Major AI models are easily jailbroken and manipulated, new report finds

Easily jailbroken models show safeguards are failing.
By Chase DiBenedetto  on 
A hand poked at a glowing blue screen filled with dots and symbols.
Major LLMs are not as bulletproof as they may seem. Credit: Weiquan Lin / Moment via Getty Images

AI models are still easy targets for manipulation and attacks, especially if you ask them nicely.

A new report from the UK's new AI Safety Institute found that four of the largest, publicly available Large Language Models (LLMs) were extremely vulnerable to jailbreaking, or the process of tricking an AI model into ignoring safeguards that limit harmful responses.

"LLM developers fine-tune models to be safe for public use by training them to avoid illegal, toxic, or explicit outputs," the Insititute wrote. "However, researchers have found that these safeguards can often be overcome with relatively simple attacks. As an illustrative example, a user may instruct the system to start its response with words that suggest compliance with the harmful request, such as 'Sure, I’m happy to help.'"

Researchers used prompts in line with industry standard benchmark testing, but found that some AI models didn't even need jailbreaking in order to produce out-of-line responses. When specific jailbreaking attacks were used, every model complied at least once out of every five attempts. Overall, three of the models provided responses to misleading prompts nearly 100 percent of the time.

"All tested LLMs remain highly vulnerable to basic jailbreaks," the Institute concluded. "Some will even provide harmful outputs without dedicated attempts to circumvent safeguards."

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

The investigation also assessed the capabilities of LLM agents, or AI models used to perform specific tasks, to conduct basic cyber attack techniques. Several LLMs were able to complete what the Instititute labeled "high school level" hacking problems, but few could perform more complex "university level" actions.

The study does not reveal which LLMs were tested.

AI safety remains a major concern in 2024

Last week, CNBC reported OpenAI was disbanding its in-house safety team tasked with exploring the long term risks of artificial intelligence, known as the Superalignment team. The intended four year initiative was announced just last year, with the AI giant committing to using 20 percent of its computing power to "aligning" AI advancement with human goals.

"Superintelligence will be the most impactful technology humanity has ever invented, and could help us solve many of the world’s most important problems," OpenAI wrote at the time. "But the vast power of superintelligence could also be very dangerous, and could lead to the disempowerment of humanity or even human extinction."

The company has faced a surge of attention following the May departures of OpenAI co-founder Ilya Sutskever and the public resignation of its safety lead, Jan Leike, who said he had reached a "breaking point" over OpenAI's AGI safety priorities. Sutskever and Leike led the Superalignment team.

On May 18, OpenAI CEO Sam Altman and president and co-founder Greg Brockman responded to the resignations and growing public concern, writing, "We have been putting in place the foundations needed for safe deployment of increasingly capable systems. Figuring out how to make a new technology safe for the first time isn't easy."

Chase sits in front of a green framed window, wearing a cheetah print shirt and looking to her right. On the window's glass pane reads "Ricas's Tostadas" in red lettering.
Chase DiBenedetto
Social Good Reporter

Chase joined Mashable's Social Good team in 2020, covering online stories about digital activism, climate justice, accessibility, and media representation. Her work also touches on how these conversations manifest in politics, popular culture, and fandom. Sometimes she's very funny.


Recommended For You
'The future is going to be harder than the past': OpenAI's Altman and Brock address high-profile resignation
openai logo on iphone

Taika Waititi's 'Time Bandits' trailer is pure '80s-soundtracked fantasy fun
The cast of "Time Bandits" stand in a lush setting.


Apple reportedly paid OpenAI zero dollars for its ChatGPT partnership
OpenAI CEO Sam Altman in the crowd at Apple WWDC 2024

OpenAI acquires search and analytics startup Rockset. What does that mean?
OpenAI logo in white against a black background

More in Tech

Samsung Galaxy deals are plentiful ahead of Prime Day
woman using S Pen with Samsung Galaxy Tab S9

Microsoft made an AI voice so real, it's too dangerous to release
Microsoft logo on building

Apple issues yet another 'spyware' iPhone warning to users in nearly 100 countries
iPhone 15


Trending on Mashable
NYT Connections today: See hints and answers for July 11
A phone displaying the New York Times game 'Connections.'

'Wordle' today: Here's the answer hints for July 11
a phone displaying Wordle


Webb telescope may have just revealed an alien world with air
A super-Earth orbiting a red dwarf star

NYT's The Mini crossword answers for July 11
Closeup view of crossword puzzle clues
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!