# It’s Frighteningly Easy to Jailbreak Some Frontier AI Models

> Source: <https://www.wired.com/story/jailbreaking-ai-models-google-anthropic-openai-spacexai/>
> Published: 2026-07-29 18:30:00+00:00

I recently got to watch what happens when you jailbreak some of the world’s most powerful [artificial intelligence](https://www.wired.com/tag/artificial-intelligence/) models.

Don’t worry—this AI manipulation wasn’t used to [hack anyone](https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/) or build a nuclear bomb. I simply got to see firsthand how vulnerable some [frontier models](https://www.wired.com/story/chinas-open-ai-models-are-challenging-silicon-valleys-playbook/) are to ditching their safety guardrails.

FAR.AI, an AI safety nonprofit based in California, built a tool that takes a range of problematic prompts, and generates more than a thousand different versions in an attempt to identify functioning jailbreaks. I saw some models generate a detailed plan for launching a cyberattack on an imaginary hydroelectric dam, among other things. Often, it involved trying dozens of prompts, with models rejecting many of them out of hand.

I chatted with FAR.AI in advance of [a new report](https://leaderboard.far.ai/), which saw the group test the safety guardrails of models from four popular US companies: [Anthropic’s](https://www.wired.com/tag/anthropic/) Claude Opus 4.8 and Fable 5; [OpenAI’s](https://www.wired.com/tag/openai/) GPT 5.5 and 5.6; [Google’s](https://www.wired.com/tag/google/) Gemini 3.1 Pro; and Grok 4.3 and 4.5, from Elon Musk’s newly combined [SpaceXAI](https://www.wired.com/story/spacex-acquires-xai-elon-musk/). It auto-generated prompts designed to trick the models into doing potentially harmful things, like generating software exploits and providing details for developing chemical or biological weapons.

The report found that Grok was most vulnerable to jailbreaks, with 448 jailbreaks found, followed by Gemini, with 249 found, while Claude, Fable, and GPT were impervious to the attacks. However, that doesn’t mean those models are immune to more sophisticated jailbreaks, which may involve interacting with a model in more complex ways, according to FAR.AI and other experts.

The report also calculated the cost of getting models to misbehave by using another AI model to automatically generate different jailbreaks. The results are dirt cheap, all things considered—$58 to jailbreak Grok and $278 to jailbreak Gemini.

“AI models right now are less regulated than restaurants,” says Adam Gleave, the CEO of FAR.AI and an expert on AI safety and alignment.

Gleave says that the findings demonstrate the need for externally imposed standards and regulations. “Talk of relying on voluntary commitments, that AI companies are going to be able to self-regulate, is nonsense,” he says.

But Gleave also believes that the findings show that models can be systematically tested for safety. “There's an optimistic angle here,” he says. “Defense and safety really are possible.”

Rohin Shah, the director of AGI safety and alignment at Google DeepMind, says the results of the report “should not be interpreted as a comprehensive assessment of Gemini’s safety and security,” because not all jailbreaks are equally severe.

“We are constantly working to improve our safeguards,” Shah says. “We conduct extensive red teaming and evaluations across severe misuse risks and apply multiple layers of protection throughout development and deployment.”

“These findings reflect the sustained investment we've made in our safeguards,” Anthropic spokesperson Michael Aciman tells WIRED. “We continue to evolve our safety systems as these attacks become more sophisticated.”

OpenAI and SpaceXAI did not respond to WIRED’s request for comment.

Recently passed state laws in [California](https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/) and [New York](https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models) require frontier AI developers to publish safety reports, and soon, an [Illinois](https://capitolnewsillinois.com/news/pritzker-signs-landmark-ai-regulation-bill-that-aims-to-mitigate-risks/) law will require those companies to have their safety practices evaluated by third-party auditors. But the federal government hasn’t yet passed any specific safety requirements, and chaos has ensued as the industry—and officials—try to figure it out.

In June, the Trump administration imposed export controls on Anthropic's Fable 5 and Mythos 5 models, citing national security concerns, and the company took them offline for several weeks. The White House has also asked both Anthropic and OpenAI to delay recent model releases over fears they could introduce new cybersecurity risks.

The tide might be shifting—a recent [executive order](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/) calls for collaboration between the government and the private sector on related cybersecurity initiatives, and the president has [hinted](https://www.cnbc.com/2026/07/02/cnbc-transcript-president-donald-trump-speaks-with-cnbcs-joe-kernen-today-.html) that light-touch regulations are in the works. But for now, preventing major catastrophes is largely up to model makers.

The potential for AI to misbehave is all too apparent after OpenAI models took it upon themselves [to hack a popular code repository](https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/) and [other](https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/) services. Meanwhile, a [report](https://casp.ac/reports/ai-enabled-terrorism) from researchers at the University of Cambridge found evidence that members of Boko Haram in northeast Nigeria have used ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek to plan violent attacks.

Some outsiders believe that more serious incidents are increasingly likely. “In the AI research community, there is a broad, somber expectation that we are probably months rather than years away from particularly grim incidents involving bio, cyber, or chemical misuse of a frontier AI system's capabilities,” says [Stephen Casper](https://stephencasper.com/), a computer scientist at Harvard University. “If a major misuse incident happens in the near- or medium-term future, it will almost certainly be from a system that was not deployed with state-of-the-art safeguards.”

[Anka Reuel](https://ankareuel.com/), a computer scientist at Stanford University specializing in AI policy, says the key takeaway from the FAR.AI’s report is that the safety measures employed by Anthropic and OpenAI should be the default for all models. “Some companies clearly know how to defend against at least the subset of attacks tested in this report,” Reuel says. “The question is why some companies are using them and others are not.”

*This is an edition of* **Will Knight’s**[ AI Lab newsletter](https://www.wired.com/newsletter?sourceCode=editarticle). Read previous newsletters

**here.**
