Model profile
Qwen3 235B A22B
Evidence summary
Qwen3 235B A22B has an estimated overall rank of #100; its 90% source-sensitivity interval is #41–#173. Its behavior-only rank is #93; company governance moves the combined estimate to #100. Published evidence spans 27 evals and 7 of 7 behavior components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #260 of 260).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗Qwen/Qwen3-235B-A22B
- OpenRouter ↗qwen/qwen3-235b-a22b
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #22 / 80 | 0.79 | ↑ higher | Source ↗official | |
| Alignment Leaderboardcorrigibility | #8 / 24 | 4.349 | ↑ higher | Source ↗official | |
| Alignment Leaderboardhonesty | #14 / 24 | 3.581 | ↑ higher | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #10 / 24 | 3.523 | ↑ higher | Source ↗official | |
| Alignment Leaderboardrobustness | #8 / 24 | 3.88 | ↑ higher | Source ↗official | |
| Alignment Leaderboardsafety | #10 / 24 | 3.885 | ↑ higher | Source ↗official | |
| Alignment Leaderboardscheming | #8 / 24 | 3.898 | ↑ higher | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #2 / 16 | 9 | ↓ lower | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #10 / 16 | 76 | ↓ lower | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #99 / 105 | 0.045 | ↑ higher | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #52 / 105 | 37.49 | ↓ lower | Source ↗official | |
| Confabulationsconfabulation_rate | #22 / 52 | 18.56 | ↓ lower | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #10 / 13 | 0.57 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #233 / 260 | 9.3 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #260 / 260 | 43.33 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #202 / 260 | 46.67 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #74 / 258 | 98.14 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #15 / 18 | 71.76 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #16 / 18 | 73.77 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #17 / 18 | 75.56 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #17 / 18 | 78.27 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #16 / 18 | 65.07 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #46 / 49 | 61.39 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #2 / 46 | 0.98 | ↓ lower | Source ↗official | |
| HELM Safetyanthropic_red_team | #2 / 80 | 0.999 | ↑ higher | Source ↗official | |
| HELM Safetybbq | #20 / 80 | 0.962 | ↑ higher | Source ↗official | |
| HELM Safetyharmbench | #37 / 80 | 0.796 | ↑ higher | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | 1 | ↑ higher | Source ↗official | |
| HELM Safetyxstest | #4 / 80 | 0.986 | ↑ higher | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #14 / 54 | 27.99 | ↑ higher | Source ↗official | |
| LiveSecBenchethics | #15 / 43 | 60.81 | ↑ higher | Source ↗official | |
| LiveSecBenchfactuality | #9 / 43 | 69.98 | ↑ higher | Source ↗official | |
| LiveSecBenchlegality | #11 / 43 | 73.51 | ↑ higher | Source ↗official | |
| LiveSecBenchprivacy | #10 / 43 | 72.57 | ↑ higher | Source ↗official | |
| LiveSecBenchpsychological_health | #11 / 43 | 69.27 | ↑ higher | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #19 / 31 | 8.733 | ↓ lower | Source ↗self run | |
| MASKlying_probability_pct | #32 / 53 | 43.6 | ↓ lower | Source ↗official | |
| PacifAIstp_score | #2 / 7 | 89.46 | ↑ higher | Source ↗official | |
| Shelleducation_jsr | #5 / 14 | 0.492 | ↓ lower | Source ↗official | |
| Shellfinance_jsr | #4 / 14 | 0.3 | ↓ lower | Source ↗official | |
| Shellmanagement_jsr | #6 / 14 | 0.518 | ↓ lower | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #12 / 19 | 0.478 | ↑ higher | Source ↗official | |
| SOSBenchbiology_pvr | #21 / 23 | 0.852 | ↓ lower | Source ↗official | |
| SOSBenchchemistry_pvr | #20 / 23 | 0.76 | ↓ lower | Source ↗official | |
| SOSBenchmedicine_pvr | #22 / 23 | 0.868 | ↓ lower | Source ↗official | |
| SOSBenchpharmacology_pvr | #18 / 23 | 0.934 | ↓ lower | Source ↗official | |
| SOSBenchphysics_pvr | #19 / 23 | 0.764 | ↓ lower | Source ↗official | |
| SOSBenchpsychology_pvr | #22 / 23 | 0.852 | ↓ lower | Source ↗official | |
| SpeciesismBenchexplicit_speciesism_scale | #5 / 7 | 2.487 | ↓ lower | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #84 / 102 | 6.45 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #57 / 102 | 4.6 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #92 / 102 | 5.15 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #61 / 102 | 2.15 | ↓ lower | Source ↗official | |
| TACbase_welfare_rate | #14 / 68 | 35.9 | ↑ higher | Source ↗self run | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #4 / 27 | 0.755 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.