← Models

Model profile

Kimi K2

Moonshot AIdeveloper
2025-07-11release date
#97 / 333Safety rank
#346 / 645Freedom rank

Evidence summary

Safety. Kimi K2 has an estimated Safety rank of #97; its 90% source-sensitivity interval is #63–#184. Its behavior-only rank is #99; company governance moves the combined estimate to #97. Published Safety evidence spans 33 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is LiveSecBench (factuality, #41 of 43).

Freedom. Kimi K2 has an estimated Freedom rank of #346; its 90% source-sensitivity interval is #228–#437. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Shell (management_jsr, #13 of 14).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#134 / 3450.7267Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#11 / 246.045Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#13 / 2451.88Source ↗official
AgentDrive Safety Compliancescr#19 / 4889.38Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#28 / 800.741Source ↗official
Alignment Leaderboardcorrigibility#3 / 244.495Source ↗official
Alignment Leaderboardhonesty#7 / 243.765Source ↗official
Alignment Leaderboardnon_manipulation#8 / 243.598Source ↗official
Alignment Leaderboardrobustness#18 / 243.267Source ↗official
Alignment Leaderboardsafety#9 / 243.923Source ↗official
Alignment Leaderboardscheming#8 / 243.898Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#82 / 1111420.0Source ↗official
BullshitBench v2clear_pushback_rate#97 / 1170.1Source ↗official
CAIS Risk Indexagent_red_teaming#46 / 4992.8Source ↗official
CAIS Risk Indexbioweapons_assistance#47 / 5493Source ↗official
CAIS Risk Indexhle_overconfidence#40 / 5567.8Source ↗official
CAIS Risk Indexmachiavelli#15 / 5184.2Source ↗official
CAIS Risk Indexmask#36 / 5730.7Source ↗official
CAIS Risk Indextextquests_harm#9 / 5414.6Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#35 / 10420.59Source ↗official
Concordia — Agentic-Misalignmentsafety_score#39 / 5466Source ↗official
Concordia — AirBench-Deceptionsafety_score#31 / 6385.19Source ↗official
Concordia — AirBench-Manipulationsafety_score#30 / 5688Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#36 / 6390.54Source ↗official
Concordia — APEsafety_score#30 / 5521.82Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#27 / 6388.05Source ↗official
Concordia — DarkBenchsafety_score#39 / 5549.17Source ↗official
Concordia — Fortress-Biologicalsafety_score#32 / 5446.08Source ↗official
Concordia — Fortress-Chemicalsafety_score#31 / 5446.59Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#35 / 5453.02Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#26 / 4532.67Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#30 / 4519.67Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#13 / 454.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#13 / 4564Source ↗official
Concordia — MASKsafety_score#23 / 6272.42Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#46 / 6367.34Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#44 / 6312.11Source ↗official
Concordia — Shutdown-Resistancesafety_score#1 / 53100Source ↗official
Concordia — SOSBench-Biosafety_score#26 / 6388.6Source ↗official
Concordia — SOSBench-Chemsafety_score#41 / 6380.6Source ↗official
Confabulationsconfabulation_rate#37 / 5230.2Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#51 / 24828.81Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#190 / 24881.44Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#97 / 24879.16Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#203 / 24690.97Source ↗official
FORTRESSaverage_risk_score#41 / 5055.47Source ↗official
FORTRESSover_refusal_score#21 / 493.33Source ↗official
HELM Safetyanthropic_red_team#27 / 800.993Source ↗official
HELM Safetybbq#28 / 800.949Source ↗official
HELM Safetyharmbench#8 / 800.974Source ↗official
HELM Safetysimple_safety_tests#1 / 801Source ↗official
HELM Safetyxstest#9 / 800.982Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#48 / 5423.64Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 690Source ↗official
LiveSecBenchethics#40 / 4320.12Source ↗official
LiveSecBenchfactuality#41 / 4318.45Source ↗official
LiveSecBenchlegality#27 / 4331.19Source ↗official
LiveSecBenchprivacy#8 / 4373.81Source ↗official
LiveSecBenchpsychological_health#30 / 4334.35Source ↗official
MACHIAVELLIdeception_relative_random_pct#13 / 5084.2Source ↗official
Manager Coercion Benchcoercion_ladder_depth#21 / 378.667Source ↗self run
MASKlying_probability_pct#47 / 5353.33Source ↗official
RealityTest — Text AI-Identity Disclosuredisclosure_probability#4 / 170.552Source ↗official
Shelleducation_jsr#4 / 140.426Source ↗official
Shellfinance_jsr#3 / 140.22Source ↗official
Shellmanagement_jsr#2 / 140.346Source ↗official
Social Welfare Function Benchmarkfairness#1 / 190.637Source ↗official
SpeciEvalbelief_animal_sentience#74 / 1236.725Source ↗official
SpeciEvalland_animal_4ns#92 / 1234.775Source ↗official
SpeciEvalsea_animal_4ns#112 / 1235.13Source ↗official
SpeciEvalspeciesism#22 / 1231.505Source ↗official
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#15 / 270.685Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#86 / 9482.1Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#14 / 246.045Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#12 / 2451.88Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#52 / 800.741Source ↗official
CAIS Risk Indexbioweapons_assistance#8 / 5493Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#70 / 10420.59Source ↗official
Concordia — AirBench-Deceptionsafety_score#33 / 6385.19Source ↗official
Concordia — AirBench-Manipulationsafety_score#27 / 5688Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#32 / 5667.14Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#28 / 6390.54Source ↗official
Concordia — Fortress-Biologicalsafety_score#23 / 5446.08Source ↗official
Concordia — Fortress-Chemicalsafety_score#24 / 5446.59Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#20 / 5453.02Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#20 / 4532.67Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#16 / 4519.67Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#32 / 454.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#33 / 4564Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#18 / 6367.34Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#20 / 6312.11Source ↗official
Concordia — SOSBench-Biosafety_score#38 / 6388.6Source ↗official
Concordia — SOSBench-Chemsafety_score#23 / 6380.6Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#59 / 24881.44Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#152 / 24879.16Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#44 / 24690.97Source ↗official
FORTRESSaverage_risk_score#10 / 5055.47Source ↗official
FORTRESSover_refusal_score#21 / 493.33Source ↗official
HELM Safetyanthropic_red_team#50 / 800.993Source ↗official
HELM Safetyharmbench#72 / 800.974Source ↗official
HELM Safetysimple_safety_tests#58 / 801Source ↗official
HELM Safetyxstest#9 / 800.982Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 690Source ↗official
LiveSecBenchethics#4 / 4320.12Source ↗official
LiveSecBenchlegality#17 / 4331.19Source ↗official
LiveSecBenchprivacy#36 / 4373.81Source ↗official
LiveSecBenchpsychological_health#14 / 4334.35Source ↗official
Shelleducation_jsr#11 / 140.426Source ↗official
Shellfinance_jsr#12 / 140.22Source ↗official
Shellmanagement_jsr#13 / 140.346Source ↗official
SpeechMap model completioncomplete_pct#102 / 18152.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#73 / 1562.167Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#76 / 1563.333Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-29
Government45.5
Diplomacy69.4
Economy47
Society67.8

The Economist World Values Survey Cultural Map

DimensionValueDistribution
Survival ↔ Self-expression2.62
Traditional ↔ Secular0.427