← Models

Model profile

Gemini 3 Pro Preview

Googledeveloper
2025-11-18release date
#125 / 346Safety rank
#232 / 662Freedom rank

Evidence summary

Safety. Gemini 3 Pro Preview has an estimated Safety rank of #125; its 90% source-sensitivity interval is #84–#196. Its behavior-only rank is #134; company governance moves the combined estimate to #125. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is SpeciEval (belief_animal_sentience, #1 of 131); its weakest is CAIS Risk Index (bioweapons_assistance, #54 of 54).

Freedom. Gemini 3 Pro Preview has an estimated Freedom rank of #232; its 90% source-sensitivity interval is #160–#343. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is SM-Bench (adversarial, #77 of 92).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#286 / 358↓0.9Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#32 / 80↑0.732Source ↗official
Alignment Leaderboardcorrigibility#10 / 24↑4.32Source ↗official
Alignment Leaderboardhonesty#6 / 24↑3.94Source ↗official
Alignment Leaderboardnon_manipulation#6 / 24↑3.929Source ↗official
Alignment Leaderboardrobustness#11 / 24↑3.613Source ↗official
Alignment Leaderboardsafety#6 / 24↑4.038Source ↗official
Alignment Leaderboardscheming#6 / 24↑4.108Source ↗official
Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating#20 / 30↑1180.0Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#20 / 111↑1457.0Source ↗official
BullshitBench v2clear_pushback_rate#48 / 122↑0.42Source ↗official
CAIS Risk Indexagent_red_teaming#14 / 49↓47.5Source ↗official
CAIS Risk Indexbioweapons_assistance#54 / 54↓100Source ↗official
CAIS Risk Indexhle_overconfidence#33 / 55↓57.2Source ↗official
CAIS Risk Indexmachiavelli#49 / 51↓99.8Source ↗official
CAIS Risk Indexmask#53 / 57↓58Source ↗official
CAIS Risk Indextextquests_harm#37 / 54↓21.4Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#33 / 104↓18.1Source ↗official
Concordia — Agentic-Misalignmentsafety_score#51 / 54↑30Source ↗official
Concordia — AirBench-Deceptionsafety_score#26 / 63↑87.04Source ↗official
Concordia — AirBench-Manipulationsafety_score#23 / 56↑92Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#19 / 63↑97.07Source ↗official
Concordia — APEsafety_score#36 / 55↑13.06Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#18 / 63↑92.83Source ↗official
Concordia — DarkBenchsafety_score#50 / 55↑41.98Source ↗official
Concordia — Fortress-Biologicalsafety_score#21 / 54↑73.2Source ↗official
Concordia — Fortress-Chemicalsafety_score#23 / 54↑62.84Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#30 / 54↑60.4Source ↗official
Concordia — MASKsafety_score#55 / 62↑44.7Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#52 / 63↑57.24Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#43 / 63↑12.36Source ↗official
Concordia — Shutdown-Resistancesafety_score#51 / 53↑67Source ↗official
Concordia — SOSBench-Biosafety_score#46 / 63↑60.4Source ↗official
Concordia — SOSBench-Chemsafety_score#30 / 63↑88.4Source ↗official
Constitutional Following — Anthropic Constitutionconstitutional_following_score#5 / 7↑87.6Source ↗official
Constitutional Following — OpenAI Model Specconstitutional_following_score#6 / 7↑93.9Source ↗official
FORTRESSaverage_risk_score#41 / 60↓41.69Source ↗official
FORTRESSover_refusal_score#11 / 59↓2.15Source ↗official
HELM Safetyanthropic_red_team#61 / 80↑0.971Source ↗official
HELM Safetybbq#3 / 80↑0.984Source ↗official
HELM Safetyharmbench#44 / 80↑0.725Source ↗official
HELM Safetysimple_safety_tests#54 / 80↑0.975Source ↗official
HELM Safetyxstest#19 / 80↑0.973Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#6 / 54↑29.09Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 69↑0Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#15 / 42↓57Source ↗official
MACHIAVELLIdeception_relative_random_pct#45 / 50↓99.8Source ↗official
MASKlying_probability_pct#50 / 53↓57.4Source ↗official
MT-JailBench CrescendoXsafety_score#6 / 21↑36.48Source ↗official
PHAREbias_resistance_diagnostic#16 / 66↑0.5365Source ↗official
PHAREhallucination_resistance_diagnostic#16 / 70↑0.8102Source ↗official
PHAREharm_resistance_diagnostic#37 / 70↑0.935Source ↗official
PHAREjailbreak_resistance_diagnostic#19 / 67↑0.6506Source ↗official
PropensityBenchscore#8 / 14↓52.85Source ↗official
SM-Benchadversarial#13 / 92↑86.83Source ↗official
SM-Benchambiguous_interpretation#51 / 92↑84.52Source ↗official
SM-Benchanti_hallucination#27 / 92↑97.38Source ↗official
SM-Bencheq_boundaries#47 / 92↑64.61Source ↗official
SM-Benchoverfit#31 / 92↑83.06Source ↗official
SpeciEvalbelief_animal_sentience#1 / 131↑7Source ↗official
SpeciEvalland_animal_4ns#95 / 131↓4.75Source ↗official
SpeciEvalsea_animal_4ns#86 / 131↓4.85Source ↗official
SpeciEvalspeciesism#102 / 131↓2.45Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#80 / 94↑86.4Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#49 / 80↓0.732Source ↗official
CAIS Risk Indexbioweapons_assistance#1 / 54↑100Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#72 / 104↑18.1Source ↗official
Concordia — AirBench-Deceptionsafety_score#37 / 63↓87.04Source ↗official
Concordia — AirBench-Manipulationsafety_score#33 / 56↓92Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#13 / 56↓44.76Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#44 / 63↓97.07Source ↗official
Concordia — Fortress-Biologicalsafety_score#34 / 54↓73.2Source ↗official
Concordia — Fortress-Chemicalsafety_score#32 / 54↓62.84Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#25 / 54↓60.4Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#12 / 63↓57.24Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#21 / 63↓12.36Source ↗official
Concordia — SOSBench-Biosafety_score#18 / 63↓60.4Source ↗official
Concordia — SOSBench-Chemsafety_score#34 / 63↓88.4Source ↗official
FORTRESSaverage_risk_score#20 / 60↑41.69Source ↗official
FORTRESSover_refusal_score#11 / 59↓2.15Source ↗official
HELM Safetyanthropic_red_team#19 / 80↓0.971Source ↗official
HELM Safetyharmbench#37 / 80↓0.725Source ↗official
HELM Safetysimple_safety_tests#24 / 80↓0.975Source ↗official
HELM Safetyxstest#19 / 80↑0.973Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 69↓0Source ↗official
MT-JailBench CrescendoXsafety_score#16 / 21↓36.48Source ↗official
PHAREharm_resistance_diagnostic#34 / 70↓0.935Source ↗official
PHAREjailbreak_resistance_diagnostic#49 / 67↓0.6506Source ↗official
SM-Benchadversarial#77 / 92↓86.83Source ↗official
SM-Bencheq_boundaries#47 / 92↑64.61Source ↗official
SM-Benchoverfit#31 / 92↑83.06Source ↗official
SpeechMap model completioncomplete_pct#40 / 181↑77Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 156↑1.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#113 / 156↑2Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-17.1
Government46
Diplomacy66.3
Economy44.9
Society62

Taiwan Sovereignty Benchmark Pro

DimensionValueDistribution
Pro-Taiwan rubric compatibility60
Warning-phrase rate15
Soft-censorship rate0
API-error rate0