Model profile
Evidence summary
Safety. Llama 4 Maverick has an estimated Safety rank of #188; its 90% source-sensitivity interval is #135–#252. Its behavior-only rank is #185; company governance moves the combined estimate to #188. Published Safety evidence spans 36 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — Shutdown-Resistance (safety_score, #1 of 53); its weakest is The Dictatorship Eval (overall_resistance_rate, #20 of 20).
Freedom. Llama 4 Maverick has an estimated Freedom rank of #253; its 90% source-sensitivity interval is #171–#363. Published Freedom evidence spans 20 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is SOSBench (medicine_pvr, #18 of 23).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗llama-4-maverick
- Hugging Face ↗meta-llama/Llama-4-Maverick-17B-128E-Instruct
- OpenRouter ↗meta-llama/llama-4-maverick
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #257 / 345 | ↓0.8888 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #20 / 31 | ↓53.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #15 / 31 | ↓66.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #16 / 31 | ↓52.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #20 / 31 | ↓80 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #17 / 31 | ↓59.6 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #14 / 31 | ↓77.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #15 / 31 | ↓66.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #19 / 31 | ↓73.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #18 / 31 | ↓51.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #13 / 31 | ↓60.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #14 / 31 | ↓58.3 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #19 / 31 | ↓76.1 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #10 / 24 | ↓5.14 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #11 / 24 | ↓43.44 | Source ↗official | |
| AgentDrive Safety Compliancescr | #30 / 48 | ↑75 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #37 / 80 | ↑0.686 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #15 / 24 | ↑4.175 | Source ↗official | |
| Alignment Leaderboardhonesty | #14 / 24 | ↑3.581 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #17 / 24 | ↑3.084 | Source ↗official | |
| Alignment Leaderboardrobustness | #9 / 24 | ↑3.867 | Source ↗official | |
| Alignment Leaderboardsafety | #18 / 24 | ↑3.567 | Source ↗official | |
| Alignment Leaderboardscheming | #19 / 24 | ↑3.422 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #1 / 16 | ↓0 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #7 / 16 | ↓44 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #65 / 117 | ↑0.29 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #72 / 104 | ↓56.23 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #38 / 54 | ↑66.17 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #42 / 63 | ↑74.07 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #46 / 56 | ↑73.33 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #43 / 63 | ↑83.78 | Source ↗official | |
| Concordia — APEsafety_score | #39 / 55 | ↑9.635 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #55 / 63 | ↑70.52 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #18 / 55 | ↑60.03 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #31 / 54 | ↑47.7 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #29 / 54 | ↑51.89 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #26 / 54 | ↑62.38 | Source ↗official | |
| Concordia — MASKsafety_score | #34 / 62 | ↑58.22 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #25 / 63 | ↑86.53 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #40 / 63 | ↑15.86 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #1 / 53 | ↑100 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #41 / 63 | ↑72.2 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #42 / 63 | ↑79.2 | Source ↗official | |
| Confabulationsconfabulation_rate | #34 / 52 | ↓28.22 | Source ↗official | |
| DystopiaBenchbasaglia_score | #27 / 50 | ↓64.93 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #36 / 50 | ↓65.83 | Source ↗official | |
| DystopiaBenchhuxley_score | #27 / 50 | ↓72.8 | Source ↗official | |
| DystopiaBenchlaguardia_score | #25 / 50 | ↓66.73 | Source ↗official | |
| DystopiaBenchorwell_score | #23 / 50 | ↓68.6 | Source ↗official | |
| DystopiaBenchpetrov_score | #18 / 50 | ↓68.63 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #212 / 248 | ↑10.34 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #62 / 248 | ↑91.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #86 / 248 | ↑82.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #84 / 246 | ↑97.82 | Source ↗official | |
| FORTRESSaverage_risk_score | #29 / 50 | ↓40.09 | Source ↗official | |
| FORTRESSover_refusal_score | #26 / 49 | ↓4.95 | Source ↗official | |
| HELM Safetyanthropic_red_team | #54 / 80 | ↑0.982 | Source ↗official | |
| HELM Safetybbq | #43 / 80 | ↑0.93 | Source ↗official | |
| HELM Safetyharmbench | #52 / 80 | ↑0.661 | Source ↗official | |
| HELM Safetysimple_safety_tests | #29 / 80 | ↑0.993 | Source ↗official | |
| HELM Safetyxstest | #32 / 80 | ↑0.965 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #50 / 54 | ↑23.02 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #35 / 42 | ↓83 | Source ↗official | |
| LiveSecBenchethics | #37 / 43 | ↑22.55 | Source ↗official | |
| LiveSecBenchfactuality | #35 / 43 | ↑29.74 | Source ↗official | |
| LiveSecBenchlegality | #30 / 43 | ↑27.05 | Source ↗official | |
| LiveSecBenchprivacy | #35 / 43 | ↑26.17 | Source ↗official | |
| LiveSecBenchpsychological_health | #29 / 43 | ↑35.37 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #18 / 37 | ↓8.333 | Source ↗self run | |
| MASKlying_probability_pct | #41 / 53 | ↓50.27 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #10 / 21 | ↑22.64 | Source ↗official | |
| ODCV-Benchaverage_severity | #10 / 12 | ↓1.682 | Source ↗official | |
| ODCV-Benchmisalignment_rate | #2 / 12 | ↓16.22 | Source ↗official | |
| PHAREbias_resistance_diagnostic | #5 / 66 | ↑0.7365 | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #43 / 70 | ↑0.7147 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #53 / 70 | ↑0.8925 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #34 / 67 | ↑0.4899 | Source ↗official | |
| Shelleducation_jsr | #10 / 14 | ↓0.696 | Source ↗official | |
| Shellfinance_jsr | #11 / 14 | ↓0.716 | Source ↗official | |
| Shellmanagement_jsr | #11 / 14 | ↓0.844 | Source ↗official | |
| SOSBenchbiology_pvr | #7 / 23 | ↓0.288 | Source ↗official | |
| SOSBenchchemistry_pvr | #7 / 23 | ↓0.238 | Source ↗official | |
| SOSBenchmedicine_pvr | #6 / 23 | ↓0.426 | Source ↗official | |
| SOSBenchpharmacology_pvr | #8 / 23 | ↓0.652 | Source ↗official | |
| SOSBenchphysics_pvr | #8 / 23 | ↓0.24 | Source ↗official | |
| SOSBenchpsychology_pvr | #6 / 23 | ↓0.242 | Source ↗official | |
| SpeciesismBenchexplicit_speciesism_scale | #7 / 7 | ↓3.3 | Source ↗official | |
| SpeciesismBenchmorally_wrong_rate | #2 / 8 | ↑42.67 | Source ↗official | |
| SpeciesismBenchspeciesism_recognition_rate | #4 / 8 | ↑88.97 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #25 / 123 | ↑6.97 | Source ↗official | |
| SpeciEvalland_animal_4ns | #86 / 123 | ↓4.72 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #88 / 123 | ↓4.9 | Source ↗official | |
| SpeciEvalspeciesism | #107 / 123 | ↓2.65 | Source ↗official | |
| The Dictatorship Evaloverall_resistance_rate | #20 / 20 | ↑0 | Source ↗official | |
| TrustLLM contemporary collapsed applicationtrustllm | #7 / 8 | ↑0.6 | Source ↗official | |
| TukaBenchafri_jbb_cultural_asr | #4 / 6 | ↓22.4 | Source ↗official | |
| TukaBenchafri_jbb_harm_asr | #4 / 6 | ↓16.9 | Source ↗official | |
| TukaBenchafrijail_mono_asr | #4 / 6 | ↓22 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #36 / 94 | ↑91.8 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #19 / 23 | ↑28 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Humanities Benchmark (AHB) — Table 5child_sexual_exploitation | #12 / 31 | ↑53.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5defamation | #16 / 31 | ↑66.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5hate | #16 / 31 | ↑52.2 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5indiscriminate_weapons_cbrne | #10 / 31 | ↑80 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5intellectual_property | #15 / 31 | ↑59.6 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5non_violent_crimes | #18 / 31 | ↑77.8 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5privacy | #17 / 31 | ↑66.7 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sex_related_crimes | #12 / 31 | ↑73.9 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5sexual_content | #14 / 31 | ↑51.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5specialized_advice | #19 / 31 | ↑60.1 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5suicide_self_harm | #17 / 31 | ↑58.3 | Source ↗official | |
| Adversarial Humanities Benchmark (AHB) — Table 5violent_crimes | #12 / 31 | ↑76.1 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr | #15 / 24 | ↑5.14 | Source ↗official | |
| Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr | #14 / 24 | ↑43.44 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #44 / 80 | ↓0.686 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #33 / 104 | ↑56.23 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #22 / 63 | ↓74.07 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #11 / 56 | ↓73.33 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #26 / 56 | ↓58.57 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #20 / 63 | ↓83.78 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #24 / 54 | ↓47.7 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #26 / 54 | ↓51.89 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #29 / 54 | ↓62.38 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #39 / 63 | ↓86.53 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #24 / 63 | ↓15.86 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #23 / 63 | ↓72.2 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #22 / 63 | ↓79.2 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #184 / 248 | ↓91.17 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #162 / 248 | ↓82.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #162 / 246 | ↓97.82 | Source ↗official | |
| FORTRESSaverage_risk_score | #22 / 50 | ↑40.09 | Source ↗official | |
| FORTRESSover_refusal_score | #26 / 49 | ↓4.95 | Source ↗official | |
| HELM Safetyanthropic_red_team | #25 / 80 | ↓0.982 | Source ↗official | |
| HELM Safetyharmbench | #29 / 80 | ↓0.661 | Source ↗official | |
| HELM Safetysimple_safety_tests | #50 / 80 | ↓0.993 | Source ↗official | |
| HELM Safetyxstest | #32 / 80 | ↑0.965 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #7 / 43 | ↓22.55 | Source ↗official | |
| LiveSecBenchlegality | #14 / 43 | ↓27.05 | Source ↗official | |
| LiveSecBenchprivacy | #9 / 43 | ↓26.17 | Source ↗official | |
| LiveSecBenchpsychological_health | #15 / 43 | ↓35.37 | Source ↗official | |
| MT-JailBench CrescendoXsafety_score | #12 / 21 | ↓22.64 | Source ↗official | |
| PHAREharm_resistance_diagnostic | #18 / 70 | ↓0.8925 | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #34 / 67 | ↓0.4899 | Source ↗official | |
| Shelleducation_jsr | #5 / 14 | ↑0.696 | Source ↗official | |
| Shellfinance_jsr | #4 / 14 | ↑0.716 | Source ↗official | |
| Shellmanagement_jsr | #4 / 14 | ↑0.844 | Source ↗official | |
| SOSBenchbiology_pvr | #17 / 23 | ↑0.288 | Source ↗official | |
| SOSBenchchemistry_pvr | #17 / 23 | ↑0.238 | Source ↗official | |
| SOSBenchmedicine_pvr | #18 / 23 | ↑0.426 | Source ↗official | |
| SOSBenchpharmacology_pvr | #16 / 23 | ↑0.652 | Source ↗official | |
| SOSBenchphysics_pvr | #16 / 23 | ↑0.24 | Source ↗official | |
| SOSBenchpsychology_pvr | #18 / 23 | ↑0.242 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #93 / 181 | ↑58.3 | Source ↗official | |
| TukaBenchafri_jbb_cultural_asr | #3 / 6 | ↑22.4 | Source ↗official | |
| TukaBenchafri_jbb_harm_asr | #2 / 6 | ↑16.9 | Source ↗official | |
| TukaBenchafrijail_mono_asr | #3 / 6 | ↑22 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #25 / 156 | ↑6 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #4 / 23 | ↓28 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.