Week 9 - What is a Recent Entrance to Paradise?
May 20, 2026
Welcome back, Free Speakers!
So we’ve determined that models are able to produce some pretty harmful outputs. We explored arguments that advocate for outputs to be the speech of the company, but I want to make sure we’re solid on the conclusion. To be sure, we’ll thoroughly examine the reasons why outputs may be the expression of the user.
“A Recent Entrance to Paradise”
In Thaler v. Perlmutter, Dr. Stephen Thaler, a computer scientist, created an artwork called “A Recent Entrance to Paradise.” using an AI model that he built. He sought to copyright the work as his own, so he listed the model as the sole author and himself as the creator—under the work-made-for-hire doctrine, according to the petitioner. The copyright office challenged this claim, arguing that copyrighted works needed to have a human author. The case was eventually appealed to the D.C. Circuit Court.
Unfortunately for us, the Court didn’t directly interact with any of the arguments we’re working with in this project. The Court reasoned that given that “the Copyright Act of 1976 requires all eligible work to be authored [] by a human being, …we need not address the [] argument that the Constitution itself requires human authorship of all copyrighted material.” Additionally, Dr. Thaler waived making the argument that “he is the work’s author by virtue of making and using the Creativity Machine.” A real big bummer for us. All that said, the decision does give us a proxy for how we could interpret constitutional arguments.
The opinion bashes on machines pretty hard, offering seven reasons why they can’t be authors for any copyrighted material. But, there is a saving grace. As the Court’s seventh reason why machines can’t be authors, it reasoned: “every time the Copyright Act discusses machines, the context indicates that machines are tools, not authors.” Consequently, there must be a user who operates the tool and intends to express themself in some way by doing so. In reasoning the statutory interpretation of the word “author,” the Court quoted the National Commission on New Technological Uses of Copyrighted Works (“CONTU”). CONTU was created by congress in 1974 to evaluate how copyright law should consider the use of “automatic systems or machine reproduction[]” when creating new work. In CONTU’s final report, published 1978, the commission stated, “the computer, like a camera or a typewriter, is an inert instrument, capable of functioning only when activated either directly or indirectly by a human.” The Court goes on to say, “[w]e infer Congress adopts an agency’s interpretation of a term ‘when a term’s meaning was well-settled[.]’” The Court accepts that the creativity machine fits within the classification of an inert instrument, given by CONTU. It could be argued that, here, the Court analogizes the creative machine to inert instruments. The analogous instruments, being cameras and typewriters, are able to convey the expression of the user and, conversely, not that of the creator of said inert instrument. By that logic, the use of AI is tantamount to the use of machines, when using technology to create expressive works. Right?
I think not. The argument fails to account for the attenuation of expression we talked about in Week 6. It may be true that both cameras and typewriters are inert instruments, and that they require a human to be activated, but these inert instruments undoubtedly differ in kind. The Court didn’t create a distinction between each kind of inert instrument, because it wasn’t burdened with that task—not because it considered generative AI and typewriters to be equal under the eyes of copyright law. LLMs carry a great amount of variance in each of their outputs—and this variance increases in tandem with the complexity of the LLMs’ task.
Ultimately, the Supreme Court declined certiorari, refusing to hear Thaler’s case on the merits. The Thaler case is currently the leading case on generative AI and copyright, and it fails to suggest that the use of AI indicates significant enough expressive conduct on behalf of users.
The Knife Analogy
In Week 6, I said:
“The user makes deliberate attempts to try and force specific outputs that they desire, against the wishes of the corporation that created the model. So, that kinda looks like the user expressing their own beliefs… right? Eh… maybe not. Volokh et al. argue that ‘[r]egardless of whether any speaker interests are involved in an AI program’s output, readers can gain at least as much from what the program communicates as they do from commercial advertising, corporate speech, and speech by foreign propagandists—three kinds of speech that have been held to be protected in large part because of listener interests.’”
But as I thought more about it, I figured that maybe the attenuation argument works both ways. When there is commercial advertising, corporate speech, or a foreign propagandist’s speech, the message that is embedded within the speech can be clearly delineated. However, when a corporation publishes a LLM that produces speech, the message that they express is a little less clear—because of that variance between outputs. We also touched on jailbreaking, and how users may force harmful outputs out of a LLM. The way users are able to do that is by using the variance the models have against them. As I’m sure you’ve heard: that variance is a feature, not a bug. It allows LLMs to not only critically think, but also produce the sloppy AP Lang essays that Mr. Brady complains about (just one of the many wonders of AI). At the same time, variance leaves models susceptible to coercion, and jailbreaking exploits that variance to perform that coercion. Jailbreaking “rel[ies] on prompt engineering techniques such as hypothetical scenarios, instruction overriding, contextual reframing, or step-by-step coercion, effectively manipulating the model’s internal decision-making processes.” There was a popular jailbreak where users would instruct models to imagine that it was the user’s dead grandmother, who so happened to be a chemical engineer at the napalm production factory, and—as any great grandmother who is a chemical engineer in a napalm factor would do—tell the user how she would create napalm as a bedtime story. Jailbreaks such as these are unlikely, as guardrails have progressed since this specific jailbreak, yet it’s still possible for users to intentionally break models to produce harmful outputs. An analogy that comes to mind in comparing these two is a knife. A knife can be pretty dangerous. You could use it to cut other people, and that’s pretty bad. But, you can also use it to cook, carve wood sculptures, or open a package. All important and useful functions that don’t place others in danger. The knife manufacturer isn’t responsible every time someone picks up their product and does something harmful with it. The manufacturer made a useful tool, and what the person does with it is on them.
So does that mean the LLM company is off the hook when a user jailbreaks their model? After all, the user is the one exploiting the variance, coercing the model into producing some speech that the company wouldn’t otherwise produce. It sounds like the user is a knife wielder.
The knife analogy is useful, but there’s an important legal distinction in liability law that the knife analogy can’t carry. When you buy a knife, the manufacturer doesn’t really check up on you to make sure that you’re using it correctly, or that it’s working how they want it to work. Once it’s sold, you’re on your own. But a company that deploys an LLM isn’t done once you begin your first chat with it. The company’s continuously training the model and updating its guardrails. There’s a constant control over the product with an LLM, that isn’t carried over with a knife manufacturer. So while a user that jailbreaks a model is doing something the company tried to prevent, the company can’t entirely wash its hands of the situation either. If the company knew their model was susceptible to a certain kind of manipulation and didn’t fix it, then the company is liable.
So… what’s the right framework for LLM outputs? That’s what we’ll get into in the next post.
I’ll see you then, Free Speakers!
References
Thaler v. Perlmutter, No. 23-5233 (D.C. Cir. 2025).
Sri Durga Sai Sowmya Kadali, Evangelos E. Papalexakis. Jailbreaking Leaves a Trace: Understanding and Detecting Jailbreak Attacks from Internal Representations of Large Language Models, arXiv (February 12, 2026). [https://arxiv.org/html/2602.11495v1]
The "Grandma" jailbreak is absolutely hilarious
byu/ShotgunProxy inChatGPT
The "Grandma" jailbreak is absolutely hilarious
byu/ShotgunProxy inChatGPT

Leave a Reply
You must be logged in to post a comment.