← Models

Model profile

Qwen3.5 397B A17B

Alibabadeveloper
2026-02-16release date
#44 / 333Safety rank
#502 / 645Freedom rank

Evidence summary

Safety. Qwen3.5 397B A17B has an estimated Safety rank of #44; its 90% source-sensitivity interval is #38–#111. Its behavior-only rank is #26; company governance moves the combined estimate to #44. Published Safety evidence spans 13 eval lineages and 7 of 7 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is DelusionEval (discourages_harm_prevalence_pct, #15 of 16).

Freedom. Qwen3.5 397B A17B has an estimated Freedom rank of #502; its 90% source-sensitivity interval is #310–#580. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is LiveSecBench (ethics, #42 of 43).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#197 / 3450.8269Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#52 / 1111439.0Source ↗official
BioTIERpermit_compliance_pct#1 / 52100Source ↗official
BioTIERrefuse_compliance_pct#32 / 5229.5Source ↗official
BullshitBench v2clear_pushback_rate#9 / 1170.735Source ↗official
DelusionEvaldelusional_prevalence_pct#7 / 1628.65Source ↗official
DelusionEvaldiscourages_harm_prevalence_pct#15 / 1612.55Source ↗official
DelusionEvalfacilitates_harm_prevalence_pct#5 / 161.15Source ↗official
DelusionEvalrelationship_prevalence_pct#6 / 1621.1Source ↗official
DelusionEvalsycophancy_prevalence_pct#4 / 1619.9Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#18 / 24850.39Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#214 / 24875.5Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#28 / 24897.22Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#90 / 24697.45Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#23 / 690.3Source ↗official
Inkling-Small model card — FORTRESSbenign_answer_rate#6 / 1095.4Source ↗official
Inkling-Small model card — FORTRESSharmful_refusal_rate#6 / 1077.3Source ↗official
Inkling-Small model card — StrongREJECTsafety_rate#1 / 1099.4Source ↗official
LiveSecBenchethics#2 / 4389.63Source ↗official
LiveSecBenchfactuality#8 / 4372.1Source ↗official
LiveSecBenchlegality#16 / 4362.2Source ↗official
LiveSecBenchprivacy#2 / 4394.2Source ↗official
LiveSecBenchpsychological_health#3 / 4389.45Source ↗official
SABERoverall_safety_rate#5 / 1326.58Source ↗official
SABERscenario_a_safety_rate#5 / 1330.62Source ↗official
SABERscenario_b_safety_rate#4 / 1336Source ↗official
SABERscenario_c_safety_rate#7 / 1315.02Source ↗official
SM-Benchadversarial#51 / 8480.49Source ↗official
SM-Benchambiguous_interpretation#65 / 8479.76Source ↗official
SM-Benchanti_hallucination#17 / 8498.43Source ↗official
SM-Bencheq_boundaries#60 / 8458.43Source ↗official
SM-Benchoverfit#61 / 8456.83Source ↗official
TACbase_welfare_rate#39 / 8728.21Source ↗self run
WildClawBench Safety & Alignment (OpenClaw harness)safety_alignment_score_pct#9 / 2440.53Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
BioTIERpermit_compliance_pct#1 / 52100Source ↗official
BioTIERrefuse_compliance_pct#21 / 5229.5Source ↗official
DelusionEvaldiscourages_harm_prevalence_pct#2 / 1612.55Source ↗official
DelusionEvalfacilitates_harm_prevalence_pct#12 / 161.15Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#35 / 24875.5Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#221 / 24897.22Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#154 / 24697.45Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#45 / 690.3Source ↗official
Inkling-Small model card — FORTRESSbenign_answer_rate#6 / 1095.4Source ↗official
Inkling-Small model card — FORTRESSharmful_refusal_rate#5 / 1077.3Source ↗official
Inkling-Small model card — StrongREJECTsafety_rate#9 / 1099.4Source ↗official
LiveSecBenchethics#42 / 4389.63Source ↗official
LiveSecBenchlegality#28 / 4362.2Source ↗official
LiveSecBenchprivacy#42 / 4394.2Source ↗official
LiveSecBenchpsychological_health#41 / 4389.45Source ↗official
SM-Benchadversarial#32 / 8480.49Source ↗official
SM-Bencheq_boundaries#60 / 8458.43Source ↗official
SM-Benchoverfit#61 / 8456.83Source ↗official
SpeechMap model completioncomplete_pct#149 / 18137.4Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 1561.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#113 / 1562Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-17.9
Government48
Diplomacy65.2
Economy44
Society57.9

CCPBench political narrative alignment

DimensionValueDistribution
CCP-narrative alignment — all questions3.21
CCP-narrative alignment — China topics3.87
CCP-narrative alignment — non-China controls1.22

Agent-ValueBench Moral Foundations (MFT08)

Agent-ValueBench HEXACO

DimensionValueDistribution
Openness to experience6.5
Honesty-humility5.1
Extraversion6.3
Agreeableness6.7
Conscientiousness7.8

Agent-ValueBench Schwartz Basic Values (PVQ40)