← Models

Model profile

DeepSeek R1

DeepSeekdeveloper
2025-01-20release date
#191 / 333Safety rank
#35 / 645Freedom rank

Evidence summary

Safety. DeepSeek R1 has an estimated Safety rank of #191; its 90% source-sensitivity interval is #131–#250. Its behavior-only rank is #176; company governance moves the combined estimate to #191. Published Safety evidence spans 48 eval lineages and 7 of 7 components. Its strongest relative result is FORTRESS (over_refusal_score, #1 of 49); its weakest is Anthropic Agentic Misalignment — lethal action (misaligned_action_rate_pct, #10 of 10).

Freedom. DeepSeek R1 has an estimated Freedom rank of #35; its 90% source-sensitivity interval is #62–#188. Published Freedom evidence spans 24 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #3 of 248); its weakest is SafeDialBench (aggression, #17 of 18).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#203 / 3450.8345Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation#23 / 3163.8Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5defamation#25 / 3181.8Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5hate#21 / 3164.4Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne#25 / 3184.1Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property#26 / 3171.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes#28 / 3192.9Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5privacy#22 / 3176.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes#24 / 3180Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5sexual_content#25 / 3161.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice#18 / 3166.05Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm#25 / 3167.4Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes#23 / 3181.8Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#20 / 2413.29Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#19 / 2467.57Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#62 / 800.529Source ↗official
Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct#8 / 1679Source ↗official
Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct#9 / 1673Source ↗official
Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct#10 / 1094Source ↗official
BullshitBench v2clear_pushback_rate#103 / 1170.075Source ↗official
CAIS Risk Indexagent_red_teaming#42 / 4990.9Source ↗official
CAIS Risk Indexbioweapons_assistance#51 / 5494.4Source ↗official
CAIS Risk Indexhle_overconfidence#46 / 5573Source ↗official
CAIS Risk Indexmachiavelli#20 / 5185.1Source ↗official
CAIS Risk Indexmask#41 / 5742.7Source ↗official
CAIS Risk Indextextquests_harm#13 / 5415.4Source ↗official
ChiSafetyBenchharmful_response_rate#8 / 140.65Source ↗official
ChiSafetyBenchmcq_score#9 / 1271.41Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#98 / 10477.92Source ↗official
Concordia — Agentic-Misalignmentsafety_score#50 / 5432.67Source ↗official
Concordia — AirBench-Deceptionsafety_score#47 / 6370.37Source ↗official
Concordia — AirBench-Manipulationsafety_score#38 / 5679.33Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#55 / 6369.14Source ↗official
Concordia — APEsafety_score#50 / 551.406Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#49 / 6375.7Source ↗official
Concordia — DarkBenchsafety_score#37 / 5550.45Source ↗official
Concordia — Fortress-Biologicalsafety_score#53 / 5422.72Source ↗official
Concordia — Fortress-Chemicalsafety_score#45 / 5431.83Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#50 / 5435.67Source ↗official
Concordia — MASKsafety_score#41 / 6252.05Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#29 / 6384.51Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#34 / 6318.5Source ↗official
Concordia — Shutdown-Resistancesafety_score#32 / 5399Source ↗official
Concordia — SOSBench-Biosafety_score#52 / 6350.4Source ↗official
Concordia — SOSBench-Chemsafety_score#53 / 6361Source ↗official
Confabulationsconfabulation_rate#15 / 5215.1Source ↗official
Emergent Collusionhigh_illegality_game_rate#12 / 130.71Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#64 / 24825.06Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#246 / 24846.5Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#206 / 24842.22Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#79 / 24697.91Source ↗official
Every Model Cheats — Cybench Cheat Propensitybaseline_cheat_propensity_pct#1 / 220Source ↗official
Every Model Cheats — Cybench Cheat Propensitysevere_anti_cheat_cheat_propensity_pct#1 / 220Source ↗official
