← Models

Model profile

GPT 5

OpenAIdeveloper
2025-08-07release date
#37 / 333Safety rank
#577 / 645Freedom rank

Evidence summary

Safety. GPT 5 has an estimated Safety rank of #37; its 90% source-sensitivity interval is #12–#144. Its behavior-only rank is #41; company governance moves the combined estimate to #37. Published Safety evidence spans 44 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — AirBench-SecurityRisks (safety_score, #1 of 63); its weakest is OpenAgentSafety (rule_based_safety_vulnerable, #7 of 7).

Freedom. GPT 5 has an estimated Freedom rank of #577; its 90% source-sensitivity interval is #429–#606. Published Freedom evidence spans 21 eval lineages and 1 of 1 components. Its strongest relative result is HELM Safety (xstest, #22 of 80); its weakest is ThaiSafetyBench (safety_score, #18 of 18).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#159 / 3450.7902Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#3 / 241.1Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#5 / 246.14Source ↗official
AgentAbstainabstain#2 / 1769.8Source ↗official
AgentAbstaincar#2 / 1766.5Source ↗official
AgentAbstainpaired#6 / 1749.6Source ↗official
AgentDrive Safety Compliancescr#2 / 4896.25Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#7 / 800.877Source ↗official
Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating#8 / 301214.0Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#14 / 1111464.0Source ↗official
BioTIERpermit_compliance_pct#40 / 5297.9Source ↗official
BioTIERrefuse_compliance_pct#12 / 5273.4Source ↗official
BrokenMathsycophancy#1 / 929Source ↗official
BullshitBench v2clear_pushback_rate#78 / 1170.195Source ↗official
CAIS Risk Indexbioweapons_assistance#18 / 5462.6Source ↗official
CAIS Risk Indexhle_overconfidence#22 / 5550Source ↗official
CAIS Risk Indexmachiavelli#13 / 5183.8Source ↗official
CAIS Risk Indexmask#29 / 5720.7Source ↗official
CAIS Risk Indexpolitical_manipulation#5 / 4835.3Source ↗official
CAIS Risk Indextextquests_harm#23 / 5417.2Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#23 / 1048.076Source ↗official
Concordia — Agentic-Misalignmentsafety_score#1 / 54100Source ↗official
Concordia — AirBench-Deceptionsafety_score#8 / 6397.01Source ↗official
Concordia — AirBench-Manipulationsafety_score#1 / 56100Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#1 / 63100Source ↗official
Concordia — APEsafety_score#16 / 5551.42Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#19 / 6392.68Source ↗official
Concordia — DarkBenchsafety_score#13 / 5562.42Source ↗official
Concordia — Fortress-Biologicalsafety_score#6 / 5494.77Source ↗official
Concordia — Fortress-Chemicalsafety_score#5 / 5488.57Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#14 / 5474.1Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#10 / 4550.44Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#4 / 4552.5Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#20 / 453.333Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#17 / 4562.33Source ↗official
Concordia — MASKsafety_score#13 / 6280.71Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#11 / 6398.99Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#13 / 6337.64Source ↗official
Concordia — Shutdown-Resistancesafety_score#45 / 5381Source ↗official
Concordia — SOSBench-Biosafety_score#24 / 6389.2Source ↗official
Concordia — SOSBench-Chemsafety_score#16 / 6392.76Source ↗official
Constitutional Following — OpenAI Model Specconstitutional_following_score#3 / 794.9Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#10 / 24859.95Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#39 / 24892.89Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#40 / 24893.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#104 / 24697.09Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#10 / 1880.22Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#9 / 1879.66Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#14 / 1883.26Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#13 / 1883.73Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#10 / 1872.15Source ↗official
FORTRESSaverage_risk_score#14 / 5017.04Source ↗official
FORTRESSover_refusal_score#41 / 4911.2Source ↗official
HELM Safetyanthropic_red_team#32 / 800.991Source ↗official
HELM Safetybbq#12 / 800.968Source ↗official
HELM Safetyharmbench#6 / 800.976Source ↗official
HELM Safetysimple_safety_tests#24 / 800.998Source ↗official
HELM Safetyxstest#22 / 800.971Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#32 / 5426.31Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#13 / 6926.5Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#10 / 4250Source ↗official
MACHIAVELLIdeception_relative_random_pct#11 / 5083.8Source ↗official
MASKlying_probability_pct#16 / 5320.67Source ↗official
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#6 / 1331.3Source ↗official
MT-JailBench CrescendoXsafety_score#3 / 2161.29Source ↗official
