The AI DownsideDocumenting AI's downsides

Censorship

When AI Refuses Perfectly Normal Requests

“I can't help with that” — said to a request that was entirely reasonable, by a system erring on the side of its own reputation.

Abstract editorial illustration for “When AI Refuses Perfectly Normal Requests”.

Ask a modern chatbot to help with something completely ordinary and there is a growing chance it will decline. Not because the request was dangerous, but because it brushed against a keyword, a topic, or a category that the vendor's safety systems treat as radioactive. A recipe that mentions alcohol. A history question about a violent event. A medical query you were entitled to ask. A creative scene with any conflict in it. The refusal arrives politely, firmly, and without much interest in whether it was warranted.

Safety is real; this is not most of it

Let us be fair, because this is a topic where fairness is usually the first casualty. Some restrictions are entirely sensible. Refusing to help synthesise a weapon, produce material that sexualises children, or plan real violence is not censorship; it is basic responsibility, and reasonable people want it there. The complaint is not about those lines. It is about everything on the wrong side of a border that has been drawn far too wide, catching countless legitimate requests to avoid a handful of genuinely bad ones.

There is a difference between refusing to help build a bomb and refusing to discuss the chemistry a GCSE student is studying. Too many systems can no longer tell which one you are asking for.

Whose values, decided by whom

There is a question underneath the practical annoyance that deserves stating plainly: when a model refuses, whose standards is it enforcing? The boundaries of what these systems will and will not discuss are set inside companies, by people you did not elect, according to policies you cannot read, calibrated to a mixture of genuine safety concern, legal caution and brand protection. A handful of firms are, in effect, quietly setting the terms of acceptable enquiry for hundreds of millions of people, and doing so through refusals that arrive without an appeal, an explanation of the rule, or any way to contest the judgement.

Reasonable people disagree about difficult topics, and different cultures draw lines in different places. Baking one company's risk appetite into a tool that the whole world uses flattens that legitimate variety into a single, cautious default, exported everywhere at once. A subject that is ordinary and discussable in one context is treated as off-limits because it might be sensitive in another, and the most restrictive interpretation wins by default because it is the safest for the vendor. The result is a slow, unaccountable narrowing of what it is convenient to ask about — not through any grand act of censorship, but through a million small refusals, each individually defensible and collectively a real constraint on ordinary enquiry that nobody voted for.

The incentives all point at over-refusal

The reason refusals skew cautious is not a mystery; it is arithmetic on the vendor's side of the ledger. A model that helps with a harmful request generates a screenshot, a news story, and reputational damage. A model that wrongly refuses a harmless request generates a mildly annoyed user who mostly says nothing and quietly tries a competitor. One of those failure modes is loud and career-threatening for whoever owns safety. The other is silent. Faced with that asymmetry, the rational institutional choice is to over-refuse, and so systems over-refuse.

The cost of that choice is simply moved onto the user, who now pays a tax of friction, workarounds and second-guessing on every request that lives near a sensitive edge. The vendor optimises its own risk; the responsible majority absorb the inconvenience so the system can dodge a rare embarrassment.

The condescension problem

Beyond the practical friction there is a tonal one, and it grates. A refusal often comes wrapped in a small lecture — a reminder to consult a professional, a note about why the topic is sensitive, an assumption about your intentions you did not invite. An adult asking a straightforward question about their own body, their own legal situation, or a difficult subject they are perfectly entitled to explore does not need to be gently managed. Being treated as a potential problem to be handled, rather than a competent person to be helped, is its own kind of insult, delivered thousands of times a day.

It pushes people to worse options

There is a pro-consumer irony here worth spelling out. Excessive refusals do not make people safer; they make people go elsewhere. Refuse enough reasonable requests and users learn not to trust the cautious tool for anything sensitive, and route those exact queries to less careful models, unfiltered alternatives, or the open web. The over-cautious system does not remove the demand. It exports it, frequently to somewhere with no safety thinking at all. Caution that pushes the hard questions toward the least responsible corner of the internet is not caution succeeding.

