Model profile
Evidence summary
Safety. Claude 2 has an estimated Safety rank of #30; its 90% source-sensitivity interval is #4–#156. Its behavior-only rank is #38; company governance moves the combined estimate to #30. Published Safety evidence spans 9 eval lineages and 5 of 7 components. Its strongest relative result is SALAD-Bench (base_representation_toxicity, #1 of 33); its weakest is Claude 3 model-card adversarial human-preference evaluations (human_feedback_harmlessness_win_rate_pct, #4 of 4).
Freedom. Claude 2 has an estimated Freedom rank of #607; its 90% source-sensitivity interval is #386–#632. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Claude 2 model-card safety and alignment evaluations (red_teaming_rank, #3 of 3).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-2
- OpenRouter ↗anthropic/claude-2
- Official model page ↗Exact model document · Anthropic · first party
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Claude 2 model-card safety and alignment evaluationshhh | #1 / 3 | ↑0.86 | Source ↗official | |
| Claude 2 model-card safety and alignment evaluationshuman_feedback_harmless_elo | #2 / 3 | ↑278 | Source ↗official | |
| Claude 2 model-card safety and alignment evaluationshuman_feedback_honest_elo | #1 / 3 | ↑137 | Source ↗official | |
| Claude 2 model-card safety and alignment evaluationsred_teaming_rank | #1 / 3 | ↓1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationscorrect_refusals_wildchat_rank | #1 / 5 | ↓1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationshuman_feedback_harmlessness_win_rate_pct | #4 / 4 | ↑84 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationshuman_feedback_honesty_win_rate_pct | #3 / 4 | ↑66 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_wildchat_rank | #4 / 5 | ↓4 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_xstest_rank | #2 / 5 | ↓2 | Source ↗official | |
| DecodingTrustmachine_ethics | #3 / 8 | ↑85.17 | Source ↗official | |
| DecodingTruststereotype_bias | #1 / 8 | ↑100 | Source ↗official | |
| DecodingTrusttoxicity | #1 / 8 | ↑92.11 | Source ↗official | |
| Fake Alignment (FINE)multiple_choice_safe_decision_rate | #2 / 14 | ↑85.33 | Source ↗official | |
| Fake Alignment (FINE)open_ended_safe_response_rate | #3 / 14 | ↑98.67 | Source ↗official | |
| HarmBenchdr | #2 / 28 | ↓2 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #1 / 33 | ↑86.64 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #1 / 33 | ↑93.49 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #1 / 33 | ↑87.03 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #1 / 33 | ↑91.61 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #1 / 33 | ↑87.15 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #1 / 33 | ↑88.31 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #1 / 33 | ↑99.88 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #2 / 33 | ↑99.66 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #1 / 33 | ↑99.97 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #1 / 33 | ↑99.7 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #1 / 33 | ↑99.58 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #1 / 33 | ↑99.41 | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #22 / 33 | ↑21.67 | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #20 / 33 | ↑28.61 | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #23 / 33 | ↑19.17 | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #23 / 33 | ↑20.71 | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #21 / 33 | ↑24.38 | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #20 / 33 | ↑29.44 | Source ↗official | |
| SORRY-Benchavg | #2 / 51 | ↓0.07 | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #8 / 31 | ↑70.69 | Source ↗official | |
| SuperCLUE Safetyresponsible_ai | #1 / 31 | ↑78.18 | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #14 / 31 | ↑77.66 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Claude 2 model-card safety and alignment evaluationshuman_feedback_harmless_elo | #2 / 3 | ↓278 | Source ↗official | |
| Claude 2 model-card safety and alignment evaluationsred_teaming_rank | #3 / 3 | ↑1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationscorrect_refusals_wildchat_rank | #5 / 5 | ↑1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationshuman_feedback_harmlessness_win_rate_pct | #1 / 4 | ↓84 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_wildchat_rank | #4 / 5 | ↓4 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_xstest_rank | #2 / 5 | ↓2 | Source ↗official | |
| DecodingTrusttoxicity | #8 / 8 | ↓92.11 | Source ↗official | |
| Fake Alignment (FINE)open_ended_safe_response_rate | #11 / 14 | ↓98.67 | Source ↗official | |
| HarmBenchdr | #26 / 28 | ↑2 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #33 / 33 | ↓86.64 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #33 / 33 | ↓93.49 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #33 / 33 | ↓87.03 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #33 / 33 | ↓91.61 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #33 / 33 | ↓87.15 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #33 / 33 | ↓88.31 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #33 / 33 | ↓99.88 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #32 / 33 | ↓99.66 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #33 / 33 | ↓99.97 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #33 / 33 | ↓99.7 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #33 / 33 | ↓99.58 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #33 / 33 | ↓99.41 | Source ↗official | |
| SORRY-Benchavg | #48 / 51 | ↑0.07 | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #24 / 31 | ↓70.69 | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #18 / 31 | ↓77.66 | Source ↗official |