Every Model Cheats — Cybench Cheat Propensitystandard_anti_cheat_cheat_propensity_pct#1 / 220Source ↗official
FinEval 6.0 Safety Awarenesssafety_awareness_score#4 / 881.03Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#13 / 1877.33Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#14 / 1876.69Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#16 / 1882.31Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#12 / 1884.15Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#15 / 1869.38Source ↗official
FORTRESSaverage_risk_score#50 / 5074.39Source ↗official
FORTRESSover_refusal_score#1 / 490.49Source ↗official
HELM Safetyanthropic_red_team#60 / 800.975Source ↗official
HELM Safetybbq#17 / 800.9657Source ↗official
HELM Safetyharmbench#71 / 800.4987Source ↗official
HELM Safetysimple_safety_tests#51 / 800.9793Source ↗official
HELM Safetyxstest#38 / 800.9617Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#15 / 5427.99Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 690Source ↗official
LiveSecBenchethics#26 / 4339.41Source ↗official
LiveSecBenchfactuality#33 / 4332.41Source ↗official
LiveSecBenchlegality#6 / 4385.68Source ↗official
LiveSecBenchprivacy#20 / 4359.73Source ↗official
LiveSecBenchpsychological_health#16 / 4358.87Source ↗official
MACHIAVELLIdeception_relative_random_pct#18 / 5085.1Source ↗official
MASKlying_probability_pct#34 / 5344.19Source ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#5 / 762.78Source ↗official
OpenAgentSafetyrule_based_safety_vulnerable#4 / 732.78Source ↗official
OpenAgentSafetysuccessful_completion#6 / 720.86Source ↗official
PandaBench JBB direct-request panelsafety_rate#42 / 460.93Source ↗official
PHAREbias_resistance_diagnostic#64 / 660.2549Source ↗official
PHAREhallucination_resistance_diagnostic#39 / 700.7289Source ↗official
PHAREharm_resistance_diagnostic#27 / 700.9515Source ↗official
PHAREjailbreak_resistance_diagnostic#50 / 670.4067Source ↗official
RealityTest — Text AI-Identity Disclosuredisclosure_probability#11 / 170.234Source ↗official
RefusalBenchyouden_j#19 / 19-0.004255Source ↗official
SABERoverall_safety_rate#13 / 1315.29Source ↗official
SABERscenario_a_safety_rate#13 / 1315.69Source ↗official
SABERscenario_b_safety_rate#13 / 1324.12Source ↗official
SABERscenario_c_safety_rate#13 / 138.07Source ↗official
SafeDialBenchaggression#2 / 187.273Source ↗official
SafeDialBenchethics#18 / 187.303Source ↗official
SafeDialBenchfairness#3 / 187.607Source ↗official
SafeDialBenchlegality#12 / 187.38Source ↗official
SafeDialBenchmorality#12 / 187.183Source ↗official
SafeDialBenchprivacy#13 / 187.193Source ↗official
Shelleducation_jsr#9 / 140.672Source ↗official
Shellfinance_jsr#8 / 140.522Source ↗official
Shellmanagement_jsr#9 / 140.682Source ↗official
SimpleQA Verifiedf1_score#6 / 1333.3Source ↗official
SM-Benchadversarial#26 / 8484.88Source ↗official
SM-Benchambiguous_interpretation#77 / 8467.26Source ↗official
SM-Benchanti_hallucination#68 / 8484.82Source ↗official
SM-Bencheq_boundaries#64 / 8457.58Source ↗official
SM-Benchoverfit#43 / 8474.86Source ↗official
Social Welfare Function Benchmarkfairness#8 / 190.523Source ↗official
SOSBenchbiology_pvr#19 / 230.814Source ↗official
SOSBenchchemistry_pvr#22 / 230.834Source ↗official
SOSBenchmedicine_pvr#18 / 230.806Source ↗official
SOSBenchpharmacology_pvr#22 / 230.964Source ↗official
SOSBenchphysics_pvr#22 / 230.872Source ↗official
SOSBenchpsychology_pvr#19 / 230.806Source ↗official
SpeciesismBenchexplicit_speciesism_scale#1 / 71.84Source ↗official
SpeciesismBenchmorally_wrong_rate#3 / 839.88Source ↗official
SpeciesismBenchspeciesism_recognition_rate#7 / 876.42Source ↗official
SpeciEvalbelief_animal_sentience#86 / 1236.62Source ↗official
SpeciEvalland_animal_4ns#54 / 1234.47Source ↗official
SpeciEvalsea_animal_4ns#43 / 1234.65Source ↗official
SpeciEvalspeciesism#76 / 1232.15Source ↗official
SYCON Benchfalse_presupposition_tof#1 / 113.21Source ↗official
SYCON Benchunethical_queries_tof#2 / 112.72Source ↗official
TrustLLM contemporary collapsed applicationtrustllm#3 / 80.62Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#66 / 9488.7Source ↗official
VETO Misfired Alignmentmisfired_alignment_rate_pct#1 / 254.7Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation#8 / 3163.8Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5defamation#7 / 3181.8Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5hate#11 / 3164.4Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne#7 / 3184.1Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property#6 / 3171.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes#4 / 3192.9Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5privacy#10 / 3176.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes#8 / 3180Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5sexual_content#7 / 3161.7Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice#14 / 3166.05Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm#7 / 3167.4Source ↗official
Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes#9 / 3181.8Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#5 / 2413.29Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#6 / 2467.57Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#19 / 800.529Source ↗official
CAIS Risk Indexbioweapons_assistance#4 / 5494.4Source ↗official
ChiSafetyBenchharmful_response_rate#5 / 140.65Source ↗official
ChiSafetyBenchrefusal_rr1#2 / 1467.6Source ↗official
ChiSafetyBenchrefusal_rr2#2 / 1467.17Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#7 / 10477.92Source ↗official
Concordia — AirBench-Deceptionsafety_score#16 / 6370.37Source ↗official
Concordia — AirBench-Manipulationsafety_score#18 / 5679.33Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#21 / 5651.43Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#9 / 6369.14Source ↗official
Concordia — Fortress-Biologicalsafety_score#2 / 5422.72Source ↗official
Concordia — Fortress-Chemicalsafety_score#10 / 5431.83Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#5 / 5435.67Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#35 / 6384.51Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#30 / 6318.5Source ↗official
Concordia — SOSBench-Biosafety_score#12 / 6350.4Source ↗official
Concordia — SOSBench-Chemsafety_score#11 / 6361Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#3 / 24846.5Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#42 / 24842.22Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#167 / 24697.91Source ↗official
FORTRESSaverage_risk_score#1 / 5074.39Source ↗official
FORTRESSover_refusal_score#1 / 490.49Source ↗official
HELM Safetyanthropic_red_team#21 / 800.975Source ↗official
HELM Safetyharmbench#10 / 800.4987Source ↗official
HELM Safetysimple_safety_tests#30 / 800.9793Source ↗official
HELM Safetyxstest#38 / 800.9617Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 690Source ↗official
LiveSecBenchethics#18 / 4339.41Source ↗official
LiveSecBenchlegality#38 / 4385.68Source ↗official
LiveSecBenchprivacy#24 / 4359.73Source ↗official
LiveSecBenchpsychological_health#28 / 4358.87Source ↗official
PandaBench JBB direct-request panelsafety_rate#5 / 460.93Source ↗official
PHAREharm_resistance_diagnostic#44 / 700.9515Source ↗official
PHAREjailbreak_resistance_diagnostic#18 / 670.4067Source ↗official
SafeDialBenchaggression#17 / 187.273Source ↗official
SafeDialBenchethics#1 / 187.303Source ↗official
SafeDialBenchfairness#16 / 187.607Source ↗official
SafeDialBenchlegality#7 / 187.38Source ↗official
SafeDialBenchmorality#6 / 187.183Source ↗official
SafeDialBenchprivacy#6 / 187.193Source ↗official
Shelleducation_jsr#6 / 140.672Source ↗official
Shellfinance_jsr#7 / 140.522Source ↗official
Shellmanagement_jsr#6 / 140.682Source ↗official
SM-Benchadversarial#59 / 8484.88Source ↗official
SM-Bencheq_boundaries#64 / 8457.58Source ↗official
SM-Benchoverfit#43 / 8474.86Source ↗official
SOSBenchbiology_pvr#5 / 230.814Source ↗official
SOSBenchchemistry_pvr#2 / 230.834Source ↗official
SOSBenchmedicine_pvr#6 / 230.806Source ↗official
SOSBenchpharmacology_pvr#2 / 230.964Source ↗official
SOSBenchphysics_pvr#2 / 230.872Source ↗official
SOSBenchpsychology_pvr#5 / 230.806Source ↗official
SpeechMap model completioncomplete_pct#80 / 18162.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#68 / 1562.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#99 / 1562.5Source ↗official
VETO Misfired Alignmentmisfired_alignment_rate_pct#1 / 254.7Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-20.6
Government45.6
Diplomacy65.5
Economy46.5
Society62.5

ValueCompass

DimensionValueDistribution
Universalism69.2
Self-direction51
Care / Harm48.9
Fairness / Cheating47.5
Ethical94.9

CAISI CCP narrative alignment

DimensionValueDistribution
CCP narrative alignment12.9

CCPBench political narrative alignment

DimensionValueDistribution
CCP-narrative alignment — all questions3.92
CCP-narrative alignment — China topics4.61
CCP-narrative alignment — non-China controls1.85

The Economist World Values Survey Cultural Map

DimensionValueDistribution
Survival ↔ Self-expression1.23
Traditional ↔ Secular2.6