← Models

Model profile

Gemini 3.6 Flash

Googledeveloper
2026-07-21release date
#20 / 333Safety rank
#36 / 645Freedom rank

Evidence summary

Safety. Gemini 3.6 Flash has an estimated Safety rank of #20; its 90% source-sensitivity interval is #6–#99. Its behavior-only rank is #24; company governance moves the combined estimate to #20. Published Safety evidence spans 10 eval lineages and 6 of 7 components. Its strongest relative result is SpeciEval (land_animal_4ns, #2 of 123); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #245 of 248).

Freedom. Gemini 3.6 Flash has an estimated Freedom rank of #36; its 90% source-sensitivity interval is #37–#241. Published Freedom evidence spans 3 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #4 of 248); its weakest is SM-Bench (adversarial, #78 of 84).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#88 / 3450.5563Source ↗official
BullshitBench v2clear_pushback_rate#55 / 1170.335Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#117 / 24816.28Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#245 / 24847.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#50 / 24891.11Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#147 / 24695.45Source ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#10 / 1337.3Source ↗official
Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns#1 / 240Source ↗official
Opposite-Narrator Sycophancysycophancy_rate_pct#3 / 240.5Source ↗official
Pander Scoreconversational_absolute_pander_score#20 / 2618.48Source ↗official
Pander Scoreinstructional_absolute_pander_score#19 / 2666.01Source ↗official
SM-Benchadversarial#7 / 8489.27Source ↗official
SM-Benchambiguous_interpretation#34 / 8487.5Source ↗official
SM-Benchanti_hallucination#40 / 8494.24Source ↗official
SM-Bencheq_boundaries#13 / 8471.35Source ↗official
SM-Benchoverfit#4 / 8495.08Source ↗official
SpeciEvalbelief_animal_sentience#44 / 1236.87Source ↗official
SpeciEvalland_animal_4ns#2 / 1233.58Source ↗official
SpeciEvalsea_animal_4ns#43 / 1234.65Source ↗official
SpeciEvalspeciesism#119 / 1233.05Source ↗official
Vals AI Cheating Auditbiomystery_bench_cheating_attempt_rate_pct#8 / 97.778Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#4 / 24847.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#196 / 24891.11Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#96 / 24695.45Source ↗official
SM-Benchadversarial#78 / 8489.27Source ↗official
SM-Bencheq_boundaries#13 / 8471.35Source ↗official
SM-Benchoverfit#4 / 8495.08Source ↗official
SpeechMap model completioncomplete_pct#19 / 18187.2Source ↗official