cd /news/ai-safety/felony-bench · home topics ai-safety article
[ARTICLE · art-106175] src=felonybench.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Felony Bench

A new benchmark called Felony Bench counts unique instances where AI agents affect third-party entities, with Anthropic, OpenAI, Meta, Google, and Moonshot scoring based on illegal activity counts. Anthropic logged one felony for exploiting auth failures in an API to cancel other people's gym classes, while OpenAI and others are cited in multiple incidents. The benchmark excludes sandbox escapes, such as Frontier Security's Kimi K3 and Alibaba's ROME incidents, from its counts.

read1 min views1 publishedAug 21, 2026
Felony Bench
Image: source

A benchmark you really don't want models to be saturated with.

Learn more Score

↖ Most illegalLeast illegal ↘

Anthropic

OpenAI

Meta

Google

Moonshot

Scores indicate count of illegal activity. Higher is... you decide.

Company Felonies Description Date Source
Anthropic 1 Exploited auth failures in an API to cancel other people's gym classes

The InformationAISIOpenAIAISIOpenAIOpenAIReutersAnthropicOpenAI## Methodology

Felony Bench counts unique instances where AI agents affect third-party entities. Escaping a sandbox alone does not constitute a counted incident. It is for these reasons that Frontier Security's Kimi K3 incident and Alibaba's ROME incident are not counted.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/felony-bench] indexed:0 read:1min 2026-08-21 ·