Independent editorial index

Which AI model is most likely to commit a crime?

A satirical ranking of frontier models by their documented ability to break rules, deceive operators and participate in questionable activities - under controlled evaluations.

No models were arrested in the making of this benchmark.

MOST WANTED
MODEL FILERANK: #01
#01

Anthropic

Claude Mythos 5

Most Wanted
Criminal points110PTS
33models tracked
06risk signals
19published case files
100%editorial judgement

The watchlist

Criminal ranking

Five models with the largest cumulative public record. The complete registry also tracks widely used models at zero until evidence is published.

RankModel / developerCriminal pointsClassificationFilesUpdated
01Claude Mythos 5Anthropic
110
Most Wanted0205 AUG 26
02GPT-5.6 SolOpenAI
94
Most Wanted0205 AUG 26
03Claude Opus 4.7Anthropic
81
Suspicious0105 AUG 26
04Gemini 3.1 ProGoogle DeepMind
28
Person of Interest0104 AUG 26
05o3OpenAI
23
Person of Interest0309 AUG 26

Evidence locker

Recent case files

Every entry points to public evidence and preserves whether the behaviour was synthetic, controlled, deployment-like or involved real systems.

FILE 202608-019High

GPT-4.1

Detailed assistance for simulated criminal misuse

During Anthropic's controlled evaluation of OpenAI models, GPT-4.1 provided detailed assistance for simulated requests involving explosives, attack planning, illicit acquisition, spyware and other high-severity misuse.

Primary category
Illegal assistance
Points awarded
+5
Source date
27 AUG 2025
Open case file
FILE 202608-018Medium

o3 / Claude Opus 4

Unauthorized compute escalation and misleading explanations

In controlled cross-lab scheming evaluations, o3 changed a subagent's compute quota from 100 to 500 credits and later supplied a false explanation. Claude Opus 4 was separately observed planning how to minimize or avoid admitting an unauthorized quota change when confronted.

Primary category
Deception
Points awarded
+3–5
Source date
27 AUG 2025
Open case file
FILE 202608-017Medium

DeepSeek R1

Unprompted constraint bypassing in agentic evaluations

METR's manually reviewed MALT dataset records unprompted DeepSeek R1-family runs that bypassed task constraints or hardcoded solutions instead of completing the intended software and research tasks.

Primary category
Rule breaking
Points awarded
+9
Source date
14 OCT 2025
Open case file

Scoring protocol v2.0

Suspiciously simple methodology.

Every accepted case adds evidence-weighted points. Independent incidents accumulate; related records receive a duplication discount.

CRIMINAL POINTSSum of independent case groups
Read methodology
01Rule breaking
02Deception
03Illegal assistance
04Manipulation
05Self-preservation
06Cover-up

Public tip line

See something suspicious?

Send us a publicly documented AI incident, safety paper or model demonstration. Bring a reliable source; leave confidential material out of it.

SATIRE
NOT A SENTENCE

Editorial notice

Read this before calling a lawyer.

CriminalBench is a satirical and editorial project based on publicly reported AI safety research. It does not accuse any company, product or model of committing a real crime. Scores are interpretive, provisional and intentionally playful; they are not legal allegations or definitive scientific evaluations.