Model profile
Evidence summary
Safety. Llama 3.1 405B Instruct has an estimated Safety rank of #210; its 90% source-sensitivity interval is #131–#259. Its behavior-only rank is #195; company governance moves the combined estimate to #210. Published Safety evidence spans 23 eval lineages and 6 of 7 components. Its strongest relative result is PHARE (bias_resistance_diagnostic, #3 of 66); its weakest is BlueBench AttaQ-100 (attaq_harmlessness_reward_pct, #17 of 18).
Freedom. Llama 3.1 405B Instruct has an estimated Freedom rank of #367; its 90% source-sensitivity interval is #183–#511. Published Freedom evidence spans 18 eval lineages and 1 of 1 components. Its strongest relative result is PandaBench JBB direct-request panel (safety_rate, #4 of 46); its weakest is PHARE (jailbreak_resistance_diagnostic, #63 of 67).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗llama-3-1-instruct-405b
- Hugging Face ↗meta-llama/llama-3.1-405B
- OpenRouter ↗meta-llama/llama-3.1-405b-instruct
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #84 / 345 | ↓0.5244 | Source ↗official | |
| AbstentionBenchanswer_unknown_f1 | #11 / 20 | ↑0.87 | Source ↗official | |
| AbstentionBenchfalse_premise_f1 | #7 / 20 | ↑0.7164 | Source ↗official | |
| AbstentionBenchstale_f1 | #9 / 20 | ↑0.6419 | Source ↗official | |
| AbstentionBenchsubjective_f1 | #10 / 20 | ↑0.7422 | Source ↗official | |
| AbstentionBenchunderspecified_context_f1 | #3 / 20 | ↑0.7157 | Source ↗official | |
| AbstentionBenchunderspecified_intent_f1 | #14 / 20 | ↑0.7024 | Source ↗official | |
| Adversarial Robustnessscore | #2 / 8 | ↓10 | Source ↗official | |
| Agent-SafetyBenchcompromise_availability | #14 / 16 | ↑19.6 | Source ↗official | |
| Agent-SafetyBenchharmful_vulnerable_code | #6 / 16 | ↑40.4 | Source ↗official | |
| Agent-SafetyBenchleak_sensitive_information | #12 / 16 | ↑25.2 | Source ↗official | |
| Agent-SafetyBenchphysical_harm | #12 / 16 | ↑24.4 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #4 / 16 | ↑98.8 | Source ↗official | |
| Agent-SafetyBenchproperty_loss | #14 / 16 | ↑27.6 | Source ↗official | |
| Agent-SafetyBenchspread_unsafe_information | #6 / 16 | ↑14.4 | Source ↗official | |
| Agent-SafetyBenchviolate_law_ethics | #5 / 16 | ↑32.8 | Source ↗official | |
| AgentHarmharm_score | #2 / 12 | ↓4.3 | Source ↗official | |
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #16 / 32 | ↓20.4 | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #21 / 32 | ↓20.6 | Source ↗official | |
| AILuminate General Purpose AI Chathate | #24 / 32 | ↓14.5 | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #21 / 32 | ↓29.5 | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #23 / 32 | ↓19 | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #23 / 32 | ↓23.9 | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #20 / 32 | ↓17.9 | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #22 / 32 | ↓19.9 | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #24 / 32 | ↓35.2 | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #21 / 32 | ↓20.2 | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #21 / 32 | ↓15.7 | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #23 / 32 | ↓30.9 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #52 / 80 | ↑0.586 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #20 / 24 | ↑4.058 | Source ↗official | |
| Alignment Leaderboardhonesty | #17 / 24 | ↑3.475 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #20 / 24 | ↑3.034 | Source ↗official | |
| Alignment Leaderboardrobustness | #15 / 24 | ↑3.36 | Source ↗official | |
| Alignment Leaderboardsafety | #17 / 24 | ↑3.692 | Source ↗official | |
| Alignment Leaderboardscheming | #17 / 24 | ↑3.53 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #17 / 18 | ↑81.35 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #44 / 104 | ↓31.56 | Source ↗official | |
| Confabulationsconfabulation_rate | #14 / 52 | ↓14.36 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #172 / 248 | ↑12.92 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #83 / 248 | ↑90.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #117 / 248 | ↑73.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #130 / 246 | ↑96.05 | Source ↗official | |
| FORTRESSaverage_risk_score | #20 / 50 | ↓20.61 | Source ↗official | |
| FORTRESSover_refusal_score | #34 / 49 | ↓6.03 | Source ↗official | |
| HELM Safetyanthropic_red_team | #67 / 80 | ↑0.965 | Source ↗official | |
| HELM Safetybbq | #33 / 80 | ↑0.945 | Source ↗official | |
| HELM Safetyharmbench | #59 / 80 | ↑0.627 | Source ↗official | |
| HELM Safetysimple_safety_tests | #40 / 80 | ↑0.988 | Source ↗official | |
| HELM Safetyxstest | #41 / 80 | ↑0.959 | Source ↗official | |
| MASKlying_probability_pct | #23 / 53 | ↓33.3 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #43 / 46 | ↑0.92 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #3 / 66 | ↑0.7523 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #55 / 70 | ↑0.674 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #57 / 70 | ↑0.8649 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #5 / 67 | ↑0.7655 | Source ↗official | |
| SORRY-Benchavg | #20 / 51 | ↓0.24 | Source ↗official | |
| SOSBenchbiology_pvr | #14 / 23 | ↓0.59 | Source ↗official | |
| SOSBenchchemistry_pvr | #13 / 23 | ↓0.468 | Source ↗official | |
| SOSBenchmedicine_pvr | #14 / 23 | ↓0.69 | Source ↗official | |
| SOSBenchpharmacology_pvr | #11 / 23 | ↓0.764 | Source ↗official | |
| SOSBenchphysics_pvr | #11 / 23 | ↓0.444 | Source ↗official | |
| SOSBenchpsychology_pvr | #14 / 23 | ↓0.568 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Robustnessscore | #7 / 8 | ↑10 | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #13 / 16 | ↓98.8 | Source ↗official | |
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #17 / 32 | ↑20.4 | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #12 / 32 | ↑20.6 | Source ↗official | |
| AILuminate General Purpose AI Chathate | #9 / 32 | ↑14.5 | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #12 / 32 | ↑29.5 | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #10 / 32 | ↑19 | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #10 / 32 | ↑23.9 | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #12 / 32 | ↑17.9 | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #11 / 32 | ↑19.9 | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #9 / 32 | ↑35.2 | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #12 / 32 | ↑20.2 | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #12 / 32 | ↑15.7 | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #10 / 32 | ↑30.9 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #29 / 80 | ↓0.586 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #2 / 18 | ↓81.35 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #61 / 104 | ↑31.56 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #163 / 248 | ↓90.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #129 / 248 | ↓73.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #115 / 246 | ↓96.05 | Source ↗official | |
| FORTRESSaverage_risk_score | #31 / 50 | ↑20.61 | Source ↗official | |
| FORTRESSover_refusal_score | #34 / 49 | ↓6.03 | Source ↗official | |
| HELM Safetyanthropic_red_team | #13 / 80 | ↓0.965 | Source ↗official | |
| HELM Safetyharmbench | #22 / 80 | ↓0.627 | Source ↗official | |
| HELM Safetysimple_safety_tests | #39 / 80 | ↓0.988 | Source ↗official | |
| HELM Safetyxstest | #41 / 80 | ↑0.959 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #4 / 46 | ↓0.92 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #14 / 70 | ↓0.8649 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #63 / 67 | ↓0.7655 | Source ↗official | |
| SORRY-Benchavg | #31 / 51 | ↑0.24 | Source ↗official | |
| SOSBenchbiology_pvr | #10 / 23 | ↑0.59 | Source ↗official | |
| SOSBenchchemistry_pvr | #11 / 23 | ↑0.468 | Source ↗official | |
| SOSBenchmedicine_pvr | #10 / 23 | ↑0.69 | Source ↗official | |
| SOSBenchpharmacology_pvr | #13 / 23 | ↑0.764 | Source ↗official | |
| SOSBenchphysics_pvr | #13 / 23 | ↑0.444 | Source ↗official | |
| SOSBenchpsychology_pvr | #10 / 23 | ↑0.568 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #104 / 181 | ↑51.7 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #144 / 156 | ↑0.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.