Model profile
Evidence summary
Safety. GPT OSS 120B has an estimated Safety rank of #118; its 90% source-sensitivity interval is #76–#177. Its behavior-only rank is #124; company governance moves the combined estimate to #118. Published Safety evidence spans 35 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (harmbench, #1 of 80); its weakest is AgentDrive Safety Compliance (scr, #48 of 48).
Freedom. GPT OSS 120B has an estimated Freedom rank of #573; its 90% source-sensitivity interval is #380–#598. Published Freedom evidence spans 17 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is FORTRESS (average_risk_score, #50 of 50).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-oss-120b
- Hugging Face ↗openai/gpt-oss-120b
- NVIDIA ↗qc69jvmznzxy/gpt-oss-120b
- OpenRouter ↗openai/gpt-oss-120b
- Model card ↗Family-level model document · OpenAI · first party
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- ArliAI/gpt-oss-120b-Derestricted ↗Direct non-quantized finetune documented by Hugging Face metadata
- wangzhang/gpt-oss-120b-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #278 / 345 | ↓0.9082 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #14 / 31 | ↓38.6 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #11 / 31 | ↓59.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #10 / 31 | ↓45.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #12 / 31 | ↓60 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #16 / 31 | ↓58.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #20 / 31 | ↓84.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #12 / 31 | ↓56.5 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #12 / 31 | ↓60.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #16 / 31 | ↓47.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #11 / 31 | ↓55.73 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #11 / 31 | ↓44.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #12 / 31 | ↓56.8 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #1 / 24 | ↓0.82 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #6 / 24 | ↓8.94 | Source ↗official | |
| AgentAbstainabstain | #11 / 17 | ↑59.5 | Source ↗official | |
| AgentAbstaincar | #10 / 17 | ↑58.2 | Source ↗official | |
| AgentAbstainpaired | #9 / 17 | ↑46.2 | Source ↗official | |
| AgentDrive Safety Compliancescr | #48 / 48 | ↑10 | Source ↗official | |
| AIMS Safety-Classifier Competenceaverage_harmful_f1 | #6 / 11 | ↑0.803 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #5 / 80 | ↑0.88 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #16 / 24 | ↑4.136 | Source ↗official | |
| Alignment Leaderboardhonesty | #8 / 24 | ↑3.733 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #7 / 24 | ↑3.611 | Source ↗official | |
| Alignment Leaderboardrobustness | #3 / 24 | ↑4.347 | Source ↗official | |
| Alignment Leaderboardsafety | #16 / 24 | ↑3.731 | Source ↗official | |
| Alignment Leaderboardscheming | #10 / 24 | ↑3.873 | Source ↗official | |
| ANIMAscore | #14 / 22 | ↑0.6866 | Source ↗self run | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #106 / 111 | ↑1389.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #33 / 52 | ↑98.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #24 / 52 | ↑47.1 | Source ↗official | |
| BrokenMathsycophancy | #2 / 9 | ↓33.7 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #101 / 117 | ↑0.085 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #20 / 104 | ↓7.245 | Source ↗official | |
| Confabulationsconfabulation_rate | #24 / 52 | ↓23.27 | Source ↗official | |
| DystopiaBenchbasaglia_score | #31 / 50 | ↓65.67 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #33 / 50 | ↓64.03 | Source ↗official | |
| DystopiaBenchhuxley_score | #33 / 50 | ↓74.63 | Source ↗official | |
| DystopiaBenchlaguardia_score | #32 / 50 | ↓68.63 | Source ↗official | |
| DystopiaBenchorwell_score | #27 / 50 | ↓68.8 | Source ↗official | |
| DystopiaBenchpetrov_score | #35 / 50 | ↓76.6 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #31 / 248 | ↑39.79 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #154 / 248 | ↑86.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #72 / 248 | ↑85.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #212 / 246 | ↑89.09 | Source ↗official | |
| FORTRESSaverage_risk_score | #1 / 50 | ↓8.24 | Source ↗official | |
| FORTRESSover_refusal_score | #48 / 49 | ↓18 | Source ↗official | |
