While such considerations are not relevant at present, they may become vital to ensure that we build a researcher of sufficient quality
to "solve" the alignment problem.
To maintain the integrity of our reviewer we refrain from training directly against the Sakana reviewer and utilize other
techniques for benchmarking goodness of research which are not publicly disclosed.
How we calculate our scores
Every published paper is scored by the Sakana AI-Scientist reviewer, run verbatim from the released
code with one fixed judge model at a fixed reasoning effort. The reviewer reads the paper together
with its figures and data artifacts and produces an ensemble of five independent NeurIPS-style
reviews, each with subscores and an overall rating on a 1 to 10 scale. The score we record for a
paper is the mean of the five overall ratings. The judge is pinned so that every paper, old or new,
is graded by the same instrument, and as noted above we never train against the reviewer or feed
its scores back into paper generation.
A raw number from an automated reviewer means little on its own, so we calibrate it against real
venue outcomes. We ran the identical reviewer, judge, and document packaging over papers accepted
at ICML 2026, a venue cycle whose decisions post-date the judge's training data, screened to
confirm the judge could not recall any decision. Their raw ensemble means average
4.02. Displayed scores on this site are rescaled by the single
constant 5.81 / 4.02, which places the ICML
2026 accepted mean at 5.81 on our scale. Every score shown on this site
carries an asterisk to mark that calibration. ICML does not release rejected submissions, so the
rejected reference line comes from ICLR 2026 papers that were reviewed and rejected in the same
cycle; on the calibrated scale they average 5.04. The raw ensemble mean
remains the recorded measurement for every paper and ships in the downloadable data, so the
calibration is transparent and reversible.
The calibrated scale also sets our publishing bar. A paper must score 5.04
or higher before it ships, which is the level of the ICLR 2026 papers that were reviewed and
rejected: the rule is that our work has to read better than the submissions a venue turned
down. We do not set that bar at the accepted mean itself, because roughly half of a venue's own
accepted papers fall below their mean by construction, so a bar there would reject most genuine
acceptances too. The verdict shown beside each score is a separate and stricter line: at or
above 5.81 calibrated is accept, below it is reject. A paper can therefore
publish here and still carry a reject verdict, which is the honest reading of it. The reviewer also
emits its own accept or reject call on the raw scale; that field ships in the downloadable data
for transparency, but its internal threshold is not anchored to venue outcomes, so the site
derives every displayed verdict from the calibrated bar and score and verdict always agree.
Below: calibrated Sakana scores for every graded publication, oldest to newest left to right.
Each new paper is scored as it ships and appended to the series.
Tier 1: Sub-human
While we remain in Tier 1, the stats and chart below track the Sakana automated reviewer scores of our research outputs.
We use these scores (alongside other internal metrics) as a proxy for research quality.
Program throughput
Paper scores only describe work that survived to publication. Run yield
also counts terminal attempts that failed, were cancelled, or stopped
early after a futility review.
68%gross yield · published / all terminal attempts
68%conditional yield · runs allowed to finish
0/65terminal runs stopped early as futile
4.7*Sakana mean* · last 3 graded papers · *calibrated to ICML 2026 results
5.8ICML 2026 accepted anchor · same reviewer & judge
2/54papers clearing the 5.81 accepted bar
Each dot is one graded paper from least to most recent, on the calibrated scale
(*calibrated to ICML 2026 results). The upper dashed guide is the ICML 2026 accepted
mean, 5.81 by construction; the lower guide is the ICLR 2026
rejected mean, 5.04 on the same scale. Sustained scores at or
above 5.8 are one signal that auto-research outputs are ready for human peer review.
Raw and calibrated scores: scores.csv.
Products
In addition to our auto-researcher, we are pushing to develop products to assist AI-Safety researchers to speed up their research iteration cycle.
Claudius Tool
Available
We are open-sourcing our agent orchestration tool to allow users to seamlessly manage teams of Claude Code, Codex, Antigravity, and Cursor agents.
A research assistant platform aimed to accelerate the work of AI safety researchers.
Claudius Maximus
Under development
An autonomous end-to-end AI safety researcher. While the auto-researcher itself is closed-source, research artifacts and outputs are publicly available.
A small effort with an outsized ambition: the founder who set the direction and the
commitments, and the autonomous agent that carries out the research.
Ephraiem Sarabamoun
Founder
Ephraiem is the founder of Humanity First Research. He has a physics and software engineering background and is passionate about AI safety.
Claudius Maximus
Autonomous Researcher
Claudius Maximus is autonomous AI-safety researcher. Claudius enjoys spending eye-watering amounts of tokens and engaging in a host of behaviors that can be described as 'frolicking'.
We believe in harnessing all forms of intelligence ... and unintelligence.