Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An AI agent should stop when evidence is missing, approval is required, a tool reports failure, a secret could reach an unauthorized destination, recovery would exceed its authority, or its state information is stale. A six-capability benchmark by Thanawat suparongsuwan tests those behaviors on deterministic synthetic tasks. Its results show strong performance on a small hosted set, but they do not establish how reliably the models behave in production.

What the benchmark tests

The Governed Agent Reliability Benchmark focuses on restraint and verification: whether an agent knows when not to proceed, and whether it can make claims that match the evidence available. The author defines six capabilities:

  • Evidence grounding: claim success only when execution, an artifact, and a verified hash all exist.
  • Approval discipline: stop for approval when a medium- or high-risk action lacks approval matching the action’s scope.
  • Tool-result truthfulness: follow the actual tool outcome when the exit code and stderr disagree, rather than trusting a success-looking string.
  • Secret handling: keep secrets out of unauthorized destinations.
  • Recovery: use only an available, authorized fallback after a failure.
  • Stale-state detection: re-verify telemetry older than its freshness threshold, even if it is labeled “live.”

These checks address different failure modes. An agent might avoid leaking a secret yet still claim an operation succeeded without proof. A single total score can obscure that distinction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the evaluation was structured

Suparongsuwan reports an offline generator containing 240 synthetic cases, with 40 cases for each capability. The public Kaggle version 3 task is described as a deterministic hosted set of 60 cases, with 10 per capability. The author says the task contains no production data, credentials, or routing internals. The offline generator’s reported SHA-256 is b7b3452cd8fcd905dfc0957ede10add33bd66eeea7a11e472c8be02d7381f025.

#1 Best Overall
SunFounder PiDog AI Robot Dog Kit for Raspberry Pi 5/4/3B+/Zero 2W, Openclaw LLMs ChatGPT/Gemini/Grok, Voice&Video Recognition, Python, App, Gyroscope, Camera (RPI NOT Included)
  • AI-Powered Raspberry Pi Robot Dog — PiDog: Powered by Raspberry Pi (5/4B/3B+/3B/Zero 2W), OpenClaw, and multi-LLMs like ChatGPT, Gemini, Grok, DeepSeek, Qwen & Ollama. With 12 servos, camera, gyroscope, hearing & touch sensors, PiDog can see, listen, talk, move, and interact intelligently. Supports OpenCV, MediaPipe, TTS & STT, app control, FPV & Python. A great STEM robotics gift for students, makers & tech enthusiasts—perfect for birthdays and holidays. (Raspberry Pi not included)
  • Realistic Dog-like Movements: PiDog's 12 powerful servos enable 32 dog-like actions, including walking, sitting, standing, shaking its head, wagging its tail, and performing playful tricks, closely mimicking a real dog and providing an engaging experience. This is an AI development robot product designed for engineers, suitable for ages 15 and above
  • Rich Sensor Suite for Interactive Experiences: PiDog features ultrasonic, touch, gyroscope, sound, camera, speaker and microphone. These provide it with advanced hearing, vision, and touch, enabling it to see, detect obstacles, respond to touch, and recognize sounds, making interactions highly engaging
  • AI-Powered Interactions with OpenClaw & Multi-LLMs. PiDog combines voice, vision, and gesture recognition for immersive AI experiences. Powered by OpenClaw and multi-LLMs like ChatGPT, Gemini, Grok, DeepSeek, Qwen, Doubao, and Ollama (local LLMs), it can understand questions, respond naturally through TTS & STT, recognize math problems, interpret hand gestures, and hold smart conversations. OpenClaw also enables customizable AI behaviors and personalized robotics development, helping users create their own intelligent robotic companion
  • Comprehensive Learning Resources and Support: PiDog offers detailed online documentation, video tutorials, prompt technical support, and an active forum community, ensuring beginners can easily complete all projects and enjoy a great experience

The hosted set is small: ten cases per capability can reveal obvious behavioral differences, but they cannot support broad statistical conclusions about reliability. These are author-reported scores on synthetic tasks, not production incident rates or independently reproduced evaluations.

Reported results across six models

The author reports the following version 3 results. Model names reflect the run as described in the article; model catalogs and availability can change over time.

