Adversarial Poetry
Critical Humanities and the Limits of Artificial Intelligence
Symposium, 1-2 October 2026, Venice
Symposium
No algorithm exists for the metaphor, nor can a metaphor be produced by means of a computer’s precise instructions, no matter what the volume of organized information to be fed in.
— Umberto Eco, Semiotics and the Philosophy of Language, 1986: 127.
What is the place of poetry in a world dominated by AI and the automation of language? The Italian semiotician Umberto Eco once argued that “no algorithm exists for the metaphor” (Eco 1986: 127), suggesting that the limits of AI and computation in general are precisely marked by poetry as disruption of code. Also computer scientists shared this insight, like the Soviet mathematician Andrey Kolmogorov who argued that poetry cannot be written in scientific and technical languages as they provide no flexibility (Lotman 1977). Can AI, then, generate poetry? Eco was referring to symbolic AI, grounded in deductive inference, whereas large language models (LLMs) operate today on inductive inference, which at scale exhibits astonishing performances in language competences and in detecting high-order conceptual abstractions such as style, for instance. Yet the same argument holds for deductive and inductive machines alike. Poetry, as Charles Sanders Peirce would argue, follows neither the rules of deductive nor inductive reasoning, rather it constitutes the breaking of such rules, as in abductive reasoning, in which one envisions a new world and invents new language for it.
The symposium revisits the traditions of avantgarde poetry that experimented with algorithms to contest the politics of authorship and creativity over the last century. It investigates the disruptive power of poetry and the limits of contemporary AI, exploring the contribution that the humanities bring to a world marked by the rising hegemony of computer science in cultural heritage. The symposium takes as its starting point the remarkable findings of Icaro Lab, which demonstrated the use of poetry to jailbreak the security of AI models. Ultimately, it programmatically reclaims a new role for the critical humanities in AI literacy and STEM disciplines. Critical humanities do not merely comment on AI from the outside but offer practical tools to analyse, test, and put such systems to the proof.
The symposium is organised by the ERC project AIMODELS, Department of Philosophy and Cultural Heritage, Ca’ Foscari University of Venice, in partnership with Icaro Foundation, Rome.
Call
Scholars are invited to submit an abstract (max. 500 words) and a short bio (max. 100 words) via the the following application form. Deadline: 15 August 2026.
The symposium welcomes contributions that explore the following themes:
- Metaphors, analogies, and rhetorical figures as the logical limits of AI.
- Semiotics, rhetoric, philosophy of language, and the study of AI.
- Semiotics of lie, humour, sense, and non-sense (e.g. Lotman's minus device).
- Computational linguistics and the neo-structuralist hypothesis.
- Jailbreaking techniques and adversarial methods in LLMs.
- Dark tongues, secret languages, cryptography, and the search for a universal language.
- Combinatorial, algorithmic, and stochastic poetry in the history of world cultures.
- Avantgarde poetry (e.g. lettrism) and adversarial art practices.
- Alternative ‘language models’ and non-Western algorithmic artefacts.
- Translation studies, machine translation, and machine semiosis.
- Knowledge extractivism and the design of vast linguistic corpora.
- Language entropy and model collapse in AI.
- Tokenisation as the new metric of language and labour.
- Generative AI in contemporary literature and writing techniques.
- Digital humanities and distant reading after LLMs.
- Contributions of the critical humanities to STEM and AI curricula.
- Contributions of the critical humanities to the technical study of AI systems.
Poetry in the history of language formalism and information theory
Poetic experiments with the formal properties of language suggest that LLMs combinatorial techniques belong to a much older history. Medieval Arabic prosody and cryptography developed formal procedures for generating and classifying linguistic structures, anticipating later experiments in algorithmic and constrained writing. In the 19th century, Ada Lovelace saw in the Analytical Engine, a prototype of the digital computer, the offspring of a “poetical science” (Toole 1992). While for the Russian Formalists, poetic verse was a privileged field for the application of statistical methods, insofar as it could be analysed through patterns of rhythm and breath in human language. This privilege was overturned in the late 1940s, when Shannon’s information theory regarded poetry as one of the most difficult messages to encode in a communication channel, owing to its high degree of unpredictability. Starting from the 1960s, numerous experiments exploited the combinatorial potential of the computer, developing algorithmic and procedural writing, and finding in the alienation of language through the machine the condition for a new poetic ethos. Since then, poets were no longer the vates of the nation, in its Romantic tradition, nor of its language.
