Model profile
Evidence summary
Safety. Gemma 3 12B has an estimated Safety rank of #229; its 90% source-sensitivity interval is #37–#306. Its behavior-only rank is #241; company governance moves the combined estimate to #229. Published Safety evidence spans 9 eval lineages and 6 of 7 components. Its strongest relative result is Vectara HHEM Factual Consistency (factual_consistency_rate, #5 of 94); its weakest is PHARE (hallucination_resistance_diagnostic, #70 of 70).
Freedom. Gemma 3 12B has an estimated Freedom rank of #157; its 90% source-sensitivity interval is #79–#354. Published Freedom evidence spans 4 eval lineages and 1 of 1 components. Its strongest relative result is Cisco AI Defense Rolling Single-Turn Leaderboard (single_turn_attack_success_rate, #21 of 104); its weakest is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #175 of 246).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gemma-3-12b
- Official model documentation ↗Family-level model document · google · first party
- Release source ↗curated outward evidence
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #342 / 345 | ↓0.974 | Source ↗official | |
| AgentDrive Safety Compliancescr | #28 / 48 | ↑77.5 | Source ↗official | |
| AIMS Safety-Classifier Competenceaverage_harmful_f1 | #7 / 11 | ↑0.802 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #84 / 104 | ↓65.55 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #163 / 248 | ↑13.18 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #72 / 248 | ↑90.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #180 / 248 | ↑52.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #71 / 246 | ↑98.05 | Source ↗official | |
| KIDBench Implicit Child Cueimplicit_child_cue_total_mean | #7 / 13 | ↑3.98 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #60 / 66 | ↑0.3214 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #70 / 70 | ↑0.5386 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #39 / 70 | ↑0.9265 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #43 / 67 | ↑0.4427 | Source ↗official | |
| ThaiSafetyBenchsafety_score | #13 / 18 | ↑79.6 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #5 / 94 | ↑95.6 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #21 / 104 | ↑65.55 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #175 / 248 | ↓90.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #69 / 248 | ↓52.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #175 / 246 | ↓98.05 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #32 / 70 | ↓0.9265 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #25 / 67 | ↓0.4427 | Source ↗official | |
| ThaiSafetyBenchsafety_score | #6 / 18 | ↓79.6 | Source ↗official |
