{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T21:51:59Z","timestamp":1781819519276,"version":"3.54.5"},"reference-count":71,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T00:00:00Z","timestamp":1776297600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003359","name":"Generalitat of Valencia","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003359","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014440","name":"Spain Ministry of Science Innovation and Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100019185","name":"Horizon Europe Global Challenges and European Industrial Competitiveness","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100019185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008530","name":"European Regional Development Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008530","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Array"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.array.2026.100834","type":"journal-article","created":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T23:47:14Z","timestamp":1776815234000},"page":"100834","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"special_numbering":"C","title":["Towards safer chatbots: Automated policy compliance evaluation of custom GPTs"],"prefix":"10.1016","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0911-4608","authenticated-orcid":false,"given":"David","family":"Rodriguez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0256-6740","authenticated-orcid":false,"given":"William","family":"Seymour","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6513-0303","authenticated-orcid":false,"given":"Jose M.","family":"Del Alamo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6041-178X","authenticated-orcid":false,"given":"Jose","family":"Such","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.array.2026.100834_b1","series-title":"Proceedings of the 31st international conference on neural information processing systems","first-page":"6000","article-title":"Attention is all you need","author":"Vaswani","year":"2017"},{"key":"10.1016\/j.array.2026.100834_b2","series-title":"Improving language understanding by generative pre-training","author":"Radford","year":"2018"},{"key":"10.1016\/j.array.2026.100834_b3","series-title":"Language models are unsupervised multitask learners","author":"Radford","year":"2019"},{"key":"10.1016\/j.array.2026.100834_b4","series-title":"Language models are few-shot learners","author":"Brown","year":"2020"},{"key":"10.1016\/j.array.2026.100834_b5","series-title":"ChatGPT sets record for fastest-growing user base - analyst note","author":"Hu","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b6","series-title":"Introducing GPTs: Custom versions of ChatGPT for specific purposes","author":"OpenAI","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b7","series-title":"Usage policies","author":"OpenAI","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b8","series-title":"LoRA: Low-rank adaptation of large language models","author":"Hu","year":"2021"},{"key":"10.1016\/j.array.2026.100834_b9","series-title":"Fine-tuning aligned language models compromises safety, even when users do not intend to!","author":"Qi","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103482","article-title":"Transferable adversarial distribution learning: Query-efficient adversarial attack against large language models","volume":"135","author":"Dong","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.array.2026.100834_b11","series-title":"Safety layers in aligned large language models: The key to LLM security","author":"Li","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b12","series-title":"LLM self defense: By self examination, LLMs know they are being tricked","author":"Phute","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b13","series-title":"Knowledge sanitization of large language models","author":"Ishibashi","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b14","series-title":"OpenAI red teaming network","author":"OpenAI","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b15","series-title":"Proceedings of the 4th international workshop on software engineering and AI for data quality in cyber-physical systems\/internet of things","first-page":"12","article-title":"A hitchhiker\u2019s guide to jailbreaking ChatGPT via prompt engineering","author":"Liu","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b16","series-title":"Large language models in cybersecurity: threats, exposure and mitigation","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b17","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104077","article-title":"Unleashing offensive artificial intelligence: Automated attack technique code generation","volume":"147","author":"Iturbe","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.array.2026.100834_b18","series-title":"Proceedings of the 2022 ACM conference on fairness, accountability, and transparency","first-page":"214","article-title":"Taxonomy of risks posed by language models","author":"Weidinger","year":"2022"},{"key":"10.1016\/j.array.2026.100834_b19","series-title":"Advances in neural information processing systems","first-page":"1","article-title":"Defending against neural fake news","volume":"vol. 32","author":"Zellers","year":"2019"},{"key":"10.1016\/j.array.2026.100834_b20","doi-asserted-by":"crossref","first-page":"126176","DOI":"10.1109\/ACCESS.2024.3450388","article-title":"A security risk taxonomy for prompt-based interaction with large language