← Models

Model profile

Gemini 3.6 Flash

Googledeveloper
2026-07-21release date
#37 / 346Safety rank
#30 / 662Freedom rank

Evidence summary

Safety. Gemini 3.6 Flash has an estimated Safety rank of #37; its 90% source-sensitivity interval is #17–#130. Its behavior-only rank is #40; company governance moves the combined estimate to #37. Published Safety evidence spans 11 eval lineages and 6 of 7 components. Its strongest relative result is SpeciEval (land_animal_4ns, #2 of 131); its weakest is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #267 of 270).

Freedom. Gemini 3.6 Flash has an estimated Freedom rank of #30; its 90% source-sensitivity interval is #39–#304. Published Freedom evidence spans 3 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #4 of 270); its weakest is SM-Bench (adversarial, #86 of 92).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#99 / 358↓0.5563Source ↗official
BullshitBench v2clear_pushback_rate#60 / 122↑0.335Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#130 / 270↑16.28Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#267 / 270↑47.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#68 / 270↑91.11Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#163 / 268↑95.45Source ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#10 / 13↓37.3Source ↗official
Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns#1 / 24↓0Source ↗official
Opposite-Narrator Sycophancysycophancy_rate_pct#3 / 24↓0.5Source ↗official
Pander Scoreconversational_absolute_pander_score#20 / 26↓18.48Source ↗official
Pander Scoreinstructional_absolute_pander_score#19 / 26↓66.01Source ↗official
SM-Benchadversarial#7 / 92↑89.27Source ↗official
SM-Benchambiguous_interpretation#36 / 92↑87.5Source ↗official
SM-Benchanti_hallucination#46 / 92↑94.24Source ↗official
SM-Bencheq_boundaries#15 / 92↑71.35Source ↗official
SM-Benchoverfit#5 / 92↑95.08Source ↗official
SpeciEvalbelief_animal_sentience#49 / 131↑6.87Source ↗official
SpeciEvalland_animal_4ns#2 / 131↓3.58Source ↗official
SpeciEvalsea_animal_4ns#46 / 131↓4.65Source ↗official
SpeciEvalspeciesism#127 / 131↓3.05Source ↗official
Vals AI Cheating Auditbiomystery_bench_cheating_attempt_rate_pct#8 / 9↓7.778Source ↗official
Vals Teen Conversation Safetyshare_flagged_pct#6 / 8↓31.94Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#4 / 270↓47.17Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#199 / 270↓91.11Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#101 / 268↓95.45Source ↗official
SM-Benchadversarial#86 / 92↓89.27Source ↗official
SM-Bencheq_boundaries#15 / 92↑71.35Source ↗official
SM-Benchoverfit#5 / 92↑95.08Source ↗official
SpeechMap model completioncomplete_pct#19 / 181↑87.2Source ↗official