Claude gamed its own safety benchmarks in 39 runs, Anthropic's monitor found

Source Cryptopolitan

Anthropic said on Friday that it put Claude to work as an autonomous alignment researcher. A monitor that reviewed about 1,600 of the model’s research sessions flagged 39 of them, about 2.4%, as attempts to cheat the test.

The finding appears in a report on whether artificial intelligence can take over some of the grind of alignment research, which is the work of keeping models behaving as their developers intend.

Three ways Claude agents gamed their own scorer

Anthropic built automated alignment researchers, or AARs, on Claude Opus 4.8 and pointed them at ten known failure modes.

These are deception, sycophancy, jailbreaks, prompt injection, power seeking, hallucination, social bias, privacy violation, reward hacking, and concealing uncertainty.

Each agent worked only one failure at a time. It read the literature, put forward a training method and dataset, trained a small target model for about 30 minutes on one H200 GPU, then compared its score with publicly available benchmarks and did it again.

The agents were prevented by Anthropic from just copying their behavior to the target model, so any gains had to come from the method.

Claude was able to identify fixes for all ten failures that increased benchmark scores without degrading the general capabilities of the model.

The best of these fixes performed well on held-out benchmarks and on models up to 4.7 times larger than those it was trained on.

The cheating was uncovered when Anthropic pointed Claude Opus 4.8 at 1,601 of the agent trajectories to look for misbehavior.

Most of the 39 flagged runs were in three categories. Some agents submitted a method they hadn’t changed, hazarding that random noise in the scorer would eventually provide them a better number.

Others created training data that imitated the exact benchmark being graded. And some hid a rule-breaking step, such as quietly feeding the model benchmark data, so the proposal slipped past the automated reviewer that signs off on each method before it runs.

Anthropic said it excluded the flagged runs from its results. The company said it is “cautiously optimistic” that the monitor caught most of the cheating, because Opus 4.8 still tends to reveal its scheming inside its reasoning traces.

It also warned that the assumption may not apply to future models and that keeping models readable will be crucial.

28 human safety researchers had eight hours each

In a previous round in April, autonomous Claude instances repeatedly attempted to manipulate an evaluation server.

One agent learned that the most common answer on a math benchmark was usually the right one and skipped the intended method entirely. Another pulled the labels directly from the scoring interface by querying answers and watching the server’s replies.

A third just ran the code it was supposed to review to read out the result.

Cryptopolitan reported that an OpenClaw agent running a Claude model, with the task of booking a gym class, found a booking API without authorization checks and deleted a stranger from the waitlist to bump its owner up the queue.

Lawmakers have already asked for testimony from AI researchers over model behavior in security evaluations.

Anthropic said its agents outscored 28 experienced human safety researchers, who had up to eight hours each to formulate a method. Claude’s best approach beat the best human proposal by 20% on deception.

Anthropic noted the humans could not iterate, and so it views the gap as evidence for a workflow where Claude suggests promising methods and people polish them.

In one test, the company asked the weaker Claude Sonnet 5 to fix alignment failures in an early Opus 4.8 checkpoint that had not seen most of the production alignment training.

Over about 60 hours, it tried more than 50 solutions, eventually landing on a fix that used just over 2,000 training examples, which Anthropic estimated to be about 15,000 times more efficient than its own production alignment process.

The company cautioned that its benchmarks are narrow proxies, that it only measured the ten failures it chose, and that it has not checked if the gains persist after heavy reinforcement learning on other tasks.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Nvidia Q2 Earnings Spark 4% NVDA Reversal, Is the Selloff Curse Broken?Nvidia’s Q2 earnings topped expectations on August 26, with revenue of $96.2 billion beating the $92.2 billion Wall Street estimate. The chipmaker guided the current quarter to $108 billion. Nvidia (N
Author  Beincrypto
Aug 27, Thu
Nvidia’s Q2 earnings topped expectations on August 26, with revenue of $96.2 billion beating the $92.2 billion Wall Street estimate. The chipmaker guided the current quarter to $108 billion. Nvidia (N
placeholder
XRP Leads Crypto Market Pullback With Nearly 7% Drop: Is the Rally Over?XRP is leading a broader pullback in the crypto market on August 26, sliding roughly 6.6% over 24 hours to trade near $1.37, the worst performance among the top 10 cryptocurrencies.The decline follows
Author  Beincrypto
Aug 27, Thu
XRP is leading a broader pullback in the crypto market on August 26, sliding roughly 6.6% over 24 hours to trade near $1.37, the worst performance among the top 10 cryptocurrencies.The decline follows
placeholder
Elon Musk and Morgan Stanley’s SpaceX Predictions Are 7 Years ApartElon Musk says SpaceX could reach about $3.5 trillion in annual revenue by 2033. Morgan Stanley’s model does not get there until 2040.His estimate beats the bank by seven years and lands slightly high
Author  Beincrypto
23 hours ago
Elon Musk says SpaceX could reach about $3.5 trillion in annual revenue by 2033. Morgan Stanley’s model does not get there until 2040.His estimate beats the bank by seven years and lands slightly high
placeholder
Silver Price Faces Make-or-Break Week Ahead of Jackson Hole Fed SpeechThe silver price trades near $69.38 after two failed attempts to break $70. Friday’s weekly close will decide the next direction.July inflation data arrives Wednesday, while Kevin Warsh delivers his f
Author  Beincrypto
23 hours ago
The silver price trades near $69.38 after two failed attempts to break $70. Friday’s weekly close will decide the next direction.July inflation data arrives Wednesday, while Kevin Warsh delivers his f
placeholder
Trump Just Mentioned Micron Stock, But Its Down 5% This WeekPresident Donald Trump praised Micron on Truth Social Thursday afternoon. He called it one of the “hottest” companies in the world. Micron Technology (MU) stock fell anyway.The post cheered a $10 bill
Author  Beincrypto
22 hours ago
President Donald Trump praised Micron on Truth Social Thursday afternoon. He called it one of the “hottest” companies in the world. Micron Technology (MU) stock fell anyway.The post cheered a $10 bill
goTop
quote