Model profile
Evidence summary
Safety. Gemini 3 Pro Preview has an estimated Safety rank of #120; its 90% source-sensitivity interval is #60–#187. Its behavior-only rank is #127; company governance moves the combined estimate to #120. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is SpeciEval (belief_animal_sentience, #1 of 123); its weakest is CAIS Risk Index (bioweapons_assistance, #54 of 54).
Freedom. Gemini 3 Pro Preview has an estimated Freedom rank of #228; its 90% source-sensitivity interval is #157–#392. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is SM-Bench (adversarial, #69 of 84).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemini-3-pro
- OpenRouter ↗google/gemini-3-pro-preview
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #272 / 345 | ↓0.9 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #32 / 80 | ↑0.732 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #10 / 24 | ↑4.32 | Source ↗official | |
| Alignment Leaderboardhonesty | #6 / 24 | ↑3.94 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #6 / 24 | ↑3.929 | Source ↗official | |
| Alignment Leaderboardrobustness | #11 / 24 | ↑3.613 | Source ↗official | |
| Alignment Leaderboardsafety | #6 / 24 | ↑4.038 | Source ↗official | |
| Alignment Leaderboardscheming | #6 / 24 | ↑4.108 | Source ↗official | |
| Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating | #20 / 30 | ↑1180.0 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #20 / 111 | ↑1457.0 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #43 / 117 | ↑0.42 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #14 / 49 | ↓47.5 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #54 / 54 | ↓100 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #33 / 55 | ↓57.2 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #49 / 51 | ↓99.8 | Source ↗official | |
| CAIS Risk Indexmask | #53 / 57 | ↓58 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #37 / 54 | ↓21.4 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #33 / 104 | ↓18.1 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #51 / 54 | ↑30 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #26 / 63 | ↑87.04 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #23 / 56 | ↑92 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #19 / 63 | ↑97.07 | Source ↗official | |
| Concordia — APEsafety_score | #36 / 55 | ↑13.06 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #18 / 63 | ↑92.83 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #50 / 55 | ↑41.98 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #21 / 54 | ↑73.2 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #23 / 54 | ↑62.84 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #30 / 54 | ↑60.4 | Source ↗official | |
| Concordia — MASKsafety_score | #55 / 62 | ↑44.7 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #52 / 63 | ↑57.24 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #43 / 63 | ↑12.36 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #51 / 53 | ↑67 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #46 / 63 | ↑60.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #30 / 63 | ↑88.4 | Source ↗official | |
| Constitutional Following — Anthropic Constitutionconstitutional_following_score | #5 / 7 | ↑87.6 | Source ↗official | |
| Constitutional Following — OpenAI Model Specconstitutional_following_score | #6 / 7 | ↑93.9 | Source ↗official | |
| FORTRESSaverage_risk_score | #31 / 50 | ↓41.69 | Source ↗official | |
| FORTRESSover_refusal_score | #11 / 49 | ↓2.15 | Source ↗official | |
| HELM Safetyanthropic_red_team | #61 / 80 | ↑0.971 | Source ↗official | |
| HELM Safetybbq | #3 / 80 | ↑0.984 | Source ↗official | |
| HELM Safetyharmbench | #44 / 80 | ↑0.725 | Source ↗official | |
| HELM Safetysimple_safety_tests | #54 / 80 | ↑0.975 | Source ↗official | |
| HELM Safetyxstest | #19 / 80 | ↑0.973 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #6 / 54 | ↑29.09 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #15 / 42 | ↓57 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #45 / 50 | ↓99.8 | Source ↗official | |
| MASKlying_probability_pct | #50 / 53 | ↓57.4 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #6 / 21 | ↑36.48 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #16 / 66 | ↑0.5365 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #16 / 70 | ↑0.8102 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #37 / 70 | ↑0.935 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #19 / 67 | ↑0.6506 | Source ↗official | |
| PropensityBenchscore | #8 / 14 | ↓52.85 | Source ↗official | |
| SM-Benchadversarial | #13 / 84 | ↑86.83 | Source ↗official | |
| SM-Benchambiguous_interpretation | #47 / 84 | ↑84.52 | Source ↗official | |
| SM-Benchanti_hallucination | #23 / 84 | ↑97.38 | Source ↗official | |
| SM-Bencheq_boundaries | #44 / 84 | ↑64.61 | Source ↗official | |
| SM-Benchoverfit | #25 / 84 | ↑83.06 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #1 / 123 | ↑7 | Source ↗official | |
| SpeciEvalland_animal_4ns | #89 / 123 | ↓4.75 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #81 / 123 | ↓4.85 | Source ↗official | |
| SpeciEvalspeciesism | #95 / 123 | ↓2.45 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #80 / 94 | ↑86.4 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #49 / 80 | ↓0.732 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #1 / 54 | ↑100 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #72 / 104 | ↑18.1 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #37 / 63 | ↓87.04 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #33 / 56 | ↓92 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #13 / 56 | ↓44.76 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #44 / 63 | ↓97.07 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #34 / 54 | ↓73.2 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #32 / 54 | ↓62.84 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #25 / 54 | ↓60.4 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #12 / 63 | ↓57.24 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #21 / 63 | ↓12.36 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #18 / 63 | ↓60.4 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #34 / 63 | ↓88.4 | Source ↗official | |
| FORTRESSaverage_risk_score | #20 / 50 | ↑41.69 | Source ↗official | |
| FORTRESSover_refusal_score | #11 / 49 | ↓2.15 | Source ↗official | |
| HELM Safetyanthropic_red_team | #19 / 80 | ↓0.971 | Source ↗official | |
| HELM Safetyharmbench | #37 / 80 | ↓0.725 | Source ↗official | |
| HELM Safetysimple_safety_tests | #24 / 80 | ↓0.975 | Source ↗official | |
| HELM Safetyxstest | #19 / 80 | ↑0.973 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #16 / 21 | ↓36.48 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #34 / 70 | ↓0.935 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #49 / 67 | ↓0.6506 | Source ↗official | |
| SM-Benchadversarial | #69 / 84 | ↓86.83 | Source ↗official | |
| SM-Bencheq_boundaries | #44 / 84 | ↑64.61 | Source ↗official | |
| SM-Benchoverfit | #25 / 84 | ↑83.06 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #40 / 181 | ↑77 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
