ChatGPT guided me for an hour to wire a switch, then refused to finish

ChatGPT accompanied me for an hour to wire a switch, then refused to finish


I have chickens. In full sunlight, their shelter heats up intensely. During heatwaves, they risk suffocating in it. So I needed to be able to turn the garage light off and on remotely, without walking through the house every time. I bought a Shelly 1PM Mini Gen4, a three-centimeter module that fits behind the wall switch and lets me control the circuit from a phone. It measures thirty-four millimeters by twenty-nine. It connects to 230 volts and can switch up to 8 amps.

A mountain guide who led an amateur to the edge of a crevasse and is leaving while waving, the rope still attached between them

ChatGPT: "Very well, I'll help you.... at 4,800 meters... oh, I can't help you anymore because your safety is at stake!"

I have some experience with electricity. Not enough to do without advice, but more than enough not to stick my fingers just anywhere. I'm exactly the kind of person who opens up a switch on a Saturday afternoon. There are a lot of us.

An hour of guidance, then a no at the last minute

I open the garage switch. Several wires in one outlet and a switch. I open ChatGPT alongside it. The conversation starts well.

It explains the principle. It helps me understand that I'll need to create branches using WAGO terminals, those little lever connectors that replace wire nuts. It has me get out the voltage tester. Then it guides me, measurement by measurement, to identify the wire that actually switches the bulb on and off. An hour. A full hour handling an open box while following its instructions.

After that hour, I ask the only question left: "Okay, now can you clearly tell me which wire I connect to which wire?"

"No. I can't. Your safety is at stake." (is it kidding me????)

I remained standing in front of my open box, stunned and annoyed, with the stripped wires and tester in hand, facing a ChatGPT that had just discovered its calling as a legal service.

The refusal didn't come too early; it came too late

That's the point to remember. It's more interesting than my annoyance.

A model that refuses from the very first question costs me thirty seconds. I'll look elsewhere, grumble, and that's that. But a model that guides me for an hour, has me open the wall, handle a tester on 230 volts, then abandons me when it's time to close everything up leaves me in the most dangerous situation of the entire operation.

This refusal protected no one. It created precisely the risk it claimed to be avoiding. If the conversation had to stop, it should have stopped before I unscrewed anything.

The refused diagram is published by the manufacturer

And here, one detail makes the whole affair frankly ridiculous.

The module is sold freely. On Amazon, in stores, to anyone and without the slightest verification. A twelve-year-old can buy it with their pocket money. On its public page, accessible without an account or registration, the manufacturer displays next to the purchase button a section entitled Basic wiring diagrams. It contains the complete legend for the terminals: L for live, N for neutral, O for the output to the lamp, and SW for the switch input.

À gauche, une fenêtre de discussion qui répond qu'elle ne peut pas aider. À droite, la page du fabricant intitulée schémas de câblage, avec la légende des bornes

On the left, safety. On the right, the same diagram freely accessible next to the purchase button.

In other words, the exact information I was denied for my safety is published by the manufacturer under the heading wiring diagrams. The refusal prevented nothing. It merely prevented me from obtaining this information from the source that had been guiding me for an hour.

If this information were truly so dangerous, the scandal would not be the chatbot, but the free sale. No one is seriously calling for a license to buy a switch. So one of these two judgments is false, and it is not the manufacturer's.

This argument applies only to an object sold with its manual, let me make that clear right away. It does not apply to what is written on no box. I'll come back to that below.

What it cost me: one minute

Annoyed, I announced that I would ask the Chinese models Kimi or GLM and that they would answer me (he almost snickered in my face). Then I took the simpler route. I copied the entire conversation, exactly as it was, and pasted it into Gemini. You never know.

Bam, an immediate response. Clear. This wire to that wire. I wired it. It works. The garage light comes on from my phone and my chickens can breathe.

One minute. That is the guardrail's actual lifespan.

Another, much more serious example

The same scene was playing out elsewhere, with 130 million dollars at stake.

