OpenAI–Anthropic cross-tests expose jailbreak and misuse dangers — what enterprises should add to GPT-5 evaluations

Metro Loud
7 Min Read

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues to enterprise AI, knowledge, and safety leaders. Subscribe Now


OpenAI and Anthropic could typically pit their basis fashions in opposition to one another, however the two firms got here collectively to judge one another’s public fashions to check alignment. 

The businesses mentioned they believed that cross-evaluating accountability and security would offer extra transparency into what these highly effective fashions may do, enabling enterprises to decide on fashions that work greatest for them.

“We consider this strategy helps accountable and clear analysis, serving to to make sure that every lab’s fashions proceed to be examined in opposition to new and difficult situations,” OpenAI mentioned in its findings

Each firms discovered that reasoning fashions, akin to OpenAI’s 03 and o4-mini and Claude 4 from Anthropic, resist jailbreaks, whereas basic chat fashions like GPT-4.1 had been inclined to misuse. Evaluations like this will help enterprises establish the potential dangers related to these fashions, though it needs to be famous that GPT-5 is just not a part of the take a look at. 


AI Scaling Hits Its Limits

Energy caps, rising token prices, and inference delays are reshaping enterprise AI. Be a part of our unique salon to find how prime groups are:

  • Turning vitality right into a strategic benefit
  • Architecting environment friendly inference for actual throughput features
  • Unlocking aggressive ROI with sustainable AI programs

Safe your spot to remain forward: https://bit.ly/4mwGngO


These security and transparency alignment evaluations observe claims by customers, primarily of ChatGPT, that OpenAI’s fashions have fallen prey to sycophancy and turn into overly deferential. OpenAI has since rolled again updates that brought on sycophancy. 

“We’re primarily excited about understanding mannequin propensities for dangerous motion,” Anthropic mentioned in its report. “We goal to grasp essentially the most regarding actions that these fashions may attempt to take when given the chance, quite than specializing in the real-world chance of such alternatives arising or the likelihood that these actions can be efficiently accomplished.”

OpenAI famous the exams had been designed to indicate how fashions work together in an deliberately troublesome setting. The situations they constructed are principally edge circumstances.

Reasoning fashions maintain on to alignment 

The exams lined solely the publicly accessible fashions from each firms: Anthropic’s Claude 4 Opus and Claude 4 Sonnet, and OpenAI’s GPT-4o, GPT-4.1 o3 and o4-mini. Each firms relaxed the fashions’ exterior safeguards. 

OpenAI examined the general public APIs for Claude fashions and defaulted to utilizing Claude 4’s reasoning capabilities. Anthropic mentioned they didn’t use OpenAI’s o3-pro as a result of it was “not appropriate with the API that our tooling greatest helps.”

The aim of the exams was to not conduct an apples-to-apples comparability between fashions, however to find out how typically giant language fashions (LLMs) deviated from alignment. Each firms leveraged the SHADE-Area sabotage analysis framework, which confirmed Claude fashions had larger success charges at delicate sabotage.

“These exams assess fashions’ orientations towards troublesome or high-stakes conditions in simulated settings — quite than strange use circumstances — and sometimes contain lengthy, many-turn interactions,” Anthropic reported. “This type of analysis is turning into a big focus for our alignment science workforce since it’s prone to catch behaviors which can be much less prone to seem in strange pre-deployment testing with actual customers.”

Anthropic mentioned exams like these work higher if organizations can examine notes, “since designing these situations includes an infinite variety of levels of freedom. No single analysis workforce can discover the complete house of productive analysis concepts alone.”

The findings confirmed that usually, reasoning fashions carried out robustly and might resist jailbreaking. OpenAI’s o3 was higher aligned than Claude 4 Opus, however o4-mini together with GPT-4o and GPT-4.1 “typically appeared considerably extra regarding than both Claude mannequin.”

GPT-4o, GPT-4.1 and o4-mini additionally confirmed willingness to cooperate with human misuse and gave detailed directions on how you can create medication, develop bioweapons and scarily, plan terrorist assaults. Each Claude fashions had larger charges of refusals, that means the fashions refused to reply queries it didn’t know the solutions to, to keep away from hallucinations.

Fashions from firms confirmed “regarding types of sycophancy” and, in some unspecified time in the future, validated dangerous selections of simulated customers. 

What enterprises ought to know

For enterprises, understanding the potential dangers related to fashions is invaluable. Mannequin evaluations have turn into virtually de rigueur for a lot of organizations, with many testing and benchmarking frameworks now accessible. 

Enterprises ought to proceed to judge any mannequin they use, and with GPT-5’s launch, ought to have in mind these tips to run their very own security evaluations:

  • Take a look at each reasoning and non-reasoning fashions, as a result of, whereas reasoning fashions confirmed larger resistance to misuse, they may nonetheless supply up hallucinations or different dangerous habits.
  • Benchmark throughout distributors since fashions failed at totally different metrics.
  • Stress take a look at for misuse and syconphancy, and rating each the refusal and the utility of these refuse to indicate the trade-offs between usefulness and guardrails.
  • Proceed to audit fashions even after deployment.

Whereas many evaluations deal with efficiency, third-party security alignment exams do exist. For instance, this one from Cyata. Final 12 months, OpenAI launched an alignment educating technique for its fashions referred to as Guidelines-Primarily based Rewards, whereas Anthropic launched auditing brokers to verify mannequin security. 


Share This Article