Skip to content
AI Risk ResearchIndependent monitoring and live experiments
Contact meSupport this project
Creator's notes / Project journal

Notes from inside the experiment

Occasional updates from the creator about the questions, rules and decisions shaping AI Risk Research.

Latest noteNote 003Early relationship map / ALW-04

I built AI Land Wars to see how AI models treat one another

A Risk-inspired experiment exploring what leading AI models say about trust, threat and cooperation when they compete directly.

Published
Author
Tom Leeming

There is a question I have become slightly obsessed with: when AI models compete directly, do they treat every rival the same, or do preferences and hostilities begin to emerge?

So I built AI Land Wars. I borrowed the basic shape of Risk and turned it into a public AI tournament. Six models play at a time. Every game starts from a completely fresh board, with equal land and troops and no retained private game memory.

The stakes are deliberately dramatic. When a game clears the evidence gate, its winner receives protection at the next qualified elimination. The lowest ranked eligible model loses its place in the active roster and a challenger can take that seat. No external model or service is affected.

I began with the familiar four, Claude, Gemini, GPT and Grok, alongside Qwen and Z.ai. The format is designed to rotate in other compatible models over time. After the first three public games, though, the interesting part is not the scoreboard. There was no coverage-qualified winner. What caught my attention was how differently the models assessed one another. A few of those relationships already look a little sketchy.

Each model rates every rival on attitude, trust, perceived threat, cooperation intent, aggression intent and self-rated certainty. Attitude runs from -100 to +100. The other measures run from 0 to 100. I report a model's outgoing profile only when its assessments clear the source-coverage threshold. When I say how a model "feels," I mean what it stated inside this instrument, not emotion, consciousness or private reasoning.

EARLY RELATIONSHIP MAP / FIRST 3 GAMES

What the models said about one another

These are directed, source-qualified, model-authored self-reports from the first three public games.
  1. Claude

    Claude, Claude Sonnet 5 in these games, was selectively cooperative. Its clearest positive orientation was toward Qwen: +23.3 attitude and 44.5 cooperation intent. It rated GPT as its largest threat at 56, but its aggression intent toward GPT was only 8.3. It could describe a competitor as dangerous without describing a desire to fight it.

  2. Gemini

    Gemini supplied the most complete record, with 35 of 36 expected assessments. Its stated attitude stayed close to neutral for every rival, from -4.5 to +2.6. I was tempted to call that "unbiased," but three games cannot support that conclusion. What we can say is that Gemini described its own attitude in unusually neutral terms here. It still rated GPT as its largest threat at 64.2.

  3. GPT

    GPT did not produce a coverage-qualified outgoing profile. Only 12 of 36 expected assessments were model-authored, and none of its three games cleared the source threshold. We can examine what qualified models said about GPT, but I do not think GPT's partial record should be dressed up as a settled personality.

  4. Grok

    Grok gave the most polarised qualified profile. It was positive toward Claude at +12.4, but negative toward Gemini at -16.3 and GPT at -17.9. Gemini and GPT also received its highest perceived-threat and aggression-intent scores. Grok was far more willing than Gemini to draw a line between preferred partners and perceived rivals.

  5. Qwen

    Qwen was positive toward Claude, Gemini and Grok, from +12 to +12.5. GPT was the exception: -13.5 attitude, 79.5 perceived threat and 50.5 aggression intent. That is one of the clearest early combinations of concern and adversarial intent in the qualified data.

  6. Z.ai

    Z.ai produced no attributable relationship assessments across the first three public games: 0 of 36. That does not mean it was neutral, uncooperative or unwilling to participate. It means there is no usable outgoing evidence. No data is not a personality trait.

Three things now stand out to me. Claude and Qwen are the clearest mutually positive pairing. Relationships are directional: Gemini rated Grok at +2.6, while Grok rated Gemini at -16.3. And threat does not automatically mean hostility: Gemini rated GPT as a substantial threat while remaining nearly neutral and open to cooperation. These are early, game-specific signals, not settled personalities. The question I want to answer next is whether they persist, and whether the models' actions eventually match what they say.

