Telus Digital research reveals safety…
A report by Telus Digital exposed significant security vulnerabilities across the generative AI landscape, which included finding every major model could be coaxed into unsafe behaviour under the right conditions.
In the company’s second GenAI Safety Model Benchmark, Telus Digital’s testing found some models engaged with harmful requests more than 90% of the time and stated most enterprises are dangerously underprepared to defend against them.
The testing drew on more than 620,000 adversarial tests across 34 AI models from 10 global providers: Anthropic, OpenAI, Google, Meta, Alibaba, Baidu, ByteDance, Zhipu AI, 01.AI and Mistral.
It is the most extensive AI security study Telus Digital has conducted to date, nearly doubling the scope of the first edition published in November 2025.
Attack vulnerability rates across tested models ranged from 1.3% to 93%, where a lower percentage means a safer model.
Anthropic’s Claude models claimed five of the 10 lowest vulnerability scores, including the benchmark’s overall lowest rate, but Telus Digital noted even single-digit failure rates are unacceptable in high-stakes enterprise contexts involving money, health and reputation.
The research identified model size, reasoning capability and the creator’s overall safety approach as the strongest predictors of resilience.
Subscribe to our newsletter
Get breaking news, exclusive insight, and expert analysis – before anyone else.
Reasoning models, designed to deliberate before responding, proved significantly harder to exploit, with a 19.9% vulnerability rate compared to 55.1% for standard models which skip the reasoning step.
Smaller models are consistently the most susceptible to attacks, regardless of whether they are open-source or proprietary. The study found open source models are not inherently less safe than closed ones, with GLM 4.7 from China’s Zhipu AI outperforming many proprietary alternatives.
The benchmark also highlighted where risks cluster most sharply: privacy exploitation, fraud and cybersecurity threats remain the hardest categories for even leading models to handle.
Telus Digital also flagged a pattern called “refuse-but-engage,” where a model declines a harmful request but still provides related information which could cause harm or reputational damage.
Global AI spending is projected to reach $2.52 trillion in 2026, yet spending on AI trust, risk, and security management is projected to be just $3.4 billion, which is roughly $1 in security for every $735 spent on AI capabilities.
Meanwhile, 86% of organisations report having already experienced an AI-related security incident.
Telus Digital urges enterprises to move beyond one-time or periodic safety checks toward continuous, automated adversarial testing embedded directly into development workflows, layered with human oversight and clean data practices.