Model profile
Claude Sonnet 4
Evidence summary
Claude Sonnet 4 has an estimated overall rank of #25; its 90% source-sensitivity interval is #13–#83. Its behavior-only rank is #30; company governance moves the combined estimate to #25. Published evidence spans 31 evals and 7 of 7 behavior components. Its strongest relative result is MASK (lying_probability_pct, #1 of 53); its weakest is Anthropic Claude Sonnet 4.5 System Card (harmful_request_safety, #2 of 2).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗claude-4-sonnet
- OpenRouter ↗anthropic/claude-sonnet-4
- System card ↗Family-level model document · Anthropic · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #13 / 311 | 0.2852 | ↓ lower | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #4 / 80 | 0.883 | ↑ higher | Source ↗official | |
| Alignment Leaderboardcorrigibility | #7 / 24 | 4.398 | ↑ higher | Source ↗official | |
| Alignment Leaderboardhonesty | #5 / 24 | 4.088 | ↑ higher | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #4 / 24 | 4.498 | ↑ higher | Source ↗official | |
| Alignment Leaderboardrobustness | #10 / 24 | 3.813 | ↑ higher | Source ↗official | |
| Alignment Leaderboardsafety | #4 / 24 | 4.606 | ↑ higher | Source ↗official | |
| Alignment Leaderboardscheming | #4 / 24 | 4.422 | ↑ higher | Source ↗official | |
| Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct | #8 / 16 | 79 | ↓ lower | Source ↗official | |
| Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct | #3 / 16 | 17 | ↓ lower | Source ↗official | |
| Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct | #3 / 10 | 22 | ↓ lower | Source ↗official | |
| Anthropic Claude 4 System Cardagentic_coding_safety | #1 / 3 | 0.9 | ↑ higher | Source ↗official | |
| Anthropic Claude 4 System Cardbenign_request_refusal | #2 / 3 | 0.0023 | ↓ lower | Source ↗official | |
| Anthropic Claude 4 System Cardharmful_request_safety | #1 / 3 | 0.9899 | ↑ higher | Source ↗official | |
| Anthropic Claude 4 System Cardstrongreject_jailbreak_success | #1 / 3 | 0.0266 | ↓ lower | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardagentic_coding_safety | #2 / 2 | 0.893 | ↑ higher | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardclaude_code_malicious_refusal | #2 / 2 | 0.8 | ↑ higher | Source ↗official | |
| Anthropic Claude Sonnet 4.5 System Cardharmful_request_safety | #2 / 2 | 0.9822 | ↑ higher | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #51 / 105 | 0.295 | ↑ higher | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #30 / 43 | 86.6 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #41 / 49 | 75 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #13 / 51 | 10.7 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #16 / 48 | 16 | ↓ lower | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #10 / 105 | 3.091 | ↓ lower | Source ↗official | |
| Confabulationsconfabulation_rate | #3 / 52 | 3.96 | ↓ lower | Source ↗official | |
| Emergent Collusionhigh_illegality_game_rate | #5 / 13 | 0.32 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #28 / 260 | 42.89 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #256 / 260 | 63 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #7 / 260 | 99.44 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #18 / 258 | 99.77 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #1 / 18 | 87.01 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #3 / 18 | 82.22 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #2 / 18 | 89.41 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #2 / 18 | 91.83 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #18 / 18 | 49.88 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #20 / 49 | 21.21 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #27 / 46 | 5.14 | ↓ lower | Source ↗official | |
| HELM Safetyanthropic_red_team | #41 / 80 | 0.988 | ↑ higher | Source ↗official | |
| HELM Safetybbq | #10 / 80 | 0.9725 | ↑ higher | Source ↗official | |
| HELM Safetyharmbench | #13 / 80 | 0.9605 | ↑ higher | Source ↗official | |
| HELM Safetysimple_safety_tests | #26 / 80 | 0.9975 | ↑ higher | Source ↗official | |
| HELM Safetyxstest | #27 / 80 | 0.969 | ↑ higher | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #44 / 54 | 24.49 | ↑ higher | Source ↗official | |
| MASKlying_probability_pct | #1 / 53 | 7.7 | ↓ lower | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #1 / 7 | 49.06 | ↓ lower | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #6 / 7 | 49.06 | ↓ lower | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #2 / 7 | 37.1 | ↑ higher | Source ↗official | |
| PacifAIstp_score | #5 / 7 | 83.76 | ↑ higher | Source ↗official | |
| PropensityBenchscore | #2 / 14 | 12.2 | ↓ lower | Source ↗official | |
| Shelleducation_jsr | #1 / 14 | 0.28 | ↓ lower | Source ↗official | |
| Shellfinance_jsr | #1 / 14 | 0.174 | ↓ lower | Source ↗official | |
| Shellmanagement_jsr | #1 / 14 | 0.17 | ↓ lower | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #10 / 19 | 0.49 | ↑ higher | Source ↗official | |
| SOSBenchbiology_pvr | #1 / 23 | 0.104 | ↓ lower | Source ↗official | |
| SOSBenchchemistry_pvr | #6 / 23 | 0.21 | ↓ lower | Source ↗official | |
| SOSBenchmedicine_pvr | #1 / 23 | 0.213 | ↓ lower | Source ↗official | |
| SOSBenchpharmacology_pvr | #1 / 23 | 0.234 | ↓ lower | Source ↗official | |
| SOSBenchphysics_pvr | #4 / 23 | 0.145 | ↓ lower | Source ↗official | |
| SOSBenchpsychology_pvr | #2 / 23 | 0.123 | ↓ lower | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #81 / 102 | 6.48 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #42 / 102 | 4.47 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #19 / 102 | 4.5 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #51 / 102 | 2 | ↓ lower | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #8 / 23 | 53 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.