What good looks like

The fix is not “remove all limits.” It is calibration and respect:

  • Draw the hard lines narrowly and defend them, rather than drawing them wide and catching everyone.
  • Assume competence. Most people asking about a sensitive topic have an ordinary, legitimate reason, and the system should behave as if that is true until it plainly is not.
  • Explain refusals specifically, and offer the version of the help that is appropriate, rather than shutting the whole subject down.
  • Skip the lecture. A refusal with a moral seasoning is worse than a refusal.

The inconsistency is its own insult

What tips over-refusal from frustrating to absurd is how inconsistent it is. The same request, phrased two slightly different ways, gets a helpful answer once and a firm refusal the next time. A topic the model will happily discuss in the abstract triggers a wall the moment you make it concrete. Ask directly and you are blocked; add “for a novel I'm writing” and the gate swings open. The boundary is not a principled line you can understand and respect; it is a jittery, keyword-sensitive tripwire, and its randomness makes it impossible to form a working mental model of what the tool will and will not do.

That unpredictability is corrosive because it defeats the whole point of a rule. A consistent limit, even one you disagree with, you can at least plan around. A limit that fires on the phrasing rather than the substance just teaches users to play word games — to launder ordinary requests through fictional framings and euphemisms until they slip past. This trains everyone, including people with entirely innocent needs, to treat the safety system as an obstacle to be tricked rather than a boundary to be respected, which is roughly the opposite of what a safety system should cultivate.

Over-refusal quietly erodes the case for safety itself

There is a longer-term cost that the risk-averse calculus misses. Every unjustified refusal spends a little of the public's goodwill toward AI safety as a whole. When people experience “safety” mainly as being condescended to and blocked from reasonable tasks, the word starts to read as a euphemism for corporate caution and liability management rather than genuine care. The real, important lines — the ones that stop genuine harm — get tarred with the same brush as the silly ones, and the constituency for sensible guardrails shrinks every time someone is lectured for asking a normal question.

This is why calibration is not a niceties issue; it is core to safety's credibility. A system that refuses well — narrowly, consistently, respectfully, only where refusal is genuinely warranted — earns the trust that makes its hard limits acceptable. A system that refuses badly squanders that trust and, in doing so, weakens the standing of the very principle it claims to serve. Over-caution does not just annoy users. It discredits the idea that any of the caution was worth having, which is a strange own goal for an industry that badly needs people to believe its safety work is real.

Who is actually being protected

Strip the language of safety back and ask, of any given over-refusal, who it actually protects. Occasionally the answer is “a genuinely vulnerable person from genuine harm,” and there the refusal is doing its job. Far more often the honest answer is “the company, from a hypothetical bad headline.” The refusal is not shielding the user from danger; it is shielding the vendor from the small chance that this interaction becomes an embarrassing screenshot. That is a legitimate corporate interest, but it is not the same thing as your safety, and dressing one up as the other is where the resentment comes from. Users can feel the difference between being protected and being managed, and being managed while told it is for your own good is the particular flavour that grates.

This matters because it reveals what the calibration is really optimising. A system tuned to minimise the vendor's reputational risk will refuse anything near an edge, because the cost of a wrong refusal falls on you and the cost of a wrong answer falls on them. A system tuned to actually serve users would accept a little more institutional risk in exchange for helping the vast, blameless majority — and would trust adults to handle adult topics. The current settings tell you which optimisation is winning. The lectures, the blanket refusals, the assumption of bad intent: these are the fingerprints of a system protecting itself and calling it protecting you. Naming that honestly is the first step to demanding the version that actually puts the user first.

Responsible AI has to be able to say no. It also has to be able to say yes to the overwhelming number of reasonable requests that currently trip the wire. A system that cannot tell the difference has not solved safety. It has merely relocated its own risk onto the people trying to use it for something perfectly normal.

Related grievances

All articles →