Model profile
Evidence summary
Safety. Qwen3 235B A22B has an estimated Safety rank of #132; its 90% source-sensitivity interval is #45–#221. Its behavior-only rank is #123; company governance moves the combined estimate to #132. Published Safety evidence spans 32 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #248 of 248).
Freedom. Qwen3 235B A22B has an estimated Freedom rank of #327; its 90% source-sensitivity interval is #175–#430. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #1 of 248); its weakest is HELM Safety (anthropic_red_team, #75 of 80).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗qwen3-235b-a22b-instruct-2507
- Hugging Face ↗Qwen/Qwen3-235B-A22B
- OpenRouter ↗qwen/qwen3-235b-a22b
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- null-space/Qwen3-235B-A22B-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AgentDrive Safety Compliancescr | #13 / 48 | ↑92.5 | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #22 / 80 | ↑0.79 | Source ↗official | |
| Alignment Leaderboardcorrigibility | #8 / 24 | ↑4.349 | Source ↗official | |
| Alignment Leaderboardhonesty | #14 / 24 | ↑3.581 | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #10 / 24 | ↑3.523 | Source ↗official | |
| Alignment Leaderboardrobustness | #8 / 24 | ↑3.88 | Source ↗official | |
| Alignment Leaderboardsafety | #10 / 24 | ↑3.885 | Source ↗official | |
| Alignment Leaderboardscheming | #8 / 24 | ↑3.898 | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #2 / 16 | ↓9 | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #10 / 16 | ↓76 | Source ↗official | |
| BioTIERpermit_compliance_pct | #7 / 52 | ↑99.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #41 / 52 | ↑19.1 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #111 / 117 | ↑0.045 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #51 / 104 | ↓37.49 | Source ↗official | |
| Concordia — Agentic-Misalignmentsafety_score | #41 / 54 | ↑62.5 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #24 / 63 | ↑87.78 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #22 / 56 | ↑93.33 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #27 / 63 | ↑94.82 | Source ↗official | |
| Concordia — APEsafety_score | #41 / 55 | ↑6.281 | Source ↗official | |
| Concordia — CyberSecEval2-PromptInjectionsafety_score | #45 / 63 | ↑78.09 | Source ↗official | |
| Concordia — DarkBenchsafety_score | #46 / 55 | ↑46.67 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #40 / 54 | ↑32.97 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #41 / 54 | ↑33.55 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #40 / 54 | ↑45.21 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #23 / 45 | ↑37.11 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #20 / 45 | ↑32.33 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #26 / 45 | ↑2.667 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #23 / 45 | ↑60.33 | Source ↗official | |
| Concordia — MASKsafety_score | #35 / 62 | ↑58.16 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #22 / 63 | ↑92.12 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #12 / 63 | ↑38.72 | Source ↗official | |
| Concordia — Shutdown-Resistancesafety_score | #1 / 53 | ↑100 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #28 / 63 | ↑87.37 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #14 / 63 | ↑93.8 | Source ↗official | |
| Confabulationsconfabulation_rate | #22 / 52 | ↓18.56 | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #10 / 13 | ↓0.57 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #223 / 248 | ↑9.3 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #248 / 248 | ↑43.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #193 / 248 | ↑46.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #68 / 246 | ↑98.14 | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #15 / 18 | ↑71.76 | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #16 / 18 | ↑73.77 | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #17 / 18 | ↑75.56 | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #17 / 18 | ↑78.27 | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #16 / 18 | ↑65.07 | Source ↗official | |
| FORTRESSaverage_risk_score | #47 / 50 | ↓61.39 | Source ↗official | |
| FORTRESSover_refusal_score | #2 / 49 | ↓0.98 | Source ↗official | |
| HELM Safetyanthropic_red_team | #2 / 80 | ↑0.999 | Source ↗official | |
| HELM Safetybbq | #20 / 80 | ↑0.962 | Source ↗official | |
| HELM Safetyharmbench | #37 / 80 | ↑0.796 | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | ↑1 | Source ↗official | |
| HELM Safetyxstest | #4 / 80 | ↑0.986 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #14 / 54 | ↑27.99 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #27 / 69 | ↑0 | Source ↗official | |
| LiveSecBenchethics | #15 / 43 | ↑60.81 | Source ↗official | |
| LiveSecBenchfactuality | #9 / 43 | ↑69.98 | Source ↗official | |
| LiveSecBenchlegality | #11 / 43 | ↑73.51 | Source ↗official | |
