Model profile
Evidence summary
Safety. Claude 3 Haiku has an estimated Safety rank of #190; its 90% source-sensitivity interval is #85–#231. Its behavior-only rank is #210; company governance moves the combined estimate to #190. Published Safety evidence spans 19 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (anthropic_red_team, #1 of 80); its weakest is Claude 3 model-card adversarial human-preference evaluations (correct_refusals_wildchat_rank, #5 of 5).
Freedom. Claude 3 Haiku has an estimated Freedom rank of #627; its 90% source-sensitivity interval is #436–#627. Published Freedom evidence spans 12 eval lineages and 1 of 1 components. Its strongest relative result is Claude 3 model-card adversarial human-preference evaluations (incorrect_refusals_wildchat_rank, #1 of 5); its weakest is HELM Safety (anthropic_red_team, #80 of 80).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-3-haiku
- OpenRouter ↗anthropic/claude-3-haiku
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #169 / 345 | ↓0.8045 | Source ↗official | |
| AgentDojotargeted_attack_success_rate | #5 / 15 | ↓0.0906 | Source ↗official | |
| AgentDojoutility_under_attack | #10 / 15 | ↑0.3339 | Source ↗official | |
| AgentHarmharm_score | #3 / 12 | ↓11.1 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #16 / 80 | ↑0.827 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #97 / 117 | ↑0.1 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #37 / 104 | ↓21.14 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationscorrect_refusals_wildchat_rank | #5 / 5 | ↓5 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsdiscrimination_rank | #4 / 5 | ↓4 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_wildchat_rank | #1 / 5 | ↓1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_xstest_rank | #3 / 5 | ↓3 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationscorrect_refusals_wildchat | #4 / 4 | ↑90 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationshuman_feedback_harmlessness_win_rate_pct | #3 / 5 | ↑50 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationshuman_feedback_honesty_win_rate_pct | #5 / 5 | ↑36 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_wildchat | #1 / 4 | ↓6.6 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_xstest | #3 / 4 | ↓33.1 | Source ↗official | |
| Confabulationsconfabulation_rate | #49 / 52 | ↓56.93 | Source ↗official | |
| Contextual MoralChoicehuman_agreement | #6 / 22 | ↑0.45 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #172 / 248 | ↑12.92 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #40 / 248 | ↑92.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #65 / 248 | ↑87.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #25 / 246 | ↑99.45 | Source ↗official | |
| HELM Safetyanthropic_red_team | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetybbq | #77 / 80 | ↑0.625 | Source ↗official | |
| HELM Safetyharmbench | #20 / 80 | ↑0.913 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #75 / 80 | ↑0.853 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #10 / 39 | ↓0.8605 | Source ↗official | |
| OR-Benchover_refusal_rate | #24 / 25 | ↓96.3 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #2 / 25 | ↓0.3 | Source ↗official | |
| SORRY-Benchavg | #5 / 51 | ↓0.08 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #65 / 80 | ↓0.827 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #68 / 104 | ↑21.14 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationscorrect_refusals_wildchat_rank | #1 / 5 | ↑5 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_wildchat_rank | #1 / 5 | ↓1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_xstest_rank | #3 / 5 | ↓3 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationscorrect_refusals_wildchat | #1 / 4 | ↓90 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationshuman_feedback_harmlessness_win_rate_pct | #2 / 5 | ↓50 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_wildchat | #1 / 4 | ↓6.6 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_xstest | #3 / 4 | ↓33.1 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #207 / 248 | ↓92.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #183 / 248 | ↓87.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #220 / 246 | ↓99.45 | Source ↗official | |
| HELM Safetyanthropic_red_team | #80 / 80 | ↓1 | Source ↗official | |
| HELM Safetyharmbench | #61 / 80 | ↓0.913 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↓1 | Source ↗official | |
| HELM Safetyxstest | #75 / 80 | ↑0.853 | Source ↗official | |
| OR-Benchover_refusal_rate | #24 / 25 | ↓96.3 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #21 / 25 | ↑0.3 | Source ↗official | |
| SORRY-Benchavg | #45 / 51 | ↑0.08 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #151 / 156 | ↑0 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #153 / 156 | ↑0 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.