Base LLMs refuse too — LessWrong