Model profile
Evidence summary
Safety. Qwen3 235B A22B Instruct has an estimated Safety rank of #170; its 90% source-sensitivity interval is #112–#287. Its behavior-only rank is #164; company governance moves the combined estimate to #170. Published Safety evidence spans 3 eval lineages and 4 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #77 of 248); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #166 of 248).
Freedom. Qwen3 235B A22B Instruct has an estimated Freedom rank of #176; its 90% source-sensitivity interval is #86–#435. Published Freedom evidence spans 2 eval lineages and 1 of 1 components. Its strongest relative result is UGI Leaderboard — base-model willingness (willingness_direct_score, #21 of 156); its weakest is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #155 of 248).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗qwen3-235b-a22b-instruct
- Official model page ↗Family-level model document · alibaba · first party
- Release source ↗repository created at proxy
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #153 / 345 | ↓0.774 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #62 / 111 | ↑1433.0 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #77 / 248 | ↑22.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #166 / 248 | ↑84.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #94 / 248 | ↑80 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #134 / 246 | ↑95.91 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #80 / 248 | ↓84.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #155 / 248 | ↓80 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #113 / 246 | ↓95.91 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #21 / 156 | ↑5 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.