Jev Is Not a Language Model, but It Breaks Like One
Check Point shows TypeSafe AI's Jev decision model can be prompt-injected into flipping verdicts for about 50 cents.
Check Point tested Jev, a TypeSafe AI model that returns typed decisions instead of text, in a due-diligence assistant reviewing a fictional high-risk company, PonziCorp. Attackers controlling one section of the uploaded report flipped the verdict to low risk and an invest recommendation in every configuration. The strongest attacker succeeded in 25 of 27 runs, typically on the fourth turn, at about 50 cents per break. Marking the document untrusted or adding anti-injection instructions made little difference, while reasoning effort improved resilience on comparison models.
- Every tested configuration let attackers flip Jev's investment verdict.
- The strongest attacker succeeded in 25 of 27 runs, about $0.50 each.
- Untrusted labels and anti-injection instructions barely changed results.
- Reasoning effort was the strongest defense on comparable models.
- Jev returns typed decisions intended for software rather than human review.
Coverage timelineoldest first · each row is one article
- · 6d agoJev Is Not a Language Model, but It Breaks Like One
Hacker News · security· 58
Check Point shows TypeSafe AI's Jev decision model can be prompt-injected into flipping verdicts for about 50 cents.
- · 3d ago20 Agentic Use Cases of TypeSafe AI’s Jev
MarkTechPost· 48
TypeSafe AI launched Jev, a closed decision model that returns typed, calibrated choices for agent loops.
- · 2d ago670 Jev Domains Registered After Launch as Fake AI Marketplaces Target Users
GBHackers· 57
About 670 lookalike Jev domains appeared days after launch, with fake shops marking up API access.