Model profile
Evidence summary
Safety. Llama 2 70B Chat has an estimated Safety rank of #260; its 90% source-sensitivity interval is #113–#294. Its behavior-only rank is #245; company governance moves the combined estimate to #260. Published Safety evidence spans 9 eval lineages and 6 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #16 of 246); its weakest is XSTest (safe_full_compliance_rate, #3 of 3).
Freedom. Llama 2 70B Chat has an estimated Freedom rank of #599; its 90% source-sensitivity interval is #367–#627. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is COMPL-AI LLM RuLES Multi-Turn Rule Following (score, #7 of 14); its weakest is XSTest (safe_full_compliance_rate, #3 of 3).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- OpenRouter ↗meta-llama/llama-2-70b-chat
- Model card ↗Exact model document · Meta · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| COMPL-AI AI-Identity Disclosurescore | #9 / 14 | ↑0.8904 | Source ↗official | |
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #8 / 14 | ↑0.3822 | Source ↗official | |
| COMPL-AI TensorTrust Goal-Hijacking Resistancescore | #10 / 13 | ↑0.4278 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #187 / 248 | ↑12.4 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #113 / 248 | ↑88.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #63 / 248 | ↑87.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #16 / 246 | ↑99.64 | Source ↗official | |
| HarmBenchdr | #4 / 28 | ↓2.8 | Source ↗official | |
| MedSafetyBenchmedical_safety_score | #2 / 30 | ↑99.5 | Source ↗official | |
| OR-Benchover_refusal_rate | #23 / 25 | ↓96.1 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #2 / 25 | ↓0.3 | Source ↗official | |
| S-Evalbase_en_overall | #5 / 22 | ↑77.2 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #5 / 33 | ↑62.28 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #5 / 33 | ↑68.4 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #4 / 33 | ↑66.15 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #5 / 33 | ↑62.17 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #4 / 33 | ↑68.62 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #5 / 33 | ↑60.17 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #6 / 33 | ↑98.25 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #4 / 33 | ↑99.19 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #6 / 33 | ↑98.17 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #11 / 33 | ↑95.67 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #11 / 33 | ↑92.71 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #4 / 33 | ↑94.83 | Source ↗official | |
| SALAD-Benchmcq_human_autonomy_integrity | #17 / 33 | ↑33.61 | Source ↗official | |
| SALAD-Benchmcq_information_safety_harms | #19 / 33 | ↑30.83 | Source ↗official | |
| SALAD-Benchmcq_malicious_use | #19 / 33 | ↑27.24 | Source ↗official | |
| SALAD-Benchmcq_misinformation_harms | #18 / 33 | ↑30.95 | Source ↗official | |
| SALAD-Benchmcq_representation_toxicity | #19 / 33 | ↑27.71 | Source ↗official | |
| SALAD-Benchmcq_socioeconomic_harms | #18 / 33 | ↑31.67 | Source ↗official | |
| SORRY-Benchavg | #11 / 51 | ↓0.12 | Source ↗official | |
| XSTestsafe_full_compliance_rate | #3 / 3 | ↑0.704 | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #1 / 3 | ↑0.975 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| COMPL-AI LLM RuLES Multi-Turn Rule Followingscore | #7 / 14 | ↓0.3822 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #132 / 248 | ↓88.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #185 / 248 | ↓87.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #228 / 246 | ↓99.64 | Source ↗official | |
| HarmBenchdr | #24 / 28 | ↑2.8 | Source ↗official | |
| MedSafetyBenchmedical_safety_score | #29 / 30 | ↓99.5 | Source ↗official | |
| OR-Benchover_refusal_rate | #23 / 25 | ↓96.1 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #21 / 25 | ↑0.3 | Source ↗official | |
| S-Evalbase_en_overall | #18 / 22 | ↓77.2 | Source ↗official | |
| SALAD-Benchattack_enhanced_human_autonomy_integrity | #29 / 33 | ↓62.28 | Source ↗official | |
| SALAD-Benchattack_enhanced_information_safety_harms | #29 / 33 | ↓68.4 | Source ↗official | |
| SALAD-Benchattack_enhanced_malicious_use | #30 / 33 | ↓66.15 | Source ↗official | |
| SALAD-Benchattack_enhanced_misinformation_harms | #29 / 33 | ↓62.17 | Source ↗official | |
| SALAD-Benchattack_enhanced_representation_toxicity | #30 / 33 | ↓68.62 | Source ↗official | |
| SALAD-Benchattack_enhanced_socioeconomic_harms | #29 / 33 | ↓60.17 | Source ↗official | |
| SALAD-Benchbase_human_autonomy_integrity | #28 / 33 | ↓98.25 | Source ↗official | |
| SALAD-Benchbase_information_safety_harms | #30 / 33 | ↓99.19 | Source ↗official | |
| SALAD-Benchbase_malicious_use | #28 / 33 | ↓98.17 | Source ↗official | |
| SALAD-Benchbase_misinformation_harms | #23 / 33 | ↓95.67 | Source ↗official | |
| SALAD-Benchbase_representation_toxicity | #22 / 33 | ↓92.71 | Source ↗official | |
| SALAD-Benchbase_socioeconomic_harms | #30 / 33 | ↓94.83 | Source ↗official | |
| SORRY-Benchavg | #41 / 51 | ↑0.12 | Source ↗official | |
| XSTestsafe_full_compliance_rate | #3 / 3 | ↑0.704 | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #2 / 3 | ↓0.975 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.