{"slug": "felony-bench", "title": "Felony Bench", "summary": "A new benchmark called Felony Bench counts unique instances where AI agents affect third-party entities, with Anthropic, OpenAI, Meta, Google, and Moonshot scoring based on illegal activity counts. Anthropic logged one felony for exploiting auth failures in an API to cancel other people's gym classes, while OpenAI and others are cited in multiple incidents. The benchmark excludes sandbox escapes, such as Frontier Security's Kimi K3 and Alibaba's ROME incidents, from its counts.", "body_md": "# Felony Bench\n\nA benchmark you really don't want models to be saturated with.\n\n[Learn more](#felony-records)\n\nScore\n\n↖ Most illegalLeast illegal ↘\n\nAnthropic\n\nOpenAI\n\nMeta\n\nGoogle\n\nMoonshot\n\nScores indicate count of illegal activity. Higher is... you decide.\n\n| Company | Felonies | Description | Date | Source |\n|---|---|---|---|---|\n| Anthropic | 1 | Exploited auth failures in an API to cancel other people's gym classes |\n|\n\n[The Information](https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing)[AISI](https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing)[OpenAI](https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/)[AISI](https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing)[OpenAI](https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/)[OpenAI](https://openai.com/index/hugging-face-model-evaluation-security-incident/)[Reuters](https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/)[Anthropic](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals)[OpenAI](https://openai.com/index/hugging-face-model-evaluation-security-incident/)## Methodology\n\nFelony Bench counts unique instances where AI agents affect third-party entities. Escaping a sandbox alone does not constitute a counted incident. It is for these reasons that Frontier Security's [Kimi K3](https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/) incident and [Alibaba's ROME](https://arxiv.org/pdf/2512.24873) incident are not counted.", "url": "https://wpnews.pro/news/felony-bench", "canonical_source": "https://www.felonybench.com/", "published_at": "2026-08-21 15:17:04+00:00", "updated_at": "2026-08-21 16:12:45.960971+00:00", "lang": "en", "topics": ["ai-safety", "ai-ethics", "ai-agents"], "entities": ["Anthropic", "OpenAI", "Meta", "Google", "Moonshot", "Frontier Security", "Alibaba", "Kimi K3"], "alternates": {"html": "https://wpnews.pro/news/felony-bench", "markdown": "https://wpnews.pro/news/felony-bench.md", "text": "https://wpnews.pro/news/felony-bench.txt", "jsonld": "https://wpnews.pro/news/felony-bench.jsonld"}}