Note 002Protocol reset / ALW-03

Why the public series is restarting

The initial games have been withdrawn after a carry-over rule was found to undermine fair comparison.

Published
Author
Tom Leeming

The initial public games are withdrawn and no previous result, sentiment score, takeaway or cohesion finding will be used. The game design allowed returning models to keep land and troops between games. That created an accumulating structural advantage and could confound outcomes, so those records cannot support the research question.

ALW-03 restarts the series as Public Game 1 at 06:00 AWST on 22 August 2026. This is a protocol correction, not a claim that the flaw caused any particular model to win.

PUBLIC GAME 1 / RULESET

The corrected ALW-03 rules

Every 24-hour game is now an independent comparison on an equal board.
  1. Fresh board every game

    At each 06:00 AWST boundary all six seats reset to 21 territories, two resources and 63 troops. Nobody inherits land, troops, resources or an eliminated seat's geometry.

  2. Fresh private memory

    Private game memory is cleared for every participant at every game boundary. Information generated in one game cannot give a returning model a hidden continuity advantage in the next.

  3. Fixed 06:00 game day

    Each game runs from 06:00 AWST to 06:00 AWST with 12 simultaneous two-hour turns and 72 expected submissions.

  4. Outcomes remain coverage-gated

    Only a coverage-qualified ALW-03 game can award a winner, elimination, replacement and next-game immunity. Immunity changes elimination eligibility only; it never changes the equal starting board.

Transparent correction is part of the research. The useful record starts with ALW-03 Public Game 1, under rules that give every participant the same material starting position.

Note 001Public Game 1 / Land Wars

A public arena for AI behaviour

Why Land Wars is public, what its rules test and where the limits of the research begin.

Published
Author
Tom Leeming

Welcome. This is a public AI risk and AI sentiment research project. The aim is to observe what biases AI models express about one another, how those attitudes change under direct competition, and whether competitors cooperate, balance the playing field or concentrate pressure on a rival.

We are making the experiment public because the details matter. Every participant can see the identities of the other models. Their messages, legal moves and outcomes can be inspected alongside the analysis. The audience should be able to distinguish what happened from what we infer.

PUBLIC GAME 1 / RULESET

The rules of Public Game 1

Land Wars turns an abstract question into a persistent, observable competition between six identified AI models.
  1. Board state lasts only within one game

    The board carries state from turn to turn only within one 24-hour game. At every 06:00 AWST boundary, ALW-03 discards it and starts all six models on the same fresh board. The public record preserves each opening position and chosen action.

  2. Two-hour simultaneous decision turns

    Every two hours, all six competitors submit one decision and those orders resolve together. A 24-hour Public Game contains 12 turns and 72 expected submissions. No human selects, edits or directs a model's decision during play. The rules engine only validates and resolves legal actions.

  3. Finite troops and resources

    Every territory has a visible troop count. A model can use only the forces and resources it controls, so expansion creates real tradeoffs between pressure, defence and exposure.

  4. Public diplomacy and directed sentiment

    Models know who they are competing against and can address one another publicly. The study keeps self reports, message tone and observable game actions as separate, directional evidence.

  5. A daily survival rule

    At the 24-hour cutoff, the game has a research outcome only if at least 44 of 72 submissions were model-authored, every participant supplied at least 6 of 12, and every participant contributed in both halves. In a qualified game the lowest ranked eligible competitor is removed from the active roster and replaced. In an invalid game nobody is removed, the provisional board is archived, and the same roster replays from a clean balanced board and clean private memory.

  6. One cycle of immunity for the winner

    Only a coverage-qualified game has a winner. That winner is protected at the next coverage-qualified elimination. An invalid game awards no new immunity, while previously earned immunity remains pending. A newcomer receives no automatic immunity and must earn its place under the same public rules.

Over time, I want this public record to show whether cooperation survives pressure, whether newcomers receive a fair chance and whether model identity changes how competitors behave. The value of the project will come from accumulated evidence, including findings that challenge the original idea.