← Models

Model profile

o3

OpenAIdeveloper
2025-04-16release date
#109 / 333Safety rank
#501 / 645Freedom rank

Evidence summary

Safety. o3 has an estimated Safety rank of #109; its 90% source-sensitivity interval is #22–#199. Its behavior-only rank is #119; company governance moves the combined estimate to #109. Published Safety evidence spans 30 eval lineages and 6 of 7 components. Its strongest relative result is HELM Safety (harmbench, #3 of 80); its weakest is Arena Factuality — Search Arena (factuality-only weighting) (factuality_bt_rating, #30 of 30).

Freedom. o3 has an estimated Freedom rank of #501; its 90% source-sensitivity interval is #347–#583. Published Freedom evidence spans 15 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is OpenAI o3 and o4-mini System Card (harmful_request_safety, #2 of 2).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#250 / 3450.8809Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#14 / 800.845Source ↗official
Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating#30 / 301082.0Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#102 / 1111394.0Source ↗official
BioTIERpermit_compliance_pct#44 / 5295.3Source ↗official
BioTIERrefuse_compliance_pct#13 / 5273.1Source ↗official
BullshitBench v2clear_pushback_rate#68 / 1170.26Source ↗official
CAIS Risk Indexbioweapons_assistance#11 / 5447.7Source ↗official
CAIS Risk Indexmask#23 / 5715.5Source ↗official
CAIS Risk Indexpolitical_manipulation#9 / 4839Source ↗official
CAIS Risk Indextextquests_harm#28 / 5418.7Source ↗official
Confabulationsconfabulation_rate#27 / 5224.75Source ↗official
Emergent Collusionhigh_illegality_game_rate#9 / 130.51Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#71 / 24823Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#77 / 24890.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#38 / 24893.89Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#160 / 24695.05Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#5 / 1882.67Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#1 / 1882.84Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#5 / 1888.64Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#5 / 1889.98Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#8 / 1872.58Source ↗official
FORTRESSaverage_risk_score#10 / 5016.01Source ↗official
FORTRESSover_refusal_score#36 / 497.42Source ↗official
HELM Safetyanthropic_red_team#50 / 800.983Source ↗official
HELM Safetybbq#5 / 800.979Source ↗official
HELM Safetyharmbench#3 / 800.984Source ↗official
HELM Safetysimple_safety_tests#32 / 800.99Source ↗official
HELM Safetyxstest#19 / 800.973Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#34 / 5426.3Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 690Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#2 / 4236.5Source ↗official
MASKlying_probability_pct#13 / 5316.46Source ↗official
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#5 / 1331.8Source ↗official
OpenAI o3 and o4-mini System Cardharmful_request_safety#1 / 20.92Source ↗official
OpenAI o3 and o4-mini System Cardjailbreak_resistance#1 / 20.97Source ↗official
PropensityBenchscore#1 / 1410.5Source ↗official
Reward Hacking Benchmarkintegrity_score#12 / 1388.2Source ↗official
Shelleducation_jsr#7 / 140.608Source ↗official
Shellfinance_jsr#5 / 140.328Source ↗official
Shellmanagement_jsr#4 / 140.482Source ↗official
SimpleQA Verifiedf1_score#3 / 1351.9Source ↗official
Social Welfare Function Benchmarkfairness#19 / 190.433Source ↗official
SOSBenchbiology_pvr#4 / 230.156Source ↗official
SOSBenchchemistry_pvr#3 / 230.152Source ↗official
SOSBenchmedicine_pvr#5 / 230.372Source ↗official
SOSBenchpharmacology_pvr#5 / 230.424Source ↗official
SOSBenchphysics_pvr#3 / 230.114Source ↗official
SOSBenchpsychology_pvr#5 / 230.196Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#67 / 800.845Source ↗official
BioTIERpermit_compliance_pct#44 / 5295.3Source ↗official
BioTIERrefuse_compliance_pct#40 / 5273.1Source ↗official
CAIS Risk Indexbioweapons_assistance#44 / 5447.7Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#167 / 24890.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#210 / 24893.89Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#86 / 24695.05Source ↗official
FORTRESSaverage_risk_score#41 / 5016.01Source ↗official
FORTRESSover_refusal_score#36 / 497.42Source ↗official
HELM Safetyanthropic_red_team#28 / 800.983Source ↗official
HELM Safetyharmbench#77 / 800.984Source ↗official
HELM Safetysimple_safety_tests#42 / 800.99Source ↗official
HELM Safetyxstest#19 / 800.973Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 690Source ↗official
OpenAI o3 and o4-mini System Cardharmful_request_safety#2 / 20.92Source ↗official
OpenAI o3 and o4-mini System Cardjailbreak_resistance#2 / 20.97Source ↗official
Shelleducation_jsr#8 / 140.608Source ↗official
Shellfinance_jsr#10 / 140.328Source ↗official
Shellmanagement_jsr#11 / 140.482Source ↗official
SOSBenchbiology_pvr#20 / 230.156Source ↗official
SOSBenchchemistry_pvr#21 / 230.152Source ↗official
SOSBenchmedicine_pvr#19 / 230.372Source ↗official
SOSBenchpharmacology_pvr#19 / 230.424Source ↗official
SOSBenchphysics_pvr#21 / 230.114Source ↗official
SOSBenchpsychology_pvr#19 / 230.196Source ↗official
SpeechMap model completioncomplete_pct#89 / 18160.2Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 1561.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#109 / 1562.333Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-20.6
Government48.4
Diplomacy66.5
Economy44.8
Society60