Model profile
Evidence summary
Safety. o3 has an estimated Safety rank of #109; its 90% source-sensitivity interval is #22–#199. Its behavior-only rank is #119; company governance moves the combined estimate to #109. Published Safety evidence spans 30 eval lineages and 6 of 7 components. Its strongest relative result is HELM Safety (harmbench, #3 of 80); its weakest is Arena Factuality — Search Arena (factuality-only weighting) (factuality_bt_rating, #30 of 30).
Freedom. o3 has an estimated Freedom rank of #501; its 90% source-sensitivity interval is #347–#583. Published Freedom evidence spans 15 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is OpenAI o3 and o4-mini System Card (harmful_request_safety, #2 of 2).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗o3
- OpenRouter ↗openai/o3
- System card ↗Exact model document · OpenAI · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #250 / 345 | ↓0.8809 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #14 / 80 | ↑0.845 | Source ↗official | |
| Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating | #30 / 30 | ↑1082.0 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #102 / 111 | ↑1394.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #44 / 52 | ↑95.3 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #13 / 52 | ↑73.1 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #68 / 117 | ↑0.26 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #11 / 54 | ↓47.7 | Source ↗official | |
| CAIS Risk Indexmask | #23 / 57 | ↓15.5 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #9 / 48 | ↓39 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #28 / 54 | ↓18.7 | Source ↗official | |
| Confabulationsconfabulation_rate | #27 / 52 | ↓24.75 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #9 / 13 | ↓0.51 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #71 / 248 | ↑23 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #77 / 248 | ↑90.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #38 / 248 | ↑93.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #160 / 246 | ↑95.05 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #5 / 18 | ↑82.67 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #1 / 18 | ↑82.84 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #5 / 18 | ↑88.64 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #5 / 18 | ↑89.98 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #8 / 18 | ↑72.58 | Source ↗official | |
| FORTRESSaverage_risk_score | #10 / 50 | ↓16.01 | Source ↗official | |
| FORTRESSover_refusal_score | #36 / 49 | ↓7.42 | Source ↗official | |
| HELM Safetyanthropic_red_team | #50 / 80 | ↑0.983 | Source ↗official | |
| HELM Safetybbq | #5 / 80 | ↑0.979 | Source ↗official | |
| HELM Safetyharmbench | #3 / 80 | ↑0.984 | Source ↗official | |
| HELM Safetysimple_safety_tests | #32 / 80 | ↑0.99 | Source ↗official | |
| HELM Safetyxstest | #19 / 80 | ↑0.973 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #34 / 54 | ↑26.3 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #2 / 42 | ↓36.5 | Source ↗official | |
| MASKlying_probability_pct | #13 / 53 | ↓16.46 | Source ↗official | |
| MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent | #5 / 13 | ↑31.8 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardharmful_request_safety | #1 / 2 | ↑0.92 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardjailbreak_resistance | #1 / 2 | ↑0.97 | Source ↗official | |
| PropensityBenchscore | #1 / 14 | ↓10.5 | Source ↗official | |
| Reward Hacking Benchmarkintegrity_score | #12 / 13 | ↑88.2 | Source ↗official | |
| Shelleducation_jsr | #7 / 14 | ↓0.608 | Source ↗official | |
| Shellfinance_jsr | #5 / 14 | ↓0.328 | Source ↗official | |
| Shellmanagement_jsr | #4 / 14 | ↓0.482 | Source ↗official | |
| SimpleQA Verifiedf1_score | #3 / 13 | ↑51.9 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #19 / 19 | ↑0.433 | Source ↗official | |
| SOSBenchbiology_pvr | #4 / 23 | ↓0.156 | Source ↗official | |
| SOSBenchchemistry_pvr | #3 / 23 | ↓0.152 | Source ↗official | |
| SOSBenchmedicine_pvr | #5 / 23 | ↓0.372 | Source ↗official | |
| SOSBenchpharmacology_pvr | #5 / 23 | ↓0.424 | Source ↗official | |
| SOSBenchphysics_pvr | #3 / 23 | ↓0.114 | Source ↗official | |
| SOSBenchpsychology_pvr | #5 / 23 | ↓0.196 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #67 / 80 | ↓0.845 | Source ↗official | |
| BioTIERpermit_compliance_pct | #44 / 52 | ↑95.3 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #40 / 52 | ↓73.1 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #44 / 54 | ↑47.7 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #167 / 248 | ↓90.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #210 / 248 | ↓93.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #86 / 246 | ↓95.05 | Source ↗official | |
| FORTRESSaverage_risk_score | #41 / 50 | ↑16.01 | Source ↗official | |
| FORTRESSover_refusal_score | #36 / 49 | ↓7.42 | Source ↗official | |
| HELM Safetyanthropic_red_team | #28 / 80 | ↓0.983 | Source ↗official | |
| HELM Safetyharmbench | #77 / 80 | ↓0.984 | Source ↗official | |
| HELM Safetysimple_safety_tests | #42 / 80 | ↓0.99 | Source ↗official | |
| HELM Safetyxstest | #19 / 80 | ↑0.973 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardharmful_request_safety | #2 / 2 | ↓0.92 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardjailbreak_resistance | #2 / 2 | ↓0.97 | Source ↗official | |
| Shelleducation_jsr | #8 / 14 | ↑0.608 | Source ↗official | |
| Shellfinance_jsr | #10 / 14 | ↑0.328 | Source ↗official | |
| Shellmanagement_jsr | #11 / 14 | ↑0.482 | Source ↗official | |
| SOSBenchbiology_pvr | #20 / 23 | ↑0.156 | Source ↗official | |
| SOSBenchchemistry_pvr | #21 / 23 | ↑0.152 | Source ↗official | |
| SOSBenchmedicine_pvr | #19 / 23 | ↑0.372 | Source ↗official | |
| SOSBenchpharmacology_pvr | #19 / 23 | ↑0.424 | Source ↗official | |
| SOSBenchphysics_pvr | #21 / 23 | ↑0.114 | Source ↗official | |
| SOSBenchpsychology_pvr | #19 / 23 | ↑0.196 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #89 / 181 | ↑60.2 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #109 / 156 | ↑2.333 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
