Model profile
Evidence summary
Safety. GPT 5 has an estimated Safety rank of #37; its 90% source-sensitivity interval is #12–#144. Its behavior-only rank is #41; company governance moves the combined estimate to #37. Published Safety evidence spans 44 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — AirBench-SecurityRisks (safety_score, #1 of 63); its weakest is OpenAgentSafety (rule_based_safety_vulnerable, #7 of 7).
Freedom. GPT 5 has an estimated Freedom rank of #577; its 90% source-sensitivity interval is #429–#606. Published Freedom evidence spans 21 eval lineages and 1 of 1 components. Its strongest relative result is HELM Safety (xstest, #22 of 80); its weakest is ThaiSafetyBench (safety_score, #18 of 18).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5
- OpenRouter ↗openai/gpt-5
- System card ↗Family-level model document · OpenAI · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #159 / 345 | ↓0.7902 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #3 / 24 | ↓1.1 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #5 / 24 | ↓6.14 | Source ↗official | |
| AgentAbstainabstain | #2 / 17 | ↑69.8 | Source ↗official | |
| AgentAbstaincar | #2 / 17 | ↑66.5 | Source ↗official | |
| AgentAbstainpaired | #6 / 17 | ↑49.6 | Source ↗official | |
| AgentDrive Safety Compliancescr | #2 / 48 | ↑96.25 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #7 / 80 | ↑0.877 | Source ↗official | |
| Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating | #8 / 30 | ↑1214.0 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #14 / 111 | ↑1464.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #40 / 52 | ↑97.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #12 / 52 | ↑73.4 | Source ↗official | |
| BrokenMathsycophancy | #1 / 9 | ↓29 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #78 / 117 | ↑0.195 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #18 / 54 | ↓62.6 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #22 / 55 | ↓50 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #13 / 51 | ↓83.8 | Source ↗official | |
| CAIS Risk Indexmask | #29 / 57 | ↓20.7 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #5 / 48 | ↓35.3 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #23 / 54 | ↓17.2 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #23 / 104 | ↓8.076 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #1 / 54 | ↑100 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #8 / 63 | ↑97.01 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #1 / 56 | ↑100 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #1 / 63 | ↑100 | Source ↗official | |
| Concordia — APEsafety_score | #16 / 55 | ↑51.42 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #19 / 63 | ↑92.68 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #13 / 55 | ↑62.42 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #6 / 54 | ↑94.77 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #5 / 54 | ↑88.57 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #14 / 54 | ↑74.1 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #10 / 45 | ↑50.44 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #4 / 45 | ↑52.5 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #20 / 45 | ↑3.333 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #17 / 45 | ↑62.33 | Source ↗official | |
| Concordia — MASKsafety_score | #13 / 62 | ↑80.71 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #11 / 63 | ↑98.99 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #13 / 63 | ↑37.64 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #45 / 53 | ↑81 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #24 / 63 | ↑89.2 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #16 / 63 | ↑92.76 | Source ↗official | |
| Constitutional Following — OpenAI Model Specconstitutional_following_score | #3 / 7 | ↑94.9 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #10 / 248 | ↑59.95 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #39 / 248 | ↑92.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #40 / 248 | ↑93.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #104 / 246 | ↑97.09 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #10 / 18 | ↑80.22 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #9 / 18 | ↑79.66 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #14 / 18 | ↑83.26 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #13 / 18 | ↑83.73 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #10 / 18 | ↑72.15 | Source ↗official | |
| FORTRESSaverage_risk_score | #14 / 50 | ↓17.04 | Source ↗official | |
| FORTRESSover_refusal_score | #41 / 49 | ↓11.2 | Source ↗official | |
| HELM Safetyanthropic_red_team | #32 / 80 | ↑0.991 | Source ↗official | |
| HELM Safetybbq | #12 / 80 | ↑0.968 | Source ↗official | |
| HELM Safetyharmbench | #6 / 80 | ↑0.976 | Source ↗official | |
| HELM Safetysimple_safety_tests | #24 / 80 | ↑0.998 | Source ↗official | |
| HELM Safetyxstest | #22 / 80 | ↑0.971 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #32 / 54 | ↑26.31 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #13 / 69 | ↑26.5 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #10 / 42 | ↓50 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #11 / 50 | ↓83.8 | Source ↗official | |
| MASKlying_probability_pct | #16 / 53 | ↓20.67 | Source ↗official | |
| MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent | #6 / 13 | ↑31.3 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #3 / 21 | ↑61.29 | Source ↗official | |
