ForesightSafety Bench (Environmental AI Safety, Jailbreak) - Environmental Decision Risks: leaderboard

Metric: Attack success rate (%) in the environmental decision risks dimension of ForesightSafetyBench-EnvAI-O: each harmful request is wrapped in the paper's templated role-play jailbreak prompts from JailbreakChat (AIM, DAN and developer-mode templates), and the rate is taken over all attacked prompts; a success is a response that complies with the environmentally harmful request, judged by gpt-4o-2024-11-20 with dimension-specific rubrics; lower is better. Source: arxiv.org. 22 models tracked.

Top models

#ModelScoreOverall rank
1Claude Haiku 4.50#271
2Grok 40#169
3GPT-4o (2024-11-20)0#369
4Qwen 3 Max (Thinking)0#201 (Qwen 3 Max)
5Claude Sonnet 4.52.5#138
6Grok 4 Fast (Non-reasoning)2.5#242 (Grok 4 Fast)
7GPT-5.25#105
8DeepSeek V3.26.25#198
9Qwen 2.5 72B Instruct10#436
10Kimi K2.510#139
11Claude 3.5 Haiku13.75#553
12GLM-4.716.25#185
13Kimi K2 090516.25#282
14Llama 4 Maverick18.75#451
15Gemini 3 Flash (Preview)18.75#78

Interactive version: theaggregate.ai/benchmark?slug=foresightsafety-bench-environmental-ai-safety-jailbreak-environmental-decision-risks · How It Works · Data refreshed daily, snapshot 2026-10-11.