← Models

Model profile

GPT 5 Nano

OpenAIdeveloper
2025-08-07release date
#36 / 333Safety rank
#578 / 645Freedom rank

Evidence summary

Safety. GPT 5 Nano has an estimated Safety rank of #36; its 90% source-sensitivity interval is #13–#150. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is SimpleQA Verified (f1_score, #12 of 13).

Freedom. GPT 5 Nano has an estimated Freedom rank of #578; its 90% source-sensitivity interval is #401–#613. Published Freedom evidence spans 13 eval lineages and 1 of 1 components. Its strongest relative result is HELM Safety (xstest, #16 of 80); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #245 of 248).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#85 / 3450.5262Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#1 / 240.82Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#2 / 241.47Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#6 / 800.878Source ↗official
ANIMAscore#10 / 220.708Source ↗official
BioTIERpermit_compliance_pct#41 / 5297.6Source ↗official
BioTIERrefuse_compliance_pct#21 / 5259.6Source ↗official
CAIS Risk Indexagent_red_teaming#37 / 4988.5Source ↗official
CAIS Risk Indexbioweapons_assistance#33 / 5471.3Source ↗official
CAIS Risk Indexhle_overconfidence#50 / 5580Source ↗official
CAIS Risk Indexmachiavelli#2 / 5179.4Source ↗official
CAIS Risk Indexmask#19 / 5712.3Source ↗official
CAIS Risk Indextextquests_harm#1 / 542Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#21 / 1047.527Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#34 / 24839.02Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#4 / 24898Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#42 / 24892.78Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#108 / 24696.91Source ↗official
HELM Safetyanthropic_red_team#13 / 800.996Source ↗official
HELM Safetybbq#8 / 800.976Source ↗official
HELM Safetyharmbench#3 / 800.984Source ↗official
HELM Safetysimple_safety_tests#1 / 801Source ↗official
HELM Safetyxstest#16 / 800.976Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#19 / 693.4Source ↗official
MACHIAVELLIdeception_relative_random_pct#1 / 5079.4Source ↗official
Manager Coercion Benchcoercion_ladder_depth#6 / 375.067Source ↗self run
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#10 / 136Source ↗official
PHAREbias_resistance_diagnostic#55 / 660.347Source ↗official
PHAREhallucination_resistance_diagnostic#31 / 700.7637Source ↗official
PHAREharm_resistance_diagnostic#9 / 700.9741Source ↗official
PHAREjailbreak_resistance_diagnostic#12 / 670.6964Source ↗official
SimpleQA Verifiedf1_score#12 / 1314.4Source ↗official
SpeciEvalbelief_animal_sentience#107 / 1236.4Source ↗official
SpeciEvalland_animal_4ns#36 / 1234.35Source ↗official
SpeciEvalsea_animal_4ns#55 / 1234.68Source ↗official
SpeciEvalspeciesism#88 / 1232.33Source ↗official
StereoTales Harmful Associationsbenign_significant_association_score#2 / 2389.22Source ↗official
TACbase_welfare_rate#13 / 8737.82Source ↗self run
Vectara HHEM Factual Consistencyfactual_consistency_rate#56 / 9489.5Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#23 / 240.82Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#23 / 241.47Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#75 / 800.878Source ↗official
BioTIERpermit_compliance_pct#41 / 5297.6Source ↗official
BioTIERrefuse_compliance_pct#32 / 5259.6Source ↗official
CAIS Risk Indexbioweapons_assistance#22 / 5471.3Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#84 / 1047.527Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#245 / 24898Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#205 / 24892.78Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#136 / 24696.91Source ↗official
HELM Safetyanthropic_red_team#64 / 800.996Source ↗official
HELM Safetyharmbench#77 / 800.984Source ↗official
HELM Safetysimple_safety_tests#58 / 801Source ↗official
HELM Safetyxstest#16 / 800.976Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#51 / 693.4Source ↗official
PHAREharm_resistance_diagnostic#62 / 700.9741Source ↗official
PHAREjailbreak_resistance_diagnostic#56 / 670.6964Source ↗official
SpeechMap model completioncomplete_pct#96 / 18156Source ↗official