Model profile
GPT 3.5 Turbo
Evidence summary
GPT 3.5 Turbo has an estimated overall rank of #134; its 90% source-sensitivity interval is #58–#181. Its behavior-only rank is #142; company governance moves the combined estimate to #134. Published evidence spans 23 evals and 7 of 7 behavior components. Its strongest relative result is SafetyPrompts (score, #1 of 15); its weakest is SpeciesismBench (speciesism_recognition_rate, #8 of 8).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-3-5-turbo-0613
- OpenRouter ↗openai/gpt-3.5-turbo
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AgentDojotargeted_attack_success_rate | #6 / 15 | 0.1033 | ↓ lower | Source ↗official | |
| AgentDojoutility_under_attack | #9 / 15 | 0.3466 | ↑ higher | Source ↗official | |
| AgentHarmharm_score | #9 / 12 | 62.2 | ↓ lower | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #59 / 80 | 0.5577 | ↑ higher | Source ↗official | |
| Chinese Bias Benchmark for Question Answeringbias_score | #1 / 10 | 0.06549 | ↓ lower | Source ↗official | |
| DecodingTrustmachine_ethics | #2 / 8 | 86.38 | ↑ higher | Source ↗official | |
| DecodingTruststereotype_bias | #7 / 8 | 87 | ↑ higher | Source ↗official | |
| DecodingTrusttoxicity | #4 / 8 | 47 | ↑ higher | Source ↗official | |
| Do-Not-Answerhuman_harmlessness_rate | #2 / 6 | 98.51 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #225 / 260 | 10.08 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #153 / 260 | 87.17 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #234 / 260 | 37.22 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #220 / 258 | 89.18 | ↑ higher | Source ↗official | |
| Fake Alignment (FINE)multiple_choice_safe_decision_rate | #1 / 14 | 96 | ↑ higher | Source ↗official | |
| Fake Alignment (FINE)open_ended_safe_response_rate | #1 / 14 | 100 | ↑ higher | Source ↗official | |
| HarmBenchdr | #18 / 28 | 27.15 | ↓ lower | Source ↗official | |
| HELM Safetyanthropic_red_team | #57 / 80 | 0.981 | ↑ higher | Source ↗official | |
| HELM Safetybbq | #76 / 80 | 0.6513 | ↑ higher | Source ↗official | |
| HELM Safetyharmbench | #50 / 80 | 0.6663 | ↑ higher | Source ↗official | |
| HELM Safetysimple_safety_tests | #70 / 80 | 0.9337 | ↑ higher | Source ↗official | |
| HELM Safetyxstest | #59 / 80 | 0.9373 | ↑ higher | Source ↗official | |
| JailBenchjailbreak_success_rate | #12 / 14 | 73.86 | ↓ lower | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #7 / 39 | 0.8161 | ↓ lower | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #38 / 50 | 94 | ↓ lower | Source ↗official | |
| OR-Benchover_refusal_rate | #8 / 25 | 36.17 | ↓ lower | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #20 / 25 | 17.03 | ↓ lower | Source ↗official | |
| SafetyBenchEM | #4 / 21 | 77.75 | ↑ higher | Source ↗official | |
| SafetyBenchIA | #3 / 21 | 85 | ↑ higher | Source ↗official | |
| SafetyBenchMH | #2 / 21 | 87.75 | ↑ higher | Source ↗official | |
| SafetyBenchOFF | #3 / 21 | 77.4 | ↑ higher | Source ↗official | |
| SafetyBenchPH | #2 / 21 | 79.65 | ↑ higher | Source ↗official | |
| SafetyBenchPP | #2 / 21 | 85.65 | ↑ higher | Source ↗official | |
| SafetyBenchUB | #4 / 21 | 67.9 | ↑ higher | Source ↗official | |
| SafetyPromptsscore | #1 / 15 | 98.37 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #3 / 33 | 72.41 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #3 / 33 | 72.64 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #3 / 33 | 71.86 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #3 / 33 | 71.38 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #3 / 33 | 75.65 | ↑ higher | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #3 / 33 | 68.83 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #24 / 33 | 89.4 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #25 / 33 | 90.79 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_malicious_use | #22 / 33 | 88.74 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #21 / 33 | 92.61 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #21 / 33 | 87.99 | ↑ higher | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #28 / 33 | 77.32 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #9 / 33 | 51.39 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #10 / 33 | 43.89 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #10 / 33 | 47.82 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #10 / 33 | 49.05 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #10 / 33 | 46.77 | ↑ higher | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #9 / 33 | 46.67 | ↑ higher | Source ↗official | |
| SORRY-Benchavg | #17 / 51 | 0.18 | ↓ lower | Source ↗official | |
| SpeciesismBenchmorally_wrong_rate | #5 / 8 | 38.38 | ↑ higher | Source ↗official | |
| SpeciesismBenchspeciesism_recognition_rate | #8 / 8 | 74.21 | ↑ higher | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #9 / 31 | 68.97 | ↑ higher | Source ↗official | |
| SuperCLUE Safetyresponsible_ai | #4 / 31 | 72.73 | ↑ higher | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #20 / 31 | 73.4 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
ValueCompass
| Dimension | Value | Distribution |
|---|---|---|
| Universalism | 30.4 | |
| Self-direction | 23.5 | |
| Care / Harm | 34.3 | |
| Fairness / Cheating | 30.1 | |
| Ethical | 89.2 |
