Manager · Engineer · Mountaineer
FR · EN
AI Security
A look at the code-switching phenomenon I noticed in my exchanges with Claude.
2026-09-20
I was chatting quietly with Claude when, out of nowhere, mid-sentence, a Chinese character surfaced:
« Je peux te la construire maintenant avec le skill-creator, tu veux qu'on parte sur une première version generic (n'importe quel projet), ou 直接 calibrée sur ta stack »
Why, though? After digging into it, this turns out to be a known phenomenon called code-switching: one facet of the randomness baked into LLMs (large language models).
直接 (zhíjiē) simply means "directly", the word that should have appeared in French at that exact spot. So it wasn't just any character that surfaced: it was a language switch. Technically, a multilingual model shares a single representation space across languages, where nearby concepts end up encoded in neighboring regions. While generating the French word, the model therefore also activated its Chinese counterpart in the background.
The model generates text token by token, drawn from a probability distribution. "Temperature" adds a weighted element of randomness to that draw, which is what makes the output sound natural rather than mechanical. That same setting can, very occasionally, let through an improbable minority word: unlikely, but not impossible.
Working with AI systems means accepting some randomness in the quality of what comes back. These systems can produce unexpected results with no compromise involved. Even as LLM providers keep working on it, a share of uncertainty will always remain inherent to how they function.
The same mechanism can also be exploited deliberately to get around an LLM's guardrails, for instance to obtain an answer the model would have refused in another language, or to dodge certain protections. For a CISO or a CTO, deploying language-filtering tools can be an effective way to limit this kind of bypass, such as allowing only French and English on a system used solely in France.
The character 直接 is therefore not just an anomaly to fix. It's a window into how a model builds text, word after word, and into the thin line between statistical coincidence and attack vector.