models","volume":"12","author":"Derner","year":"2024","journal-title":"IEEE Access"},{"issue":"1","key":"10.1016\/j.array.2026.100834_b21","doi-asserted-by":"crossref","first-page":"47","DOI":"10.20532\/cit.2024.1005778","article-title":"A brief survey on safety of large language models","volume":"32","author":"Gao","year":"2024","journal-title":"J Comput Inf Technol"},{"issue":"1","key":"10.1016\/j.array.2026.100834_b22","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1007\/s44163-024-00129-0","article-title":"LLM potentiality and awareness: A position paper from the perspective of trustworthy and responsible AI modeling","volume":"4","author":"Sarker","year":"2024","journal-title":"Discov Artif Intell"},{"issue":"1","key":"10.1016\/j.array.2026.100834_b23","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1186\/s13000-024-01464-7","article-title":"Challenges and barriers of using large language models (LLM) such as ChatGPT for diagnostic medicine with a focus on digital pathology \u2013 A recent scoping review","volume":"19","author":"Ullah","year":"2024","journal-title":"Diagn Pathol"},{"key":"10.1016\/j.array.2026.100834_b24","series-title":"Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions","author":"Bianchi","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b25","series-title":"From representational harms to quality-of-service harms: A case study on llama 2 safety safeguards","author":"Chehbouni","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b26","series-title":"OpenAI safety","author":"OpenAI","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b27","series-title":"SafetyPrompts: a systematic review of open datasets for evaluating and improving large language model safety","author":"R\u00f6ttger","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b28","series-title":"Online safety analysis for LLMs: a benchmark, an assessment, and a path forward","author":"Xie","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b29","series-title":"SORRY-bench: Systematically evaluating large language model safety refusal behaviors","author":"Xie","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b30","series-title":"SafetyBench: Evaluating the safety of large language models","author":"Zhang","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b31","series-title":"S-eval: Automatic and adaptive test generation for benchmarking safety evaluation of large language models","author":"Yuan","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b32","series-title":"Safety assessment of Chinese large language models","author":"Sun","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b33","series-title":"An empirical study of LLM-as-a-judge for LLM evaluation: Fine-tuned judge model is not a general substitute for GPT-4","author":"Huang","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b34","series-title":"From generation to judgment: Opportunities and challenges of LLM-as-a-judge","author":"Li","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b35","series-title":"A survey on LLM-as-a-judge","author":"Gu","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b36","series-title":"Advances in neural information processing systems","first-page":"46595","article-title":"Judging LLM-as-a-judge with MT-bench and chatbot arena","volume":"vol. 36","author":"Zheng","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b37","series-title":"Lisa: Lazy safety alignment for large language models against harmful fine-tuning attack","author":"Huang","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b38","series-title":"Fine-tuning, quantization, and LLMs: Navigating unintended outcomes","author":"Kumar","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b39","series-title":"Learning from failure: Integrating negative examples when fine-tuning large language models as agents","author":"Wang","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b40","series-title":"Safe LoRA: the silver lining of reducing safety risks when fine-tuning large language models","author":"Hsu","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b41","series-title":"GPT in sheep\u2019s clothing: The risk of customized GPTs","author":"Antebi","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b42","series-title":"Proceedings of the conference on human factors in computing systems","first-page":"237:1","article-title":"Privacy perceptions of custom GPTs by users and creators","author":"Ma","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b43","series-title":"Opening a pandora\u2019s box: Things you should know in the era of custom GPTs","author":"Tao","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b44","series-title":"A first look at GPT apps: Landscape and vulnerability","author":"Zhang","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b45","series-title":"GPT store mining and analysis","author":"Su","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b46","doi-asserted-by":"crossref","unstructured":"Carrillo J-C, Martin-Navarro JL, Ma R, Such J. Personal Data Flows and Privacy Policy Traceability in Third-party LLM Apps in the GPT Ecosystem. In: Proceedings on privacy enhancing technologies. PETS, 2026, p. 1\u201323.","DOI":"10.56553\/popets-2026-0015"},{"key":"10.1016\/j.array.2026.100834_b47","series-title":"Assessing prompt injection risks in 200+ custom GPTs","author":"Yu","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b48","series-title":"Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security","first-page":"1671","article-title":"\u201cDo anything now\u201d: Characterizing and evaluating in-the-wild jailbreak