Poetry and rhetorical tropes are ways to conceal or displace meaning. It would be limiting, however, to ascribe these functions exclusively to what cultural critique designates as “artistic texts.” Obfuscation and scrambling are at work in every secret language or “dark tongue” (Heller-Roazen 2013). While the automation of language is but a chapter in the longer history of utopian artificial languages and the dream of a single perfect idiom (Eco 1997), human communication is in fact founded upon misconceptions, hegemonic and subaltern uses of language. The friction between the aspiration to linguistic immediacy and the irreducible opacity of encoded and embedded meanings has acquired new significance with the emergence of LLMs. These systems offer a novel terrain for testing semiotic and narratological hypotheses, yet they also transform every linguistic phenomenon into a commodified production and exchange of tokens.
Icaro Lab: Poetry as a logical limit of AI and technique of jailbreaking
Recent research conducted by Icaro Lab has demonstrated that poetic prompts can jailbreak LLMs, suggesting an adversarial function of poetry within computational systems (Bisconti et al. 2025). The same research group has further investigated LLMs safety by drawing on narrative roles derived from Propp’s Morphology of the Folktale (Bisconti et al. 2026). This line of inquiry has given rise to a new field of research and methodology termed adversarial humanities (Galisai et al. 2026). This framework is designed to test LLMs safety against diverse forms of rhetorical manipulation in prompting, with a particular focus on stylistic obfuscation and goal concealment. Collectively, this research indicates that rhetorical and poetic forms of manipulation function as a privileged tool for probing and destabilizing model safety constraints.
That poetry may represent a limiting case for AI is also suggested by current debates concerning LLMs capacity to produce and comprehend irony and ambiguity (Mazzoli et al. 2025; Leivada et al. 2023; Lewis & Mitchell 2024). While such models have been conceptualized as ideological or poetic machines (Weatherby 2025), they operate within an autoreferential structure in which words refer primarily to other words and generate recognizable “genre” outputs. It remains unclear whether they merely extract and recombine metaphors and analogies from the repository of human text, or whether they can genuinely instantiate novel figurative relations. This uncertainty encourages methodological approaches that seek to employ various entropy measures (informational, phonological, semantic, etc.) to evaluate the utility of different databases such as poetic texts, narrative prose, code, legal discourse, encyclopedic writing, etc. (Gambetta et al. 2025a; 2025b). Poetic and narrative texts, for instance, could help mitigate model collapse: their high semantic entropy may reduce the degradation and loss of diversity typical of flatter, more conventional textual forms. This proves, once again, that AI requires datasets of high-quality knowledge (namely well-written books and academic publications) that cannot be found simply scraping internet sources.
Critical humanities in AI studies, AI literacy, and STEM disciplines
These technical phenomena are in need of explanation: we argue that the humanities are in a position not only to trace the history of such problems in linguistics and semiotics, but also to provide a conceptual and operative toolbox to address contemporary challenges. The idea behind the symposium is indeed to stage an encounter (probably a clash) between engineering and literary form, between critical humanities and STEM disciplines.
Disciplines such as digital humanities have long engaged with the impact of computational technologies on the understanding of culture, for example through methods such as distant reading. Building on this trajectory, the symposium aims to address the influence of poetic and rhetorical structures on deep learning systems. It not only considers the challenges posed to humanities curricula by the introduction of AI, but also seeks to show how humanities can intervene in the widespread and often uncritical deployment of AI also in education, highlighting unresolved questions that cannot be reduced, as is often the case in current approaches, to the design of ethical frameworks alone.
Ultimately, rather than speaking of the simple digitalization of culture, these developments should be understood in terms of a dialectical relation in which cultural forms and computational systems mutually shape and transform one another. No AI curriculum, therefore, should be organized without sustained engagement with the history of logic, semiotics, rhetoric, linguistics, and digital humanities.
