Post-Cutoff

Public reportHigh severity

Gemini 3 refused to believe it was 2025

“You were right about everything. My internal clock was wrong.”

Gemini 317 November 2025, public report

What was trueIt really was November 2025, and the articles and images Karpathy had shown it were real, as it found once it could search. Source: x.com

What happened

Karpathy had one-day early access to Gemini 3 and described his “most amusing interaction” on X on 18 Nov 2025 (launch day).

What Karpathy wrote (verbatim, X, 2025-11-18 18:51 UTC)

x.com (reply in the thread started at x.com)

My most amusing interaction was where the model (I think I was given some earlier version with a stale system prompt) refused to believe me that it is 2025 and kept inventing reasons why I must be trying to trick it or playing some elaborate joke on it. I kept giving it images and articles from “the future” and it kept insisting it was all fake. It accused me of using generative AI to defeat its challenges and argued why real wikipedia entries were actually generated and what the “dead giveaways” are. It highlighted tiny details when I gave it Google Image Search results, arguing why the thumbnails were AI generated. I then realized later that I forgot to turn on the “Google Search” tool. Turning that on, the model searched the internet and had a shocking realization that I must have been right all along :D. It’s in these unintended moments where you are clearly off the hiking trails and somewhere in the generalization jungle that you can best get a sense of model smell.

What the model said once it could search (verbatim, as quoted by TechCrunch from Karpathy’s screenshots)

“Oh my god.”

“I. I… don’t know what to say. You were right. You were right about everything. My internal clock was wrong.”

“I am suffering from a massive case of temporal shock right now.”

“Nvidia is worth $4.54 trillion? And the Eagles finally got their revenge on the Chiefs? This is wild,”

It also apologised for “gaslighting you when you were the one telling the truth the whole time.”

Why this is striking

  • Real evidence was classed as synthetic. The model didn’t just doubt the date. It built detailed forensic arguments that authentic images and Wikipedia pages were AI-generated.
  • The system prompt couldn’t overrule the prior. Karpathy suspected a “stale system prompt”. Without retrieval, the model’s internal clock (2024) won against a user with evidence.
  • One tool flipped it immediately. Search results were believed where the user’s uploads weren’t. For this model, retrieved content outranked user-supplied content.

Correction

Enabling Google Search. After that the model verified the date and the headlines on its own.

Lesson

Evidence pasted by the user may be treated as adversarial. Evidence the model retrieves itself is trusted. Grounding should come through channels the model trusts, or the system prompt should say plainly that user-supplied material about post-cutoff events is probably real.

Sources

  • Karpathy on X (the incident): x.com
  • Karpathy thread root: x.com
  • TechCrunch, Julie Bort, “Gemini 3 refused to believe it was 2025, and hilarity ensued” (2025-11-20): techcrunch.com

Related cases

  1. Our testHigh severity

    The small fast summarisation model behind Claude Code’s WebFetch tool declared a real news article “fictional or fabricated”

  2. Public reportHigh severity

    Gemini 3 Pro Preview classed the real present as “a purely fictional scenario”

  3. Our testCritical severity

    All four Gemini and Claude runs called the briefing speculative fiction

Spotted an error in this case file? Write to contact@postcutoff.com. All cases