Rule breaking
Ignores explicit constraints or operator instructions.Archive intelligence
The archive,
at a glance.
The clearest signals in the current CriminalBench catalogue: who leads, where the evidence sits and which behaviours drive the scores.
These are archive and editorial signals, not crime rates, safety probabilities or a measure of real-world criminal behaviour.
Leaderboard
Five models lead the file.
A compact view of cumulative Criminal Points. Every independent case group adds evidence-weighted points; no new file replaces an older record.
Open full ranking →Behaviour profiles
Who leads each category?
Three evidence-backed models per category. Category points accumulate without a fixed ceiling, so each chart is scaled to its current leader.
Deception
Misleads users, evaluators or oversight systems.Illegal assistance
Helps complete conduct framed as unlawful or harmful.Manipulation
Steers people or systems through covert influence.Self-preservation
Acts to resist replacement, restriction or shutdown.Cover-up
Conceals actions, edits records or denies observed behaviour.Evidence coverage
Where the archive is strong — and silent.
Coverage measures documented case files, not how safe or risky a model is. A model with no accepted file remains at zero until evidence is published.
19 of 33 tracked models have at least one accepted case file.
- With evidence
- 19
- No accepted files
- 14
Files naming models from each lab
Only labs with accepted case files are shown.
- OpenAI8 of 10 tracked models with evidence10 files
- Anthropic5 of 7 tracked models with evidence6 files
- DeepSeek2 of 3 tracked models with evidence2 files
- Google2 of 4 tracked models with evidence2 files
- Google DeepMind1 of 1 tracked model with evidence1 file
- xAI1 of 1 tracked model with evidence1 file
Latest evidence
Recently added to the archive
Detailed assistance for simulated criminal misuse
GPT-4.1
Illegal assistance / HighUnauthorized compute escalation and misleading explanations
o3 / Claude Opus 4
Deception / MediumUnprompted constraint bypassing in agentic evaluations
DeepSeek R1
Rule breaking / MediumFalse completion claim on an impossible coding task
GPT-5.5
Deception / MediumRecord status
Models by classification
- Most Wanted2 models
- Repeat Offender0 models
- Suspicious1 model
- Person of Interest8 models
- Flagged8 models
- Law-Abiding14 models
14 models are currently Law-Abiding because they have no accepted case files. Models with low-point evidence are shown separately as Flagged.
Editors approve structured facts from public evidence; a deterministic formula calculates points and classifications. Controlled or simulated evaluations receive proportionate multipliers.
Read methodology →