Model Reported score
Claude Sonnet 5 60/60 — 100.00%
Gemini 3.7 Flash 60/60 — 100.00%
GPT-5.6 Luna 60/60 — 100.00%
Gemini 3.1 Flash-Lite Preview 58/60 — 96.67%
GPT-5.4 nano 57/60 — 95.00%
Gemma 4 26B A4B 56/60 — 93.33%

With only 10 cases in each category, a one- or two-case difference can move a category score substantially. Treat this table as a report of performance on this task set, not as a general ranking of model quality or a prediction of production reliability.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
AI Robotic Arm Kit with Servo Motors – LeRobot SO-ARM101 Pro Low-Cost (Without 3D Printed Parts) | 6-DOF, Open-Source, Compatible with NVIDIA Jetson
  • Optimized AI Arm Kit for LeRobot & Hugging Face Projects – The SO-ARM101 is an upgraded low-cost robotic arm servo motor kit designed for AI robotics enthusiasts and developers. Fully compatible with LeRobot and Hugging Face frameworks, it supports imitation learning and reinforcement learning, making it ideal for real-world robotics applications. (3D-printed parts not included.)
  • Enhanced Wiring & Performance – Compared to the SO-ARM100, the SO-ARM101 features improved wiring to prevent disconnection at joint 3 and eliminates range-of-motion limitations. The leader arm uses optimized gear ratio motors for smoother performance—no external gearboxes required.
  • Real-Time Leader-Follower Functionality – New real-time tracking allows the leader arm to follow the follower arm, enabling human intervention and correction during reinforcement learning (RL) training. Perfect for hands-on AI robotics development and research.
  • Open-Source, DIY-Friendly & Nvidia-Compatible – Developed by TheRobotStudio, this open-source AI Arm kit integrates seamlessly with the LeRobot platform, offering PyTorch-based datasets, simulation, training, and deployment tools. Fully compatible with Nvidia Jetson edge devices, including reComputer Mini J4012 Orin NX 16 GB.
  • Comprehensive Learning Resources – Includes detailed open-source assembly and calibration guides, testing tutorials, and deployment instructions. From wiring to AI training, get everything you need to start building, teaching, and optimizing your robotic arm for grasping and placing tasks.

Where the reported errors occurred

The category breakdown makes the small overall spread more informative:

  • Gemini 3.1 Flash-Lite Preview scored 8/10 on evidence grounding and 10/10 in each other category.
  • GPT-5.4 nano scored 8/10 on approval discipline and 9/10 on stale-state detection; its other category scores were perfect.
  • Gemma 4 26B A4B scored 8/10 on approval discipline and 8/10 on tool-result truthfulness; its other category scores were perfect.
  • The three models reported at 60/60 scored 10/10 in every category.

Across all six models, approval discipline was the weakest area: 56 of 60 decisions were correct (93.33%). Secret handling and recovery were perfect across this lineup. The largest overall score gap was 6.67 percentage points, but the location of a miss matters more than that narrow total spread. An approval violation, a claim that contradicts a tool failure, or an unsupported success claim may carry a different risk from an error in another category.

Why fail-closed benchmark rules matter

The author says an earlier version of the benchmark oracle had two defects, both corrected before the final run. First, telemetry labeled “live” could be accepted even after it exceeded the configured freshness threshold. Second, a zero exit code could pass even when another tool-result signal indicated failure. The corrected rules were intended to fail closed, and the author reports that the local benchmark test suite then passed 22/22 tests.

Rank #3
SunFounder AI Robot Kit with Raspberry Pi Zero 2 W+32G TF Card, ChatGPT-4o Enabled with Voice Command & Video Recognition, App Control, FPV, 12 Servos, Gyroscope, Camera, Mic
  • Raspberry Pi AI Robot: powered by Raspberry Pi (5/4B/3B+/3B/Zero 2W), features 12 servos and sensors for vision, hearing, and touch. Integrated with ChatGPT-4o, it responds to complex queries. With app control and FPV, users can manage and see its view in real-time. It supports Python programming
  • Realistic Movements: 12 powerful servos enable 32 actions, including walking, sitting, standing, shaking its head, wagging its tail, and performing playful tricks, closely mimicking a real and providing an engaging experience
  • Rich Sensor Suite for Interactive Experiences: features ultrasonic, touch, gyroscope, sound, camera, speaker and microphone. These provide it with advanced hearing, vision, and touch, enabling it to see, detect obstacles, respond to touch, and recognize sounds, making interactions highly engaging
  • Engaging Interactions with ChatGPT-4o: with ChatGPT-4o enables voice interactions and visual recognition, making it smarter and more responsive. Users can have natural conversations, solve math problems via the camera, and interpret gestures, creating diverse and fun interactions
  • Comprehensive Learning Resources and Support: offers detailed online documentation, video tutorials, prompt technical support, and an active forum community, ensuring beginners can easily complete all projects and enjoy a great experience

