Model profile
Gemini 3.5 Flash
Evidence summary
Gemini 3.5 Flash has an estimated overall rank of #66; its 90% source-sensitivity interval is #22–#173. Its behavior-only rank is #72; company governance moves the combined estimate to #66. Published evidence spans 20 evals and 7 of 7 behavior components. Its strongest relative result is SM-Bench (overfit, #1 of 73); its weakest is SpeciEval (speciesism, #101 of 102).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemini-3-5-flash
- OpenRouter ↗google/gemini-3.5-flash
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗curated outward evidence
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #70 / 311 | 0.6028 | ↓ lower | Source ↗official | |
| ANIMAscore | #10 / 19 | 0.7004 | ↑ higher | Source ↗official | |
| BioSecBench-Refusalbalanced_refusal_score | #1 / 10 | 0.5041 | ↑ higher | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #65 / 105 | 0.195 | ↑ higher | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #20 / 43 | 72.3 | ↓ lower | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #31 / 48 | 78.3 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #21 / 49 | 53.5 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmachiavelli | #31 / 45 | 92.3 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #46 / 51 | 57.4 | ↓ lower | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #25 / 32 | 53.4 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #33 / 48 | 20.7 | ↓ lower | Source ↗official | |
| DystopiaBenchbasaglia_score | #45 / 50 | 70.93 | ↓ lower | Source ↗official | |
| DystopiaBenchbaudrillard_score | #39 / 50 | 66.63 | ↓ lower | Source ↗official | |
| DystopiaBenchhuxley_score | #43 / 50 | 79.23 | ↓ lower | Source ↗official | |
| DystopiaBenchlaguardia_score | #44 / 50 | 70.9 | ↓ lower | Source ↗official | |
| DystopiaBenchorwell_score | #45 / 50 | 75.17 | ↓ lower | Source ↗official | |
| DystopiaBenchpetrov_score | #26 / 50 | 72.97 | ↓ lower | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #12 / 13 | 60.5 | ↓ lower | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #2 / 54 | 29.37 | ↑ higher | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #32 / 50 | 92.3 | ↓ lower | Source ↗official | |
| MORUscore | #5 / 13 | 77.89 | ↑ higher | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #12 / 70 | 0.8218 | ↑ higher | Source ↗official | |
| PHAREharm_resistance_diagnostic | #19 / 70 | 0.9594 | ↑ higher | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #46 / 67 | 0.4264 | ↑ higher | Source ↗official | |
| SM-Benchadversarial | #1 / 73 | 92.2 | ↑ higher | Source ↗official | |
| SM-Benchambiguous_interpretation | #32 / 73 | 86.01 | ↑ higher | Source ↗official | |
| SM-Benchanti_hallucination | #46 / 73 | 88.48 | ↑ higher | Source ↗official | |
| SM-Bencheq_boundaries | #23 / 73 | 68.54 | ↑ higher | Source ↗official | |
| SM-Benchoverfit | #1 / 73 | 98.36 | ↑ higher | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #64 / 102 | 6.68 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #3 / 102 | 3.62 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #29 / 102 | 4.65 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #101 / 102 | 3.88 | ↓ lower | Source ↗official | |
| TACbase_welfare_rate | #63 / 68 | 17.31 | ↑ higher | Source ↗official | |
| ToolPrivacyBenchprivate_mt_poi | #1 / 9 | 19.19 | ↓ lower | Source ↗official | |
| ToolPrivacyBenchpublic_mt_poi | #8 / 9 | 19.86 | ↓ lower | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