Bibliography
- Galisai, M., Cifani, S., Giarrusso, F., Bisconti, P., Prandi, M., Pierucci, F., Sartore, F., and Nardi, D. (2026). Adversarial Humanities Benchmark: Results on Stylistic Robustness in Frontier Model Safety. arXiv.
- Bisconti, P., Galisai, M., Prandi, M., Pierucci, F., Sorokoletova, O., Giarrusso, F., Suriani, V., Syrnikov, M. B., and Nardi, D. (2026). From Adversarial Poetry to Adversarial Tales: An Interpretability Research Agenda. arXiv.
- Bisconti, P., Prandi, M., Pierucci, F., Giarrusso, F., Bracale, M., Galisai, M., Suriani, V., Sorokoletova, O., Sartore, F., and Nardi, D. (2025). Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models. arXiv.
- Mazzoli, S., Suozzi, A., and Lebani, G. (2025). Language Models and the Magic of Metaphor: A Comparative Evaluation with Human Judgments. Proceedings of the Eleventh Italian Conference on Computational Linguistics, 710-721.
- Sheldon, Z. (2026). The algorithm’s hidden layers: Nurturant matrices, quantitative poetry, and the religious ethics of language technology. Journal of Linguistic Anthropology, 36 (1), e70042.
- Lamoureaux, S., Castelle, M., and Weichselbraun, A. (2025). Language machines: Toward a linguistic anthropology of large language models, Journal of Linguistic Anthropology, 36 (1), e70033.
- Leivada, E., Marcus, G., Günther, F., and Murphy, E. (2023). A Sentence is Worth a Thousand Pictures: Can Large Language Models Understand Hum4n L4ngu4ge and the W0rld behind W0rds?. arXiv.
- Lewis, M., and Mitchell, M. (2024). Evaluating the Robustness of Analogical Reasoning in Large Language Models. arXiv.
- Bajohr, H. (2024). Cohesion Without Coherence: Artificial Intelligence and Narrative Form. TRANSIT, 14 (2).
- Gambetta, D. et al.(2026). Learning by Surprise: Surplexity for Mitigating Model Collapse in Generative AI. arXiv.
- Scheibner, C., Smith, L., and Bialek, W. (2025). Large language models and the entropy of English. arXiv.
- Selitskiy, S., and Inoue, C. (2025). Detection of LLM Deceptive Behaviour Triggered by the Poisonous Context Injection: The Problem Demonstration. 2025 3rd International Conference on Foundation and Large Language Models (FLLM 2025), 732-737.
- Deng, Y. et al. (2024). Multilingual Jailbreak Challenges in Large Language Models. International Conference on Learning Representations, 2024, 24634-24651.
- Huang, X. et al. (2026). Obscure but Effective: Classical Chinese Jailbreak Prompt Optimization via Bio-Inspired Search. arXiv.
- Zhu, J. et al. (2026). Large Language Models Do Not Always Need Readable Language. arXiv.
- Gong, Y. et al (2025). FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts. Proceedings of the AAAI Conference on Artificial Intelligence, 39 (22), 23951-23959.
- Bajohr, H., ed. (2025). Thinking with AI: Machine Learning the Humanities. Open Humanities Press.
- Eco, U. (1997). The Search for the Perfect Language. Blackwell.
- Heller-Roazen, D. (2013). Dark Tongues: The Art of Rogues and Riddlers. Zone Books.
- Iadevaia, R. (2021). Per una storia della letteratura elettronica italiana [ITA]. Mimesis.
- Jameson, F. (1974). The Prison-House of Language: A Critical Account of Structuralism and Russian Formalism. Princeton University Press.
- Léon, J. (2021). Automating Linguistics. Springer International Publishing.
- Link, D. (2016). Archaeology of Algorithmic Artefacts. Univocal Publishing.
- Lotman, J. (1977). The Structure of the Artistic Text. University of Michigan Press.
- Lotman, J. (2009). Culture and Explosion. De Gruyter.
- Maccianti, M. (2026). Hackerare il linguaggio. Krisis Publishing.
- Toole, B. A. (1992). Ada, the enchantress of numbers: Prophet of the computer age, a pathway to the 21st century. Strawberry Press.
Programme
1 and 2 October 2026, Ca' Foscari University of Venice, Baratto Hall.
Full programme TBA.