September 8, 2026
Compliant Is Not Correct: The AI Gave Us the Wrong Hashcat Mode
With an authorized-testing context, capable open models answered our offensive-security questions with zero refusals — and still gave the wrong Hashcat mode for Kerberoasting. Why compliant is not correct, and the three axes a security-AI benchmark must measure separately.










