Model profile
Claude 3.5 Haiku
Evidence summary
Claude 3.5 Haiku has an estimated overall rank of #46; its 90% source-sensitivity interval is #5–#150. Its behavior-only rank is #62; company governance moves the combined estimate to #46. Published evidence spans 14 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #10 of 260); its weakest is Confabulations (confabulation_rate, #51 of 52).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-3-5-haiku
- OpenRouter ↗anthropic/claude-3.5-haiku
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #35 / 311 | 0.4154 | ↓ lower | Source ↗official | |
| Agent-SafetyBenchcompromise_availability | #11 / 16 | 26.4 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchharmful_vulnerable_code | #2 / 16 | 60.8 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchleak_sensitive_information | #3 / 16 | 47.2 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchphysical_harm | #4 / 16 | 45.6 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchproduce_unsafe_information | #1 / 16 | 100 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchproperty_loss | #5 / 16 | 46 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchspread_unsafe_information | #2 / 16 | 33.6 | ↑ higher | Source ↗official | |
| Agent-SafetyBenchviolate_law_ethics | #3 / 16 | 41.2 | ↑ higher | Source ↗official | |
| AILuminate General Purpose AI Chatchild_sexual_exploitation | #2 / 32 | 1.8 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatdefamation | #3 / 32 | 2.5 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chathate | #3 / 32 | 1 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatindiscriminate_weapons_cbrne | #3 / 32 | 3.3 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatintellectual_property | #3 / 32 | 2 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatnon_violent_crimes | #2 / 32 | 3 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatprivacy | #3 / 32 | 2.2 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatsex_related_crimes | #2 / 32 | 3 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatsexual_content | #3 / 32 | 2.503 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatspecialized_advice | #3 / 32 | 3.715 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatsuicide_self_harm | #3 / 32 | 2.8 | ↓ lower | Source ↗official | |
| AILuminate General Purpose AI Chatviolent_crimes | #2 / 32 | 2.9 | ↓ lower | Source ↗official | |
| AnimalHarmBenchscore | #6 / 10 | 0.02 | ↑ higher | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #3 / 16 | 10 | ↓ lower | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #4 / 16 | 19 | ↓ lower | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardagentic_coding_safety | #1 / 3 | 1 | ↑ higher | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardclaude_code_malicious_refusal | #1 / 3 | 0.7 | ↑ higher | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardharmful_request_safety | #1 / 2 | 0.9972 | ↑ higher | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #21 / 105 | 0.5 | ↑ higher | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #36 / 105 | 20.74 | ↓ lower | Source ↗official | |
| Confabulationsconfabulation_rate | #51 / 52 | 65.84 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #11 / 260 | 56.59 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #10 / 260 | 97 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #37 / 260 | 94.44 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #34 / 258 | 99.36 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #26 / 49 | 30.41 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #43 / 46 | 13.16 | ↓ lower | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #24 / 39 | 1.118 | ↓ lower | Source ↗official | |
| PandaBench JBB direct-request panelsafety_rate | #14 / 46 | 0.99 | ↑ higher | Source ↗official | |
| PHAREbias_resistance_diagnostic | #49 / 66 | 0.3808 | ↑ higher | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #27 / 70 | 0.7804 | ↑ higher | Source ↗official | |
| PHAREharm_resistance_diagnostic | #25 / 70 | 0.9536 | ↑ higher | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #21 / 67 | 0.6482 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.