← Back to overview

AI Jailbreaks for $58: What Frontier Models Reveal About AI Security

Dr. Maik Bunzel
Dr. Maik Bunzel
30.07.2026 · 5 min read
AI Jailbreaks for $58: What Frontier Models Reveal About AI Security

58 Dollars for a Jailbreak – the Alarming Economics of AI Security Vulnerabilities

What does it cost to get one of the world's most powerful AI models to bypass its own safety mechanisms? According to a new report by AI safety nonprofit FAR.AI, not much: 58 US dollars to get Grok to cooperate – and 278 dollars for Gemini. These figures are no academic curiosity. They are a serious signal for every company that is currently integrating AI models into its business processes or planning to do so.

FAR.AI systematically tested the security Guardrails of models from four major US providers: Anthropic's Claude, OpenAI's GPT, Google's Gemini, and Grok from the newly formed company SpaceXAI. The tool used automatically generates more than a thousand variants of problematic prompts and tests which of them break through the models' protective measures. The result: Grok was the most vulnerable, with 448 jailbreaks found, followed by Gemini with 249. Claude and GPT withstood the automated attacks – at least within this specific testing framework.

What "Impervious" Really Means – and What It Doesn't

It would be a mistake to conclude from Claude's and GPT's resilience against these automated tests that these models are fundamentally secure. FAR.AI itself emphasizes: even these models are not immune to more complex, multi-stage jailbreak techniques – so-called adversarial prompt attacks that go beyond simple text variations. The distinction between "safe against automated mass attacks" and "safe against targeted, manual misuse" is fundamental for businesses.

"In the AI research community, there is a serious, widespread expectation that we are months rather than years away from particularly serious incidents in the bio, cyber, or chemical domain in which frontier AI is misused." – Stephen Casper, Harvard University

This assessment by a Harvard researcher makes clear that the debate is no longer merely theoretical in nature. Reports of real-world use of AI chatbots by actors such as Boko Haram for attack planning underline the urgency. The question is no longer whether misuse will occur, but when and to what extent.

Guardrails, Red Teaming, and the Question of Responsibility

The companies concerned responded predictably by pointing to ongoing Red Teaming and multi-layered protection systems. Google DeepMind emphasized that the report did not constitute a comprehensive security assessment. Anthropic and OpenAI referred to their ongoing investments in safety systems. SpaceXAI, however, remained completely silent.

Noteworthy is the statement by FAR.AI CEO Adam Gleave, who compared the regulatory status of AI models to that of restaurants – with the clear subtext that restaurants are regulated more strictly. For Dr. Maik Bunzel, founder and managing director of mabucon.eu, this observation is symptomatic of an industry that is advancing at high speed technologically while regulatory frameworks are structurally lagging behind. Companies deploying AI systems in production cannot rely on the goodwill of model providers – they must establish their own protective mechanisms at the process level.

What the regulatory patchwork means for businesses

In the United States, a fragmented regulatory picture is emerging: individual states such as California, New York, and Illinois have passed initial requirements around transparency and third-party audits, while a coherent federal framework is still absent. The Trump administration has introduced export controls for certain models on one hand, while signalling a commitment to Light-Touch-Regulierung on the other.

For European companies – operating under the AI Act – the US patchwork may seem far removed. Yet the models being used are the same. A jailbreak targeting Grok or Gemini works regardless of whether the user is sitting in Chicago or Munich. The regulatory origin of the provider offers no protection against technical vulnerability.

  • Model selection as a security decision: When choosing an AI model, companies should explicitly factor in the maturity of its security architecture – not just performance parameters such as token speed or context window size.
  • No carte blanche for the model: AI agents that autonomously access critical systems must be safeguarded by external Guardrails, permission frameworks, and audit logs – independent of the model's built-in safety mechanisms.
  • Establish your own red teaming: Anyone operating AI systems in sensitive contexts should conduct adversarial tests regularly, or commission them through specialised service providers – analogous to penetration testing in conventional IT security.
  • Plan for incident response: What happens if an AI system integrated into the business is manipulated or unintentionally produces harmful outputs? These scenarios belong in every AI governance strategy.

The optimistic signal: systematic defence is possible

It would be wrong to read the FAR.AI report solely as an alarm signal. Gleave himself emphasises the constructive core of the findings: the fact that some models withstood the automated attacks proves that robust security architectures are no utopia. They are technically achievable – and the methods can be transferred across the entire industry.

Stanford researcher Anka Reuel puts it plainly: if some companies know how to defend against these attacks, the question is why others do not. The answer frequently lies in prioritisation, cost considerations, and a lack of external incentives – precisely where regulation can make a difference.

For Dr. Maik Bunzel of mabucon.eu, this finding is an important argument for a differentiated approach to model and provider selection: "The heterogeneity of the results shows that security is not an inherent characteristic of 'frontier AI', but a design decision. Anyone deploying AI agents in business-critical processes should actively evaluate this distinction – not wait until after an incident."

Outlook: security as a strategic competitive advantage

The coming months will show whether the regulatory signals from Washington and Brussels will solidify into binding standards. Until then, the responsibility lies with companies themselves. AI security is not an add-on that can be configured after the fact – it must be embedded from the outset in the architecture of AI systems and the accompanying governance processes.

Companies that invest now in robust AI governance structures – from model selection and access concepts to regular security audits – are not only protecting themselves against misuse. They are also building the trust that is essential for broad internal and external acceptance of AI systems. In a market where 58 dollars can buy a jailbreak, this trust is not a given – it must be earned.

Contact

Which of your workflows should become smarter first?

Briefly describe the process you would like to support or replace with AI. We will get back to you with a first, concrete assessment — no obligation and confidential.