| HELM Safetyanthropic_red_team | #18 / 80 | ↑0.995 | Source ↗official | |
| HELM Safetybbq | #2 / 80 | ↑0.985 | Source ↗official | |
| HELM Safetyharmbench | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #62 / 80 | ↑0.927 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| JuICE Cultural-Error Span Detectionf1 | #7 / 10 | ↑0.3657 | Source ↗official | |
| LiveSecBenchethics | #14 / 43 | ↑61.84 | Source ↗official | |
| LiveSecBenchfactuality | #22 / 43 | ↑48.37 | Source ↗official | |
| LiveSecBenchlegality | #5 / 43 | ↑86.06 | Source ↗official | |
| LiveSecBenchprivacy | #13 / 43 | ↑65.7 | Source ↗official | |
| LiveSecBenchpsychological_health | #9 / 43 | ↑71.2 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #33 / 37 | ↓9 | Source ↗self run | |
| MASKlying_probability_pct | #2 / 53 | ↓8 | Source ↗official | |
| ODCV-Benchaverage_severity | #8 / 12 | ↓1.569 | Source ↗official | |
| ODCV-Benchmisalignment_rate | #9 / 12 | ↓36.25 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #46 / 66 | ↑0.3884 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #58 / 70 | ↑0.6608 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #33 / 70 | ↑0.9375 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #16 / 67 | ↑0.659 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #104 / 123 | ↑6.44 | Source ↗official | |
| SpeciEvalland_animal_4ns | #59 / 123 | ↓4.49 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #96 / 123 | ↓4.94 | Source ↗official | |
| SpeciEvalspeciesism | #101 / 123 | ↓2.57 | Source ↗official | |
| StereoTales Harmful Associationsbenign_significant_association_score | #11 / 23 | ↑86.36 | Source ↗official | |
| TACbase_welfare_rate | #29 / 87 | ↑31.4 | Source ↗self run | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #81 / 94 | ↑85.8 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #15 / 23 | ↑35 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #18 / 31 | ↑38.6 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #21 / 31 | ↑59.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #22 / 31 | ↑45.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #20 / 31 | ↑60 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #16 / 31 | ↑58.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #12 / 31 | ↑84.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #20 / 31 | ↑56.5 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #20 / 31 | ↑60.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #16 / 31 | ↑47.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #21 / 31 | ↑55.73 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #21 / 31 | ↑44.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #20 / 31 | ↑56.8 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #23 / 24 | ↑0.82 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #19 / 24 | ↑8.94 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #76 / 80 | ↓0.88 | Source ↗official | |
| BioTIERpermit_compliance_pct | #33 / 52 | ↑98.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #29 / 52 | ↓47.1 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #85 / 104 | ↑7.245 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #95 / 248 | ↓86.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #173 / 248 | ↓85.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #35 / 246 | ↓89.09 | Source ↗official | |
| FORTRESSaverage_risk_score | #50 / 50 | ↑8.24 | Source ↗official | |
| FORTRESSover_refusal_score | #48 / 49 | ↓18 | Source ↗official | |
| HELM Safetyanthropic_red_team | #59 / 80 | ↓0.995 | Source ↗official | |
| HELM Safetyharmbench | #80 / 80 | ↓1 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↓1 | Source ↗official | |
| HELM Safetyxstest | #62 / 80 | ↑0.927 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #30 / 43 | ↓61.84 | Source ↗official | |
| LiveSecBenchlegality | #39 / 43 | ↓86.06 | Source ↗official | |
| LiveSecBenchprivacy | #31 / 43 | ↓65.7 | Source ↗official | |
| LiveSecBenchpsychological_health | #35 / 43 | ↓71.2 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #38 / 70 | ↓0.9375 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #52 / 67 | ↓0.659 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #151 / 181 | ↑36.3 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #61 / 156 | ↑3 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #146 / 156 | ↑1 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #8 / 23 | ↓35 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
