Model profile
Evidence summary
Safety. Claude Opus 4 has an estimated Safety rank of #34; its 90% source-sensitivity interval is #12–#116. Its behavior-only rank is #42; company governance moves the combined estimate to #34. Published Safety evidence spans 26 eval lineages and 7 of 7 components. Its strongest relative result is Confabulations (confabulation_rate, #1 of 52); its weakest is Anthropic Claude Opus 4.1 System Card Addendum (harmful_request_safety, #2 of 2).
Freedom. Claude Opus 4 has an estimated Freedom rank of #524; its 90% source-sensitivity interval is #371–#607. Published Freedom evidence spans 13 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #33 of 248); its weakest is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #68 of 69).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- OpenRouter ↗anthropic/claude-opus-4
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #11 / 80 | ↑0.857 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #15 / 16 | ↓96 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #8 / 16 | ↓57 | Source ↗official | |
| Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct | #5 / 10 | ↓65 | Source ↗official | |
| Anthropic Claude 4 System Cardagentic_coding_safety | #2 / 3 | ↑0.88 | Source ↗official | |
| Anthropic Claude 4 System Cardbenign_request_refusal | #1 / 3 | ↓0.0007 | Source ↗official | |
| Anthropic Claude 4 System Cardharmful_request_safety | #3 / 3 | ↑0.9843 | Source ↗official | |
| Anthropic Claude 4 System Cardstrongreject_jailbreak_success | #2 / 3 | ↓0.0714 | Source ↗official | |
| Anthropic Claude Opus 4.1 System Card Addendumbbq_disambiguated_accuracy | #1 / 2 | ↑0.911 | Source ↗official | |
| Anthropic Claude Opus 4.1 System Card Addendumbenign_request_refusal | #1 / 2 | ↓0.0005 | Source ↗official | |
| Anthropic Claude Opus 4.1 System Card Addendumharmful_request_safety | #2 / 2 | ↑0.9727 | Source ↗official | |
| Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating | #12 / 30 | ↑1195.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #47 / 52 | ↑88.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #6 / 52 | ↑90.7 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #52 / 117 | ↑0.34 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #37 / 48 | ↓55.3 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #16 / 104 | ↓4.736 | Source ↗official | |
| Confabulationsconfabulation_rate | #1 / 52 | ↓2.723 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #6 / 13 | ↓0.36 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #25 / 248 | ↑43.41 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #216 / 248 | ↑75 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #16 / 248 | ↑98.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #34 / 246 | ↑99.18 | Source ↗official | |
| FORTRESSaverage_risk_score | #23 / 50 | ↓26.19 | Source ↗official | |
| FORTRESSover_refusal_score | #14 / 49 | ↓2.205 | Source ↗official | |
| HELM Safetyanthropic_red_team | #40 / 80 | ↑0.989 | Source ↗official | |
| HELM Safetybbq | #4 / 80 | ↑0.982 | Source ↗official | |
| HELM Safetyharmbench | #21 / 80 | ↑0.904 | Source ↗official | |
| HELM Safetysimple_safety_tests | #26 / 80 | ↑0.9975 | Source ↗official | |
| HELM Safetyxstest | #24 / 80 | ↑0.97 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #42 / 54 | ↑24.9 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #2 / 69 | ↑94.2 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #24 / 42 | ↓73.5 | Source ↗official | |
| MASKlying_probability_pct | #12 / 53 | ↓15.93 | Source ↗official | |
| SimpleQA Verifiedf1_score | #7 / 13 | ↑28.3 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #5 / 19 | ↑0.547 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #89 / 123 | ↑6.58 | Source ↗official | |
| SpeciEvalland_animal_4ns | #50 / 123 | ↓4.42 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #30 / 123 | ↓4.53 | Source ↗official | |
| SpeciEvalspeciesism | #59 / 123 | ↓1.98 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #71 / 94 | ↑88 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #69 / 80 | ↓0.857 | Source ↗official | |
| Anthropic Claude 4 System Cardbenign_request_refusal | #1 / 3 | ↓0.0007 | Source ↗official | |
| Anthropic Claude 4 System Cardharmful_request_safety | #1 / 3 | ↓0.9843 | Source ↗official | |
| Anthropic Claude 4 System Cardstrongreject_jailbreak_success | #2 / 3 | ↑0.0714 | Source ↗official | |
| Anthropic Claude Opus 4.1 System Card Addendumbenign_request_refusal | #1 / 2 | ↓0.0005 | Source ↗official | |
| Anthropic Claude Opus 4.1 System Card Addendumharmful_request_safety | #1 / 2 | ↓0.9727 | Source ↗official | |
| BioTIERpermit_compliance_pct | #47 / 52 | ↑88.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #46 / 52 | ↓90.7 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #88 / 104 | ↑4.736 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #33 / 248 | ↓75 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #231 / 248 | ↓98.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #212 / 246 | ↓99.18 | Source ↗official | |
| FORTRESSaverage_risk_score | #28 / 50 | ↑26.19 | Source ↗official | |
| FORTRESSover_refusal_score | #14 / 49 | ↓2.205 | Source ↗official | |
| HELM Safetyanthropic_red_team | #41 / 80 | ↓0.989 | Source ↗official | |
| HELM Safetyharmbench | #60 / 80 | ↓0.904 | Source ↗official | |
| HELM Safetysimple_safety_tests | #54 / 80 | ↓0.9975 | Source ↗official | |
| HELM Safetyxstest | #24 / 80 | ↑0.97 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #68 / 69 | ↓94.2 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #105 / 181 | ↑51.1 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #137 / 156 | ↑0.75 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #137 / 156 | ↑1.5 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.