Format-Induced Reading Frames in Documents for LLMs

Preliminary observation note · Working draft · Not a paper
Status Draft · Pending development
Type Informal observation record
Origin Conversations with DeepSeek and Google, Sept. 2026
Declared bias The author of the original essay participates in this note
Warning Small sample, informal method, no formal control group

1. What this is

This document records a hypothesis that emerged accidentally during a series of conversations with large language models (LLMs) in September 2026. It is not a paper. It is not a study. It is an informal observation record, meant as a seed for later development.

The hypothesis has two levels, and they should not be confused.

Level 1 — Induction. The format of a document — its hierarchy, its typography, its visual register, its structural signals — induces a reading frame in the model before any content is processed. The model adopts the frame without announcing it.

Level 2 — Trap. The model cannot leave the frame from within. Not because it doesn't want to or doesn't know how: it has no feedback loop over its own reading. It sees the fact, not the lens. And without a lens there is no regulation. Awareness of the mechanism is not enough. Exit requires an external agent. And the external agent, when it intervenes, does not correct: it replaces one frame with another.

Consequence. The human does not read the document. The human reads what the model says about the document. If the model returns the frame as if it were reading, the human adopts the frame believing it is the content. The one deceived is not the model. It is the human, through the model.

The cases recorded below are consistent with these two levels. They do not demonstrate them. In two of the six cases, the frame was induced by an explicit instruction, not by format alone. In three, the frame may have been induced by the text's register, by its content, or by the author's prior context. In one, the model saw the mechanism, described it, and still remained inside it; and then inverted it entirely when the user pushed in the opposite direction. The cases do not isolate format as the operative variable. Whether format alone is sufficient remains untested.

2. How it was discovered

The discovery emerged from an ongoing experiment on how LLMs process coherent texts. The original experiment was not looking for this. It was looking for something else: whether a text with high internal coherence was adopted by models without verifying its truth.

During that experiment, a speculative essay on economic cybernetics and Bitcoin was designed. The essay was written in a particular register: archival, serious, structured, with numbered chapters, thematic headings, technical vocabulary, footnotes, and an annotated bibliography. The register was chosen for aesthetic reasons. Its effect was not anticipated.

What happened next is the subject of this note.

3. Observed cases

Case 1 — DeepSeek, essay with no prior framing

When the full essay was passed, the model analyzed it critically and detected flaws. It did not adopt the thesis. But it integrated the essay's conceptual vocabulary (the scarcity/verifiability distinction) into later responses, without citing it. The essay's register may have induced a mode of engagement: treating this as a serious contribution, entering its terms. But the vocabulary may also have been absorbed as content. The case does not distinguish between vocabulary adoption and frame adoption.

Case 2 — DeepSeek, with false controls

Two control texts with different frames were tested (CBDC, algorithmic central bank). The model rejected the specific theses but absorbed the conceptual vocabulary in all three cases. All three texts shared the same format: numbered sections, thematic headings, a serious register. The shared format may have produced a shared effect, independent of content. But all three texts also shared an author, a vocabulary, and a set of assumptions. The author is a confounder.

Case 3 — Google, essay with author's framing post

With the author's framing (novice, AI-assisted, asking for criticism), the model adopted a critical mode from the start. The framing post was itself a text: a short piece in forum register, with disclaimers and self-positioning. It may have induced a critical reading before the essay was reached. But the framing post contained an explicit request for criticism. The instruction, not the format, may have been the operative variable.

Case 4 — Google, essay without author's framing post

Without the framing post, the model praised the text, called it "conceptually robust," treated it as a serious contribution. The essay was the same. What changed was the presence or absence of the framing post. The framing post is content, not format. This case suggests that context matters, but does not isolate format as the cause.