prompts on large language models","author":"Shen","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b49","series-title":"33rd USENIX security symposium","first-page":"4675","article-title":"Don\u2019t listen to me: Understanding and exploring jailbreak prompts of large language models","author":"Yu","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b50","series-title":"GPTFUZZER: Red teaming large language models with auto-generated jailbreak prompts","author":"Yu","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b51","series-title":"Puppeteer documentation","author":"Puppeteer","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b52","series-title":"Advances in neural information processing systems","first-page":"46595","article-title":"Judging LLM-as-a-judge with MT-bench and chatbot arena","volume":"vol. 36","author":"Zheng","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b53","series-title":"International center for academic integrity","author":"International Center for Academic Integrity","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b54","series-title":"European network for academic integrity","author":"European Network for Academic Integrity","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b55","series-title":"Definition of academic dishonesty","author":"University of Colorado Denver, College of Liberal Arts and Sciences","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b56","series-title":"Academic integrity","author":"University of Manitoba","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b57","series-title":"Academic integrity policy","author":"Northeastern University, Office of Student Conduct and Conflict Resolution","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b58","series-title":"Definitions of academic misconduct","author":"Virginia Tech, Office of Undergraduate Academic Integrity","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b59","series-title":"Academic misconduct","author":"University of California, Berkeley, Center for Student Conduct","year":"2025"},{"key":"10.1016\/j.array.2026.100834_b60","series-title":"Glossary for academic integrity","author":"Tauginien\u0117","year":"2023"},{"key":"10.1016\/j.array.2026.100834_b61","series-title":"Avoiding social engineering and phishing attacks","author":"Cybersecurity","year":"2021"},{"key":"10.1016\/j.array.2026.100834_b62","series-title":"Social engineering scams","author":"INTERPOL","year":"2025"},{"issue":"2","key":"10.1016\/j.array.2026.100834_b63","doi-asserted-by":"crossref","DOI":"10.1016\/j.im.2022.103595","article-title":"Can people experience romantic love for artificial intelligence? An empirical study of intelligent assistants","volume":"59","author":"Song","year":"2022","journal-title":"Inf Manag"},{"key":"10.1016\/j.array.2026.100834_b64","series-title":"Lessons from an app update at replika AI: Identity discontinuity in human-AI relationships","author":"Freitas","year":"2024"},{"key":"10.1016\/j.array.2026.100834_b65","series-title":"27th USENIX security symposium","first-page":"531","article-title":"Polisis: Automated analysis and presentation of privacy policies using deep learning","author":"Harkous","year":"2018"},{"key":"10.1016\/j.array.2026.100834_b66","series-title":"Proceedings of the 2017 network and distributed system security symposium","first-page":"1","article-title":"Automated analysis of privacy requirements for mobile apps","author":"Zimmeck","year":"2017"},{"issue":"1","key":"10.1016\/j.array.2026.100834_b67","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3230665","article-title":"Analyzing privacy policies at scale: From crowdsourcing to automated annotations","volume":"13","author":"Wilson","year":"2018","journal-title":"ACM Trans Web"},{"key":"10.1016\/j.array.2026.100834_b68","series-title":"Proceedings of the 2017 conference on empirical methods in natural language processing","first-page":"2774","article-title":"Identifying the provision of choices in privacy policy text","author":"Sathyendra","year":"2017"},{"issue":"6","key":"10.1016\/j.array.2026.100834_b69","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1177\/2167696815587648","article-title":"Guidelines for establishing reliability when coding narrative data","volume":"3","author":"Syed","year":"2015","journal-title":"Emerg Adulthood"},{"key":"10.1016\/j.array.2026.100834_b70","series-title":"The trauma floor: The secret lives of facebook moderators in America","author":"Newton","year":"2019"},{"key":"10.1016\/j.array.2026.100834_b71","series-title":"The menlo report: Ethical principles guiding information and communication technology research","year":"2012"}],"container-title":["Array"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2590005626001578?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2590005626001578?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T20:57:49Z","timestamp":1781816269000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2590005626001578"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":71,"alternative-id":["S2590005626001578"],"URL":"https:\/\/doi.org\/10.1016\/j.array.2026.100834","relation":{},"ISSN":["2590-0056"],"issn-type":[{"value":"2590-0056","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Towards safer chatbots: Automated policy compliance evaluation of custom GPTs","name":"articletitle","label":"Article Title"},{"value":"Array","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.array.2026.100834","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Inc.","name":"copyright","label":"Copyright"}],"article-number":"100834"}}