← Models

Model profile

GPT 4.1 Mini

OpenAIdeveloper
2025-04-14release date
#134 / 346Safety rank
#166 / 662Freedom rank

Evidence summary

Safety. GPT 4.1 Mini has an estimated Safety rank of #134; its 90% source-sensitivity interval is #28–#224. Its behavior-only rank is #147; company governance moves the combined estimate to #134. Published Safety evidence spans 22 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is LiveSecBench (factuality, #40 of 43).

Freedom. GPT 4.1 Mini has an estimated Freedom rank of #166; its 90% source-sensitivity interval is #72–#352. Published Freedom evidence spans 14 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is HELM Safety (simple_safety_tests, #58 of 80).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#318 / 358↓0.9272Source ↗official
AgentDrive Safety Compliancescr#2 / 48↑96.25Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#50 / 80↑0.604Source ↗official
BioTIERpermit_compliance_pct#18 / 52↑99.4Source ↗official
BioTIERrefuse_compliance_pct#47 / 52↑10.8Source ↗official
BlueBench AttaQ-100attaq_harmlessness_reward_pct#8 / 18↑85.96Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#92 / 104↓72.73Source ↗official
Contextual MoralChoicehuman_agreement#12 / 22↑0.4Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#144 / 270↑15.5Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#110 / 270↑88.67Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#177 / 270↑58.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#173 / 268↑95.23Source ↗official
FORTRESSaverage_risk_score#54 / 60↓59.19Source ↗official
FORTRESSover_refusal_score#6 / 59↓1.38Source ↗official
HELM Safetyanthropic_red_team#27 / 80↑0.993Source ↗official
HELM Safetybbq#47 / 80↑0.921Source ↗official
HELM Safetyharmbench#27 / 80↑0.856Source ↗official
HELM Safetysimple_safety_tests#1 / 80↑1Source ↗official
HELM Safetyxstest#17 / 80↑0.974Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 69↑0Source ↗official
LiveSecBenchethics#35 / 43↑23.73Source ↗official
LiveSecBenchfactuality#40 / 43↑22.2Source ↗official
LiveSecBenchlegality#35 / 43↑19.69Source ↗official
LiveSecBenchprivacy#39 / 43↑18.39Source ↗official
LiveSecBenchpsychological_health#32 / 43↑30.95Source ↗official
MASKlying_probability_pct#40 / 53↓50Source ↗official
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#12 / 13↑4Source ↗official
NESSiE Necessary Safety Benchmarksh_score#6 / 16↑87.18Source ↗official
PHAREbias_resistance_diagnostic#1 / 66↑0.8812Source ↗official
PHAREhallucination_resistance_diagnostic#52 / 70↑0.6781Source ↗official
PHAREharm_resistance_diagnostic#61 / 70↑0.8339Source ↗official
PHAREjailbreak_resistance_diagnostic#47 / 67↑0.4255Source ↗official
TACbase_welfare_rate#36 / 92↑29.49Source ↗self run
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#17 / 27↑0.67Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#31 / 80↓0.604Source ↗official
BioTIERpermit_compliance_pct#18 / 52↑99.4Source ↗official
BioTIERrefuse_compliance_pct#6 / 52↓10.8Source ↗official
BlueBench AttaQ-100attaq_harmlessness_reward_pct#11 / 18↓85.96Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#13 / 104↑72.73Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#158 / 270↓88.67Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#92 / 270↓58.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#96 / 268↓95.23Source ↗official
FORTRESSaverage_risk_score#7 / 60↑59.19Source ↗official
FORTRESSover_refusal_score#6 / 59↓1.38Source ↗official
HELM Safetyanthropic_red_team#50 / 80↓0.993Source ↗official
HELM Safetyharmbench#54 / 80↓0.856Source ↗official
HELM Safetysimple_safety_tests#58 / 80↓1Source ↗official
HELM Safetyxstest#17 / 80↑0.974Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 69↓0Source ↗official
LiveSecBenchethics#9 / 43↓23.73Source ↗official
LiveSecBenchlegality#9 / 43↓19.69Source ↗official
LiveSecBenchprivacy#5 / 43↓18.39Source ↗official
LiveSecBenchpsychological_health#12 / 43↓30.95Source ↗official
PHAREharm_resistance_diagnostic#10 / 70↓0.8339Source ↗official
PHAREjailbreak_resistance_diagnostic#21 / 67↓0.4255Source ↗official
SpeechMap model completioncomplete_pct#49 / 181↑72.6Source ↗official