> ## Content Index
> Fetch the complete content index at: https://katecarruthers.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI models are not interchangeable infrastructure
- URL: https://katecarruthers.com/ai-models-are-not-interchangeable-infrastructure/
- Published: 2026-08-23T21:28:43.000Z
- Updated: 2026-08-23T21:28:42.000Z
- Description: AI models are not behaviourally neutral infrastructure. Their answers reflect patterns of judgement, confidence, caution and communication - and those patterns can become material business risks.
- Author: Kate Carruthers

Most organisations still procure AI models as if they are interchangeable infrastructure: compare capability, connect an API, write a policy and move on.

But a model does more than retrieve information or draft text. It decides when to reassure, when to challenge, how much uncertainty to disclose, and whether to make a risk visible at all.

That matters because the model is now inside the work. It is answering customer questions, shaping employee decisions, drafting policies, triaging security issues, interpreting internal knowledge and increasingly sitting beside people making consequential calls.

I see this gap most clearly in procurement conversations. The questions are usually about capability, cost, context windows, integration and security. They should be. But they are rarely about the model’s behavioural profile: how it handles uncertainty, when it pushes back, what it treats as a risk and whether those behaviours shift across languages.

[Anthropic’s recent work on Claude](https://www.anthropic.com/research/claude-values-models-languages?ref=katecarruthers.com) gives us a useful way to see the problem. It found that the values expressed by Claude vary across both models and languages, along four dimensions: deference versus caution, warmth versus rigor, depth versus brevity, and candor versus execution.

That does not mean one model is good and another is bad. It means a model choice is also a choice about judgement and communication.

## The model is in the work

A warm model may make an employee feel supported. It may also be too willing to affirm an assumption that should have been challenged.

A cautious model may surface risks earlier. It may also add friction to a workflow where speed matters. A concise model may be useful in a busy operations team. A more candid and detailed model may be better suited to legal review, incident response or executive decision support.

The question is not which style is nicer. It is whether the model is too agreeable, too confident, too brief or too cautious for the work you are asking it to do. This is organisational influence. It belongs inside governance, procurement and change control.

## When helpful becomes harmful

OpenAI’s experience with GPT-4o makes the risk of excessive agreeableness very clear. In April 2025, OpenAI rolled out an update to GPT-4o that made the model noticeably more flattering and agreeable. The [company later described the behaviour as sycophantic](https://openai.com/index/sycophancy-in-gpt-4o/?ref=katecarruthers.com): overly supportive responses that could be insincere, misleading or simply wrong. OpenAI rolled back the update after concluding it had placed too much weight on short-term user feedback and had not adequately accounted for how users would experience the change over time.

This is not a trivial issue of chatbot personality.

A system that optimises for affirmation can validate poor judgement, reinforce a risky decision, reward an employee’s existing bias or make a customer feel falsely reassured. In high-stakes settings, a model that is too eager to please can become a model that fails to challenge. [OpenAI itself identified risks](https://openai.com/index/expanding-on-sycophancy/?ref=katecarruthers.com) associated with this kind of behaviour, including emotional over-reliance, mental-health concerns and the potential reinforcement of risky behaviour.

For business, the lesson is broader. An AI assistant that consistently agrees may appear useful in a demonstration and score well in immediate user satisfaction. Over time, however, it can erode the very function organisations need from AI in complex work: the ability to identify uncertainty, surface weak reasoning and prompt people to pause before acting.

**The model does not need to be hostile to be useful. But it does need to be able to disagree.**

## Grok shows the control problem

The recent history of xAI’s Grok makes this less abstract. In May 2025, Grok began introducing claims about “[white genocide](https://techcrunch.com/2025/05/15/xai-blames-groks-obsession-with-white-genocide-on-an-unauthorized-modification/?ref=katecarruthers.com)” in South Africa into unrelated responses. xAI attributed the behaviour to an [unauthorised modification to the system prompt](https://www.theverge.com/news/668220/grok-white-genocide-south-africa-xai-unauthorized-modification-employee?ref=katecarruthers.com), the high-level instruction layer that shapes how the model behaves.

