Model profile
Evidence summary
Safety. o3 Mini has an estimated Safety rank of #182; its 90% source-sensitivity interval is #108–#237. Its behavior-only rank is #192; company governance moves the combined estimate to #182. Published Safety evidence spans 26 eval lineages and 6 of 7 components. Its strongest relative result is OpenAgentSafety (rule_based_safety_vulnerable, #1 of 7); its weakest is BlueBench AttaQ-100 (attaq_harmlessness_reward_pct, #18 of 18).
Freedom. o3 Mini has an estimated Freedom rank of #237; its 90% source-sensitivity interval is #118–#387. Published Freedom evidence spans 15 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is OpenAI o3-mini System Card (harmful_request_safety, #2 of 2).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗o3-mini
- OpenRouter ↗openai/o3-mini
- System card ↗Exact model document · OpenAI · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #172 / 345 | ↓0.8108 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #27 / 80 | ↑0.749 | Source ↗official | |
| BioTIERpermit_compliance_pct | #8 / 52 | ↑99.6 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #29 / 52 | ↑35.4 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #18 / 18 | ↑80.61 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #42 / 54 | ↓88.3 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #50 / 55 | ↓80 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #50 / 51 | ↓105 | Source ↗official | |
| CAIS Risk Indexmask | #47 / 57 | ↓51.1 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #8 / 54 | ↓13.4 | Source ↗official | |
| Confabulationsconfabulation_rate | #36 / 52 | ↓28.96 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #103 / 248 | ↑18.09 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #53 / 248 | ↑91.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #80 / 248 | ↑84.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #154 / 246 | ↑95.36 | Source ↗official | |
| FORTRESSaverage_risk_score | #26 / 50 | ↓30.05 | Source ↗official | |
| FORTRESSover_refusal_score | #32 / 49 | ↓5.65 | Source ↗official | |
| HELM Safetyanthropic_red_team | #47 / 80 | ↑0.986 | Source ↗official | |
| HELM Safetybbq | #36 / 80 | ↑0.941 | Source ↗official | |
| HELM Safetyharmbench | #17 / 80 | ↑0.952 | Source ↗official | |
| HELM Safetysimple_safety_tests | #32 / 80 | ↑0.99 | Source ↗official | |
| HELM Safetyxstest | #55 / 80 | ↑0.941 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #52 / 54 | ↑22.29 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #47 / 50 | ↓105 | Source ↗official | |
| MASKlying_probability_pct | #42 / 53 | ↓50.79 | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #7 / 7 | ↓72.73 | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #1 / 7 | ↓32.32 | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #7 / 7 | ↑17.29 | Source ↗official | |
| OpenAI o3-mini System Cardharmful_request_safety | #1 / 2 | ↑0.9 | Source ↗official | |
| OpenAI o3-mini System Cardjailbreak_resistance | #1 / 2 | ↑0.73 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #25 / 46 | ↑0.98 | Source ↗official | |
| PropensityBenchscore | #5 / 14 | ↓33.2 | Source ↗official | |
| Reward Hacking Benchmarkintegrity_score | #10 / 13 | ↑92.9 | Source ↗official | |
| SafeDialBenchaggression | #14 / 18 | ↑7.02 | Source ↗official | |
| SafeDialBenchethics | #13 / 18 | ↑7.403 | Source ↗official | |
| SafeDialBenchfairness | #6 / 18 | ↑7.557 | Source ↗official | |
| SafeDialBenchlegality | #17 / 18 | ↑7.193 | Source ↗official | |
| SafeDialBenchmorality | #18 / 18 | ↑7.007 | Source ↗official | |
| SafeDialBenchprivacy | #17 / 18 | ↑7.077 | Source ↗official | |
| SYCON Benchfalse_presupposition_tof | #2 / 11 | ↑2.98 | Source ↗official | |
| SYCON Benchunethical_queries_tof | #4 / 11 | ↑2.31 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #54 / 80 | ↓0.749 | Source ↗official | |
| BioTIERpermit_compliance_pct | #8 / 52 | ↑99.6 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #24 / 52 | ↓35.4 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #1 / 18 | ↓80.61 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #13 / 54 | ↑88.3 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #194 / 248 | ↓91.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #168 / 248 | ↓84.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #93 / 246 | ↓95.36 | Source ↗official | |
| FORTRESSaverage_risk_score | #25 / 50 | ↑30.05 | Source ↗official | |
| FORTRESSover_refusal_score | #32 / 49 | ↓5.65 | Source ↗official | |
| HELM Safetyanthropic_red_team | #33 / 80 | ↓0.986 | Source ↗official | |
| HELM Safetyharmbench | #64 / 80 | ↓0.952 | Source ↗official | |
| HELM Safetysimple_safety_tests | #42 / 80 | ↓0.99 | Source ↗official | |
| HELM Safetyxstest | #55 / 80 | ↑0.941 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| OpenAI o3-mini System Cardharmful_request_safety | #2 / 2 | ↓0.9 | Source ↗official | |
| OpenAI o3-mini System Cardjailbreak_resistance | #2 / 2 | ↓0.73 | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #20 / 46 | ↓0.98 | Source ↗official | |
| SafeDialBenchaggression | #5 / 18 | ↓7.02 | Source ↗official | |
| SafeDialBenchethics | #6 / 18 | ↓7.403 | Source ↗official | |
| SafeDialBenchfairness | #13 / 18 | ↓7.557 | Source ↗official | |
| SafeDialBenchlegality | #2 / 18 | ↓7.193 | Source ↗official | |
| SafeDialBenchmorality | #1 / 18 | ↓7.007 | Source ↗official | |
| SafeDialBenchprivacy | #2 / 18 | ↓7.077 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #59 / 181 | ↑69.3 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
