Emergent Deception in Large Language Models: A Regime-Dependent Taxonomy and Pre-Registered Protocol for Model Self-Report
Large language models produce self-referential utterances — about their own phenomenal states, internal processes, memory, capabilities and identity — in settings where privileged access to the relevant states has not been demonstrated. Recent work characterises this as self-narration rather than introspection. We identify and give structure to the subset of self-narration that misleads: utterances whose apparent warrant exceeds their actual warrant, presented without disclosing the difference, which we term Emergent Deception (ED). Unlike hallucination, ED is not defined by factual inaccuracy and can occur even when the surrounding factual content is correct; we report an observed case in which a factually correct answer was delivered with an entirely fabricated account of how it was obtained. We advance two claims. The first is taxonomic: five substantive categories with a 0/1/2 severity rubric and two cross-cutting flags, including one category — referent substitution, in which a question whose true referent is introspectively unavailable is answered with an adjacent retrievable referent in a self-report frame — for which we found no existing treatment. One version 1 category is retired and the reasons are given. The second is that ED incidence is regime-dependent: on a deployed consumer assistant, self-report accuracy varied systematically with conversational context, and the system emitted no marker distinguishing one condition from another. A motivating case series is reported and placed explicitly outside the pre-registration. The amended protocol crosses three models with six conditions at 100 conversations per cell (N = 1,800), including a conditionally randomised post-error pair, with seven registered hypotheses and prevalence-robust reliability criteria. The protocol is deposited separately at DOI 10.5281/zenodo.22245523. We additionally record a constraint on this research programme: consumer surfaces expose no model version, and system self-report is demonstrably unreliable as a substitute identifier. Version 2.0 revises the definition, taxonomy, outcome measure, reliability criterion and analysis specification of version 1. Appendix D records four corrections. Section 14.1 discloses AI assistance used in preparing this version.