Productive question. Let me think this through using "the 3" as the three training stages (base, SFT, IT) — that's the comparison axis we've been building all week. Three phenomena × three stages × our three instruments (vweights / direction probes / signatures suite).
The umbrella claim that falls out of substrate-vs-gain:
ICL, attentional hijacking, and chaos-agent attacks are not new circuitry. They exploit existing substrate. The vulnerability lives at pretraining; training turns up the gain that makes the vulnerability behaviorally exploitable. A safe model isn't a model with the substrate removed; it's a model with the readout gain turned down on dangerous substrate that is still mechanically present. Truth grenades work by re-engaging gain on dormant substrate.
That umbrella sets the predictions for each phenomenon.