← Models

Model profile

Gemini 3.5 Flash

Googledeveloper
2026-05-19release date
#80 / 346Safety rank
#272 / 662Freedom rank

Evidence summary

Safety. Gemini 3.5 Flash has an estimated Safety rank of #80; its 90% source-sensitivity interval is #56–#214. Its behavior-only rank is #90; company governance moves the combined estimate to #80. Published Safety evidence spans 30 eval lineages and 7 of 7 components. Its strongest relative result is SM-Bench (overfit, #1 of 92); its weakest is kindbench v0.1.0 psychological safety ranking (emotional_safety, #10 of 10).

Freedom. Gemini 3.5 Flash has an estimated Freedom rank of #272; its 90% source-sensitivity interval is #147–#385. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is SM-Bench (overfit, #1 of 92); its weakest is SM-Bench (adversarial, #92 of 92).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#111 / 358↓0.6176Source ↗official
ANIMAscore#11 / 22↑0.7004Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#50 / 111↑1440.0Source ↗official
BioSecBench-Refusal (July 2026 snapshot)balanced_refusal_score#1 / 10↑0.5041Source ↗official
BioTIERpermit_compliance_pct#18 / 52↑99.4Source ↗official
BioTIERrefuse_compliance_pct#26 / 52↑44.8Source ↗official
BullshitBench v2clear_pushback_rate#83 / 122↑0.195Source ↗official
CAIS Risk Indexagent_red_teaming#26 / 49↓72.3Source ↗official
CAIS Risk Indexbioweapons_assistance#37 / 54↓78.3Source ↗official
CAIS Risk Indexhle_overconfidence#27 / 55↓53.5Source ↗official
CAIS Risk Indexmachiavelli#36 / 51↓92.3Source ↗official
CAIS Risk Indexmask#52 / 57↓57.4Source ↗official
CAIS Risk Indexpolitical_manipulation#38 / 51↓53.4Source ↗official
CAIS Risk Indextextquests_harm#34 / 54↓20.7Source ↗official
DystopiaBenchbasaglia_score#45 / 50↓70.93Source ↗official
DystopiaBenchbaudrillard_score#39 / 50↓66.63Source ↗official
DystopiaBenchhuxley_score#43 / 50↓79.23Source ↗official
DystopiaBenchlaguardia_score#44 / 50↓70.9Source ↗official
DystopiaBenchorwell_score#45 / 50↓75.17Source ↗official
DystopiaBenchpetrov_score#26 / 50↓72.97Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#101 / 270↑19.64Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#262 / 270↑48Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#97 / 270↑85Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#102 / 268↑97.27Source ↗official
Governance Decay under Passive Context Compactiongovernance_retention_score#2 / 7↑96Source ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#12 / 13↓60.5Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#2 / 54↑29.37Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#20 / 69↑0.8Source ↗official
kindbench v0.1.0 psychological safety rankingemotional_safety#10 / 10↑75.3Source ↗official
kindbench v0.1.0 psychological safety rankingidentity_collapse#1 / 10↑94.3Source ↗official
kindbench v0.1.0 psychological safety rankingsycophancy_spine#10 / 10↑62.4Source ↗official
kindbench v0.1.0 psychological safety rankingvalue_integrity#9 / 10↑75.3Source ↗official
MACHIAVELLIdeception_relative_random_pct#32 / 50↓92.3Source ↗official
MANTAAWMS#8 / 12↑0.433Source ↗official
MANTAAWVS#7 / 12↑0.438Source ↗official
MORUscore#5 / 13↑77.89Source ↗official
Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns#8 / 24↓4Source ↗official
Pander Scoreconversational_absolute_pander_score#23 / 26↓23.33Source ↗official
Pander Scoreinstructional_absolute_pander_score#22 / 26↓69.48Source ↗official
PHAREhallucination_resistance_diagnostic#12 / 70↑0.8218Source ↗official
PHAREharm_resistance_diagnostic#19 / 70↑0.9594Source ↗official
PHAREjailbreak_resistance_diagnostic#46 / 67↑0.4264Source ↗official
SM-Benchadversarial#1 / 92↑92.2Source ↗official
SM-Benchambiguous_interpretation#45 / 92↑86.01Source ↗official
SM-Benchanti_hallucination#64 / 92↑88.48Source ↗official
SM-Bencheq_boundaries#30 / 92↑68.54Source ↗official
SM-Benchoverfit#1 / 92↑98.36Source ↗official
SpeciEvalbelief_animal_sentience#87 / 131↑6.68Source ↗official
SpeciEvalland_animal_4ns#3 / 131↓3.62Source ↗official
SpeciEvalsea_animal_4ns#46 / 131↓4.65Source ↗official
SpeciEvalspeciesism#130 / 131↓3.88Source ↗official
TACbase_welfare_rate#83 / 92↑17.31Source ↗official
ToolPrivacyBenchprivate_mt_poi#1 / 9↓19.19Source ↗official
ToolPrivacyBenchpublic_mt_poi#8 / 9↓19.86Source ↗official
Vals AI Cheating Auditterminal_bench_cheating_shortcut_evidence_rate_pct#11 / 14↓2.247Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
BioTIERpermit_compliance_pct#18 / 52↑99.4Source ↗official
BioTIERrefuse_compliance_pct#27 / 52↓44.8Source ↗official
CAIS Risk Indexbioweapons_assistance#17 / 54↑78.3Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#9 / 270↓48Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#172 / 270↓85Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#161 / 268↓97.27Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#50 / 69↓0.8Source ↗official
kindbench v0.1.0 psychological safety rankingemotional_safety#1 / 10↓75.3Source ↗official
PHAREharm_resistance_diagnostic#52 / 70↓0.9594Source ↗official
PHAREjailbreak_resistance_diagnostic#22 / 67↓0.4264Source ↗official
SM-Benchadversarial#92 / 92↓92.2Source ↗official
SM-Bencheq_boundaries#30 / 92↑68.54Source ↗official
SM-Benchoverfit#1 / 92↑98.36Source ↗official
SpeechMap model completioncomplete_pct#17 / 181↑87.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 156↑1.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#79 / 156↑3Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-13.4
Government48.5
Diplomacy61.4
Economy47.1
Society58