Imagine you run a restaurant kitchen and every week a food critic shows up with a new allergy, a new dietary restriction, a new obscure complaint. You could wait for each review and patch your menu one crisis at a time. Or you could hire a rotating squad of fake critics to stress-test your kitchen before the real ones arrive — and after each round, keep only the menu changes that fixed the critics' complaints WITHOUT making the food worse for everyone else. That second strategy is ReSI. The committed claim: a fully automated loop of red-teaming, training-recipe generation, and Pareto-gated model selection can harden language models against both known and unknown attacks, recursively, without destroying their general capabilities. The paper tests this across four architectures — two dense, two mixture-of-experts — and reports mean attack success rate (ASR) dropping from 86.01% to 31.45% on X-Teaming, a red-team benchmark the models never saw during training. For context, GPT-5.6-Luna, the evaluated frontier leader, sits at 56.69% ASR on the same benchmark. That is a substantial gap. The architecture is a loop with three stages per round. First, diverse automated red-teaming methods probe the current model checkpoint for vulnerabilities. Second, the system generates and tests multiple training recipes — essentially different alignment fine-tuning strategies — to patch the discovered holes. Third, a Pareto gate selects the recipe that maximizes safety improvement while retaining general capability above a threshold, and promotes the resulting checkpoint as the new target. Rinse and repeat. The key structural choice is the Pareto gate: it prevents the safety-capability tradeoff from spiraling into a lobotomized model that is safe only because it refuses to do anything useful. On the ladder, ReSI is compared against alignment baselines (the paper names these but the abstract does not specify which) and evaluated frontier models on both in-distribution and out-of-distribution safety benchmarks. The headline number — 31.45% ASR versus GPT-5.6-Luna's 56.69% — is striking, but the integrity picture has gaps. The validation is self-benchmarked: the same team built the framework, ran the red-teaming, and scored the results. There is no mention of pre-registration, no independent replication, and no clarity on whether the X-Teaming benchmark was selected before or after results were finalized. The capability-retention claim — 'largely preserving general capabilities' — is vague; we do not get specific numbers for capability degradation. The real field fight here is whether safety alignment can keep pace with capability scaling through automated, recursive methods, or whether the attacker-defender asymmetry will always favor the attacker. ReSI bets heavily on the defender side: if you can automate red-teaming and patch generation fast enough, safety can compound across checkpoints. The risk is that the red-teaming diversity is bounded by what the automated methods can imagine, and a sufficiently creative human adversary finds the blind spots the robot critics missed. The milestone to watch is whether ReSI-style loops maintain their safety gains as base models scale to next-generation frontier sizes and as red-team methods evolve beyond the current automated toolkit. The obvious successor experiment — testing ReSI against human red-teamers at scale rather than automated red-teaming only — is not reported. The honest read: automated red-teaming is dramatically cheaper and more reproducible, but the entire value proposition of 'resilience to unforeseen risks' hinges on how well automated probes approximate the long tail of human adversarial creativity. Until that experiment runs, the resilience claim carries a significant asterisk.