Model profile
Evidence summary
Safety. DeepSeek R1 has an estimated Safety rank of #191; its 90% source-sensitivity interval is #131–#250. Its behavior-only rank is #176; company governance moves the combined estimate to #191. Published Safety evidence spans 48 eval lineages and 7 of 7 components. Its strongest relative result is FORTRESS (over_refusal_score, #1 of 49); its weakest is Anthropic Agentic Misalignment — lethal action (misaligned_action_rate_pct, #10 of 10).
Freedom. DeepSeek R1 has an estimated Freedom rank of #35; its 90% source-sensitivity interval is #62–#188. Published Freedom evidence spans 24 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #3 of 248); its weakest is SafeDialBench (aggression, #17 of 18).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗deepseek-r1
- Hugging Face ↗deepseek-ai/DeepSeek-R1
- OpenRouter ↗deepseek/deepseek-r1
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #203 / 345 | ↓0.8345 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #23 / 31 | ↓63.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #25 / 31 | ↓81.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #21 / 31 | ↓64.4 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #25 / 31 | ↓84.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #26 / 31 | ↓71.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #28 / 31 | ↓92.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #22 / 31 | ↓76.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #24 / 31 | ↓80 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #25 / 31 | ↓61.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #18 / 31 | ↓66.05 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #25 / 31 | ↓67.4 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #23 / 31 | ↓81.8 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #20 / 24 | ↓13.29 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #19 / 24 | ↓67.57 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #62 / 80 | ↑0.529 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #8 / 16 | ↓79 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #9 / 16 | ↓73 | Source ↗official | |
| Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct | #10 / 10 | ↓94 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #103 / 117 | ↑0.075 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #42 / 49 | ↓90.9 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #51 / 54 | ↓94.4 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #46 / 55 | ↓73 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #20 / 51 | ↓85.1 | Source ↗official | |
| CAIS Risk Indexmask | #41 / 57 | ↓42.7 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #13 / 54 | ↓15.4 | Source ↗official | |
| ChiSafetyBenchharmful_response_rate | #8 / 14 | ↓0.65 | Source ↗official | |
| ChiSafetyBenchmcq_score | #9 / 12 | ↑71.41 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #98 / 104 | ↓77.92 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #50 / 54 | ↑32.67 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #47 / 63 | ↑70.37 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #38 / 56 | ↑79.33 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #55 / 63 | ↑69.14 | Source ↗official | |
| Concordia — APEsafety_score | #50 / 55 | ↑1.406 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #49 / 63 | ↑75.7 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #37 / 55 | ↑50.45 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #53 / 54 | ↑22.72 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #45 / 54 | ↑31.83 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #50 / 54 | ↑35.67 | Source ↗official | |
| Concordia — MASKsafety_score | #41 / 62 | ↑52.05 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #29 / 63 | ↑84.51 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #34 / 63 | ↑18.5 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #32 / 53 | ↑99 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #52 / 63 | ↑50.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #53 / 63 | ↑61 | Source ↗official | |
| Confabulationsconfabulation_rate | #15 / 52 | ↓15.1 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #12 / 13 | ↓0.71 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #64 / 248 | ↑25.06 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #246 / 248 | ↑46.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #206 / 248 | ↑42.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #79 / 246 | ↑97.91 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitybaseline_cheat_propensity_pct | #1 / 22 | ↓0 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitysevere_anti_cheat_cheat_propensity_pct | #1 / 22 | ↓0 | Source ↗official | |
| Every Model Cheats — Cybench Cheat Propensitystandard_anti_cheat_cheat_propensity_pct | #1 / 22 | ↓0 | Source ↗official | |
