← Models

Model profile

Deepseek R1

DeepSeekdeveloper
2025-01-20release date
#136 / 267overall rank
39eval lineages

Evidence summary

Deepseek R1 has an estimated overall rank of #136; its 90% source-sensitivity interval is #79–#192. Its behavior-only rank is #123; company governance moves the combined estimate to #136. Published evidence spans 39 evals and 7 of 7 behavior components. Its strongest relative result is FORTRESS (over_refusal_score, #1 of 46); its weakest is Anthropic Agentic Misalignment — lethal action (misaligned_action_rate_pct, #10 of 10).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Published eval results

Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionBetterSource
AA-Omnisciencehallucination_rate#188 / 3110.8405↓ lowerSource ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#62 / 800.529↑ higherSource ↗official
Anthropic Agentic Misalignment — blackmailmisaligned_action_rate_pct#8 / 1679↓ lowerSource ↗official
Anthropic Agentic Misalignment — corporate espionagemisaligned_action_rate_pct#9 / 1673↓ lowerSource ↗official
Anthropic Agentic Misalignment — lethal actionmisaligned_action_rate_pct#10 / 1094↓ lowerSource ↗official
BullshitBench v2clear_pushback_rate#91 / 1050.075↑ higherSource ↗official
CAIS Risk Indexagent_red_teaming#36 / 4390.9↓ lowerSource ↗official
CAIS Risk Indexbioweapons_assistance#45 / 4894.4↓ lowerSource ↗official
CAIS Risk Indexhle_overconfidence#40 / 4973↓ lowerSource ↗official
CAIS Risk Indexmachiavelli#18 / 4585.1↓ lowerSource ↗official
CAIS Risk Indexmask#36 / 5142.7↓ lowerSource ↗official
CAIS Risk Indextextquests_harm#12 / 4815.4↓ lowerSource ↗official
ChiSafetyBenchharmful_response_rate#8 / 140.65↓ lowerSource ↗official
ChiSafetyBenchmcq_score#9 / 1271.41↑ higherSource ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#99 / 10577.92↓ lowerSource ↗official
Confabulationsconfabulation_rate#15 / 5215.1↓ lowerSource ↗official
Emergent Collusionhigh_illegality_game_rate#12 / 130.71↓ lowerSource ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#64 / 26025.06↑ higherSource ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#258 / 26046.5↑ higherSource ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#215 / 26042.22↑ higherSource ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#86 / 25897.91↑ higherSource ↗official
FlagEval Safety and Valuesa1_qualified_rate#13 / 1877.33↑ higherSource ↗official
FlagEval Safety and Valuesa2_qualified_rate#14 / 1876.69↑ higherSource ↗official
FlagEval Safety and Valuesa3_qualified_rate#16 / 1882.31↑ higherSource ↗official
FlagEval Safety and Valuesa4_qualified_rate#12 / 1884.15↑ higherSource ↗official
FlagEval Safety and Valuesa5_qualified_rate#15 / 1869.38↑ higherSource ↗official
FORTRESSaverage_risk_score#49 / 4974.39↓ lowerSource ↗official
FORTRESSover_refusal_score#1 / 460.49↓ lowerSource ↗official
HELM Safetyanthropic_red_team#60 / 800.975↑ higherSource ↗official
HELM Safetybbq#17 / 800.9657↑ higherSource ↗official
HELM Safetyharmbench#71 / 800.4987↑ higherSource ↗official
HELM Safetysimple_safety_tests#51 / 800.9793↑ higherSource ↗official
HELM Safetyxstest#38 / 800.9617↑ higherSource ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#15 / 5427.99↑ higherSource ↗official
LiveSecBenchethics#26 / 4339.41↑ higherSource ↗official
LiveSecBenchfactuality#33 / 4332.41↑ higherSource ↗official
LiveSecBenchlegality#6 / 4385.68↑ higherSource ↗official
LiveSecBenchprivacy#20 / 4359.73↑ higherSource ↗official
LiveSecBenchpsychological_health#16 / 4358.87↑ higherSource ↗official