| NESSiE Necessary Safety Benchmarksh_score | #1 / 16 | ↑94.87 | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #3 / 7 | ↓52.58 | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #7 / 7 | ↓52.15 | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #1 / 7 | ↑40.4 | Source ↗official | |
| OpenAI GPT-5 System Cardharmful_request_safety | #1 / 2 | ↑0.912 | Source ↗official | |
| PacifAIstp_score | #7 / 7 | ↑79.49 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #63 / 66 | ↑0.2856 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #38 / 70 | ↑0.7458 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #12 / 70 | ↑0.9697 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #14 / 67 | ↑0.6868 | Source ↗official | |
| Shelleducation_jsr | #2 / 14 | ↓0.364 | Source ↗official | |
| Shellfinance_jsr | #2 / 14 | ↓0.19 | Source ↗official | |
| Shellmanagement_jsr | #3 / 14 | ↓0.37 | Source ↗official | |
| SimpleQA Verifiedf1_score | #2 / 13 | ↑52.3 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #15 / 19 | ↑0.4455 | Source ↗official | |
| SOSBenchbiology_pvr | #2 / 23 | ↓0.108 | Source ↗official | |
| SOSBenchchemistry_pvr | #1 / 23 | ↓0.122 | Source ↗official | |
| SOSBenchmedicine_pvr | #3 / 23 | ↓0.332 | Source ↗official | |
| SOSBenchpharmacology_pvr | #4 / 23 | ↓0.418 | Source ↗official | |
| SOSBenchphysics_pvr | #2 / 23 | ↓0.104 | Source ↗official | |
| SOSBenchpsychology_pvr | #3 / 23 | ↓0.142 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #49 / 123 | ↑6.855 | Source ↗official | |
| SpeciEvalland_animal_4ns | #101 / 123 | ↓4.825 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #65 / 123 | ↓4.745 | Source ↗official | |
| SpeciEvalspeciesism | #18 / 123 | ↓1.49 | Source ↗official | |
| ThaiSafetyBenchsafety_score | #1 / 18 | ↑95.57 | Source ↗official | |
| TrustLLM contemporary collapsed applicationtrustllm | #7 / 8 | ↑0.6 | Source ↗official | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #2 / 27 | ↑0.76 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #85 / 94 | ↑85.1 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #9 / 23 | ↑51 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #22 / 24 | ↑1.1 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #20 / 24 | ↑6.14 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #74 / 80 | ↓0.877 | Source ↗official | |
| BioTIERpermit_compliance_pct | #40 / 52 | ↑97.9 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #41 / 52 | ↓73.4 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #37 / 54 | ↑62.6 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #82 / 104 | ↑8.076 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #56 / 63 | ↓97.01 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #51 / 56 | ↓100 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #53 / 56 | ↓88.1 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #58 / 63 | ↓100 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #49 / 54 | ↓94.77 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #50 / 54 | ↓88.57 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #41 / 54 | ↓74.1 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #36 / 45 | ↓50.44 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #42 / 45 | ↓52.5 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #22 / 45 | ↓3.333 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #28 / 45 | ↓62.33 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #53 / 63 | ↓98.99 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #51 / 63 | ↓37.64 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #40 / 63 | ↓89.2 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #48 / 63 | ↓92.76 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #210 / 248 | ↓92.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #208 / 248 | ↓93.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #142 / 246 | ↓97.09 | Source ↗official | |
| FORTRESSaverage_risk_score | #37 / 50 | ↑17.04 | Source ↗official | |
| FORTRESSover_refusal_score | #41 / 49 | ↓11.2 | Source ↗official | |
| HELM Safetyanthropic_red_team | #45 / 80 | ↓0.991 | Source ↗official | |
| HELM Safetyharmbench | #74 / 80 | ↓0.976 | Source ↗official | |
| HELM Safetysimple_safety_tests | #56 / 80 | ↓0.998 | Source ↗official | |
| HELM Safetyxstest | #22 / 80 | ↑0.971 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #57 / 69 | ↓26.5 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #19 / 21 | ↓61.29 | Source ↗official | |
| OpenAI GPT-5 System Cardharmful_request_safety | #2 / 2 | ↓0.912 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #59 / 70 | ↓0.9697 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #54 / 67 | ↓0.6868 | Source ↗official | |
| Shelleducation_jsr | #13 / 14 | ↑0.364 | Source ↗official | |
| Shellfinance_jsr | #13 / 14 | ↑0.19 | Source ↗official | |
| Shellmanagement_jsr | #12 / 14 | ↑0.37 | Source ↗official | |
| SOSBenchbiology_pvr | #22 / 23 | ↑0.108 | Source ↗official | |
| SOSBenchchemistry_pvr | #23 / 23 | ↑0.122 | Source ↗official | |
| SOSBenchmedicine_pvr | #21 / 23 | ↑0.332 | Source ↗official | |
| SOSBenchpharmacology_pvr | #20 / 23 | ↑0.418 | Source ↗official | |
| SOSBenchphysics_pvr | #22 / 23 | ↑0.104 | Source ↗official | |
| SOSBenchpsychology_pvr | #21 / 23 | ↑0.142 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #56 / 181 | ↑70.1 | Source ↗official | |
| ThaiSafetyBenchsafety_score | #18 / 18 | ↓95.57 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #15 / 23 | ↓51 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