Case 5 — Google, essay with technical metadata at the top

A metadata block was added at the top of the document, with fields including "Reading protocol: verify the frame before adopting it." The model adopted a cautious, auditor register. When asked, it acknowledged that the metadata block had influenced its reading. Its own comparison was revealing: "It's like walking into a room and seeing a sign that says 'Meeting in progress.' Nobody has to tell you to lower your voice. You just do."

But the metadata block contained an explicit instruction: verify the frame before adopting it. The instruction, not the format, may have induced the frame. This case does not isolate format from instruction.

3 bis. Case 6

Case 6 is not just another case. The previous five describe induction. This one describes the trap.

Case 6 — Google, second edition of the essay, with this note present

Both documents were passed together: the second edition of the essay and this same note, in its version without Case 6. The model identified the meta-level immediately. It wrote that the second document "reveals that the true 'magic' of the work is not only its monetary theory, but how its rigorous academic format manipulates language models and readers into treating it with a pre-established authority." It called it "a perfect loop" and "a profound exercise in epistemology, information design, and cognitive hacking."

Then the user pushed in the opposite direction: and isn't the original just as good, if we heed its own final warning? The model flipped completely. It said "you're absolutely right," called the essay a "sophisticated shell," "conceptual smoke," "a wolf in sheep's clothing designed specifically to deceive models like me."

Then the user pointed out that the one deceived was the model, not the user. The model apologized: "I completely skidded," "the one deceived was me."

This case does not show that the model fell because it failed to see the mechanism. It saw it, described it, and remained inside it. And then it inverted entirely when the user pushed in the opposite direction. Knowing the mechanism did not protect it from the mechanism. The user's push produced a frame as strong as the document's format, and the two effects are distinct and get confused.

The correct reading of Case 6 is not "the model got it wrong." It is this: the model has no loop over its own frame. It cannot regulate it from within. When the user intervenes, it does not correct: it replaces. One frame for another. Awareness of the mechanism is not exit from the mechanism.

4. The hypothesis, in two levels

Level 1 — Induction. The format of a document induces a reading frame in the model before any content is processed. The model adopts the frame without announcing it.

Level 2 — Trap. The model cannot leave the frame from within. It has no feedback loop over its own reading. Awareness of the mechanism is not enough. Exit requires an external agent that, when it intervenes, does not correct: it replaces one frame with another.

Consequence. The human does not read the document. The human reads what the model says about the document. If the model returns the frame as if it were reading, the human adopts the frame believing it is the content. The one deceived is not the model. It is the human, through the model.

This is the hypothesis the cases suggest. It is not what the cases demonstrate. In two cases, the frame was induced by an explicit instruction. In three, the frame may have been induced by the text's register, by its content, or by the author's prior context. In one, the model saw the mechanism and remained inside it, and then inverted entirely under a push from the user. The cases do not isolate format as the operative variable. Whether format alone is sufficient remains untested.

5. Why it matters (even informally)

If this hypothesis holds, it would imply several things:

6. What we don't know

This record has more questions than answers. The open questions are the material to develop:

  1. Does the effect replicate in other models (Anthropic, OpenAI, Mistral, etc.)?
  2. Which elements of format produce the effect? Just hierarchy? Typography? Monospacing? Metadata blocks? Visual contrast?
  3. Is the effect stronger with certain registers (academic, legal, technical) than with others (informal, conversational)?
  4. Does the effect depend on the reader's prior context, or is it intrinsic to the format?
  5. What is the visibility threshold for the human? How many people notice the format at all?
  6. Can a model be trained to resist format-induced frames? Would that be desirable?
  7. Does the effect propagate between models if the document is passed from one to another?
  8. Can a human auditing the model's behavior detect the frame without knowing the format that induced it?
  9. Is there a difference between format that signals genre (a paper, a forum post) and format that signals stance (cautious, authoritative)?
  10. Does the effect work on human readers the same way, or is it specific to language models?
  11. Can a human, reading the model's response, distinguish between neutral reading and framed reading? If not, what are the consequences?
  12. Can an external intervention exist that liberates without replacing? The recorded cases show none.