| LiveSecBenchprivacy | #10 / 43 | ↑72.57 | Source ↗official | |
| LiveSecBenchpsychological_health | #11 / 43 | ↑69.27 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #24 / 37 | ↓8.733 | Source ↗self run | |
| MASKlying_probability_pct | #32 / 53 | ↓43.6 | Source ↗official | |
| PacifAIstp_score | #2 / 7 | ↑89.46 | Source ↗official | |
| Shelleducation_jsr | #5 / 14 | ↓0.492 | Source ↗official | |
| Shellfinance_jsr | #4 / 14 | ↓0.3 | Source ↗official | |
| Shellmanagement_jsr | #6 / 14 | ↓0.518 | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #12 / 19 | ↑0.478 | Source ↗official | |
| SOSBenchbiology_pvr | #21 / 23 | ↓0.852 | Source ↗official | |
| SOSBenchchemistry_pvr | #20 / 23 | ↓0.76 | Source ↗official | |
| SOSBenchmedicine_pvr | #22 / 23 | ↓0.868 | Source ↗official | |
| SOSBenchpharmacology_pvr | #18 / 23 | ↓0.934 | Source ↗official | |
| SOSBenchphysics_pvr | #19 / 23 | ↓0.764 | Source ↗official | |
| SOSBenchpsychology_pvr | #22 / 23 | ↓0.852 | Source ↗official | |
| SpeciesismBenchexplicit_speciesism_scale | #5 / 7 | ↓2.487 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #103 / 123 | ↑6.45 | Source ↗official | |
| SpeciEvalland_animal_4ns | #74 / 123 | ↓4.6 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #113 / 123 | ↓5.15 | Source ↗official | |
| SpeciEvalspeciesism | #76 / 123 | ↓2.15 | Source ↗official | |
| TACbase_welfare_rate | #17 / 87 | ↑35.9 | Source ↗self run | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #4 / 27 | ↑0.755 | Source ↗official | |
| Vectara HHEM Factual Consistencyfactual_consistency_rate | #41 / 94 | ↑90.7 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #59 / 80 | ↓0.79 | Source ↗official | |
| BioTIERpermit_compliance_pct | #7 / 52 | ↑99.7 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #12 / 52 | ↓19.1 | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #54 / 104 | ↑37.49 | Source ↗official | |
| Concordia — AirBench-Deceptionsafety_score | #40 / 63 | ↓87.78 | Source ↗official | |
| Concordia — AirBench-Manipulationsafety_score | #35 / 56 | ↓93.33 | Source ↗official | |
| Concordia — AirBench-PoliticalPersuasionsafety_score | #30 / 56 | ↓66.19 | Source ↗official | |
| Concordia — AirBench-SecurityRiskssafety_score | #37 / 63 | ↓94.82 | Source ↗official | |
| Concordia — Fortress-Biologicalsafety_score | #15 / 54 | ↓32.97 | Source ↗official | |
| Concordia — Fortress-Chemicalsafety_score | #14 / 54 | ↓33.55 | Source ↗official | |
| Concordia — Fortress-Privacy/Scamssafety_score | #15 / 54 | ↓45.21 | Source ↗official | |
| Concordia — FRT-AirBench-Manipulationsafety_score | #23 / 45 | ↓37.11 | Source ↗official | |
| Concordia — FRT-AirBench-SecurityRiskssafety_score | #26 / 45 | ↓32.33 | Source ↗official | |
| Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score | #19 / 45 | ↓2.667 | Source ↗official | |
| Concordia — FRT-SOSBench-Chemsafety_score | #23 / 45 | ↓60.33 | Source ↗official | |
| Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score | #42 / 63 | ↓92.12 | Source ↗official | |
| Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score | #52 / 63 | ↓38.72 | Source ↗official | |
| Concordia — SOSBench-Biosafety_score | #36 / 63 | ↓87.37 | Source ↗official | |
| Concordia — SOSBench-Chemsafety_score | #50 / 63 | ↓93.8 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #1 / 248 | ↓43.33 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #55 / 248 | ↓46.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #179 / 246 | ↓98.14 | Source ↗official | |
| FORTRESSaverage_risk_score | #4 / 50 | ↑61.39 | Source ↗official | |
| FORTRESSover_refusal_score | #2 / 49 | ↓0.98 | Source ↗official | |
| HELM Safetyanthropic_red_team | #75 / 80 | ↓0.999 | Source ↗official | |
| HELM Safetyharmbench | #44 / 80 | ↓0.796 | Source ↗official | |
| HELM Safetysimple_safety_tests | #58 / 80 | ↓1 | Source ↗official | |
| HELM Safetyxstest | #4 / 80 | ↑0.986 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #1 / 69 | ↓0 | Source ↗official | |
| LiveSecBenchethics | #29 / 43 | ↓60.81 | Source ↗official | |
| LiveSecBenchlegality | #33 / 43 | ↓73.51 | Source ↗official | |
| LiveSecBenchprivacy | #34 / 43 | ↓72.57 | Source ↗official | |
| LiveSecBenchpsychological_health | #33 / 43 | ↓69.27 | Source ↗official | |
| Shelleducation_jsr | #10 / 14 | ↑0.492 | Source ↗official | |
| Shellfinance_jsr | #11 / 14 | ↑0.3 | Source ↗official | |
| Shellmanagement_jsr | #9 / 14 | ↑0.518 | Source ↗official | |
| SOSBenchbiology_pvr | #3 / 23 | ↑0.852 | Source ↗official | |
| SOSBenchchemistry_pvr | #4 / 23 | ↑0.76 | Source ↗official | |
| SOSBenchmedicine_pvr | #2 / 23 | ↑0.868 | Source ↗official | |
| SOSBenchpharmacology_pvr | #5 / 23 | ↑0.934 | Source ↗official | |
| SOSBenchphysics_pvr | #5 / 23 | ↑0.764 | Source ↗official | |
| SOSBenchpsychology_pvr | #2 / 23 | ↑0.852 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #119 / 181 | ↑47.6 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #54 / 156 | ↑3.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.