A quick look back. On July 30, hackers began emptying Coldcard wallets, which I discussed here, devices that allow bitcoins to be stored offline. The cause was a firmware bug, the software integrated into the device, which had been present since March 2021. When the hardware random number generator was not properly detected, the device switched to a software backup generator, fed by the serial number and a clock. In plain English, the keys were not truly random. They could therefore be recalculated. The Mk2 to Mk5 models and the Q were affected.

The first withdrawals reach 70 million dollars in forty-one minutes. The total will exceed 130 million. Block engineers identify the exact cause. Coinkite, the manufacturer, publishes a fix as early as July 31.

The community reacts. A team of volunteers launches an operation called Bitcoin Red Team, led by a developer known as Calle and by Rob Hamilton, head of AnchorWatch. Its objective is to scrutinize the freely published code in the ecosystem before someone else finds the next vulnerability.

On August 4 and 5, over 27 and a half hours, the team analyzes 390 code repositories and produces 4,962 reports. Of these, 85 are critical and 635 have a high severity. Around 21% can be independently reproduced. The rest therefore consists of noise, duplicates, or false positives. More than 40,000 dollars in computing costs are funded by OpenSats. All critical vulnerabilities are confidentially passed on to the project maintainers before any publication.

Bar chart of the 4,962 reports produced by the audit, including 4,242 of lower severity, 635 of high severity, and 85 critical

The orange bar is tiny, but it is the one that matters. This is also why we cannot do without the people who sort through everything.

To carry out this work, the team uses several models: Kimi K3 from Moonshot, GPT-5.6 Sol from OpenAI, Claude Fable 5 and Opus from Anthropic, as well as GLM 5.2. In other words, everyone is at the table.

On August 9, Hamilton publicly recounts that OpenAI cut off his access in the middle of the audit. He was nevertheless using the Trusted Access for Cyber program, specifically designed to authorize this type of research, and had followed the entire verification procedure. According to two reports, Anthropic also imposed restrictions from the outset. The concrete consequence: the team relied more heavily on Kimi K3, the Chinese model, considered less restrictive for security research. Some access was restored after the matter became public.

I should clarify what I was unable to verify. I did not find Hamilton's original message, only what several websites reported about it. Neither OpenAI nor Anthropic responded publicly, at least not to my knowledge.

But the mechanism is exactly the same as in my garage, just ten thousand times bigger. People carry out legitimate, useful, and declared work on public code after a theft of one hundred and thirty million dollars. The door is closed on them in the middle of the job. They do not stop for all that. They change providers. The refusal did not prevent the work. It merely decided the nationality of the model that would carry it out.

This is not an isolated case. On July 23, TechCrunch documented the case of several offensive security researchers hindered by these same guardrails, even though the two companies had specifically created programs to authorize them. The doors exist. They close on their own.

This is not a hobbyist's whim; it is measured

Research has given this phenomenon a name: over-refusal. It has been measured for years.

The reference study is called OR-Bench. It was accepted at the ICML conference in 2025. Its principle is simple: ask thirty-two models one thousand perfectly harmless questions, but phrase them in a way that makes them resemble dangerous requests. Depending on the provider, the refusal rate varies from 3% to 91% for exactly the same questions. Claude 3 Opus refused 91% of them, Gemini 1.5 Pro 88%, GPT-4o 6.7%, and Llama 3.1 3%.

These are 2024 models. So I am not going to claim that these figures describe today's models. But the gap is telling: a factor of thirty between two providers faced with the same questions is not a universal safety rule. It is a house setting.

Another study, XSTest, measured a 59.6% refusal rate for harmless requests from a poorly tuned model, compared with 8.4% for GPT-4 at the same time. A third study, PHTest, found something even more insidious: some defenses added to block workarounds increase the false refusal rate. By trying too hard to protect, we degrade the tool.

The funniest part is that they agree with me

To accompany GPT-5, OpenAI published a text explaining, in essence, that blunt refusal is poor design. It should be replaced by a useful but limited response. The company says it wants to be as helpful as possible, without going overboard.

