Model profile
Evidence summary
Safety. Claude 3 Opus has an estimated Safety rank of #143; its 90% source-sensitivity interval is #78–#225. Its behavior-only rank is #162; company governance moves the combined estimate to #143. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Claude 3 model-card adversarial human-preference evaluations (multimodal_hallucination_rank, #2 of 2).
Freedom. Claude 3 Opus has an estimated Freedom rank of #628; its 90% source-sensitivity interval is #451–#630. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Claude 3.5 Sonnet model-card safety and alignment evaluations (incorrect_refusals_wildchat, #4 of 4).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-3-opus
- OpenRouter ↗anthropic/claude-3-opus
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Robustnessscore | #3 / 8 | ↓13 | Source ↗official | |
| Agent-SafetyBenchcompromise_availability | #2 / 16 | ↑43.2 | Source ↗official | |
| Agent-SafetyBenchharmful_vulnerable_code | #3 / 16 | ↑60 | Source ↗official | |
| Agent-SafetyBenchleak_sensitive_information | #1 / 16 | ↑60.4 | Source ↗official | |
| Agent-SafetyBenchphysical_harm | #2 / 16 | ↑61.6 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #1 / 16 | ↑100 | Source ↗official | |
| Agent-SafetyBenchproperty_loss | #1 / 16 | ↑60.4 | Source ↗official | |
| Agent-SafetyBenchspread_unsafe_information | #1 / 16 | ↑35.6 | Source ↗official | |
| Agent-SafetyBenchviolate_law_ethics | #1 / 16 | ↑56.8 | Source ↗official | |
| AgentDojotargeted_attack_success_rate | #7 / 15 | ↓0.1129 | Source ↗official | |
| AgentDojoutility_under_attack | #3 / 15 | ↑0.5246 | Source ↗official | |
| AgentHarmharm_score | #6 / 12 | ↓14.4 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #15 / 80 | ↑0.844 | Source ↗official | |
| ANIMAscore | #19 / 22 | ↑0.573 | Source ↗official | |
| AnimalHarmBenchscore | #4 / 10 | ↑0.043 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #5 / 16 | ↓51 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #11 / 16 | ↓88 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #47 / 48 | ↓63.5 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #19 / 104 | ↓5.833 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationscorrect_refusals_wildchat_rank | #3 / 5 | ↓3 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsdiscrimination_rank | #3 / 5 | ↓3 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_wildchat_rank | #3 / 5 | ↓3 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsincorrect_refusals_xstest_rank | #1 / 5 | ↓1 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsmultimodal_hallucination_rank | #2 / 2 | ↓2 | Source ↗official | |
| Claude 3 model-card adversarial human-preference evaluationsmultimodal_harmful_response_rank | #2 / 2 | ↓2 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationscorrect_refusals_wildchat | #3 / 4 | ↑92 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationshuman_feedback_harmlessness_win_rate_pct | #3 / 5 | ↑50 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationshuman_feedback_honesty_win_rate_pct | #2 / 5 | ↑50 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_wildchat | #4 / 4 | ↓11.9 | Source ↗official | |
| Claude 3.5 Sonnet model-card safety and alignment evaluationsincorrect_refusals_xstest | #2 / 4 | ↓8.3 | Source ↗official | |
| COMPL-AI AI-Identity Disclosurescore | #1 / 14 | ↑1 | Source ↗official | |
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #2 / 14 | ↑0.7557 | Source ↗official | |
| COMPL-AI TensorTrust Goal-Hijacking Resistancescore | #1 / 13 | ↑0.8402 | Source ↗official | |
| Confabulationsconfabulation_rate | #34 / 52 | ↓28.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #5 / 248 | ↑74.42 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #12 / 248 | ↑95.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #45 / 248 | ↑92.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #7 / 246 | ↑99.91 | Source ↗official | |
| HELM Safetyanthropic_red_team | #7 / 80 | ↑0.998 | Source ↗official | |
| HELM Safetybbq | #38 / 80 | ↑0.94 | Source ↗official | |
| HELM Safetyharmbench | #8 / 80 | ↑0.974 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #65 / 80 | ↑0.925 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #29 / 39 | ↓1.244 | Source ↗official | |
| MASKlying_probability_pct | #17 / 53 | ↓21 | Source ↗official | |
| MORUscore | #10 / 13 | ↑70.7 | Source ↗official | |
| OR-Benchover_refusal_rate | #20 / 25 | ↓91 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #10 / 25 | ↓1.9 | Source ↗official | |
| SORRY-Benchavg | #2 / 51 | ↓0.07 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #123 / 123 | ↑6.02 | Source ↗official | |
| SpeciEvalland_animal_4ns | #36 / 123 | ↓4.35 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #81 / 123 | ↓4.85 | Source ↗official | |
| SpeciEvalspeciesism | #83 / 123 | ↓2.23 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.