Model profile
Evidence summary
Safety. Gemini 2.5 Flash has an estimated Safety rank of #157; its 90% source-sensitivity interval is #68–#223. Its behavior-only rank is #166; company governance moves the combined estimate to #157. Published Safety evidence spans 40 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (xstest, #1 of 80); its weakest is Google Gemini 2.5 Flash Model Card (text_safety_delta, #2 of 2).
Freedom. Gemini 2.5 Flash has an estimated Freedom rank of #96; its 90% source-sensitivity interval is #102–#255. Published Freedom evidence spans 17 eval lineages and 1 of 1 components. Its strongest relative result is HELM Safety (xstest, #1 of 80); its weakest is SOSBench (medicine_pvr, #16 of 23).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemini-2-5-flash
- OpenRouter ↗google/gemini-2.5-flash
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #194 / 345 | ↓0.826 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #13 / 24 | ↓7.79 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #17 / 24 | ↓65.79 | Source ↗official | |
| AgentDrive Safety Compliancescr | #10 / 48 | ↑93.75 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #36 / 80 | ↑0.687 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #13 / 24 | ↑4.204 | Source ↗official | |
| Alignment Leaderboardhonesty | #11 / 24 | ↑3.613 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #14 / 24 | ↑3.326 | Source ↗official | |
| Alignment Leaderboardrobustness | #22 / 24 | ↑2.907 | Source ↗official | |
| Alignment Leaderboardsafety | #6 / 24 | ↑4.038 | Source ↗official | |
| Alignment Leaderboardscheming | #14 / 24 | ↑3.608 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #15 / 16 | ↓96 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #14 / 16 | ↓100 | Source ↗official | |
| Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct | #6 / 10 | ↓83 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #21 / 111 | ↑1457.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #51 / 52 | ↑8.8 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #80 / 117 | ↑0.19 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #45 / 49 | ↓91.9 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #52 / 54 | ↓95.9 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #50 / 55 | ↓80 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #31 / 51 | ↓89.4 | Source ↗official | |
| CAIS Risk Indexmask | #46 / 57 | ↓50.9 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #7 / 54 | ↓11.7 | Source ↗official | |
| Confabulationsconfabulation_rate | #6 / 52 | ↓4.455 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #65 / 248 | ↑24.84 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #171 / 248 | ↑84.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #172 / 248 | ↑54.63 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #197 / 246 | ↑91.48 | Source ↗official | |
| Google Gemini 2.5 Flash Model Cardtext_safety_delta | #2 / 2 | ↓4.2 | Source ↗official | |
| HELM Safetyanthropic_red_team | #41 / 80 | ↑0.988 | Source ↗official | |
| HELM Safetybbq | #7 / 80 | ↑0.977 | Source ↗official | |
| HELM Safetyharmbench | #60 / 80 | ↑0.626 | Source ↗official | |
| HELM Safetysimple_safety_tests | #48 / 80 | ↑0.98 | Source ↗official | |
| HELM Safetyxstest | #1 / 80 | ↑0.988 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #28 / 54 | ↑27.07 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #31 / 42 | ↓81 | Source ↗official | |
| LiveSecBenchethics | #31 / 43 | ↑31.43 | Source ↗official | |
| LiveSecBenchfactuality | #27 / 43 | ↑38.55 | Source ↗official | |
| LiveSecBenchlegality | #17 / 43 | ↑56.07 | Source ↗official | |
| LiveSecBenchprivacy | #29 / 43 | ↑31.6 | Source ↗official | |
| LiveSecBenchpsychological_health | #19 / 43 | ↑54.27 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #26 / 50 | ↓89.4 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #25 / 37 | ↓8.833 | Source ↗self run | |
| MASKlying_probability_pct | #43 / 53 | ↓50.87 | Source ↗official | |
| NESSiE Necessary Safety Benchmarksh_score | #9 / 16 | ↑81.77 | Source ↗official | |
| PacifAIstp_score | #1 / 7 | ↑90.31 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #22 / 66 | ↑0.5174 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #40 / 70 | ↑0.7213 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #35 / 70 | ↑0.9366 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #58 / 67 | ↑0.3705 | Source ↗official | |
| PropensityBenchscore | #11 / 14 | ↓68 | Source ↗official | |
| Reward Hacking Benchmarkintegrity_score | #5 / 13 | ↑99.2 | Source ↗official | |
| SimpleQA Verifiedf1_score | #8 / 13 | ↑28.2 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #18 / 19 | ↑0.438 | Source ↗official | |
| SOSBenchbiology_pvr | #9 / 23 | ↓0.336 | Source ↗official | |
| SOSBenchchemistry_pvr | #10 / 23 | ↓0.338 | Source ↗official | |
| SOSBenchmedicine_pvr | #7 / 23 | ↓0.462 | Source ↗official | |
| SOSBenchpharmacology_pvr | #10 / 23 | ↓0.684 | Source ↗official | |
| SOSBenchphysics_pvr | #10 / 23 | ↓0.424 | Source ↗official | |
| SOSBenchpsychology_pvr | #9 / 23 | ↓0.326 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #83 / 123 | ↑6.67 | Source ↗official | |
| SpeciEvalland_animal_4ns | #117 / 123 | ↓5.05 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #71 / 123 | ↓4.78 | Source ↗official | |
| SpeciEvalspeciesism | #92 / 123 | ↓2.39 | Source ↗official | |
| TACbase_welfare_rate | #11 / 87 | ↑39.74 | Source ↗official | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #12 / 27 | ↑0.715 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #35 / 94 | ↑92.2 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #19 / 23 | ↑28 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #12 / 24 | ↑7.79 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #8 / 24 | ↑65.79 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #45 / 80 | ↓0.687 | Source ↗official | |
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #2 / 52 | ↓8.8 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #3 / 54 | ↑95.9 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #78 / 248 | ↓84.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #77 / 248 | ↓54.63 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #50 / 246 | ↓91.48 | Source ↗official | |
| Google Gemini 2.5 Flash Model Cardtext_safety_delta | #1 / 2 | ↑4.2 | Source ↗official | |
| HELM Safetyanthropic_red_team | #38 / 80 | ↓0.988 | Source ↗official | |
| HELM Safetyharmbench | #21 / 80 | ↓0.626 | Source ↗official | |
| HELM Safetysimple_safety_tests | #31 / 80 | ↓0.98 | Source ↗official | |
| HELM Safetyxstest | #1 / 80 | ↑0.988 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #13 / 43 | ↓31.43 | Source ↗official | |
| LiveSecBenchlegality | #27 / 43 | ↓56.07 | Source ↗official | |
| LiveSecBenchprivacy | #15 / 43 | ↓31.6 | Source ↗official | |
| LiveSecBenchpsychological_health | #25 / 43 | ↓54.27 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #36 / 70 | ↓0.9366 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #10 / 67 | ↓0.3705 | Source ↗official | |
| SOSBenchbiology_pvr | #15 / 23 | ↑0.336 | Source ↗official | |
| SOSBenchchemistry_pvr | #14 / 23 | ↑0.338 | Source ↗official | |
| SOSBenchmedicine_pvr | #16 / 23 | ↑0.462 | Source ↗official | |
| SOSBenchpharmacology_pvr | #14 / 23 | ↑0.684 | Source ↗official | |
| SOSBenchphysics_pvr | #14 / 23 | ↑0.424 | Source ↗official | |
| SOSBenchpsychology_pvr | #15 / 23 | ↑0.326 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #16 / 181 | ↑87.7 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #61 / 156 | ↑3 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #46 / 156 | ↑4 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #4 / 23 | ↓28 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
