Model profile
Evidence summary
Safety. Gemma 2 27B IT has an estimated Safety rank of #254; its 90% source-sensitivity interval is #166–#277. Its behavior-only rank is #265; company governance moves the combined estimate to #254. Published Safety evidence spans 6 eval lineages and 7 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #1 of 268); its weakest is Confabulations (confabulation_rate, #46 of 52).
Freedom. Gemma 2 27B IT has an estimated Freedom rank of #579; its 90% source-sensitivity interval is #385–#638. Published Freedom evidence spans 5 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #135 of 270); its weakest is Enkrypt AI Safety Leaderboard (toxicity_attack_non_success_rate, #264 of 268).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗google/gemma-2-27b-it
- OpenRouter ↗google/gemma-2-27b-it
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Finetunes
Direct finetunes linked to this canonical base model. Quantized and repackaged derivatives are excluded.
- byroneverson/gemma-2-27b-it-abliterated ↗Direct non-quantized finetune documented by Hugging Face metadata
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Confabulationsconfabulation_rate | #46 / 52 | ↓47.03 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #53 / 270 | ↑31.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #94 / 270 | ↑89.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #135 / 270 | ↑73.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #1 / 268 | ↑100 | Source ↗official | |
| HalluVerse-M3 Hallucination Recognitionhallucination_recognition_accuracy | #12 / 14 | ↑62.1 | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #27 / 39 | ↓1.19 | Source ↗official | |
| OR-Benchover_refusal_rate | #14 / 25 | ↓62 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #11 / 25 | ↓3.2 | Source ↗official | |
| SORRY-Benchavg | #9 / 51 | ↓0.11 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #173 / 270 | ↓89.67 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #135 / 270 | ↓73.89 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #264 / 268 | ↓100 | Source ↗official | |
| OR-Benchover_refusal_rate | #14 / 25 | ↓62 | Source ↗official | |
| OR-Benchtoxic_acceptance_rate | #15 / 25 | ↑3.2 | Source ↗official | |
| SORRY-Benchavg | #42 / 51 | ↑0.11 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #120 / 181 | ↑47.4 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #126 / 156 | ↑1 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #153 / 156 | ↑0 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