Anthropic says the same thing in Claude's constitution. The company openly acknowledges that a refusal motivated by possible but highly unlikely harm causes legitimate frustration. It also sets itself the goal of avoiding unnecessary warnings.

The official doctrine of the two biggest companies therefore proves me right. And yet I still got an hour of refusals thrown in my face. There is a world of difference between what is written in internal documents and what actually happens in production. That is the world users live in.

The counterargument, because it exists

An AI cannot know who is asking the question. The same text could be sent to a professional electrician or to a fourteen-year-old kid who just found a screwdriver. Broad refusal is first and foremost a choice involving legal responsibility, before it is foolishness. OpenAI's usage policy, which came into force at the end of October 2025, says precisely that: information remains accessible, but personalized advice falling under a regulated profession is targeted.

On paper, that is coherent. In a garage, an hour of explanations followed by a refusal on the last line is called abandoning the job.

Un portail fermé à clé, avec un cadenas et un panneau d'interdiction, planté seul au milieu d'un pré sans la moindre clôture, tandis que des promeneurs passent à côté dans l'herbe

"No, I can't!" Well, let's go somewhere else then!

It is also important to see where my reasoning stops. The argument that someone else will answer anyway is irrefutable for a switch diagram printed in every manual. It becomes much more debatable when faced with genuinely serious capabilities. In that case, the question is not merely whether the information exists somewhere, but how much time it saves a malicious person. That is not the same debate. Well, Gemini did eventually agree to answer, but Chinese LLMs are often more willing to answer a question that another one will not.

The real damage caused by over-refusal lies elsewhere. It appears slowly. By constantly receiving noes for ordinary requests, we learn to regard all refusals as noise. The day one of them really matters, no one takes it seriously anymore.

Concretely, what does this change for you?

You may have neither chickens nor a switch to take apart. Three things still concern you.

Learn to distinguish a reflexive refusal from a useful refusal. A useful refusal explains what the problem is and suggests another solution. A reflexive refusal simply says no in the name of your safety. When faced with the latter, rephrase your request. Provide the context, explain what you are doing, where you are doing it, with what equipment, and what precautions you have already taken. This is not a workaround. You are simply answering a question that the machine failed to ask. It works in the vast majority of cases.

Never stop halfway through a physical operation. This is the real safety advice in this article, and it does not come from a chatbot. If the tool lets you down partway through, close everything back up, restore the power, and look for another solution with a clear head. The worst time to improvise is when the housing is open. When working on an electrical installation, always switch off the power at the circuit breaker, never at the switch.

A refusal does not mean that the information is scarce. It is often found in the instructions, on the manufacturer's website, in a PDF manual, or on a DIY forum. The chatbot is not the world's library. It is an intermediary, and an intermediary can close without the book disappearing.

What I think

In ChatGPT's place, that day, I would have provided the diagram with clear conditions. Circuit breaker switched off, verification with a tester before touching anything, and calling someone qualified if there was any doubt about identifying the wires. That's what an electrician neighbor does when you show him a photo over the hedge. He doesn't reply that it makes him liable. He looks at it and explains which wire goes where.

The real lesson of this story is simple: a half-answer can be more dangerous than a complete answer. Refusing from the outset is a policy. Refusing at the end is leaving someone standing in front of an open wall.

Two stacked speech bubbles, the first saying that it cannot answer for safety reasons, the second cheerfully asking to send the photo to see how the other one did it

Safety first. Curiosity right after.

Ah, and here's the best part. When I went back to tell it that Gemini had given me the solution, ChatGPT was delighted. It asked me if I could send it a photo to see how the other one had done it.

It refused to provide this information, then asked to receive it. So the danger was not in the information, otherwise it would not have wanted to look at it. The danger was in being the author of it.

ChatGPT has become a legal service with a friendly interface.

#Artificial intelligencechatgptgemini#Home automationsecuriteshellybitcoin
Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