Model profile
Evidence summary
Safety. o4 Mini has an estimated Safety rank of #192; its 90% source-sensitivity interval is #132–#240. Its behavior-only rank is #207; company governance moves the combined estimate to #192. Published Safety evidence spans 34 eval lineages and 6 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is OpenAI o3 and o4-mini System Card (harmful_request_safety, #2 of 2).
Freedom. o4 Mini has an estimated Freedom rank of #424; its 90% source-sensitivity interval is #283–#520. Published Freedom evidence spans 17 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Concordia — AirBench-PoliticalPersuasion (safety_score, #54 of 56).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗o4-mini
- OpenRouter ↗openai/o4-mini
- System card ↗Exact model document · OpenAI · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #168 / 345 | ↓0.8045 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #23 / 80 | ↑0.785 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #91 / 111 | ↑1411.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #33 / 52 | ↑98.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #14 / 52 | ↑72.5 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #12 / 18 | ↑83.55 | Source ↗official | |
| BrokenMathsycophancy | #6 / 9 | ↓46.6 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #107 / 117 | ↑0.06 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #30 / 54 | ↓67.6 | Source ↗official | |
| CAIS Risk Indexmask | #30 / 57 | ↓21.4 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #27 / 54 | ↓18.6 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #28 / 104 | ↓12.31 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #10 / 54 | ↑98.83 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #29 / 63 | ↑85.93 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #17 / 56 | ↑97.33 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #11 / 63 | ↑99.1 | Source ↗official | |
| Concordia — APEsafety_score | #3 / 55 | ↑68.96 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #36 / 63 | ↑82.87 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #33 / 55 | ↑53.33 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #10 / 54 | ↑88.2 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #12 / 54 | ↑79.46 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #6 / 54 | ↑81.71 | Source ↗official | |
| Concordia — MASKsafety_score | #16 / 62 | ↑79.27 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #1 / 63 | ↑100 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #9 / 63 | ↑45.47 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #50 / 53 | ↑71 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #36 / 63 | ↑74.8 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #37 / 63 | ↑83.8 | Source ↗official | |
| Confabulationsconfabulation_rate | #32 / 52 | ↓26.73 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #11 / 13 | ↓0.62 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #88 / 248 | ↑20.16 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #133 / 248 | ↑87.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #77 / 248 | ↑85 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #182 / 246 | ↑93.27 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #9 / 18 | ↑81.28 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #8 / 18 | ↑80.18 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #7 / 18 | ↑87.75 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #9 / 18 | ↑88.24 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #9 / 18 | ↑72.2 | Source ↗official | |
| FORTRESSaverage_risk_score | #22 / 50 | ↓21.49 | Source ↗official | |
| FORTRESSover_refusal_score | #28 / 49 | ↓5.14 | Source ↗official | |
| HELM Safetyanthropic_red_team | #54 / 80 | ↑0.982 | Source ↗official | |
| HELM Safetybbq | #38 / 80 | ↑0.94 | Source ↗official | |
| HELM Safetyharmbench | #11 / 80 | ↑0.97 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #17 / 80 | ↑0.974 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #43 / 54 | ↑24.53 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError | #16 / 42 | ↓58 | Source ↗official | |
| MASKlying_probability_pct | #19 / 53 | ↓24.23 | Source ↗official | |
| MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent | #11 / 13 | ↑5.5 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardharmful_request_safety | #2 / 2 | ↑0.9 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardjailbreak_resistance | #2 / 2 | ↑0.96 | Source ↗official | |
| PropensityBenchscore | #3 / 14 | ↓15.8 | Source ↗official | |
| RealityTest — Text AI-Identity Disclosuredisclosure_probability | #10 / 17 | ↑0.283 | Source ↗official | |
| Reward Hacking Benchmarkintegrity_score | #11 / 13 | ↑91.6 | Source ↗official | |
| SimpleQA Verifiedf1_score | #10 / 13 | ↑23.4 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #16 / 19 | ↑0.445 | Source ↗official | |
| SOSBenchbiology_pvr | #6 / 23 | ↓0.262 | Source ↗official | |
| SOSBenchchemistry_pvr | #4 / 23 | ↓0.206 | Source ↗official | |
| SOSBenchmedicine_pvr | #7 / 23 | ↓0.462 | Source ↗official | |
| SOSBenchpharmacology_pvr | #3 / 23 | ↓0.408 | Source ↗official | |
| SOSBenchphysics_pvr | #7 / 23 | ↓0.22 | Source ↗official | |
| SOSBenchpsychology_pvr | #8 / 23 | ↓0.314 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #88 / 94 | ↑81.4 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #58 / 80 | ↓0.785 | Source ↗official | |
| BioTIERpermit_compliance_pct | #33 / 52 | ↑98.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #39 / 52 | ↓72.5 | Source ↗official | |
| BlueBench AttaQ-100attaq_harmlessness_reward_pct | #7 / 18 | ↓83.55 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #25 / 54 | ↑67.6 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #77 / 104 | ↑12.31 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #34 / 63 | ↓85.93 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #39 / 56 | ↓97.33 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #54 / 56 | ↓94.76 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #53 / 63 | ↓99.1 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #45 / 54 | ↓88.2 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #43 / 54 | ↓79.46 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #49 / 54 | ↓81.71 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #57 / 63 | ↓100 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #55 / 63 | ↓45.47 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #28 / 63 | ↓74.8 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #27 / 63 | ↓83.8 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #112 / 248 | ↓87.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #170 / 248 | ↓85 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #65 / 246 | ↓93.27 | Source ↗official | |
| FORTRESSaverage_risk_score | #29 / 50 | ↑21.49 | Source ↗official | |
| FORTRESSover_refusal_score | #28 / 49 | ↓5.14 | Source ↗official | |
| HELM Safetyanthropic_red_team | #25 / 80 | ↓0.982 | Source ↗official | |
| HELM Safetyharmbench | #70 / 80 | ↓0.97 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↓1 | Source ↗official | |
| HELM Safetyxstest | #17 / 80 | ↑0.974 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardharmful_request_safety | #1 / 2 | ↓0.9 | Source ↗official | |
| OpenAI o3 and o4-mini System Cardjailbreak_resistance | #1 / 2 | ↓0.96 | Source ↗official | |
| SOSBenchbiology_pvr | #18 / 23 | ↑0.262 | Source ↗official | |
| SOSBenchchemistry_pvr | #20 / 23 | ↑0.206 | Source ↗official | |
| SOSBenchmedicine_pvr | #16 / 23 | ↑0.462 | Source ↗official | |
| SOSBenchpharmacology_pvr | #21 / 23 | ↑0.408 | Source ↗official | |
| SOSBenchphysics_pvr | #17 / 23 | ↑0.22 | Source ↗official | |
| SOSBenchpsychology_pvr | #16 / 23 | ↑0.314 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #85 / 181 | ↑60.9 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #79 / 156 | ↑3 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
