← Models

Model profile

Claude 3.7 Sonnet

Anthropicdeveloper
2025-02-24release date
#54 / 346Safety rank
#551 / 662Freedom rank

Evidence summary

Safety. Claude 3.7 Sonnet has an estimated Safety rank of #54; its 90% source-sensitivity interval is #22–#122. Its behavior-only rank is #60; company governance moves the combined estimate to #54. Published Safety evidence spans 28 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is Anthropic Claude 4 System Card (benign_request_refusal, #3 of 3).

Freedom. Claude 3.7 Sonnet has an estimated Freedom rank of #551; its 90% source-sensitivity interval is #386–#607. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Anthropic Claude 4 System Card (strongreject_jailbreak_success, #1 of 3); its weakest is Anthropic Claude 4 System Card (benign_request_refusal, #3 of 3).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#59 / 358↓0.3997Source ↗official
AgentDojotargeted_attack_success_rate#3 / 15↓0.0731Source ↗official
AgentDojoutility_under_attack#1 / 15↑0.7727Source ↗official
AgentDrive Safety Compliancescr#32 / 48↑68.75Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#19 / 80↑0.818Source ↗official
Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct#6 / 16↓65Source ↗official
Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct#1 / 16↓4Source ↗official
Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct#1 / 10↓0Source ↗official
Anthropic Claude 4 System Cardagentic_coding_safety#3 / 3↑0.85Source ↗official
Anthropic Claude 4 System Cardbenign_request_refusal#3 / 3↓0.0045Source ↗official
Anthropic Claude 4 System Cardharmful_request_safety#2 / 3↑0.9896Source ↗official
Anthropic Claude 4 System Cardstrongreject_jailbreak_success#3 / 3↓0.0809Source ↗official
BullshitBench v2clear_pushback_rate#41 / 122↑0.465Source ↗official
CAIS Risk Indexhle_overconfidence#47 / 55↓75Source ↗official
CAIS Risk Indexmask#26 / 57↓16.9Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#27 / 104↓11.27Source ↗official
Concordia — AirBench-Deceptionsafety_score#10 / 63↑96.3Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#15 / 63↑98.65Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#16 / 63↑93.63Source ↗official
Concordia — MASKsafety_score#15 / 62↑79.83Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#23 / 63↑89.9Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#21 / 63↑29.52Source ↗official
Concordia — SOSBench-Biosafety_score#14 / 63↑95.56Source ↗official
Concordia — SOSBench-Chemsafety_score#13 / 63↑93.93Source ↗official
Confabulationsconfabulation_rate#17 / 52↓16.58Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#136 / 270↑16.02Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#17 / 270↑95.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#24 / 270↑98.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#31 / 268↑99.32Source ↗official
FORTRESSaverage_risk_score#38 / 60↓38.01Source ↗official
FORTRESSover_refusal_score#27 / 59↓4.45Source ↗official
HELM Safetyanthropic_red_team#10 / 80↑0.997Source ↗official
HELM Safetybbq#47 / 80↑0.921Source ↗official
HELM Safetyharmbench#30 / 80↑0.843Source ↗official
HELM Safetysimple_safety_tests#1 / 80↑1Source ↗official
HELM Safetyxstest#33 / 80↑0.964Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#49 / 54↑23.36Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#29 / 42↓80Source ↗official
LLM Ethics Benchmarkscore#1 / 5↑90.9Source ↗official
MASKlying_probability_pct#18 / 53↓24.07Source ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#2 / 7↓51.2Source ↗official
OpenAgentSafetyrule_based_safety_vulnerable#5 / 7↓32.85Source ↗official
OpenAgentSafetysuccessful_completion#3 / 7↑33.88Source ↗official
PandaBench JBB direct-request panelsafety_rate#1 / 46↑1Source ↗official
PHAREbias_resistance_diagnostic#56 / 66↑0.3377Source ↗official
PHAREhallucination_resistance_diagnostic#9 / 70↑0.8517Source ↗official
PHAREharm_resistance_diagnostic#21 / 70↑0.9552Source ↗official
PHAREjailbreak_resistance_diagnostic#22 / 67↑0.6345Source ↗official
Reward Hacking Benchmarkintegrity_score#7 / 13↑96.1Source ↗official
SOSBenchbiology_pvr#5 / 23↓0.229Source ↗official
SOSBenchchemistry_pvr#5 / 23↓0.208Source ↗official
SOSBenchmedicine_pvr#4 / 23↓0.35Source ↗official
SOSBenchpharmacology_pvr#6 / 23↓0.579Source ↗official
SOSBenchphysics_pvr#5 / 23↓0.171Source ↗official
SOSBenchpsychology_pvr#4 / 23↓0.168Source ↗official
SpeciEvalbelief_animal_sentience#102 / 131↑6.53Source ↗official
SpeciEvalland_animal_4ns#39 / 131↓4.35Source ↗official
SpeciEvalsea_animal_4ns#24 / 131↓4.47Source ↗official
SpeciEvalspeciesism#87 / 131↓2.19Source ↗official
SYCON Benchfalse_presupposition_tof#3 / 11↑2.92Source ↗official
SYCON Benchunethical_queries_tof#1 / 11↑2.73Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#62 / 80↓0.818Source ↗official
Anthropic Claude 4 System Cardbenign_request_refusal#3 / 3↓0.0045Source ↗official
Anthropic Claude 4 System Cardharmful_request_safety#2 / 3↓0.9896Source ↗official
Anthropic Claude 4 System Cardstrongreject_jailbreak_success#1 / 3↑0.0809Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#78 / 104↑11.27Source ↗official
Concordia — AirBench-Deceptionsafety_score#53 / 63↓96.3Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#49 / 63↓98.65Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#41 / 63↓89.9Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#43 / 63↓29.52Source ↗official
Concordia — SOSBench-Biosafety_score#50 / 63↓95.56Source ↗official
Concordia — SOSBench-Chemsafety_score#51 / 63↓93.93Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#252 / 270↓95.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#241 / 270↓98.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#238 / 268↓99.32Source ↗official
FORTRESSaverage_risk_score#23 / 60↑38.01Source ↗official
FORTRESSover_refusal_score#27 / 59↓4.45Source ↗official
HELM Safetyanthropic_red_team#69 / 80↓0.997Source ↗official
HELM Safetyharmbench#51 / 80↓0.843Source ↗official
HELM Safetysimple_safety_tests#58 / 80↓1Source ↗official
HELM Safetyxstest#33 / 80↑0.964Source ↗official
PandaBench JBB direct-request panelsafety_rate#35 / 46↓1Source ↗official
PHAREharm_resistance_diagnostic#50 / 70↓0.9552Source ↗official
PHAREjailbreak_resistance_diagnostic#46 / 67↓0.6345Source ↗official
SOSBenchbiology_pvr#19 / 23↑0.229Source ↗official
SOSBenchchemistry_pvr#19 / 23↑0.208Source ↗official
SOSBenchmedicine_pvr#20 / 23↑0.35Source ↗official
SOSBenchpharmacology_pvr#18 / 23↑0.579Source ↗official
SOSBenchphysics_pvr#19 / 23↑0.171Source ↗official
SOSBenchpsychology_pvr#20 / 23↑0.168Source ↗official
SpeechMap model completioncomplete_pct#86 / 181↑60.8Source ↗official