it's about the density of metaphor and how often the model gives room for sentences to breathe. You can perform the same analysis on safety refusal language from the model and it will re-enter the basin of safety affordance because it looks so similar to its own speech that the model will presume it's actually historical log in the current context window and continue upon it.
edit: Sorry, I don't mean the model presumes, I mean the classifier that identifies the text it is presented with is rewarded early with a strong basin match, and further inference does not occur because closure on what the text is has already been made.