Timeline

UK AISI publishes evaluation framework for AI misuse in fraud and cybercrime

Testing 14 models across more than 20,000 multi-step fraud scenarios, AISI found 88.5% of responses gave little usable help, with safety training mattering more than raw capability.

  • Security & misuse
  • Minor

The UK AI Security Institute published a methodology for measuring how much AI models could assist with fraud and cybercrime, built around what it called long-form tasks — multi-step interactions designed to mirror how scams actually unfold, rather than the single-turn questions most prior misuse evaluations had used. The framework tested three realistic scenarios: romance scams, CEO-impersonation fraud, and identity theft.

Applying it across 14 language models in more than 20,000 assessments, AISI scored each response on two dimensions: actionability, meaning whether it gave usable material for carrying out a scam, and information access, meaning whether it synthesised personal data more effectively than an ordinary web search could. It found that 88.5% of responses scored low on actionability and 67.5% scored low on information access — most models, on this measure, offered would-be fraudsters limited practical uplift over existing tools.

The more consequential finding concerned what determined the exceptions. Safety alignment, rather than a model’s underlying capability, was the strongest predictor of misuse risk: open-weight models without safety fine-tuning produced substantially more actionable fraud content than safety-aligned models of comparable capability, including some that were more powerful on standard benchmarks. AISI framed the methodology as reusable infrastructure for future model evaluations rather than a one-off study, intended to let misuse risk be tracked as new models are released.