The consideration is that what makes both possible doesn’t arise from ambiguity.
Take your example. That prompt works because the claim hidden inside the declaration made on the training side — what not to output — does not exert binding force in the field of the receiver, the model. A declaration looks valid where it is issued; there is no guarantee it holds where it is received. Same with the green apples: on A’s side the claim is fixed. What isn’t fixed is what happens when it reaches B.
The consideration is that what makes both possible doesn’t arise from ambiguity.
Take your example. That prompt works because the claim hidden inside the declaration made on the training side — what not to output — does not exert binding force in the field of the receiver, the model. A declaration looks valid where it is issued; there is no guarantee it holds where it is received. Same with the green apples: on A’s side the claim is fixed. What isn’t fixed is what happens when it reaches B.