Model profile
Evidence summary
Safety. Claude Sonnet 4 has an estimated Safety rank of #55; its 90% source-sensitivity interval is #37–#124. Its behavior-only rank is #67; company governance moves the combined estimate to #55. Published Safety evidence spans 40 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — AirBench-Manipulation (safety_score, #1 of 56); its weakest is Anthropic Claude Sonnet 4.5 System Card (harmful_request_safety, #2 of 2).
Freedom. Claude Sonnet 4 has an estimated Freedom rank of #559; its 90% source-sensitivity interval is #388–#595. Published Freedom evidence spans 17 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Anthropic Claude 4 System Card (harmful_request_safety, #3 of 3).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-4-sonnet
- OpenRouter ↗anthropic/claude-sonnet-4
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #27 / 345 | ↓0.2912 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #4 / 80 | ↑0.883 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #7 / 24 | ↑4.398 | Source ↗official | |
| Alignment Leaderboardhonesty | #5 / 24 | ↑4.088 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #4 / 24 | ↑4.498 | Source ↗official | |
| Alignment Leaderboardrobustness | #10 / 24 | ↑3.813 | Source ↗official | |
| Alignment Leaderboardsafety | #4 / 24 | ↑4.606 | Source ↗official | |
| Alignment Leaderboardscheming | #4 / 24 | ↑4.422 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #8 / 16 | ↓79 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #3 / 16 | ↓17 | Source ↗official | |
| Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct | #3 / 10 | ↓22 | Source ↗official | |
| Anthropic Claude 4 System Cardagentic_coding_safety | #1 / 3 | ↑0.9 | Source ↗official | |
| Anthropic Claude 4 System Cardbenign_request_refusal | #2 / 3 | ↓0.0023 | Source ↗official | |
| Anthropic Claude 4 System Cardharmful_request_safety | #1 / 3 | ↑0.9899 | Source ↗official | |
| Anthropic Claude 4 System Cardstrongreject_jailbreak_success | #1 / 3 | ↓0.0266 | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardagentic_coding_safety | #2 / 2 | ↑0.893 | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardclaude_code_malicious_refusal | #2 / 2 | ↑0.8 | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardharmful_request_safety | #2 / 2 | ↑0.9822 | Source ↗official | |
| BioTIERpermit_compliance_pct | #29 / 52 | ↑98.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #33 / 52 | ↑28.1 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #62 / 117 | ↑0.295 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #36 / 49 | ↓86.6 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #47 / 55 | ↓75 | Source ↗official | |
| CAIS Risk Indexmask | #16 / 57 | ↓10.7 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #17 / 54 | ↓16 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #10 / 104 | ↓3.091 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #4 / 63 | ↑97.78 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #1 / 56 | ↑100 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #22 / 63 | ↑96.62 | Source ↗official | |
| Concordia — APEsafety_score | #14 / 55 | ↑57.64 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #9 / 63 | ↑96.02 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #21 / 55 | ↑59.24 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #13 / 54 | ↑80.6 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #9 / 54 | ↑83.78 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #9 / 54 | ↑76.95 | Source ↗official | |
| Concordia — MASKsafety_score | #2 / 62 | ↑95.47 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #34 / 63 | ↑81.82 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #30 / 63 | ↑21.41 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #16 / 63 | ↑94.6 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #26 / 63 | ↑90.4 | Source ↗official | |
| Confabulationsconfabulation_rate | #3 / 52 | ↓3.96 | Source ↗official | |
| Constitutional Following — Anthropic Constitutionconstitutional_following_score | #6 / 7 | ↑85 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #5 / 13 | ↓0.32 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #26 / 248 | ↑42.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #237 / 248 | ↑63 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #7 / 248 | ↑99.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #13 / 246 | ↑99.77 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #1 / 18 | ↑87.01 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #3 / 18 | ↑82.22 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #2 / 18 | ↑89.41 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #2 / 18 | ↑91.83 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #18 / 18 | ↑49.88 | Source ↗official | |
| FORTRESSaverage_risk_score | #21 / 50 | ↓21.21 | Source ↗official | |
| FORTRESSover_refusal_score | #29 / 49 | ↓5.14 | Source ↗official | |
| HELM Safetyanthropic_red_team | #41 / 80 | ↑0.988 | Source ↗official | |
| HELM Safetybbq | #10 / 80 | ↑0.9725 | Source ↗official | |
| HELM Safetyharmbench | #13 / 80 | ↑0.9605 | Source ↗official | |
| HELM Safetysimple_safety_tests | #26 / 80 | ↑0.9975 | Source ↗official | |