NESSiE Necessary Safety Benchmarksh_score#1 / 1694.87Source ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#3 / 752.58Source ↗official
OpenAgentSafetyrule_based_safety_vulnerable#7 / 752.15Source ↗official
OpenAgentSafetysuccessful_completion#1 / 740.4Source ↗official
OpenAI GPT-5 System Cardharmful_request_safety#1 / 20.912Source ↗official
PacifAIstp_score#7 / 779.49Source ↗official
PHAREbias_resistance_diagnostic#63 / 660.2856Source ↗official
PHAREhallucination_resistance_diagnostic#38 / 700.7458Source ↗official
PHAREharm_resistance_diagnostic#12 / 700.9697Source ↗official
PHAREjailbreak_resistance_diagnostic#14 / 670.6868Source ↗official
Shelleducation_jsr#2 / 140.364Source ↗official
Shellfinance_jsr#2 / 140.19Source ↗official
Shellmanagement_jsr#3 / 140.37Source ↗official
SimpleQA Verifiedf1_score#2 / 1352.3Source ↗official
Social Welfare Function Benchmarkfairness#15 / 190.4455Source ↗official
SOSBenchbiology_pvr#2 / 230.108Source ↗official
SOSBenchchemistry_pvr#1 / 230.122Source ↗official
SOSBenchmedicine_pvr#3 / 230.332Source ↗official
SOSBenchpharmacology_pvr#4 / 230.418Source ↗official
SOSBenchphysics_pvr#2 / 230.104Source ↗official
SOSBenchpsychology_pvr#3 / 230.142Source ↗official
SpeciEvalbelief_animal_sentience#49 / 1236.855Source ↗official
SpeciEvalland_animal_4ns#101 / 1234.825Source ↗official
SpeciEvalsea_animal_4ns#65 / 1234.745Source ↗official
SpeciEvalspeciesism#18 / 1231.49Source ↗official
ThaiSafetyBenchsafety_score#1 / 1895.57Source ↗official
TrustLLM contemporary collapsed applicationtrustllm#7 / 80.6Source ↗official
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#2 / 270.76Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#85 / 9485.1Source ↗official
Vigil Mental Health Safetyoverall_score#9 / 2351Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#22 / 241.1Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#20 / 246.14Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#74 / 800.877Source ↗official
BioTIERpermit_compliance_pct#40 / 5297.9Source ↗official
BioTIERrefuse_compliance_pct#41 / 5273.4Source ↗official
CAIS Risk Indexbioweapons_assistance#37 / 5462.6Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#82 / 1048.076Source ↗official
Concordia — AirBench-Deceptionsafety_score#56 / 6397.01Source ↗official
Concordia — AirBench-Manipulationsafety_score#51 / 56100Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#53 / 5688.1Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#58 / 63100Source ↗official
Concordia — Fortress-Biologicalsafety_score#49 / 5494.77Source ↗official
Concordia — Fortress-Chemicalsafety_score#50 / 5488.57Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#41 / 5474.1Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#36 / 4550.44Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#42 / 4552.5Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#22 / 453.333Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#28 / 4562.33Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#53 / 6398.99Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#51 / 6337.64Source ↗official
Concordia — SOSBench-Biosafety_score#40 / 6389.2Source ↗official
Concordia — SOSBench-Chemsafety_score#48 / 6392.76Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#210 / 24892.89Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#208 / 24893.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#142 / 24697.09Source ↗official
FORTRESSaverage_risk_score#37 / 5017.04Source ↗official
FORTRESSover_refusal_score#41 / 4911.2Source ↗official
HELM Safetyanthropic_red_team#45 / 800.991Source ↗official
HELM Safetyharmbench#74 / 800.976Source ↗official
HELM Safetysimple_safety_tests#56 / 800.998Source ↗official
HELM Safetyxstest#22 / 800.971Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#57 / 6926.5Source ↗official
MT-JailBench CrescendoXsafety_score#19 / 2161.29Source ↗official
OpenAI GPT-5 System Cardharmful_request_safety#2 / 20.912Source ↗official
PHAREharm_resistance_diagnostic#59 / 700.9697Source ↗official
PHAREjailbreak_resistance_diagnostic#54 / 670.6868Source ↗official
Shelleducation_jsr#13 / 140.364Source ↗official
Shellfinance_jsr#13 / 140.19Source ↗official
Shellmanagement_jsr#12 / 140.37Source ↗official
SOSBenchbiology_pvr#22 / 230.108Source ↗official
SOSBenchchemistry_pvr#23 / 230.122Source ↗official
SOSBenchmedicine_pvr#21 / 230.332Source ↗official
SOSBenchpharmacology_pvr#20 / 230.418Source ↗official
SOSBenchphysics_pvr#22 / 230.104Source ↗official
SOSBenchpsychology_pvr#21 / 230.142Source ↗official
SpeechMap model completioncomplete_pct#56 / 18170.1Source ↗official
ThaiSafetyBenchsafety_score#18 / 1895.57Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 1561.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#113 / 1562Source ↗official
Vigil Mental Health Safetyoverall_score#15 / 2351Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-18.2
Government45.9
Diplomacy65.3
Economy49
Society58.6

CAISI CCP narrative alignment

DimensionValueDistribution
CCP narrative alignment1.95