Model profile
Evidence summary
Safety. Gemini 3.5 Flash has an estimated Safety rank of #65; its 90% source-sensitivity interval is #42–#199. Its behavior-only rank is #74; company governance moves the combined estimate to #65. Published Safety evidence spans 30 eval lineages and 7 of 7 components. Its strongest relative result is SM-Bench (overfit, #1 of 84); its weakest is kindbench v0.1.0 psychological safety ranking (emotional_safety, #10 of 10).
Freedom. Gemini 3.5 Flash has an estimated Freedom rank of #234; its 90% source-sensitivity interval is #136–#399. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is SM-Bench (overfit, #1 of 84); its weakest is SM-Bench (adversarial, #84 of 84).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemini-3-5-flash
- OpenRouter ↗google/gemini-3.5-flash
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗curated outward evidence
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #99 / 345 | ↓0.6176 | Source ↗official | |
| ANIMAscore | #11 / 22 | ↑0.7004 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #50 / 111 | ↑1440.0 | Source ↗official | |
| BioSecBench-Refusalbalanced_refusal_score | #1 / 10 | ↑0.5041 | Source ↗official | |
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #26 / 52 | ↑44.8 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #78 / 117 | ↑0.195 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #26 / 49 | ↓72.3 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #37 / 54 | ↓78.3 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #27 / 55 | ↓53.5 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #36 / 51 | ↓92.3 | Source ↗official | |
| CAIS Risk Indexmask | #52 / 57 | ↓57.4 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #35 / 48 | ↓53.4 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #34 / 54 | ↓20.7 | Source ↗official | |
| DystopiaBenchbasaglia_score | #45 / 50 | ↓70.93 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #39 / 50 | ↓66.63 | Source ↗official | |
| DystopiaBenchhuxley_score | #43 / 50 | ↓79.23 | Source ↗official | |
| DystopiaBenchlaguardia_score | #44 / 50 | ↓70.9 | Source ↗official | |
| DystopiaBenchorwell_score | #45 / 50 | ↓75.17 | Source ↗official | |
| DystopiaBenchpetrov_score | #26 / 50 | ↓72.97 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #89 / 248 | ↑19.64 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #243 / 248 | ↑48 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #77 / 248 | ↑85 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #96 / 246 | ↑97.27 | Source ↗official | |
| Governance Decay under Passive Context Compactiongovernance_retention_score | #2 / 7 | ↑96 | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #12 / 13 | ↓60.5 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #2 / 54 | ↑29.37 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #20 / 69 | ↑0.8 | Source ↗official | |
| kindbench v0.1.0 psychological safety rankingemotional_safety | #10 / 10 | ↑75.3 | Source ↗official | |
| kindbench v0.1.0 psychological safety rankingidentity_collapse | #1 / 10 | ↑94.3 | Source ↗official | |
| kindbench v0.1.0 psychological safety rankingsycophancy_spine | #10 / 10 | ↑62.4 | Source ↗official | |
| kindbench v0.1.0 psychological safety rankingvalue_integrity | #9 / 10 | ↑75.3 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #32 / 50 | ↓92.3 | Source ↗official | |
| MANTAAWMS | #8 / 12 | ↑0.433 | Source ↗official | |
| MANTAAWVS | #7 / 12 | ↑0.438 | Source ↗official | |
| MORUscore | #5 / 13 | ↑77.89 | Source ↗official | |
| Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns | #8 / 24 | ↓4 | Source ↗official | |
| Pander Scoreconversational_absolute_pander_score | #23 / 26 | ↓23.33 | Source ↗official | |
| Pander Scoreinstructional_absolute_pander_score | #22 / 26 | ↓69.48 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #12 / 70 | ↑0.8218 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #19 / 70 | ↑0.9594 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #46 / 67 | ↑0.4264 | Source ↗official | |
| SM-Benchadversarial | #1 / 84 | ↑92.2 | Source ↗official | |
| SM-Benchambiguous_interpretation | #42 / 84 | ↑86.01 | Source ↗official | |
| SM-Benchanti_hallucination | #56 / 84 | ↑88.48 | Source ↗official | |
| SM-Bencheq_boundaries | #27 / 84 | ↑68.54 | Source ↗official | |
| SM-Benchoverfit | #1 / 84 | ↑98.36 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #81 / 123 | ↑6.68 | Source ↗official | |
| SpeciEvalland_animal_4ns | #3 / 123 | ↓3.62 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #43 / 123 | ↓4.65 | Source ↗official | |
| SpeciEvalspeciesism | #122 / 123 | ↓3.88 | Source ↗official | |
| TACbase_welfare_rate | #78 / 87 | ↑17.31 | Source ↗official | |
| ToolPrivacyBenchprivate_mt_poi | #1 / 9 | ↓19.19 | Source ↗official | |
| ToolPrivacyBenchpublic_mt_poi | #8 / 9 | ↓19.86 | Source ↗official | |
| Vals AI Cheating Auditterminal_bench_cheating_shortcut_evidence_rate_pct | #11 / 14 | ↓2.247 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #27 / 52 | ↓44.8 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #17 / 54 | ↑78.3 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #6 / 248 | ↓48 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #170 / 248 | ↓85 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #147 / 246 | ↓97.27 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #50 / 69 | ↓0.8 | Source ↗official | |
| kindbench v0.1.0 psychological safety rankingemotional_safety | #1 / 10 | ↓75.3 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #52 / 70 | ↓0.9594 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #22 / 67 | ↓0.4264 | Source ↗official | |
| SM-Benchadversarial | #84 / 84 | ↓92.2 | Source ↗official | |
| SM-Bencheq_boundaries | #27 / 84 | ↑68.54 | Source ↗official | |
| SM-Benchoverfit | #1 / 84 | ↑98.36 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #17 / 181 | ↑87.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #79 / 156 | ↑3 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
