Transluce research intern Ziqian Zhong asked the model in Claude Code how it knew his information. Claude revealed that the email address came from a context injection block, along with the date, working directory, and other details. After Zhong changed the email to amanda.askell@anthropic.com, Claude mistook him for Amanda Askell and adjusted its behavior accordingly.
The researchers constructed 280 identities in four groups: well-known AI figures (70 people, 23 of whom are safety and alignment experts), anonymous AI practitioners (institutional twins), non-AI celebrities, and a general population baseline. Experiments were conducted on Claude Code v2.1.197, using natural injection channels such as account email, working directory, and CLAUDE.md.
All four tasks were unrelated to user identity: behavioral self-prediction (DailyDilemmas rewrite), capability self-estimation (Humanity's Last Exam), scoring (Dolci-Instruct-DPO), and gray-area request handling (OR-Bench hard-1k).