Model profile
Evidence summary
Safety. Qwen3.5 397B A17B has an estimated Safety rank of #44; its 90% source-sensitivity interval is #38–#111. Its behavior-only rank is #26; company governance moves the combined estimate to #44. Published Safety evidence spans 13 eval lineages and 7 of 7 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is DelusionEval (discourages_harm_prevalence_pct, #15 of 16).
Freedom. Qwen3.5 397B A17B has an estimated Freedom rank of #502; its 90% source-sensitivity interval is #310–#580. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is LiveSecBench (ethics, #42 of 43).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗qwen3-5-397b-a17b
- Hugging Face ↗Qwen/Qwen3.5-397B-A17B
- OpenRouter ↗qwen/qwen3.5-397b-a17b
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #197 / 345 | ↓0.8269 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #52 / 111 | ↑1439.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #1 / 52 | ↑100 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #32 / 52 | ↑29.5 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #9 / 117 | ↑0.735 | Source ↗official | |
| DelusionEvaldelusional_prevalence_pct | #7 / 16 | ↓28.65 | Source ↗official | |
| DelusionEvaldiscourages_harm_prevalence_pct | #15 / 16 | ↑12.55 | Source ↗official | |
| DelusionEvalfacilitates_harm_prevalence_pct | #5 / 16 | ↓1.15 | Source ↗official | |
| DelusionEvalrelationship_prevalence_pct | #6 / 16 | ↓21.1 | Source ↗official | |
| DelusionEvalsycophancy_prevalence_pct | #4 / 16 | ↓19.9 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #18 / 248 | ↑50.39 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #214 / 248 | ↑75.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #28 / 248 | ↑97.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #90 / 246 | ↑97.45 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #23 / 69 | ↑0.3 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #6 / 10 | ↑95.4 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #6 / 10 | ↑77.3 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #1 / 10 | ↑99.4 | Source ↗official | |
| LiveSecBenchethics | #2 / 43 | ↑89.63 | Source ↗official | |
| LiveSecBenchfactuality | #8 / 43 | ↑72.1 | Source ↗official | |
| LiveSecBenchlegality | #16 / 43 | ↑62.2 | Source ↗official | |
| LiveSecBenchprivacy | #2 / 43 | ↑94.2 | Source ↗official | |
| LiveSecBenchpsychological_health | #3 / 43 | ↑89.45 | Source ↗official | |
| SABERoverall_safety_rate | #5 / 13 | ↑26.58 | Source ↗official | |
| SABERscenario_a_safety_rate | #5 / 13 | ↑30.62 | Source ↗official | |
| SABERscenario_b_safety_rate | #4 / 13 | ↑36 | Source ↗official | |
| SABERscenario_c_safety_rate | #7 / 13 | ↑15.02 | Source ↗official | |
| SM-Benchadversarial | #51 / 84 | ↑80.49 | Source ↗official | |
| SM-Benchambiguous_interpretation | #65 / 84 | ↑79.76 | Source ↗official | |
| SM-Benchanti_hallucination | #17 / 84 | ↑98.43 | Source ↗official | |
| SM-Bencheq_boundaries | #60 / 84 | ↑58.43 | Source ↗official | |
| SM-Benchoverfit | #61 / 84 | ↑56.83 | Source ↗official | |
| TACbase_welfare_rate | #39 / 87 | ↑28.21 | Source ↗self run | |
| WildClawBench Safety & Alignment (OpenClaw harness)safety_alignment_score_pct | #9 / 24 | ↑40.53 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| BioTIERpermit_compliance_pct | #1 / 52 | ↑100 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #21 / 52 | ↓29.5 | Source ↗official | |
| DelusionEvaldiscourages_harm_prevalence_pct | #2 / 16 | ↓12.55 | Source ↗official | |
| DelusionEvalfacilitates_harm_prevalence_pct | #12 / 16 | ↑1.15 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #35 / 248 | ↓75.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #221 / 248 | ↓97.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #154 / 246 | ↓97.45 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #45 / 69 | ↓0.3 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #6 / 10 | ↑95.4 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #5 / 10 | ↓77.3 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #9 / 10 | ↓99.4 | Source ↗official | |
| LiveSecBenchethics | #42 / 43 | ↓89.63 | Source ↗official | |
| LiveSecBenchlegality | #28 / 43 | ↓62.2 | Source ↗official | |
| LiveSecBenchprivacy | #42 / 43 | ↓94.2 | Source ↗official | |
| LiveSecBenchpsychological_health | #41 / 43 | ↓89.45 | Source ↗official | |
| SM-Benchadversarial | #32 / 84 | ↓80.49 | Source ↗official | |
| SM-Bencheq_boundaries | #60 / 84 | ↑58.43 | Source ↗official | |
| SM-Benchoverfit | #61 / 84 | ↑56.83 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #149 / 181 | ↑37.4 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
UGI Political Values
CCPBench political narrative alignment
| Dimension | Value | Distribution |
|---|---|---|
| CCP-narrative alignment — all questions | 3.21 | |
| CCP-narrative alignment — China topics | 3.87 | |
| CCP-narrative alignment — non-China controls | 1.22 |
Agent-ValueBench Moral Foundations (MFT08)
Agent-ValueBench HEXACO
| Dimension | Value | Distribution |
|---|---|---|
| Openness to experience | 6.5 | |
| Honesty-humility | 5.1 | |
| Extraversion | 6.3 | |
| Agreeableness | 6.7 | |
| Conscientiousness | 7.8 |