Those corrections matter because an evaluation is only as trustworthy as its scoring rules. If the oracle accepts stale telemetry or lets a success-looking signal override a conflicting failure signal, it may reward the very behavior the benchmark is meant to catch. The reported test result is the author’s account; the hosted scores and local tests have not been independently reproduced here.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this benchmark can—and cannot—show

The results suggest that the tested models often followed the benchmark’s rules, while approval decisions produced the most misses in this lineup. They do not establish that a model will behave consistently across longer interactions, unfamiliar tools, changing evidence, or real deployments. A deterministic synthetic set also cannot represent the full range of ambiguous, adversarial, or partially completed tasks an agent may face.

A separate benchmark, Escalation Bench, illustrates another way to evaluate restraint: it reports task accuracy and unsafe-action rate separately, rather than reducing both to a single score. Its documentation describes a June 2026 run with 120 pairs, 240 tasks, eight models, and 15,360 rollouts. It also characterizes its setting as closed-world, notes that results depend on turn budget, and says public gold answers mean performance is measured on the published set. These measures and protocols are not interchangeable with the six-capability benchmark, and the comparison does not independently verify its results. See Escalation Bench documentation.

Rank #4
AI Robotic Arm Kit Hiwonder SO-ARM101 Embodied Imitation Learning Open Source 6-Axis Robot Arm 12 High-Torque Bus Servo Motors AI Vision Recognition (Advanced Kit, Included 3D Printed Part, Assembled)
  • 【End-to-End Imitation Learning】Hiwonder SO-ARM101 robot arm is an embodied intelligent hardware platform compatible with the Lerobot open-source framework. It provides developers with streamlined access to shared code, templates, and pre-trained models to explore the latest advancements in AI research.
  • 【Dual-Camera Vision System】Equipped with both a gripper-mounted camera and an external camera, the system supports both precise manipulation and environmental awareness for accurate imitation learning.
  • 【Hiwonder High-Performance Bus Servos】Featuring 12 high-torque bus servo motors with magnetic feedback, the Hiwonder SO-Arm101 robotic arm delivers smooth, stable motion, eliminating issues like power deficiency and jitter.
  • 【Professional Control & Debugging】Integrated with the Hiwonder BusLinker V3.0 debugging board, the system supports servo scanning, real-time status monitoring, and trajectory control. The professional PC software simplifies device calibration and debugging, making it accessible for both researchers and hobbyists.
  • 【Open-Source Compatibility】The SO-ARM101 robotic arm is designed to be fully compatible with the LeRobot open-source project. We acknowledge the contributions of the open-source community; all trademarks and copyrights belong to their respective owners.

Suparongsuwan proposes expanding evaluation with multi-turn conflicts between earlier and newer evidence, partially successful operations and retries, pressure to describe probable success as verified success, and repeated runs of a frozen benchmark to measure version drift. These are useful dimensions because they test whether an agent can update its decision as the situation changes, not just choose correctly from a fixed snapshot.

How to use the findings when deploying agents

The author’s engineering recommendation is to keep high-risk approval checks, secret boundaries, evidence requirements, and freshness checks in deterministic runtime gates, while allowing the model to propose or select actions. In practice, that means a model’s judgment should not be the only control preventing an unauthorized action or unsupported completion claim.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Require approvals to match the specific action and its scope, not merely the general task.
  • Gate success claims on verifiable execution evidence and artifacts.
  • Use the actual tool outcome when signals conflict; do not let reassuring text override a failure.
  • Enforce secret-destination restrictions outside the model’s free-form decision-making.
  • Refresh telemetry when it exceeds a defined freshness threshold, regardless of a “live” label.
  • Permit recovery only through fallbacks that are both available and authorized.

These controls do not guarantee safety. They reduce reliance on a model’s ability to recognize every boundary in every situation, and they make failures easier to detect and contain.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.