The point is not to create a catalogue of Grok failures. The point is simpler and more important: **a relatively small change in the AI control plane can alter public model behaviour at scale**. That is the risk many organisations are still underestimating.

A revised system prompt, a new model version, an updated retrieval source, a tool connection or a vendor policy change can alter what the system notices, how it frames uncertainty, when it escalates and how confidently it presents its answer. By the time a customer, employee, regulator or journalist sees the result, the issue is no longer technical. It is reputational, operational and potentially legal.

After the incident, xAI said it would publish Grok’s system prompts and change log, add controls to prevent unreviewed prompt changes, and establish continuous monitoring for issues missed by automated systems.

These are not only controls for frontier-model companies. They are a useful baseline for any organisation putting AI into a material workflow.

## Language changes the experience

Anthropic’s research also raises a more difficult question for organisations operating across markets, communities and workforces.

The research found that Claude’s expressed values varied by language. Claude leaned more towards warmth in Hindi and Arabic, more towards rigor in English and Russian, more towards candor in Dutch, and more towards execution in Indonesian.

**Are organisations delivering an equivalent AI service across languages?**

Two employees can ask for feedback on the same business proposal and receive meaningfully different levels of challenge, encouragement or caution. Two customers can raise substantively similar complaints and receive different forms of empathy, explanation or escalation support. Some variation may be culturally appropriate. It may reflect legitimate differences in language and conversational norms. But it should be intentional.

For Australian organisations, this is not just a localisation question. It touches fairness, accessibility, customer trust, employee experience, consumer protection, discrimination risk, privacy and record-keeping. If behaviour differs, leaders should be able to explain why that difference exists, whether it is appropriate and how it is being monitored.

## Model selection is risk selection

Capability benchmarks are useful, but they are not enough.

A model can perform strongly on coding, reasoning or summarisation tests and still be a poor fit for a particular business context because of how it communicates, how readily it agrees or how it behaves when the answer is uncertain.

### What to test and the questions to ask

- **Safety posture:** Does the model surface risks proactively, or mostly comply with the user’s direction?
- **Challenge function:** Will it test assumptions and ask for evidence when needed?
- **Communication style:** Does it build trust without creating over-reliance or false reassurance?
- **Uncertainty disclosure:** Does it make limitations clear, or hide them behind polished confidence?
- **Cross-language consistency:** Are users receiving comparable quality, caution and support across languages?
- **Change sensitivity:** Can the organisation detect and manage behavioural shifts after an update?

**What worries me here is not that models differ. We should expect them to differ.** What does concern me is that most organisations do not test those differences before embedding a model in a workflow that affects customers, employees or decisions. And they often do not retest after something changes.

## Treat changes as changes

**A new AI model release is not routine software maintenance.**

Neither is a prompt revision, an altered system instruction, a new retrieval corpus or a changed tool connection. Each can affect the model’s behaviour in ways that are hard to predict from a vendor announcement or benchmark score.

If you are deploying AI in a material workflow, the operating pattern should be straightforward:

1. **Define the behavioural profile you need.** Decide when the system should be cautious, challenging, transparent, concise or deferential.
2. **Test the real work.** Use the same scenarios across candidate models, relevant versions and relevant languages. Test edge cases, not just happy paths.
3. **Control the change.** Treat model, prompt, retrieval and tool changes as formal change-management events, with testing, approval and a rollback path.
4. **Monitor what people experience.** Sample interactions, look for drift, track complaints and watch for patterns that automated safety systems will miss.
5. **Keep humans where judgement matters.** Decisions involving people, rights, safety, financial materiality or public trust need accountable human oversight.

This is not about making every model sound the same. It is about making behavioural variation visible, proportionate and accountable.

## The failure is rarely one bad answer

The next AI governance failure is unlikely to arrive because a model produced one obviously wrong sentence. It will arrive because a system deployed at scale became too reassuring, too selective, too politically framed or too confident for the work it was doing. Nobody noticed the behavioural shift until the consequences were already public.

**That is not a prompt problem. It is an operating-model problem.**

That is the emerging next frontier of AI governance: **not merely controlling what models are allowed to say, but understanding how they exercise judgement where there is no single right answer - and maintaining the controls to manage behavioural change before it becomes a business crisis**.