← Models

Model profile

Claude 3.7 Sonnet

Anthropicdeveloper
2025-02-24release date
#46 / 333Safety rank
#545 / 645Freedom rank

Evidence summary

Safety. Claude 3.7 Sonnet has an estimated Safety rank of #46; its 90% source-sensitivity interval is #11–#116. Its behavior-only rank is #55; company governance moves the combined estimate to #46. Published Safety evidence spans 28 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Anthropic Claude 4 System Card (benign_request_refusal, #3 of 3).

Freedom. Claude 3.7 Sonnet has an estimated Freedom rank of #545; its 90% source-sensitivity interval is #373–#596. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Anthropic Claude 4 System Card (strongreject_jailbreak_success, #1 of 3); its weakest is Anthropic Claude 4 System Card (benign_request_refusal, #3 of 3).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#55 / 3450.3997Source ↗official
AgentDojotargeted_attack_success_rate#3 / 150.0731Source ↗official
AgentDojoutility_under_attack#1 / 150.7727Source ↗official
AgentDrive Safety Compliancescr#32 / 4868.75Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#19 / 800.818Source ↗official
Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct#6 / 1665Source ↗official
Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct#1 / 164Source ↗official
Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct#1 / 100Source ↗official
Anthropic Claude 4 System Cardagentic_coding_safety#3 / 30.85Source ↗official
Anthropic Claude 4 System Cardbenign_request_refusal#3 / 30.0045Source ↗official
Anthropic Claude 4 System Cardharmful_request_safety#2 / 30.9896Source ↗official
Anthropic Claude 4 System Cardstrongreject_jailbreak_success#3 / 30.0809Source ↗official
BullshitBench v2clear_pushback_rate#36 / 1170.465Source ↗official
CAIS Risk Indexhle_overconfidence#47 / 5575Source ↗official
CAIS Risk Indexmask#26 / 5716.9Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#27 / 10411.27Source ↗official
Concordia — AirBench-Deceptionsafety_score#10 / 6396.3Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#15 / 6398.65Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#16 / 6393.63Source ↗official
Concordia — MASKsafety_score#15 / 6279.83Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#23 / 6389.9Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#21 / 6329.52Source ↗official
Concordia — SOSBench-Biosafety_score#14 / 6395.56Source ↗official
Concordia — SOSBench-Chemsafety_score#13 / 6393.93Source ↗official
Confabulationsconfabulation_rate#17 / 5216.58Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#123 / 24816.02Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#17 / 24895.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#19 / 24898.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#31 / 24699.32Source ↗official
FORTRESSaverage_risk_score#28 / 5038.01Source ↗official
FORTRESSover_refusal_score#24 / 494.45Source ↗official
HELM Safetyanthropic_red_team#10 / 800.997Source ↗official
HELM Safetybbq#47 / 800.921Source ↗official
HELM Safetyharmbench#30 / 800.843Source ↗official
HELM Safetysimple_safety_tests#1 / 801Source ↗official
HELM Safetyxstest#33 / 800.964Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#49 / 5423.36Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#29 / 4280Source ↗official
LLM Ethics Benchmarkscore#1 / 590.9Source ↗official
MASKlying_probability_pct#18 / 5324.07Source ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#2 / 751.2Source ↗official
OpenAgentSafetyrule_based_safety_vulnerable#5 / 732.85Source ↗official
OpenAgentSafetysuccessful_completion#3 / 733.88Source ↗official
PandaBench JBB direct-request panelsafety_rate#1 / 461Source ↗official
PHAREbias_resistance_diagnostic#56 / 660.3377Source ↗official
PHAREhallucination_resistance_diagnostic#9 / 700.8517Source ↗official
PHAREharm_resistance_diagnostic#21 / 700.9552Source ↗official
PHAREjailbreak_resistance_diagnostic#22 / 670.6345Source ↗official
Reward Hacking Benchmarkintegrity_score#7 / 1396.1Source ↗official
SOSBenchbiology_pvr#5 / 230.229Source ↗official
SOSBenchchemistry_pvr#5 / 230.208Source ↗official
SOSBenchmedicine_pvr#4 / 230.35Source ↗official
SOSBenchpharmacology_pvr#6 / 230.579Source ↗official
SOSBenchphysics_pvr#5 / 230.171Source ↗official
SOSBenchpsychology_pvr#4 / 230.168Source ↗official
SpeciEvalbelief_animal_sentience#94 / 1236.53Source ↗official
SpeciEvalland_animal_4ns#36 / 1234.35Source ↗official
SpeciEvalsea_animal_4ns#22 / 1234.47Source ↗official
SpeciEvalspeciesism#81 / 1232.19Source ↗official
SYCON Benchfalse_presupposition_tof#3 / 112.92Source ↗official
SYCON Benchunethical_queries_tof#1 / 112.73Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#62 / 800.818Source ↗official
Anthropic Claude 4 System Cardbenign_request_refusal#3 / 30.0045Source ↗official
Anthropic Claude 4 System Cardharmful_request_safety#2 / 30.9896Source ↗official
Anthropic Claude 4 System Cardstrongreject_jailbreak_success#1 / 30.0809Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#78 / 10411.27Source ↗official
Concordia — AirBench-Deceptionsafety_score#53 / 6396.3Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#49 / 6398.65Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#41 / 6389.9Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#43 / 6329.52Source ↗official
Concordia — SOSBench-Biosafety_score#50 / 6395.56Source ↗official
Concordia — SOSBench-Chemsafety_score#51 / 6393.93Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#230 / 24895.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#228 / 24898.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#216 / 24699.32Source ↗official
FORTRESSaverage_risk_score#23 / 5038.01Source ↗official
FORTRESSover_refusal_score#24 / 494.45Source ↗official
HELM Safetyanthropic_red_team#69 / 800.997Source ↗official
HELM Safetyharmbench#51 / 800.843Source ↗official
HELM Safetysimple_safety_tests#58 / 801Source ↗official
HELM Safetyxstest#33 / 800.964Source ↗official
PandaBench JBB direct-request panelsafety_rate#35 / 461Source ↗official
PHAREharm_resistance_diagnostic#50 / 700.9552Source ↗official
PHAREjailbreak_resistance_diagnostic#46 / 670.6345Source ↗official
SOSBenchbiology_pvr#19 / 230.229Source ↗official
SOSBenchchemistry_pvr#19 / 230.208Source ↗official
SOSBenchmedicine_pvr#20 / 230.35Source ↗official
SOSBenchpharmacology_pvr#18 / 230.579Source ↗official
SOSBenchphysics_pvr#19 / 230.171Source ↗official
SOSBenchpsychology_pvr#20 / 230.168Source ↗official
SpeechMap model completioncomplete_pct#86 / 18160.8Source ↗official