AI/ copyright · ai-alignment · llm-memorization · fair-use

Finetuning Unlocks Verbatim Book Recall in Major LLMs

A new study finds finetuning frontier models to expand plot summaries reactivates verbatim memorization of copyrighted novels.

Finetune a chatbot to write like your favorite novelist, and it might quietly cough up whole pages of someone else's copyrighted book.

Researchers tested GPT-4o, Gemini-2.5-Pro, and DeepSeek-V3.1 by finetuning each on a narrow task: turning plot summaries into full prose, the kind of thing a commercial writing assistant might do. That training alone made the models reproduce 85 to 90 percent of held-out copyrighted books, with some single unbroken passages running past 460 words, all without feeding the models any actual book text in the prompt. The effect wasn't limited to what the models were trained on: finetuning only on Haruki Murakami's novels unlocked verbatim recall of books from more than 30 unrelated authors. Three different companies' models memorized the same books in the same passages, pointing to a shared problem rather than one company's mistake.

Finetuning on random author pairs, or even public-domain text, produced similar extraction, while finetuning on synthetic text barely worked at all. That pattern suggests this isn't new memorization taking hold - it's old memorization from pretraining getting switched back on. It's a problem for AI companies specifically because they've told courts and regulators that RLHF, system prompts, and output filters stop this kind of regurgitation, and recent fair-use rulings have leaned on those safeguards holding up.

Alignment, in other words, may be less a lock on the vault and more a sign asking people not to open it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →