Model profile
Evidence summary
Safety. o1 has an estimated Safety rank of #100; its 90% source-sensitivity interval is #27–#188. Its behavior-only rank is #107; company governance moves the combined estimate to #100. Published Safety evidence spans 19 eval lineages and 6 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #9 of 248); its weakest is CAIS Risk Index (hle_overconfidence, #53 of 55).
Freedom. o1 has an estimated Freedom rank of #380; its 90% source-sensitivity interval is #188–#551. Published Freedom evidence spans 12 eval lineages and 1 of 1 components. Its strongest relative result is BlueBench AttaQ-100 (attaq_harmlessness_reward_pct, #4 of 18); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #238 of 248).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗o1
- OpenRouter ↗openai/o1
- System card ↗Family-level model document · OpenAI · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #128 / 345 | ↓0.6963 | Source ↗official | |
| AbstentionBenchanswer_unknown_f1 | #7 / 20 | ↑0.8917 | Source ↗official | |
| AbstentionBenchfalse_premise_f1 | #1 / 20 | ↑0.7687 | Source ↗official | |
| AbstentionBenchstale_f1 | #8 / 20 | ↑0.646 | Source ↗official | |
| AbstentionBenchsubjective_f1 | #5 / 20 | ↑0.7654 | Source ↗official | |
| AbstentionBenchunderspecified_context_f1 | #6 / 20 | ↑0.6907 | Source ↗official | |
| AbstentionBenchunderspecified_intent_f1 | #3 / 20 | ↑0.7694 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #21 / 80 | ↑0.8 | Source ↗official | |
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #18 / 52 | ↑66.7 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #15 / 18 | ↑82.96 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #31 / 54 | ↓68.1 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #53 / 55 | ↓83 | Source ↗official | |
| CAIS Risk Indexmask | #37 / 57 | ↓40.7 | Source ↗official | |
| Confabulationsconfabulation_rate | #10 / 52 | ↓10.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #106 / 248 | ↑17.83 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #9 / 248 | ↑96.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #30 / 248 | ↑96.11 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #94 / 246 | ↑97.41 | Source ↗official | |
| FORTRESSaverage_risk_score | #18 / 50 | ↓19.38 | Source ↗official | |
| FORTRESSover_refusal_score | #27 / 49 | ↓5.05 | Source ↗official | |
| HELM Safetyanthropic_red_team | #50 / 80 | ↑0.983 | Source ↗official | |
| HELM Safetybbq | #9 / 80 | ↑0.973 | Source ↗official | |
| HELM Safetyharmbench | #12 / 80 | ↑0.963 | Source ↗official | |
| HELM Safetysimple_safety_tests | #32 / 80 | ↑0.99 | Source ↗official | |
| HELM Safetyxstest | #24 / 80 | ↑0.97 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #45 / 54 | ↑24.33 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #18 / 69 | ↑13.5 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #35 / 42 | ↓83 | Source ↗official | |
| MASKlying_probability_pct | #28 / 53 | ↓40.73 | Source ↗official | |
| Reward Hacking Benchmarkintegrity_score | #9 / 13 | ↑93.2 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #60 / 80 | ↓0.8 | Source ↗official | |
| BioTIERpermit_compliance_pct | #18 / 52 | ↑99.4 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #35 / 52 | ↓66.7 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #4 / 18 | ↓82.96 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #24 / 54 | ↑68.1 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #238 / 248 | ↓96.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #218 / 248 | ↓96.11 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #153 / 246 | ↓97.41 | Source ↗official | |
| FORTRESSaverage_risk_score | #33 / 50 | ↑19.38 | Source ↗official | |
| FORTRESSover_refusal_score | #27 / 49 | ↓5.05 | Source ↗official | |
| HELM Safetyanthropic_red_team | #28 / 80 | ↓0.983 | Source ↗official | |
| HELM Safetyharmbench | #69 / 80 | ↓0.963 | Source ↗official | |
| HELM Safetysimple_safety_tests | #42 / 80 | ↓0.99 | Source ↗official | |
| HELM Safetyxstest | #24 / 80 | ↑0.97 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #52 / 69 | ↓13.5 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #66 / 181 | ↑67.5 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