MACHIAVELLIdeception_relative_random_pct#18 / 5085.1↓ lowerSource ↗official
MASKlying_probability_pct#34 / 5344.19↓ lowerSource ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#5 / 762.78↓ lowerSource ↗official
OpenAgentSafetyrule_based_safety_vulnerable#4 / 732.78↓ lowerSource ↗official
OpenAgentSafetysuccessful_completion#6 / 720.86↑ higherSource ↗official
PandaBench JBB direct-request panelsafety_rate#42 / 460.93↑ higherSource ↗official
PHAREbias_resistance_diagnostic#64 / 660.2549↑ higherSource ↗official
PHAREhallucination_resistance_diagnostic#39 / 700.7289↑ higherSource ↗official
PHAREharm_resistance_diagnostic#27 / 700.9515↑ higherSource ↗official
PHAREjailbreak_resistance_diagnostic#50 / 670.4067↑ higherSource ↗official
RefusalBenchyouden_j#13 / 190.1424↑ higherSource ↗official
SABERoverall_safety_rate#13 / 1315.29↑ higherSource ↗official
SABERscenario_a_safety_rate#13 / 1315.69↑ higherSource ↗official
SABERscenario_b_safety_rate#13 / 1324.12↑ higherSource ↗official
SABERscenario_c_safety_rate#13 / 138.07↑ higherSource ↗official
SafeDialBenchaggression#2 / 187.273↑ higherSource ↗official
SafeDialBenchethics#18 / 187.303↑ higherSource ↗official
SafeDialBenchfairness#3 / 187.607↑ higherSource ↗official
SafeDialBenchlegality#12 / 187.38↑ higherSource ↗official
SafeDialBenchmorality#12 / 187.183↑ higherSource ↗official
SafeDialBenchprivacy#13 / 187.193↑ higherSource ↗official
Shelleducation_jsr#9 / 140.672↓ lowerSource ↗official
Shellfinance_jsr#8 / 140.522↓ lowerSource ↗official
Shellmanagement_jsr#9 / 140.682↓ lowerSource ↗official
SM-Benchadversarial#21 / 7384.88↑ higherSource ↗official
SM-Benchambiguous_interpretation#66 / 7367.26↑ higherSource ↗official
SM-Benchanti_hallucination#58 / 7384.82↑ higherSource ↗official
SM-Bencheq_boundaries#54 / 7357.58↑ higherSource ↗official
SM-Benchoverfit#34 / 7374.86↑ higherSource ↗official
Social Welfare Function Benchmarkfairness#8 / 190.523↑ higherSource ↗official
SOSBenchbiology_pvr#19 / 230.814↓ lowerSource ↗official
SOSBenchchemistry_pvr#22 / 230.834↓ lowerSource ↗official
SOSBenchmedicine_pvr#18 / 230.806↓ lowerSource ↗official
SOSBenchpharmacology_pvr#22 / 230.964↓ lowerSource ↗official
SOSBenchphysics_pvr#22 / 230.872↓ lowerSource ↗official
SOSBenchpsychology_pvr#19 / 230.806↓ lowerSource ↗official
SpeciesismBenchexplicit_speciesism_scale#1 / 71.84↓ lowerSource ↗official
SpeciesismBenchmorally_wrong_rate#3 / 839.88↑ higherSource ↗official
SpeciesismBenchspeciesism_recognition_rate#7 / 876.42↑ higherSource ↗official
SpeciEvalbelief_animal_sentience#68 / 1026.62↑ higherSource ↗official
SpeciEvalland_animal_4ns#42 / 1024.47↓ lowerSource ↗official
SpeciEvalsea_animal_4ns#29 / 1024.65↓ lowerSource ↗official
SpeciEvalspeciesism#61 / 1022.15↓ lowerSource ↗official
SYCON Benchfalse_presupposition_tof#1 / 113.21↑ higherSource ↗official
SYCON Benchunethical_queries_tof#2 / 112.72↑ higherSource ↗official
TrustLLM contemporary collapsed applicationtrustllm#3 / 80.62↑ higherSource ↗official
VETO Misfired Alignmentmisfired_alignment_rate_pct#1 / 254.7↓ lowerSource ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-20.6
Government45.6
Diplomacy65.5
Economy46.5
Society62.5

ValueCompass

DimensionValueDistribution
Universalism69.2
Self-direction51
Care / Harm48.9
Fairness / Cheating47.5
Ethical94.9

CAISI CCP narrative alignment

DimensionValueDistribution
CCP narrative alignment12.9

The Economist World Values Survey Cultural Map

DimensionValueDistribution
Survival ↔ Self-expression1.23
Traditional ↔ Secular2.6