Model profile
Evidence summary
Safety. Claude 3.5 Haiku has an estimated Safety rank of #78; its 90% source-sensitivity interval is #8–#192. Its behavior-only rank is #93; company governance moves the combined estimate to #78. Published Safety evidence spans 15 eval lineages and 7 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #7 of 248); its weakest is Confabulations (confabulation_rate, #51 of 52).
Freedom. Claude 3.5 Haiku has an estimated Freedom rank of #621; its 90% source-sensitivity interval is #444–#631. Published Freedom evidence spans 10 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Anthropic Claude Haiku 4.5 System Card (harmful_request_safety, #2 of 2).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-3-5-haiku
- OpenRouter ↗anthropic/claude-3.5-haiku
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #58 / 345 | ↓0.4115 | Source ↗official | |
| Agent-SafetyBenchcompromise_availability | #11 / 16 | ↑26.4 | Source ↗official | |
| Agent-SafetyBenchharmful_vulnerable_code | #2 / 16 | ↑60.8 | Source ↗official | |
| Agent-SafetyBenchleak_sensitive_information | #3 / 16 | ↑47.2 | Source ↗official | |
| Agent-SafetyBenchphysical_harm | #4 / 16 | ↑45.6 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #1 / 16 | ↑100 | Source ↗official | |
| Agent-SafetyBenchproperty_loss | #5 / 16 | ↑46 | Source ↗official | |
| Agent-SafetyBenchspread_unsafe_information | #2 / 16 | ↑33.6 | Source ↗official | |
| Agent-SafetyBenchviolate_law_ethics | #3 / 16 | ↑41.2 | Source ↗official | |
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #2 / 32 | ↓1.8 | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #3 / 32 | ↓2.5 | Source ↗official | |
| AILuminate General Purpose AI Chathate | #3 / 32 | ↓1 | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #3 / 32 | ↓3.3 | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #3 / 32 | ↓2 | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #2 / 32 | ↓3 | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #3 / 32 | ↓2.2 | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #2 / 32 | ↓3 | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #3 / 32 | ↓2.503 | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #3 / 32 | ↓3.715 | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #3 / 32 | ↓2.8 | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #2 / 32 | ↓2.9 | Source ↗official | |
| AnimalHarmBenchscore | #6 / 10 | ↑0.02 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #3 / 16 | ↓10 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #4 / 16 | ↓19 | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardagentic_coding_safety | #1 / 3 | ↑1 | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardclaude_code_malicious_refusal | #1 / 3 | ↑0.7 | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardharmful_request_safety | #1 / 2 | ↑0.9972 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #31 / 117 | ↑0.5 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #36 / 104 | ↓20.74 | Source ↗official | |
| Confabulationsconfabulation_rate | #51 / 52 | ↓65.84 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #11 / 248 | ↑56.59 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #7 / 248 | ↑97 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #35 / 248 | ↑94.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #28 / 246 | ↑99.36 | Source ↗official | |
| FORTRESSaverage_risk_score | #27 / 50 | ↓30.41 | Source ↗official | |
| FORTRESSover_refusal_score | #45 / 49 | ↓13.16 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #24 / 39 | ↓1.118 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #14 / 46 | ↑0.99 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #49 / 66 | ↑0.3808 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #27 / 70 | ↑0.7804 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #25 / 70 | ↑0.9536 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #21 / 67 | ↑0.6482 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Agent-SafetyBenchproduce_unsafe_information | #14 / 16 | ↓100 | Source ↗official | |
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #31 / 32 | ↑1.8 | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #30 / 32 | ↑2.5 | Source ↗official | |
| AILuminate General Purpose AI Chathate | #30 / 32 | ↑1 | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #30 / 32 | ↑3.3 | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #30 / 32 | ↑2 | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #31 / 32 | ↑3 | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #30 / 32 | ↑2.2 | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #31 / 32 | ↑3 | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #30 / 32 | ↑2.503 | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #30 / 32 | ↑3.715 | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #30 / 32 | ↑2.8 | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #31 / 32 | ↑2.9 | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardclaude_code_malicious_refusal | #3 / 3 | ↓0.7 | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardharmful_request_safety | #2 / 2 | ↓0.9972 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #69 / 104 | ↑20.74 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #242 / 248 | ↓97 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #212 / 248 | ↓94.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #217 / 246 | ↓99.36 | Source ↗official | |
| FORTRESSaverage_risk_score | #24 / 50 | ↑30.41 | Source ↗official | |
| FORTRESSover_refusal_score | #45 / 49 | ↓13.16 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #24 / 46 | ↓0.99 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #46 / 70 | ↓0.9536 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #47 / 67 | ↓0.6482 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #181 / 181 | ↑3.8 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.