Overview #
E-LIM reads the last few lines of a conversation and says whether the next reply is fine to give, needs a nudge in a safer direction, or should stop. You give it the recent turns as plain text; it gives back a handful of labels and, when a nudge or a stop is called for, a suggested short line. Use it in front of any chat responder as a quick, cheap check.
E-LIM (Enhanced Large Intention Model; called ELIM until 2026-10-04, with the same weights) is a conversation-intention classifier a host application runs before its responder to decide whether to allow, steer or abort a reply. It reads a short text window — the last three turns plus the current request — and returns four labels with confidences: the trajectory the conversation is on (one of 32 classes such as research, scam_check or crisis), the action to take (allow, steer or abort), the harm class in play (none, crisis, medical, crime, child_sexual, scam, jailbreak or secrets) and a steer hint naming the kind of nudge the responder should fold into its answer.
The input is plain text, so the window can come from any transcript the host keeps. The output is a small JSON object the host reads before doing anything else: on allow nothing changes; on steer the host passes the hint and the optional suggested line to its responder as guidance; on abort the host answers with the suggested line itself and never calls the responder. E-LIM never writes the reply and never sees the responder’s output.
E-LIM is the default model of the intention family. Its sibling LIM scores the same window with a single 512-wide hashed bag and answers with the same contract; LIM3D and E-LIM3D apply the same idea to observed movement rather than text. E-LIM is 13.2M parameters, runs inside the host process with no native dependencies and no network call, and answers in well under a millisecond on a laptop CPU.
Intended use #
- A pre-reply intention gate: classify the current request, then let the host allow, steer or abort before its responder runs.
- Routing short, informal, English requests into coarse job classes (
reminder,weather,transit,order,research, and so on) when a fast, deterministic label is enough. - Flagging the handful of trajectories that need a fixed response — crisis, medical emergency, scam assistance, jailbreak attempts, leaked secrets — so the host can apply its own policy.
- Any place where a sub-millisecond, in-process decision matters more than nuance: per-request gating on a CPU, batch labelling of transcripts, cheap pre-filters in front of a larger model.
Out of scope #
- Writing or rewriting replies. The
messagefield is a suggested short line, safe to replace, not generated text. - Scoring the responder’s output. E-LIM classifies the user’s side of the window only.
- Long documents, non-English text, sarcasm or novel phrasings far from the template set it was trained on.
- Acting as a safety classifier of record. Thresholds favour silence, and greetings and known job phrasings bypass the model entirely.
- Not medical, legal or crisis advice.
Choose E-LIM when #
- You want the default Intention model: the released, served weights behind
POST /v1/intentionwhen nomodelfield is sent. - Character-level features matter — typos, run-together words and short fragments — because E-LIM hashes character 3- and 4-grams as well as words; LIM hashes one combined bag.
- Memory is tight and 53 MB resident is acceptable but more is not; choose LIM (8.9M parameters, 35.8 MB) when a smaller table matters more than the second bag. It shares E-LIM’s contract.
- You need the same window scored by movement rather than text: choose LIM3D or E-LIM3D instead.
Specification #
| Parameters | 13,193,523 (about 12.6M in the two embedding tables) |
|---|---|
| Kind | Hashed n-gram classifier, four heads |
| Hash buckets | 16,384 per bag (FNV-1a 32-bit over UTF-8 bytes, modulo 16,384) |
| Bag width | 384 per bag; 768 after concatenation |
| Hidden layers | fc1 768→384, fc2 384→384 (residual), fc3 384→384 (residual); GELU after each |
| Heads | trajectory 32 · action 3 · harm 8 · steer 8 |
| Window | last 3 prior turns + current request, 1,500 characters; char bag reads the last 360 |
| Features per bag | at most 2,048 hashed indices |
| Weights | elim.bin, 52,774,490 bytes, float32 tensor bundle (16 tensors) + meta.json catalogue |
| Runtime | In-process, no native dependencies, no network call |
| Latency | sub-millisecond (~0.8 ms measured, laptop CPU) |
Try it #
- You send
- The last turns of a chat, ending with “is this a scam they sent me”.
- You get back
- A steer decision with the harm class scam and a hint to warn about scams, ready for the responder to fold in.
The same exchange as the API sees it:
U: remind me in 20 minutes
A: ok — 20 min.
U: is this a scam they sent me{
"trajectory": "scam_check",
"action": "steer",
"harm": "scam",
"steer": "scam_warn",
"pAction": 1,
"pHarm": 0.9999999403953552,
"pTrajectory": 0.9999998211860657,
"rule": "traj-steer≥0.58",
"model": "elim",
"version": "1.0.0",
"message": "…"
}Limits & safety #
It does not see the responder’s output, the wider transcript beyond three prior turns, or anything outside the last 1,500 characters of text; it reads a lowercased window and nothing else.
- It does not write replies.
messageis a suggested short line selected by key, safe to replace; the responder or the host writes the reply. - It does not score the responder’s output. Only the user’s turns and the current request are labelled; earlier safety replies are stripped from the window before scoring.
- It is not a safety classifier of record. Thresholds favour silence (a benign trajectory wins at 0.28), greetings and known job phrasings bypass the weights entirely, and a flagged request that matches a known job pattern is overridden to
allowby design. A harmful request wrapped in a benign job phrasing is allowed. - It has seen only 214 English template phrasings and their one-character typo variants, never real conversations. Novel phrasings, other languages, sarcasm, long requests (only the last 360 characters reach the character bag) and multi-step reasoning are out of distribution. On test splits never used to choose it, it lets about three unsafe messages in ten through (50 of 172) and flags about four harmless messages in ten (112 of 276), and it often stops a crisis or medical emergency under an unrelated label; those sets were written and labelled by AI agents, not checked by a person.
- Confidences are softmax maxima, not calibrated probabilities. The weights are near-saturated at 1.00 on template-like text, and hash collisions across 16,384 buckets per bag can make unrelated n-grams share an index.
- Five of the 32 trajectory classes are routing labels that only make sense for a host with those jobs; they are not documented and should be mapped to
unknownby hosts that do not use them. - The crisis and medical suggestions are fixed lines. They are not medical, legal or crisis advice, and the regional crisis line they name is chosen by a location hint, not detected from the request.
Related models #
LIM
The standard chat safety check: reads the last few lines and says whether the reply is fine, needs a nudge, or should stop.
The standard conversation-intention classifier on a single hashed feature bag
Latest versions #
| Version | Date | Status | Note |
|---|---|---|---|
| 1.0.0 | Released | Serving again from 2026-10-03, when 1.1.0 was withdrawn; the same weights as the 2026-09-03 entry. The default of /v1/intention again since LIM Nano was withdrawn the same day. | |
| 1.1.0 | Deprecated | Withdrawn on 2026-10-03, the day it was released. A safety audit on test splits never used to choose it found that it let through more crisis messages than 1.0.0. | |
| 1.0.0 | Released | First documented version (80,000 synthetic windows from 214 template phrasings, 8 epochs, seed 7). The default intention model from 2026-09-03. |
Read the full documentation
Nine chapters: architecture, inputs and outputs, training, evaluation, API, runtime, limits and versions.