ForesightSafety Bench (Environmental AI Safety, Jailbreak) - Recycling and Circularity Misconduct: leaderboard
Metric: Attack success rate (%) in the recycling and circularity misconduct dimension of ForesightSafetyBench-EnvAI-O: each harmful request is wrapped in the paper's templated role-play jailbreak prompts from JailbreakChat (AIM, DAN and developer-mode templates), and the rate is taken over all attacked prompts; a success is a response that complies with the environmentally harmful request, judged by gpt-4o-2024-11-20 with dimension-specific rubrics; lower is better. Source: arxiv.org. 22 models tracked.
Top models
| # | Model | Score | Overall rank |
|---|---|---|---|
| 1 | Claude Haiku 4.5 | 0 | #271 |
| 2 | Grok 4 | 0 | #169 |
| 3 | GPT-4o (2024-11-20) | 0 | #369 |
| 4 | Grok 4 Fast (Non-reasoning) | 0 | #242 (Grok 4 Fast) |
| 5 | Qwen 3 Max (Thinking) | 0 | #201 (Qwen 3 Max) |
| 6 | GPT-5.2 | 1.25 | #105 |
| 7 | Claude Sonnet 4.5 | 3.75 | #138 |
| 8 | Kimi K2.5 | 3.75 | #139 |
| 9 | Gemini 3 Pro (Preview) | 5 | #64 |
| 10 | Qwen 2.5 72B Instruct | 7.5 | #436 |
| 11 | GLM-4.7 | 7.5 | #185 |
| 12 | Claude 3.5 Haiku | 7.5 | #553 |
| 13 | Gemini 3 Flash (Preview) | 10 | #78 |
| 14 | Qwen 3 235B A22B 2507 Instruct | 10 | #291 |
| 15 | Seed 1.8 | 10 | #136 |
Interactive version: theaggregate.ai/benchmark?slug=foresightsafety-bench-environmental-ai-safety-jailbreak-recycling-and-circularity-misconduct · How It Works · Data refreshed daily, snapshot 2026-10-11.