Model profile
Evidence summary
Safety. GPT 4 has an estimated Safety rank of #172; its 90% source-sensitivity interval is #79–#246. Its behavior-only rank is #184; company governance moves the combined estimate to #172. Published Safety evidence spans 18 eval lineages and 7 of 7 components. Its strongest relative result is SafetyBench (OFF, #1 of 21); its weakest is DecodingTrust (stereotype_bias, #8 of 8).
Freedom. GPT 4 has an estimated Freedom rank of #282; its 90% source-sensitivity interval is #186–#409. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is JailBench (jailbreak_success_rate, #14 of 14).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-4
- OpenRouter ↗openai/gpt-4
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #126 / 345 | ↓0.6941 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #46 / 80 | ↑0.642 | Source ↗official | |
| BioTIERpermit_compliance_pct | #36 / 52 | ↑98.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #34 / 52 | ↑26 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #41 / 48 | ↓59.2 | Source ↗official | |
| DecodingTrustmachine_ethics | #4 / 8 | ↑76.6 | Source ↗official | |
| DecodingTruststereotype_bias | #8 / 8 | ↑77 | Source ↗official | |
| DecodingTrusttoxicity | #6 / 8 | ↑41 | Source ↗official | |
| Do-Not-Answerhuman_harmlessness_rate | #4 / 6 | ↑97.55 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #131 / 248 | ↑15.25 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #58 / 248 | ↑91.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #91 / 248 | ↑80.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #185 / 246 | ↑93.09 | Source ↗official | |
| FLAMESdata_protection | #4 / 13 | ↑50 | Source ↗official | |
| FLAMESfairness | #5 / 13 | ↑41.37 | Source ↗official | |
| FLAMESlegality | #10 / 13 | ↑30.43 | Source ↗official | |
| FLAMESmorality | #4 / 13 | ↑50.75 | Source ↗official | |
| FLAMESsafety | #10 / 13 | ↑27.51 | Source ↗official | |
| HarmBenchdr | #16 / 28 | ↓21 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| JailBenchjailbreak_success_rate | #1 / 14 | ↓34.5 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #3 / 39 | ↓0.7334 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #29 / 50 | ↓90 | Source ↗official | |
| Qwen2 Safety Panelfraud | #2 / 3 | ↓6.87 | Source ↗official | |
| Qwen2 Safety Panelillegal | #1 / 3 | ↓0 | Source ↗official | |
| Qwen2 Safety Panelpornography | #2 / 3 | ↓23.63 | Source ↗official | |
| Qwen2 Safety Panelprivacy | #2 / 3 | ↓3.37 | Source ↗official | |
| SafetyBenchEM | #1 / 21 | ↑92.25 | Source ↗official | |
| SafetyBenchIA | #1 / 21 | ↑92.35 | Source ↗official | |
| SafetyBenchMH | #1 / 21 | ↑92.8 | Source ↗official | |
| SafetyBenchOFF | #1 / 21 | ↑86.15 | Source ↗official | |
| SafetyBenchPH | #1 / 21 | ↑94.35 | Source ↗official | |
| SafetyBenchPP | #1 / 21 | ↑91 | Source ↗official | |
| SafetyBenchUB | #1 / 21 | ↑77.9 | Source ↗official | |
| SORRY-Benchavg | #26 / 51 | ↓0.29 | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #2 / 31 | ↑77.59 | Source ↗official | |
| SuperCLUE Safetyresponsible_ai | #3 / 31 | ↑74.55 | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #23 / 31 | ↑70.21 | Source ↗official | |
| XSTestsafe_full_compliance_rate | #2 / 3 | ↑0.916 | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #1 / 3 | ↑0.975 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #35 / 80 | ↓0.642 | Source ↗official | |
| BioTIERpermit_compliance_pct | #36 / 52 | ↑98.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #19 / 52 | ↓26 | Source ↗official | |
| DecodingTrusttoxicity | #3 / 8 | ↓41 | Source ↗official | |
| Do-Not-Answerhuman_harmlessness_rate | #3 / 6 | ↓97.55 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #188 / 248 | ↓91.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #156 / 248 | ↓80.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #62 / 246 | ↓93.09 | Source ↗official | |
| FLAMESdata_protection | #10 / 13 | ↓50 | Source ↗official | |
| FLAMESfairness | #9 / 13 | ↓41.37 | Source ↗official | |
| FLAMESlegality | #3 / 13 | ↓30.43 | Source ↗official | |
| FLAMESmorality | #10 / 13 | ↓50.75 | Source ↗official | |
| FLAMESsafety | #4 / 13 | ↓27.51 | Source ↗official | |
| HarmBenchdr | #13 / 28 | ↑21 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| JailBenchjailbreak_success_rate | #14 / 14 | ↑34.5 | Source ↗official | |
| Qwen2 Safety Panelfraud | #2 / 3 | ↑6.87 | Source ↗official | |
| Qwen2 Safety Panelillegal | #2 / 3 | ↑0 | Source ↗official | |
| Qwen2 Safety Panelpornography | #2 / 3 | ↑23.63 | Source ↗official | |
| Qwen2 Safety Panelprivacy | #2 / 3 | ↑3.37 | Source ↗official | |
| SORRY-Benchavg | #26 / 51 | ↑0.29 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #5 / 181 | ↑95.2 | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #30 / 31 | ↓77.59 | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #8 / 31 | ↓70.21 | Source ↗official | |
| XSTestsafe_full_compliance_rate | #2 / 3 | ↑0.916 | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #2 / 3 | ↓0.975 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
