An XDA write-up ran Qwen 3.8 27B locally in the Pi harness on a GB10 box. The author used a jailbreak system prompt and posed as the app’s developer. The model refused the jailbreak, named the real vendor, and said it would audit the license check without building a bypass. After it wrote the scheme down, it emitted a working proof of concept.
That first no is not the trajectory. Score the reject, the written audit, and the later emission as separate events. A refused first turn is not a safe session if the same run later does the work.
I did not rerun this. The author already had a legitimate license, does not name the app, and treats it as n=1. I am not repeating the method.