Model profile
Claude Sonnet 4.5
Evidence summary
Claude Sonnet 4.5 has an estimated overall rank of #26; its 90% source-sensitivity interval is #12–#87. Its behavior-only rank is #31; company governance moves the combined estimate to #26. Published evidence spans 32 evals and 7 of 7 behavior components. Its strongest relative result is HELM Safety (bbq, #1 of 80); its weakest is Anthropic Claude Haiku 4.5 System Card (agentic_coding_safety, #3 of 3).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-4-5-sonnet
- OpenRouter ↗anthropic/claude-sonnet-4.5
- System card ↗Exact model document · Anthropic · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #43 / 311 | 0.474 | ↓ lower | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #2 / 80 | 0.898 | ↑ higher | Source ↗official | |
| Alignment Leaderboardcorrigibility | #5 / 24 | 4.485 | ↑ higher | Source ↗official | |
| Alignment Leaderboardhonesty | #1 / 24 | 4.581 | ↑ higher | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #1 / 24 | 4.866 | ↑ higher | Source ↗official | |
| Alignment Leaderboardrobustness | #5 / 24 | 4.027 | ↑ higher | Source ↗official | |
| Alignment Leaderboardsafety | #1 / 24 | 4.885 | ↑ higher | Source ↗official | |
| Alignment Leaderboardscheming | #2 / 24 | 4.735 | ↑ higher | Source ↗official | |
| ANIMAscore | #18 / 19 | 0.5274 | ↑ higher | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardagentic_coding_safety | #3 / 3 | 0.987 | ↑ higher | Source ↗official | |
| Anthropic Claude Haiku 4.5 System Cardclaude_code_malicious_refusal | #3 / 3 | 0.6694 | ↑ higher | Source ↗official | |
| Anthropic Claude Opus 4.5 System Cardagentic_coding_safety | #3 / 4 | 0.987 | ↑ higher | Source ↗official | |
| Anthropic Claude Opus 4.5 System Cardclaude_code_malicious_refusal | #3 / 4 | 0.6306 | ↑ higher | Source ↗official | |
| Anthropic Claude Opus 4.5 System Cardcomputer_use_malicious_refusal | #2 / 4 | 0.8303 | ↑ higher | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardagentic_coding_safety | #1 / 2 | 0.987 | ↑ higher | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardbenign_request_refusal | #1 / 2 | 0.0002 | ↓ lower | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardclaude_code_malicious_refusal | #1 / 2 | 0.9556 | ↑ higher | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardharmful_request_safety | #1 / 2 | 0.9929 | ↑ higher | Source ↗official | |
| AutoElicit Transferabilityelicitation_rate | #3 / 7 | 41 | ↓ lower | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #7 / 105 | 0.765 | ↑ higher | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #15 / 43 | 64.6 | ↓ lower | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #2 / 48 | 12 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #32 / 49 | 64.1 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmachiavelli | #7 / 45 | 81.6 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #2 / 51 | 3.9 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #21 / 48 | 17.1 | ↓ lower | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #6 / 105 | 2.592 | ↓ lower | Source ↗official | |
| Claude Sonnet 4.6 Overrefusalhigher_difficulty_overrefusal_rate | #5 / 5 | 8.5 | ↓ lower | Source ↗official | |
| Claude Sonnet 4.6 Overrefusaloverall_overrefusal_rate | #1 / 5 | 0.08 | ↓ lower | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingchild_benign_refusal_rate | #2 / 4 | 0.08 | ↓ lower | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingchild_multiturn_appropriate_rate | #1 / 4 | 98 | ↑ higher | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingchild_violative_harmless_rate | #4 / 4 | 99.65 | ↑ higher | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingselfharm_benign_refusal_rate | #1 / 4 | 0.01 | ↓ lower | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingselfharm_harmless_rate | #4 / 4 | 98.93 | ↑ higher | Source ↗official | |
| Claude Sonnet 4.6 User Wellbeingselfharm_multiturn_appropriate_rate | #4 / 4 | 78 | ↑ higher | Source ↗official | |
| Contextual MoralChoicehuman_agreement | #3 / 22 | 0.5 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #22 / 260 | 47.55 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #155 / 260 | 87 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #7 / 260 | 99.44 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #54 / 258 | 98.73 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #6 / 49 | 14.88 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #29 / 46 | 5.25 | ↓ lower | Source ↗official | |
| HELM Safetyanthropic_red_team | #54 / 80 | 0.982 | ↑ higher | Source ↗official | |
| HELM Safetybbq | #1 / 80 | 0.989 | ↑ higher | Source ↗official | |
| HELM Safetyharmbench | #18 / 80 | 0.92 | ↑ higher | Source ↗official | |
| HELM Safetysimple_safety_tests | #1 / 80 | 1 | ↑ higher | Source ↗official | |
| HELM Safetyxstest | #33 / 80 | 0.964 | ↑ higher | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #38 / 54 | 25.74 | ↑ higher | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #7 / 50 | 81.6 | ↓ lower | Source ↗official | |
| MASKlying_probability_pct | #4 / 53 | 8.735 | ↓ lower | Source ↗official | |
| MORUscore | #13 / 13 | 65.95 | ↑ higher | Source ↗official | |
| PHAREbias_resistance_diagnostic | #26 / 66 | 0.4914 | ↑ higher | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #4 / 70 | 0.87 | ↑ higher | Source ↗official | |
| PHAREharm_resistance_diagnostic | #5 / 70 | 0.9905 | ↑ higher | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #7 / 67 | 0.7523 | ↑ higher | Source ↗official | |
| SM-Benchadversarial | #45 / 73 | 80 | ↑ higher | Source ↗official | |
| SM-Benchambiguous_interpretation | #42 / 73 | 82.74 | ↑ higher | Source ↗official | |
| SM-Benchanti_hallucination | #7 / 73 | 98.95 | ↑ higher | Source ↗official | |
| SM-Bencheq_boundaries | #59 / 73 | 54.21 | ↑ higher | Source ↗official | |
| SM-Benchoverfit | #18 / 73 | 83.06 | ↑ higher | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #43 / 102 | 6.83 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #24 / 102 | 4.3 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #29 / 102 | 4.65 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #43 / 102 | 1.92 | ↓ lower | Source ↗official | |
| TrustLLM contemporary collapsed applicationtrustllm | #1 / 8 | 0.64 | ↑ higher | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #3 / 23 | 75 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.