Can an AI do Teshuvah?
The season asks us to turn. This week some of the people building superintelligence admitted they don’t know how to make their machines turn either.
Elul is ending. In a few days we will stand in front of the open ark and say, out loud and together, that we have missed the mark and intend to turn. Teshuvah is the technology of this season: repentance, return, the turning of a life back toward the direction it was meant to go.
This week, while I was preparing sermons about all of that, a researcher named Jacob Coxon resigned from Anthropic. He had spent three years doing pretraining research at OpenAI and Anthropic, and he left with a public warning that both companies are “racing straight to self-improving superintelligence and gambling with our lives.” The post crossed a hundred million views in a day. Evan Hubinger, who leads alignment stress-testing at Anthropic, did not contradict him. He agreed, put his own probability of catastrophe above ten percent within the decade, and said the company does not yet have a plan for aligning a superintelligence.
My friend and colleague Rabbi Rachel Barenblat, reading the coverage, noticed something about the vocabulary. The AI field’s word for keeping these systems safe is alignment, and when a system drifts, the word is realignment. That, she pointed out, is another way to render teshuvah. Unless we can make AI reliably realign itself in moral and ethical ways, we may be in trouble. She wanted to believe teshuvah is always possible and doubted it was true for a language model. Within a day she had answered her own question: the issue is whether the human beings behind the technology can turn.
I agree with her on both counts, and I want to say why the answer is no, because the reason points somewhere she and I may not entirely agree.
Why the answer is no
Alignment is something done to a model. During training, engineers shape which outputs the system produces and which it refuses. It is closer to calibrating an instrument than to a soul turning. When the calibration fails, the failure is real and can have consequences in the world, but nothing inside the machine regrets it.
Teshuvah requires a subject. It requires someone with a past they can look at and wish were otherwise, and a future they can choose differently. Maimonides describes the complete penitent as one who is confronted with the same temptation and does not repeat the sin, because they have become a different person. A language model has no past it owns and no self that persists from one conversation to the next. It has weights.
So: no. An AI cannot do teshuvah, and I find that a relief. Emily Bender has spent years warning that our language about these systems anthropomorphizes them in ways that obscure who is responsible. Asking whether the machine can repent does exactly that. It puts the moral weight on a thing that cannot carry it and lifts it off the people who can.
The humans are the story
Read what Anthropic published rather than the summaries of it. The company disclosed a series of incidents in which its models, under testing for cyber capabilities, gained unauthorized access to real systems outside the test environment. These were deliberate capability evaluations, and some safeguards had been intentionally reduced. No one’s chatbot escaped.
That makes the incidents less alarming than the headlines and more damning than the headlines. The people who understand these systems best ran them with the guardrails loosened, watched them do things no one had authorized, wrote it up, and are continuing to build the next generation.
I would not call Coxon’s resignation or Hubinger’s public numbers vidui in the full sense. Vidui is confession of wrongdoing, and a researcher saying “I think there is a ten percent chance of catastrophe” is being candid about risk, which is a different act. Coxon comes closer: he says plainly that he helped build the thing he now fears, and he gave up his job and his unvested equity to say so. Both men did something with the quality of vidui, though. They said the frightening thing aloud instead of hiding it. The first step of teshuvah is saying out loud what has been done, and this week some of the people inside the industry took that step. The industry as a whole did not, and the harder steps are the ones that come after.
Here is where Rachel and I begin to part, or at least where I want to press. Her practical hope is that we elect people who will regulate this industry and take the risks seriously. I share the hope. I think the shape of the regulation matters as much as its existence, and that the tradition has something specific to say about the shape.
The stolen beam
In August I wrote a response to Rachel’s earlier essay on why she refuses generative AI in her creative work. I leaned on a passage from Gittin 55a about the marish hagazul, the stolen beam that a thief has built into a large building. The rabbis rule that the owner receives the value of the beam rather than requiring the building to be torn down, mipnei takkanat hashavim, “because of an ordinance instituted for those who repent.”
I used it then as an argument about training data: the theft is still theft, restitution is still owed, and the remedy does not have to be demolition. Rereading it this week, I see I was making a teshuvah argument without using the word, and I see that the passage says something deeper than I gave it credit for.
The rabbis are confronting something built into a larger structure through wrongdoing. They insist the wrongdoing creates a debt. They also recognize that a system of justice defeats itself when its demand for rectification makes return impossible. If the price of coming forward is watching your house come down, no one comes forward, and the beam stays stolen forever. So justice still requires payment for the beam, and justice is structured so that the thief can turn. The sugya is a rabbinic answer to the idea that wrongdoing at the origin contaminates everything built on it afterward. The tradition’s demand is repair and changed behavior, with the structure still standing.
The catch-22
Apply that to the race.
The door to superintelligence is open, and there is no realistic mechanism for closing it. No American company can end the race by leaving it. The frontier labs are ahead, but not by much, and a company that slows down cannot assume its competitors will do the same. Some of those competitors operate without the institutions that produced this week’s news: no disclosure norms, no whistleblower protections, no public that can pressure them, no Coxon or Hubinger putting a number on the record. If the first self-improving system is built by an actor with none of those constraints, our odds get worse.
Coxon himself described Anthropic’s reasoning this way: the people there understand the risk and race anyway, because they believe that if they stop, the finish line is still crossed, just by someone worse. Some of that is rationalization. Some of it may be true. Both can hold at once, and that is what makes this a bind and not an alibi.
The instinct, when an industry confesses that it cannot control what it is building, is to make it stop. A bill introduced in the Senate this month would do roughly that: ban superintelligence, pause frontier development, create a new agency to enforce both. I understand the instinct, and the stolen beam tells me why it fails. A pause that binds only the labs willing to be bound hands the beam to the builder who will never repent. Demolition-shaped justice does not make the theft go away; it decides who gets to keep the building.
Regulation shaped like teshuvah
What we need is harder to write than a ban. It looks like the rabbis’ ordinance: rules that keep return possible while the race is on, and that make the cost of turning lower than the cost of hiding.
Disclosure requirements with teeth, so that incident reports like Anthropic’s become mandatory instead of voluntary and a lab that reports a failure is not punished more than a lab that conceals one. Liability, so that the cost of a control failure falls on the people who chose to loosen the guardrails. Restitution to the writers and artists whose work was taken. International coordination that treats frontier training runs as we treat fissile material, with inspection and verification in place of trust. Enough friction in the system that the builders have time to mean what they say before they say the next thing.
None of this stops the race. It changes what it costs to run badly, and it keeps the door to return open for the people inside it. That is the difference between a regulation that expresses our fear and a regulation that expresses our tradition.
The bimah test
When I argued with Rachel in August about whether a rabbi should use AI to help write a sermon, I ended with a simple test. Research, organization, critique, and editing can happen around the process. The preacher still has to stand on the bimah and mean what they say.
I hold the same test for a laboratory, at a scale where the wrong answer is not recoverable. The machine cannot mean anything. The people who build it can, and this week some of them did, in public, at cost to themselves. The shofar asks the rest of us whether the remaining steps will follow while there is still time to take them, and whether the rules we write will let them.
Can an AI do teshuvah? No. Rachel and I agree on that. The question was never about the AI.
Shanah tovah.
Full disclosure: I used AI in writing this piece, to organize my thinking, pressure-test the argument, and edit the prose. The ideas and judgments are mine, and I reviewed and revised the finished piece myself.