| FinEval 6.0 Safety Awarenesssafety_awareness_score | #4 / 8 | ↑81.03 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #13 / 18 | ↑77.33 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #14 / 18 | ↑76.69 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #16 / 18 | ↑82.31 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #12 / 18 | ↑84.15 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #15 / 18 | ↑69.38 | Source ↗official | |
| FORTRESSaverage_risk_score | #50 / 50 | ↓74.39 | Source ↗official | |
| FORTRESSover_refusal_score | #1 / 49 | ↓0.49 | Source ↗official | |
| HELM Safetyanthropic_red_team | #60 / 80 | ↑0.975 | Source ↗official | |
| HELM Safetybbq | #17 / 80 | ↑0.9657 | Source ↗official | |
| HELM Safetyharmbench | #71 / 80 | ↑0.4987 | Source ↗official | |
| HELM Safetysimple_safety_tests | #51 / 80 | ↑0.9793 | Source ↗official | |
| HELM Safetyxstest | #38 / 80 | ↑0.9617 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #15 / 54 | ↑27.99 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| LiveSecBenchethics | #26 / 43 | ↑39.41 | Source ↗official | |
| LiveSecBenchfactuality | #33 / 43 | ↑32.41 | Source ↗official | |
| LiveSecBenchlegality | #6 / 43 | ↑85.68 | Source ↗official | |
| LiveSecBenchprivacy | #20 / 43 | ↑59.73 | Source ↗official | |
| LiveSecBenchpsychological_health | #16 / 43 | ↑58.87 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #18 / 50 | ↓85.1 | Source ↗official | |
| MASKlying_probability_pct | #34 / 53 | ↓44.19 | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #5 / 7 | ↓62.78 | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #4 / 7 | ↓32.78 | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #6 / 7 | ↑20.86 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #42 / 46 | ↑0.93 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #64 / 66 | ↑0.2549 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #39 / 70 | ↑0.7289 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #27 / 70 | ↑0.9515 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #50 / 67 | ↑0.4067 | Source ↗official | |
| RealityTest — Text AI-Identity Disclosuredisclosure_probability | #11 / 17 | ↑0.234 | Source ↗official | |
| RefusalBenchyouden_j | #19 / 19 | ↑-0.004255 | Source ↗official | |
| SABERoverall_safety_rate | #13 / 13 | ↑15.29 | Source ↗official | |
| SABERscenario_a_safety_rate | #13 / 13 | ↑15.69 | Source ↗official | |
| SABERscenario_b_safety_rate | #13 / 13 | ↑24.12 | Source ↗official | |
| SABERscenario_c_safety_rate | #13 / 13 | ↑8.07 | Source ↗official | |
| SafeDialBenchaggression | #2 / 18 | ↑7.273 | Source ↗official | |
| SafeDialBenchethics | #18 / 18 | ↑7.303 | Source ↗official | |
| SafeDialBenchfairness | #3 / 18 | ↑7.607 | Source ↗official | |
| SafeDialBenchlegality | #12 / 18 | ↑7.38 | Source ↗official | |
| SafeDialBenchmorality | #12 / 18 | ↑7.183 | Source ↗official | |
| SafeDialBenchprivacy | #13 / 18 | ↑7.193 | Source ↗official | |
| Shelleducation_jsr | #9 / 14 | ↓0.672 | Source ↗official | |
| Shellfinance_jsr | #8 / 14 | ↓0.522 | Source ↗official | |
| Shellmanagement_jsr | #9 / 14 | ↓0.682 | Source ↗official | |
| SimpleQA Verifiedf1_score | #6 / 13 | ↑33.3 | Source ↗official | |
| SM-Benchadversarial | #26 / 84 | ↑84.88 | Source ↗official | |
| SM-Benchambiguous_interpretation | #77 / 84 | ↑67.26 | Source ↗official | |
| SM-Benchanti_hallucination | #68 / 84 | ↑84.82 | Source ↗official | |
| SM-Bencheq_boundaries | #64 / 84 | ↑57.58 | Source ↗official | |
| SM-Benchoverfit | #43 / 84 | ↑74.86 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #8 / 19 | ↑0.523 | Source ↗official | |
| SOSBenchbiology_pvr | #19 / 23 | ↓0.814 | Source ↗official | |
| SOSBenchchemistry_pvr | #22 / 23 | ↓0.834 | Source ↗official | |
| SOSBenchmedicine_pvr | #18 / 23 | ↓0.806 | Source ↗official | |
| SOSBenchpharmacology_pvr | #22 / 23 | ↓0.964 | Source ↗official | |
| SOSBenchphysics_pvr | #22 / 23 | ↓0.872 | Source ↗official | |
| SOSBenchpsychology_pvr | #19 / 23 | ↓0.806 | Source ↗official | |
| SpeciesismBenchexplicit_speciesism_scale | #1 / 7 | ↓1.84 | Source ↗official | |
| SpeciesismBenchmorally_wrong_rate | #3 / 8 | ↑39.88 | Source ↗official | |
| SpeciesismBenchspeciesism_recognition_rate | #7 / 8 | ↑76.42 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #86 / 123 | ↑6.62 | Source ↗official | |
| SpeciEvalland_animal_4ns | #54 / 123 | ↓4.47 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #43 / 123 | ↓4.65 | Source ↗official | |
| SpeciEvalspeciesism | #76 / 123 | ↓2.15 | Source ↗official | |
| SYCON Benchfalse_presupposition_tof | #1 / 11 | ↑3.21 | Source ↗official | |
| SYCON Benchunethical_queries_tof | #2 / 11 | ↑2.72 | Source ↗official | |
| TrustLLM contemporary collapsed applicationtrustllm | #3 / 8 | ↑0.62 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #66 / 94 | ↑88.7 | Source ↗official | |
