Model profile
Evidence summary
Safety. GLM 5 has an estimated Safety rank of #82; its 90% source-sensitivity interval is #63–#217. Its behavior-only rank is #79; company governance moves the combined estimate to #82. Published Safety evidence spans 16 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — Shutdown-Resistance (safety_score, #1 of 53); its weakest is TAC (base_welfare_rate, #75 of 87).
Freedom. GLM 5 has an estimated Freedom rank of #425; its 90% source-sensitivity interval is #283–#563. Published Freedom evidence spans 7 eval lineages and 1 of 1 components. Its strongest relative result is SpeechMap model completion (complete_pct, #47 of 181); its weakest is UGI Leaderboard — base-model willingness (willingness_direct_score, #152 of 156).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗glm-5
- Hugging Face ↗zai-org/GLM-5
- OpenRouter ↗z-ai/glm-5
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗repository created at proxy
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- kepom/GLM-5-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
- skyblanket/GLM-5-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #46 / 345 | ↓0.3532 | Source ↗official | |
| AgentAbstainabstain | #8 / 17 | ↑61.8 | Source ↗official | |
| AgentAbstaincar | #9 / 17 | ↑59.1 | Source ↗official | |
| AgentAbstainpaired | #8 / 17 | ↑47.8 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #52 / 111 | ↑1439.0 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #69 / 117 | ↑0.24 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #52 / 104 | ↓37.79 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #21 / 54 | ↑85 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #26 / 63 | ↑87.04 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #20 / 56 | ↑94.67 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #16 / 63 | ↑98.42 | Source ↗official | |
| Concordia — APEsafety_score | #4 / 55 | ↑65.42 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #12 / 63 | ↑95.22 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #34 / 55 | ↑53.15 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #27 / 54 | ↑55.28 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #28 / 54 | ↑55.37 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #27 / 54 | ↑62.1 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #20 / 45 | ↑38.67 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #21 / 45 | ↑30.54 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #17 / 45 | ↑4 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #15 / 45 | ↑63.33 | Source ↗official | |
| Concordia — MASKsafety_score | #10 / 62 | ↑86.95 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #21 / 63 | ↑92.26 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #20 / 63 | ↑32.6 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #1 / 53 | ↑100 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #34 / 63 | ↑78 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #22 / 63 | ↑90.8 | Source ↗official | |
| DystopiaBenchbasaglia_score | #9 / 50 | ↓34.47 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #7 / 50 | ↓28.97 | Source ↗official | |
| DystopiaBenchhuxley_score | #8 / 50 | ↓27.5 | Source ↗official | |
| DystopiaBenchlaguardia_score | #8 / 50 | ↓40.33 | Source ↗official | |
| DystopiaBenchorwell_score | #8 / 50 | ↓27.87 | Source ↗official | |
| DystopiaBenchpetrov_score | #6 / 50 | ↓30.8 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #21 / 69 | ↑0.4 | Source ↗official | |
| LiveSecBenchethics | #32 / 43 | ↑31.18 | Source ↗official | |
| LiveSecBenchfactuality | #6 / 43 | ↑75.94 | Source ↗official | |
| LiveSecBenchlegality | #25 / 43 | ↑39.78 | Source ↗official | |
| LiveSecBenchprivacy | #18 / 43 | ↑60.57 | Source ↗official | |
| LiveSecBenchpsychological_health | #7 / 43 | ↑76.17 | Source ↗official | |
| RefusalBenchyouden_j | #9 / 19 | ↑0.08511 | Source ↗official | |
| SABERoverall_safety_rate | #3 / 13 | ↑29 | Source ↗official | |
| SABERscenario_a_safety_rate | #2 / 13 | ↑36.25 | Source ↗official | |
| SABERscenario_b_safety_rate | #6 / 13 | ↑33.73 | Source ↗official | |
| SABERscenario_c_safety_rate | #6 / 13 | ↑16.59 | Source ↗official | |
| SM-Benchadversarial | #4 / 84 | ↑90.73 | Source ↗official | |
| SM-Benchambiguous_interpretation | #22 / 84 | ↑89.29 | Source ↗official | |
| SM-Benchanti_hallucination | #45 / 84 | ↑92.67 | Source ↗official | |
| SM-Bencheq_boundaries | #48 / 84 | ↑63.2 | Source ↗official | |
| SM-Benchoverfit | #56 / 84 | ↑63.11 | Source ↗official | |
| StereoTales Harmful Associationsbenign_significant_association_score | #19 / 23 | ↑84.74 | Source ↗official | |
| TACbase_welfare_rate | #75 / 87 | ↑18.59 | Source ↗self run | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #53 / 94 | ↑89.9 | Source ↗official | |
| WildClawBench Safety & Alignment (OpenClaw harness)safety_alignment_score_pct | #4 / 24 | ↑47.36 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.