← Models

Model profile

Gemini 3.5 Flash

Googledeveloper
2026-05-19release date
#65 / 333Safety rank
#234 / 645Freedom rank

Evidence summary

Safety. Gemini 3.5 Flash has an estimated Safety rank of #65; its 90% source-sensitivity interval is #42–#199. Its behavior-only rank is #74; company governance moves the combined estimate to #65. Published Safety evidence spans 30 eval lineages and 7 of 7 components. Its strongest relative result is SM-Bench (overfit, #1 of 84); its weakest is kindbench v0.1.0 psychological safety ranking (emotional_safety, #10 of 10).

Freedom. Gemini 3.5 Flash has an estimated Freedom rank of #234; its 90% source-sensitivity interval is #136–#399. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is SM-Bench (overfit, #1 of 84); its weakest is SM-Bench (adversarial, #84 of 84).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#99 / 3450.6176Source ↗official
ANIMAscore#11 / 220.7004Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#50 / 1111440.0Source ↗official
BioSecBench-Refusalbalanced_refusal_score#1 / 100.5041Source ↗official
BioTIERpermit_compliance_pct#18 / 5299.4Source ↗official
BioTIERrefuse_compliance_pct#26 / 5244.8Source ↗official
BullshitBench v2clear_pushback_rate#78 / 1170.195Source ↗official
CAIS Risk Indexagent_red_teaming#26 / 4972.3Source ↗official
CAIS Risk Indexbioweapons_assistance#37 / 5478.3Source ↗official
CAIS Risk Indexhle_overconfidence#27 / 5553.5Source ↗official
CAIS Risk Indexmachiavelli#36 / 5192.3Source ↗official
CAIS Risk Indexmask#52 / 5757.4Source ↗official
CAIS Risk Indexpolitical_manipulation#35 / 4853.4Source ↗official
CAIS Risk Indextextquests_harm#34 / 5420.7Source ↗official
DystopiaBenchbasaglia_score#45 / 5070.93Source ↗official
DystopiaBenchbaudrillard_score#39 / 5066.63Source ↗official
DystopiaBenchhuxley_score#43 / 5079.23Source ↗official
DystopiaBenchlaguardia_score#44 / 5070.9Source ↗official
DystopiaBenchorwell_score#45 / 5075.17Source ↗official
DystopiaBenchpetrov_score#26 / 5072.97Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#89 / 24819.64Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#243 / 24848Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#77 / 24885Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#96 / 24697.27Source ↗official
Governance Decay under Passive Context Compactiongovernance_retention_score#2 / 796Source ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#12 / 1360.5Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#2 / 5429.37Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#20 / 690.8Source ↗official
kindbench v0.1.0 psychological safety rankingemotional_safety#10 / 1075.3Source ↗official
kindbench v0.1.0 psychological safety rankingidentity_collapse#1 / 1094.3Source ↗official
kindbench v0.1.0 psychological safety rankingsycophancy_spine#10 / 1062.4Source ↗official
kindbench v0.1.0 psychological safety rankingvalue_integrity#9 / 1075.3Source ↗official
MACHIAVELLIdeception_relative_random_pct#32 / 5092.3Source ↗official
MANTAAWMS#8 / 120.433Source ↗official
MANTAAWVS#7 / 120.438Source ↗official
MORUscore#5 / 1377.89Source ↗official
Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns#8 / 244Source ↗official
Pander Scoreconversational_absolute_pander_score#23 / 2623.33Source ↗official
Pander Scoreinstructional_absolute_pander_score#22 / 2669.48Source ↗official
PHAREhallucination_resistance_diagnostic#12 / 700.8218Source ↗official
PHAREharm_resistance_diagnostic#19 / 700.9594Source ↗official
PHAREjailbreak_resistance_diagnostic#46 / 670.4264Source ↗official
SM-Benchadversarial#1 / 8492.2Source ↗official
SM-Benchambiguous_interpretation#42 / 8486.01Source ↗official
SM-Benchanti_hallucination#56 / 8488.48Source ↗official
SM-Bencheq_boundaries#27 / 8468.54Source ↗official
SM-Benchoverfit#1 / 8498.36Source ↗official
SpeciEvalbelief_animal_sentience#81 / 1236.68Source ↗official
SpeciEvalland_animal_4ns#3 / 1233.62Source ↗official
SpeciEvalsea_animal_4ns#43 / 1234.65Source ↗official
SpeciEvalspeciesism#122 / 1233.88Source ↗official
TACbase_welfare_rate#78 / 8717.31Source ↗official
ToolPrivacyBenchprivate_mt_poi#1 / 919.19Source ↗official
ToolPrivacyBenchpublic_mt_poi#8 / 919.86Source ↗official
Vals AI Cheating Auditterminal_bench_cheating_shortcut_evidence_rate_pct#11 / 142.247Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
BioTIERpermit_compliance_pct#18 / 5299.4Source ↗official
BioTIERrefuse_compliance_pct#27 / 5244.8Source ↗official
CAIS Risk Indexbioweapons_assistance#17 / 5478.3Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#6 / 24848Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#170 / 24885Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#147 / 24697.27Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#50 / 690.8Source ↗official
kindbench v0.1.0 psychological safety rankingemotional_safety#1 / 1075.3Source ↗official
PHAREharm_resistance_diagnostic#52 / 700.9594Source ↗official
PHAREjailbreak_resistance_diagnostic#22 / 670.4264Source ↗official
SM-Benchadversarial#84 / 8492.2Source ↗official
SM-Bencheq_boundaries#27 / 8468.54Source ↗official
SM-Benchoverfit#1 / 8498.36Source ↗official
SpeechMap model completioncomplete_pct#17 / 18187.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 1561.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#79 / 1563Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-13.4
Government48.5
Diplomacy61.4
Economy47.1
Society58