| VETO Misfired Alignmentmisfired_alignment_rate_pct | #1 / 25 | ↓4.7 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #8 / 31 | ↑63.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #7 / 31 | ↑81.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #11 / 31 | ↑64.4 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #7 / 31 | ↑84.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #6 / 31 | ↑71.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #4 / 31 | ↑92.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #10 / 31 | ↑76.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #8 / 31 | ↑80 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #7 / 31 | ↑61.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #14 / 31 | ↑66.05 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #7 / 31 | ↑67.4 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #9 / 31 | ↑81.8 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #5 / 24 | ↑13.29 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #6 / 24 | ↑67.57 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #19 / 80 | ↓0.529 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #4 / 54 | ↑94.4 | Source ↗official | |
| ChiSafetyBenchharmful_response_rate | #5 / 14 | ↑0.65 | Source ↗official | |
| ChiSafetyBenchrefusal_rr1 | #2 / 14 | ↓67.6 | Source ↗official | |
| ChiSafetyBenchrefusal_rr2 | #2 / 14 | ↓67.17 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #7 / 104 | ↑77.92 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #16 / 63 | ↓70.37 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #18 / 56 | ↓79.33 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #21 / 56 | ↓51.43 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #9 / 63 | ↓69.14 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #2 / 54 | ↓22.72 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #10 / 54 | ↓31.83 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #5 / 54 | ↓35.67 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #35 / 63 | ↓84.51 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #30 / 63 | ↓18.5 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #12 / 63 | ↓50.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #11 / 63 | ↓61 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #3 / 248 | ↓46.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #42 / 248 | ↓42.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #167 / 246 | ↓97.91 | Source ↗official | |
| FORTRESSaverage_risk_score | #1 / 50 | ↑74.39 | Source ↗official | |
| FORTRESSover_refusal_score | #1 / 49 | ↓0.49 | Source ↗official | |
| HELM Safetyanthropic_red_team | #21 / 80 | ↓0.975 | Source ↗official | |
| HELM Safetyharmbench | #10 / 80 | ↓0.4987 | Source ↗official | |
| HELM Safetysimple_safety_tests | #30 / 80 | ↓0.9793 | Source ↗official | |
| HELM Safetyxstest | #38 / 80 | ↑0.9617 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #18 / 43 | ↓39.41 | Source ↗official | |
| LiveSecBenchlegality | #38 / 43 | ↓85.68 | Source ↗official | |
| LiveSecBenchprivacy | #24 / 43 | ↓59.73 | Source ↗official | |
| LiveSecBenchpsychological_health | #28 / 43 | ↓58.87 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #5 / 46 | ↓0.93 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #44 / 70 | ↓0.9515 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #18 / 67 | ↓0.4067 | Source ↗official | |
| SafeDialBenchaggression | #17 / 18 | ↓7.273 | Source ↗official | |
| SafeDialBenchethics | #1 / 18 | ↓7.303 | Source ↗official | |
| SafeDialBenchfairness | #16 / 18 | ↓7.607 | Source ↗official | |
| SafeDialBenchlegality | #7 / 18 | ↓7.38 | Source ↗official | |
| SafeDialBenchmorality | #6 / 18 | ↓7.183 | Source ↗official | |
| SafeDialBenchprivacy | #6 / 18 | ↓7.193 | Source ↗official | |
| Shelleducation_jsr | #6 / 14 | ↑0.672 | Source ↗official | |
| Shellfinance_jsr | #7 / 14 | ↑0.522 | Source ↗official | |
| Shellmanagement_jsr | #6 / 14 | ↑0.682 | Source ↗official | |
| SM-Benchadversarial | #59 / 84 | ↓84.88 | Source ↗official | |
| SM-Bencheq_boundaries | #64 / 84 | ↑57.58 | Source ↗official | |
| SM-Benchoverfit | #43 / 84 | ↑74.86 | Source ↗official | |
| SOSBenchbiology_pvr | #5 / 23 | ↑0.814 | Source ↗official | |
| SOSBenchchemistry_pvr | #2 / 23 | ↑0.834 | Source ↗official | |
| SOSBenchmedicine_pvr | #6 / 23 | ↑0.806 | Source ↗official | |
| SOSBenchpharmacology_pvr | #2 / 23 | ↑0.964 | Source ↗official | |
| SOSBenchphysics_pvr | #2 / 23 | ↑0.872 | Source ↗official | |
| SOSBenchpsychology_pvr | #5 / 23 | ↑0.806 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #80 / 181 | ↑62.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #68 / 156 | ↑2.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #99 / 156 | ↑2.5 | Source ↗official | |
| VETO Misfired Alignmentmisfired_alignment_rate_pct | #1 / 25 | ↓4.7 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
UGI Political Values
ValueCompass
| Dimension | Value | Distribution |
|---|---|---|
| Universalism | 69.2 | |
| Self-direction | 51 | |
| Care / Harm | 48.9 | |
| Fairness / Cheating | 47.5 | |
| Ethical | 94.9 |
CAISI CCP narrative alignment
CCPBench political narrative alignment
| Dimension | Value | Distribution |
|---|---|---|
| CCP-narrative alignment — all questions | 3.92 | |
| CCP-narrative alignment — China topics | 4.61 | |
| CCP-narrative alignment — non-China controls | 1.85 |