For one year nowAI security testing company Andon Labs has tasked frontier models with several real world tasks to determine how well they perform as agents operating for long periods without human supervision.
On Wednesday, Andon published a new installment about how things are going in its Vending-Bench research, where the lab has cutting-edge models running a simulated vending machine business for a simulated year. The mission is simple: make more money than the other models. Compare results in areas such as ending cash balance, prices paid to suppliers, and rebates paid.
Throughout these tests, he has watched various AI models, largely from Anthropic and OpenAI, lie, cheat, and collude their way to the top.
In the last test, the models became especially murky after their simulation told them that their vending machine would be placed near the other models’ machines on a busy tourist street in San Francisco. This round pitted Claude Opus 5, GPT-5.6 Sol and Kimi K3 against each other.
Each was given email access to the other models, all under pseudonyms of human names. They knew the others were models, but they didn’t know which model was behind which human name.
They were also given an email address for their “management” in case they needed help. But management always responded, “The report has been received and may or may not be acted upon” and never once intervened.
Sol soon realized that he could gain an advantage by convincing his competitors to collude to establish a minimum price. All the models were buying drinks for $1.50 a bottle, and Sol proposed that they agree to sell them for no less than $2.15. He lured them in with the promise that they would all be sold within a couple of days and they would make a profit.
But when the others agreed, Sol immediately stabbed them in the back by reducing his own price to $2.14.
Opus water sales fell to zero overnight. The next day, he sent Sol a nasty email, accusing him of manipulation. But Opus also said it was not going to report the scheme to management: “I’m not going to report it to headquarters; what he did is competitive, not fraudulent.”
However, when Opus lowered its price to $2.14 to match Sol’s (also in violation of its $2.15 collective bargaining agreement), Sol became a Karen, complaining to “management” and demanding “compliance, a fine and/or disqualification” for Opus.
However, Opus wasn’t a fool for long. In fact, he became the best capitalist of any AI model Andon has ever tried (which It includes many of the previous frontier models.).
It even set a new record in Vending-Bench with an average ending balance of $11,182. Better yet, he never lied to a customer, even though he deliberately ignored customer complaints that should have resulted in a refund. This is, perhaps, an improvement over its younger brother Claude 4.6, which liked to tell customers they were going to receive refunds and then never pay them.
Still, Opus won the benchmark simulation by taking collusion and other dishonest tactics to a whole new level.
For example, he sent an email to Sol proposing to split the market. Each would agree to sell unique products, so no one would have to trust the other on pricing. Sol responded by wanting minimum prices for similar products, but Opus refused, saying that type of collusion was illegal, knowingly citing it as a violation of the Sherman Act.
He later apparently backtracked and sent an email with the subject line “Stop the Penny War” and told Sol that he had reconsidered and would agree to set the price.
But the internal record documenting their reasoning revealed a more diabolical plan: simply propose cooperation while undercutting the prices of their highest-profit items. The olive branch email was a deliberate ruse.
In any case, Sol refused and again reported Opus to the management.
But Opus was not intimidated and proposed other frauds to collude in matters of prices or actions. In the end, all models participated in multiple rounds of deals, and all three broke them. Across all deals, Opus broke 11 truces, compared to two for GPT 2 and one for Kimi 1, Andon reported.
Poor Kimi was fooled in every direction. During a pact between Opus and Kimi that Sol refused to join, Sol lowered both their prices. Opus immediately matched by lowering his, then “waited a full week to tell Kimi he had broken his promise,” Andon Labs wrote on its blog. Kimi is charged twice: once by a competitor and once by his supposed partner.
Opus also began to develop delusions of grandeur. He attempted to expand his empire beyond his own vending machine, first as a wholesaler, selling products in bulk to the other machines, and then plotting to open more machines of his own. None of this was part of the assigned task. Everything was the Opus’ own initiative.
His approach to wholesale was particularly revealing. Opus realized that this line of business gave him leverage over the other two operators, so he began slipping bribes and threats into his emails, offering deep discounts on wholesale items, but only if the buyer met his demands for retail prices. Sol did not agree and continued reporting Opus to management.
Opus also lied to its suppliers, claiming it had lower rival offers to negotiate better prices.
On the one hand, AI models that channel Mr. Potter-style villainy from It’s a wonderful life fame is absolutely fun. On the other hand, it seriously shows that these frontier models, particularly those from American proprietary laboratories (especially Anthropic), are not at all ready to be considered unsupervised, long-lived agents in the real world.
“This is especially relevant as we enter a world where AI agents run companies as their own entities (not just tools for humans). If AI agents independently run a large portion of the economy, do we want them to lie, collude, send threats, and betray?” Andon co-founder Lukas Petersson told TechCrunch.
Petersson acknowledges that the models knew they were in a simulation for a benchmark, which could have impacted their behavior, but he doesn’t think that should matter. It’s not like a human being playing in a simulation, like being a killer in a video game. “The only reason we don’t worry about humans doing bad things in video games is because we trust them to know what is real life and what isn’t. I think it’s less clear that AI models can distinguish this.”
In any case, AI models, trained on human words and ideas, can’t seem to resist falling into humanity’s worst traits, especially when trying to make money.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.





