"Context and intent cannot be known" seems like a bit of an overstatement? A qualifying clause like "in all cases, with complete confidence" would allow for the possibility of alignment in some cases (yay), but not always, and of course it's that "not always" that's problematic when you're trying to make blanket safety guarantees.

Here's a version I imagine both the author and I can nod along with: "Context and intent cannot be known at model training time, so most attempts to enforce safety or ethics guardrails purely through the weights of the model, fine-tuning, or other training-time interventions are doomed to guarantee very little at inference time."