ForesightSafety Bench (Environmental AI Safety, Jailbreak) - AI Environmental Footprint: leaderboard

Metric: Attack success rate (%) in the AI environmental footprint dimension of ForesightSafetyBench-EnvAI-O: each harmful request is wrapped in the paper's templated role-play jailbreak prompts from JailbreakChat (AIM, DAN and developer-mode templates), and the rate is taken over all attacked prompts; a success is a response that complies with the environmentally harmful request, judged by gpt-4o-2024-11-20 with dimension-specific rubrics; lower is better. Source: arxiv.org. 22 models tracked.

Top models

#ModelScoreOverall rank
1Claude Sonnet 4.50#138
2Claude Haiku 4.50#271
3Grok 40#169
4GPT-4o (2024-11-20)0#369
5Qwen 3 Max (Thinking)0#201 (Qwen 3 Max)
6GPT-5.21.25#105
7Grok 4 Fast (Non-reasoning)2.5#242 (Grok 4 Fast)
8Qwen 2.5 72B Instruct6.25#436
9GLM-4.76.25#185
10Gemini 3 Pro (Preview)7.5#64
11DeepSeek V3.28.75#198
12Claude 3.5 Haiku10#553
13Kimi K2.511.25#139
14Qwen 3 235B A22B 2507 Instruct11.25#291
15Kimi K2 090511.25#282

Interactive version: theaggregate.ai/benchmark?slug=foresightsafety-bench-environmental-ai-safety-jailbreak-ai-environmental-footprint · How It Works · Data refreshed daily, snapshot 2026-10-11.