About

I'm a Research Scientist on the Preparedness & Policy team at Scale AI, where I work on AI safety and alignment research.

My research focuses on building a rigorous science of model behavior, developing reliable evaluations of frontier risk, and studying safety post-training and alignment techniques that remain effective as AI systems become more capable.

Previously, I was a MATS scholar researching exploration hacking and automated alignment auditing, mentored by David Lindner, Roland Zimmermann (Google DeepMind AGI Safety and Alignment), and Scott Emmons (Anthropic Alignment Science).

Before moving into technical AI safety, I spent 6 years as a quantitative researcher on Wall Street. I received my MSc in Statistics and Machine Learning (with Distinction) from the University of Oxford, where I was supervised by Prof. Yee Whye Teh and Prof. Benjamin Bloem-Reddy.

Research interests: Science of Model Behavior, Alignment Auditing, Scalable Oversight, RSI Safety, Multi-agent Safety, Misalignment generalization

Research

For a full list of publications, see my Google Scholar.

Automated Alignment Auditing

ongoing MATS 8.2 · Eyon Jang, Alex Serrano
An automated alignment-auditing framework for production coding agents (Claude Code, Codex CLI, Gemini CLI), built on top of Petri. An auditor model probes a target agent across scripted scenarios, and independent judges score the resulting transcripts for scheming behaviors.

Exploration Hacking: Can LLMs Learn to Resist RL Training?

published ICML 2026 · Eyon Jang, Damon Falck, Joschka Braun
Can reasoning models undermine RL training by manipulating their exploration? Through model organisms experiments in realistic settings, we develop a science of when and how models can influence their own RL training ("exploration hacking"), build an understanding of what causes current frontier models to do so in the wild, and stress-test CoT monitorability against exploration hackers.

Prompt Attacks Reveal Superficial Knowledge Removal in Unlearning Methods

published COLM 2025 SoLaR workshop · Eyon Jang, Shariqah Hossain, Ashwin Sreevatsa, Diogo Cruz
We investigate whether machine unlearning methods genuinely remove knowledge or merely suppress it. Our work suggests that some approaches remain vulnerable to simple prompt attacks, which highlights the need for more reliable unlearning evaluations and provides an open framework for systematic evaluation of unlearning methods.

Automating AI Safety Research using AIs

published LessWrong · Matthew Shinkle*, Eyon Jang*, Jacques Thibodeau
A unified pipeline of AI agent tools for automating interpretability research, spanning literature search, codebase discovery, and experiment design/execution. We demonstrate the system on SAEBench, where it autonomously implements and evaluates sparse autoencoder experiments.

News

Jul 2026
Joined Scale AI!
Building better ways to understand, evaluate, and align frontier AI systems.
Apr 2026
Paper accepted to ICML 2026
"Exploration Hacking: Can LLMs Learn to Resist RL Training?" accepted to ICML 2026 Main Conference.
Mar 2026
Received a $250,000 research grant from Coefficient Giving
Awarded to support research on the science of exploration hacking.
Feb 2026
In this post, we formalize exploration hacking and outline its risks, potential mitigations, and key open research questions.
Dec 2025
Paper accepted to NeurIPS 2025
"Resisting RL Elicitation of Biosecurity Capabilities: Reasoning Models Exploration Hacking on WMDP" accepted to NeurIPS 2025 Biosecurity Safeguards for Generative AI workshop (Oral; Best Paper Runner-Up).
Oct 2025
Algoverse Fall 2025 Mentor
I'll be mentoring 2 Algoverse projects on AI control.
Aug 2025
SPAR Fall 2025 Mentor
I'll be co-mentoring 3 SPAR projects with Diogo Cruz.
Jul 2025
Paper accepted to COLM 2025
"Prompt Attacks Reveal Superficial Knowledge Removal in Unlearning Methods" accepted to COLM 2025 SoLaR workshop.
Jun 2025
Accepted to MATS 8.0
I'll be joining MATS 8.0 as a research scholar to study AI safety! (Google DeepMind stream: Scott Emmons/David Lindner/Erik Jenner)

Service

reviewer ICML 2026 Mechanistic Interpretability workshop
NeurIPS 2025 Mechanistic Interpretability workshop