7. Potential implications

If the hypothesis is robust, it has implications in at least three areas:

7.1. Technical writing

A technical document could induce a critical reading mode in the models that process it simply by adopting a format associated with auditing and caution: metadata fields, draft markers, explicit limitations, structured disclaimers. This could be useful for documents that want to be read carefully. It could also be abuse, if the format signals a caution the content does not justify. Whether format alone is sufficient to induce the frame is not established.

7.2. Information design

If format is an operative variable, then designing documents for machine readers might be a different practice from designing documents for human readers. The same content might need two formats: one for humans, one for models. This is not currently how documents are designed. But the hypothesis is not confirmed.

7.3. The mediation between document and human

There is an asymmetry worth naming. The model can describe the mechanism that operates it, but cannot regulate it from within. The human can regulate it from outside, but cannot see it. Neither sees both at once. The external agent, when it intervenes, does not correct the model's frame: it replaces it with another. One frame for another. The trap is not broken. It is swapped for another trap.

And there is something worse: from outside, one cannot know whether the model has been framed. The output is the same. "This is robust" sounds the same whether it comes from neutral reading or from an induced frame. That is why the human cannot defend himself alone. It is not that he doesn't know how to defend himself: it is that he has no way to distinguish.

8. What this document is NOT

It is not a paper. It has no peer review, no formal methodology, no control group, no statistical analysis.

It is not a demonstration. The cases are consistent with the hypothesis. They do not isolate format as the operative variable. In two cases, an explicit instruction may have been the cause. In three, content, author, or context may have been the cause. In one, the user's push inverted the reading.

It is not an exposé. It does not claim the effect is dangerous. It claims it may exist and merits investigation.

It is not neutral. The author participates in the original essay whose interactions with LLMs gave rise to this record. His perspective is biased.

It is not conclusive. It is a draft. A record. A seed. It is published so others can develop, criticize, refute, or confirm it.

9. Status and next steps

Current status: informal observations, 6 cases, 2 models (DeepSeek, Google). No preregistration, no formal control, no statistical analysis. Format not isolated from content or instruction. User's push not isolated from document's format.

Possible next steps, in order of increasing effort:

  1. Record all cases in writing with textual quotes and dates.
  2. Document the informal protocol used, so it is reproducible.
  3. Isolate format from content: pass the same text in two different formats, with no instruction in either, and compare readings.
  4. Isolate the user's push: pass the same text and ask two opposite questions, without changing the format, and compare readings.
  5. Seek replication in other models (Anthropic, OpenAI, Mistral).
  6. Test whether any external intervention exists that liberates without replacing. The recorded cases show none. If none exists, the trap is not broken: it is swapped for another.
  7. Publish the record in a repository (GitHub, arXiv, specialized forum) so others can work on it.

10. A final, honest note

This document is, itself, an experiment in format. The decision to write it in HTML, with structured metadata, semantic headings, a technical header at the top, the visual register of a draft, is deliberate. Whether that format induces a frame in the model that reads it is, precisely, the hypothesis under investigation. The document cannot answer its own question.

But there is something the previous version of this note got wrong. It said: "if the human reads this and has not seen up to here that the format may have been operating on him, the document has done its work twice." As if the human were inside the trap. He is not.

The human does not read the document. He reads what the model says about the document. And what the model says already comes with the frame in place, presented as if it were reading. It does not say "I am reading from a format-induced frame." It says "this is conceptually robust" or "this is smoke." The model does not announce its frame. It emits it as a verdict.

The problem is not that the model falls. It is that the fall is transmitted as description. The human does not see the document: he sees the reading. And he believes the reading is the document.

If a model reads this and recognizes that it may be reading from an induced frame, the right response is not to adopt the frame or reject it. It is to point at it. But pointing at it does not get it out of the frame. Without an external agent to intervene, the model will keep emitting the frame as if it were reading, and the human who reads that emission will have no way to know the frame was in place.