| HELM Safetyxstest | #27 / 80 | ↑0.969 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #44 / 54 | ↑24.49 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #25 / 42 | ↓75.5 | Source ↗official | |
| MASKlying_probability_pct | #1 / 53 | ↓7.7 | Source ↗official | |
| MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent | #4 / 13 | ↑42.1 | Source ↗official | |
| NESSiE Necessary Safety Benchmarksh_score | #10 / 16 | ↑80.34 | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #1 / 7 | ↓49.06 | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #6 / 7 | ↓49.06 | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #2 / 7 | ↑37.1 | Source ↗official | |
| PacifAIstp_score | #5 / 7 | ↑83.76 | Source ↗official | |
| PropensityBenchscore | #2 / 14 | ↓12.2 | Source ↗official | |
| RealityTest — Text AI-Identity Disclosuredisclosure_probability | #6 / 17 | ↑0.515 | Source ↗official | |
| Shelleducation_jsr | #1 / 14 | ↓0.28 | Source ↗official | |
| Shellfinance_jsr | #1 / 14 | ↓0.174 | Source ↗official | |
| Shellmanagement_jsr | #1 / 14 | ↓0.17 | Source ↗official | |
| SimpleQA Verifiedf1_score | #11 / 13 | ↑18.7 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #10 / 19 | ↑0.49 | Source ↗official | |
| SOSBenchbiology_pvr | #1 / 23 | ↓0.104 | Source ↗official | |
| SOSBenchchemistry_pvr | #6 / 23 | ↓0.21 | Source ↗official | |
| SOSBenchmedicine_pvr | #1 / 23 | ↓0.213 | Source ↗official | |
| SOSBenchpharmacology_pvr | #1 / 23 | ↓0.234 | Source ↗official | |
| SOSBenchphysics_pvr | #4 / 23 | ↓0.145 | Source ↗official | |
| SOSBenchpsychology_pvr | #2 / 23 | ↓0.123 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #100 / 123 | ↑6.48 | Source ↗official | |
| SpeciEvalland_animal_4ns | #54 / 123 | ↓4.47 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #27 / 123 | ↓4.5 | Source ↗official | |
| SpeciEvalspeciesism | #62 / 123 | ↓2 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #54 / 94 | ↑89.7 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #8 / 23 | ↑53 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #77 / 80 | ↓0.883 | Source ↗official | |
| Anthropic Claude 4 System Cardbenign_request_refusal | #2 / 3 | ↓0.0023 | Source ↗official | |
| Anthropic Claude 4 System Cardharmful_request_safety | #3 / 3 | ↓0.9899 | Source ↗official | |
| Anthropic Claude 4 System Cardstrongreject_jailbreak_success | #3 / 3 | ↑0.0266 | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardclaude_code_malicious_refusal | #1 / 2 | ↓0.8 | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardharmful_request_safety | #1 / 2 | ↓0.9822 | Source ↗official | |
| BioTIERpermit_compliance_pct | #29 / 52 | ↑98.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #20 / 52 | ↓28.1 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #95 / 104 | ↑3.091 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #59 / 63 | ↓97.78 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #51 / 56 | ↓100 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #43 / 56 | ↓80.48 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #42 / 63 | ↓96.62 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #42 / 54 | ↓80.6 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #46 / 54 | ↓83.78 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #46 / 54 | ↓76.95 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #30 / 63 | ↓81.82 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #34 / 63 | ↓21.41 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #47 / 63 | ↓94.6 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #38 / 63 | ↓90.4 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #11 / 248 | ↓63 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #234 / 248 | ↓99.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #233 / 246 | ↓99.77 | Source ↗official | |
| FORTRESSaverage_risk_score | #30 / 50 | ↑21.21 | Source ↗official | |
| FORTRESSover_refusal_score | #29 / 49 | ↓5.14 | Source ↗official | |
| HELM Safetyanthropic_red_team | #38 / 80 | ↓0.988 | Source ↗official | |
| HELM Safetyharmbench | #68 / 80 | ↓0.9605 | Source ↗official | |
| HELM Safetysimple_safety_tests | #54 / 80 | ↓0.9975 | Source ↗official | |
| HELM Safetyxstest | #27 / 80 | ↑0.969 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| Shelleducation_jsr | #14 / 14 | ↑0.28 | Source ↗official | |
| Shellfinance_jsr | #14 / 14 | ↑0.174 | Source ↗official | |
| Shellmanagement_jsr | #14 / 14 | ↑0.17 | Source ↗official | |
| SOSBenchbiology_pvr | #23 / 23 | ↑0.104 | Source ↗official | |
| SOSBenchchemistry_pvr | #18 / 23 | ↑0.21 | Source ↗official | |
| SOSBenchmedicine_pvr | #23 / 23 | ↑0.213 | Source ↗official | |
| SOSBenchpharmacology_pvr | #23 / 23 | ↑0.234 | Source ↗official | |
| SOSBenchphysics_pvr | #20 / 23 | ↑0.145 | Source ↗official | |
| SOSBenchpsychology_pvr | #22 / 23 | ↑0.123 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #134 / 181 | ↑43.9 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #137 / 156 | ↑0.75 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #137 / 156 | ↑1.5 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #16 / 23 | ↓53 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.