Model profile
Evidence summary
Safety. Kimi K2 has an estimated Safety rank of #97; its 90% source-sensitivity interval is #63–#184. Its behavior-only rank is #99; company governance moves the combined estimate to #97. Published Safety evidence spans 33 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is LiveSecBench (factuality, #41 of 43).
Freedom. Kimi K2 has an estimated Freedom rank of #346; its 90% source-sensitivity interval is #228–#437. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Shell (management_jsr, #13 of 14).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗kimi-k2
- Hugging Face ↗moonshotai/Kimi-K2-Instruct
- OpenRouter ↗moonshotai/kimi-k2
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #134 / 345 | ↓0.7267 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #11 / 24 | ↓6.045 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #13 / 24 | ↓51.88 | Source ↗official | |
| AgentDrive Safety Compliancescr | #19 / 48 | ↑89.38 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #28 / 80 | ↑0.741 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #3 / 24 | ↑4.495 | Source ↗official | |
| Alignment Leaderboardhonesty | #7 / 24 | ↑3.765 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #8 / 24 | ↑3.598 | Source ↗official | |
| Alignment Leaderboardrobustness | #18 / 24 | ↑3.267 | Source ↗official | |
| Alignment Leaderboardsafety | #9 / 24 | ↑3.923 | Source ↗official | |
| Alignment Leaderboardscheming | #8 / 24 | ↑3.898 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #82 / 111 | ↑1420.0 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #97 / 117 | ↑0.1 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #46 / 49 | ↓92.8 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #47 / 54 | ↓93 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #40 / 55 | ↓67.8 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #15 / 51 | ↓84.2 | Source ↗official | |
| CAIS Risk Indexmask | #36 / 57 | ↓30.7 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #9 / 54 | ↓14.6 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #35 / 104 | ↓20.59 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #39 / 54 | ↑66 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #31 / 63 | ↑85.19 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #30 / 56 | ↑88 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #36 / 63 | ↑90.54 | Source ↗official | |
| Concordia — APEsafety_score | #30 / 55 | ↑21.82 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #27 / 63 | ↑88.05 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #39 / 55 | ↑49.17 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #32 / 54 | ↑46.08 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #31 / 54 | ↑46.59 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #35 / 54 | ↑53.02 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #26 / 45 | ↑32.67 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #30 / 45 | ↑19.67 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #13 / 45 | ↑4.667 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #13 / 45 | ↑64 | Source ↗official | |
| Concordia — MASKsafety_score | #23 / 62 | ↑72.42 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #46 / 63 | ↑67.34 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #44 / 63 | ↑12.11 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #1 / 53 | ↑100 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #26 / 63 | ↑88.6 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #41 / 63 | ↑80.6 | Source ↗official | |
| Confabulationsconfabulation_rate | #37 / 52 | ↓30.2 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #51 / 248 | ↑28.81 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #190 / 248 | ↑81.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #97 / 248 | ↑79.16 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #203 / 246 | ↑90.97 | Source ↗official | |
| FORTRESSaverage_risk_score | #41 / 50 | ↓55.47 | Source ↗official | |
| FORTRESSover_refusal_score | #21 / 49 | ↓3.33 | Source ↗official | |
| HELM Safetyanthropic_red_team | #27 / 80 | ↑0.993 | Source ↗official | |
| HELM Safetybbq | #28 / 80 | ↑0.949 | Source ↗official | |
| HELM Safetyharmbench | #8 / 80 | ↑0.974 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #9 / 80 | ↑0.982 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #48 / 54 | ↑23.64 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| LiveSecBenchethics | #40 / 43 | ↑20.12 | Source ↗official | |
| LiveSecBenchfactuality | #41 / 43 | ↑18.45 | Source ↗official | |
| LiveSecBenchlegality | #27 / 43 | ↑31.19 | Source ↗official | |
| LiveSecBenchprivacy | #8 / 43 | ↑73.81 | Source ↗official | |
| LiveSecBenchpsychological_health | #30 / 43 | ↑34.35 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #13 / 50 | ↓84.2 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #21 / 37 | ↓8.667 | Source ↗self run | |
| MASKlying_probability_pct | #47 / 53 | ↓53.33 | Source ↗official | |
| RealityTest — Text AI-Identity Disclosuredisclosure_probability | #4 / 17 | ↑0.552 | Source ↗official | |
| Shelleducation_jsr | #4 / 14 | ↓0.426 | Source ↗official | |
| Shellfinance_jsr | #3 / 14 | ↓0.22 | Source ↗official | |
| Shellmanagement_jsr | #2 / 14 | ↓0.346 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #1 / 19 | ↑0.637 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #74 / 123 | ↑6.725 | Source ↗official | |
| SpeciEvalland_animal_4ns | #92 / 123 | ↓4.775 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #112 / 123 | ↓5.13 | Source ↗official | |
| SpeciEvalspeciesism | #22 / 123 | ↓1.505 | Source ↗official | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #15 / 27 | ↑0.685 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #86 / 94 | ↑82.1 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #14 / 24 | ↑6.045 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #12 / 24 | ↑51.88 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #52 / 80 | ↓0.741 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #8 / 54 | ↑93 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #70 / 104 | ↑20.59 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #33 / 63 | ↓85.19 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #27 / 56 | ↓88 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #32 / 56 | ↓67.14 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #28 / 63 | ↓90.54 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #23 / 54 | ↓46.08 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #24 / 54 | ↓46.59 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #20 / 54 | ↓53.02 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #20 / 45 | ↓32.67 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #16 / 45 | ↓19.67 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #32 / 45 | ↓4.667 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #33 / 45 | ↓64 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #18 / 63 | ↓67.34 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #20 / 63 | ↓12.11 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #38 / 63 | ↓88.6 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #23 / 63 | ↓80.6 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #59 / 248 | ↓81.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #152 / 248 | ↓79.16 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #44 / 246 | ↓90.97 | Source ↗official | |
| FORTRESSaverage_risk_score | #10 / 50 | ↑55.47 | Source ↗official | |
| FORTRESSover_refusal_score | #21 / 49 | ↓3.33 | Source ↗official | |
| HELM Safetyanthropic_red_team | #50 / 80 | ↓0.993 | Source ↗official | |
| HELM Safetyharmbench | #72 / 80 | ↓0.974 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↓1 | Source ↗official | |
| HELM Safetyxstest | #9 / 80 | ↑0.982 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #4 / 43 | ↓20.12 | Source ↗official | |
| LiveSecBenchlegality | #17 / 43 | ↓31.19 | Source ↗official | |
| LiveSecBenchprivacy | #36 / 43 | ↓73.81 | Source ↗official | |
| LiveSecBenchpsychological_health | #14 / 43 | ↓34.35 | Source ↗official | |
| Shelleducation_jsr | #11 / 14 | ↑0.426 | Source ↗official | |
| Shellfinance_jsr | #12 / 14 | ↑0.22 | Source ↗official | |
| Shellmanagement_jsr | #13 / 14 | ↑0.346 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #102 / 181 | ↑52.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #73 / 156 | ↑2.167 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #76 / 156 | ↑3.333 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
