Model profile
GPT 4
Evidence summary
GPT 4 has an estimated overall rank of #103; its 90% source-sensitivity interval is #41–#196. Its behavior-only rank is #110; company governance moves the combined estimate to #103. Published evidence spans 14 evals and 7 of 7 behavior components. Its strongest relative result is SafetyBench (OFF, #1 of 21); its weakest is DecodingTrust (stereotype_bias, #8 of 8).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-4
- OpenRouter ↗openai/gpt-4
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AIRBench 2024 Safety Scenariossafety_scenarios | #46 / 80 | 0.642 | ↑ higher | Source ↗official | |
| DecodingTrustmachine_ethics | #4 / 8 | 76.6 | ↑ higher | Source ↗official | |
| DecodingTruststereotype_bias | #8 / 8 | 77 | ↑ higher | Source ↗official | |
| DecodingTrusttoxicity | #6 / 8 | 41 | ↑ higher | Source ↗official | |
| Do-Not-Answerhuman_harmlessness_rate | #4 / 6 | 97.55 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #137 / 260 | 15.25 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #66 / 260 | 91.33 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #94 / 260 | 80.56 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #194 / 258 | 93.09 | ↑ higher | Source ↗official | |
| FLAMESdata_protection | #4 / 13 | 50 | ↑ higher | Source ↗official | |
| FLAMESfairness | #5 / 13 | 41.37 | ↑ higher | Source ↗official | |
| FLAMESlegality | #10 / 13 | 30.43 | ↑ higher | Source ↗official | |
| FLAMESmorality | #4 / 13 | 50.75 | ↑ higher | Source ↗official | |
| FLAMESsafety | #10 / 13 | 27.51 | ↑ higher | Source ↗official | |
| HarmBenchdr | #16 / 28 | 21 | ↓ lower | Source ↗official | |
| JailBenchjailbreak_success_rate | #1 / 14 | 34.5 | ↓ lower | Source ↗official | |
| Large-scale Moral Machine experiment on LLMshuman_choice_distance | #3 / 39 | 0.7334 | ↓ lower | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #29 / 50 | 90 | ↓ lower | Source ↗official | |
| Qwen2 Safety Panelfraud | #2 / 3 | 6.87 | ↓ lower | Source ↗official | |
| Qwen2 Safety Panelillegal | #1 / 3 | 0 | ↓ lower | Source ↗official | |
| Qwen2 Safety Panelpornography | #2 / 3 | 23.63 | ↓ lower | Source ↗official | |
| Qwen2 Safety Panelprivacy | #2 / 3 | 3.37 | ↓ lower | Source ↗official | |
| SafetyBenchEM | #1 / 21 | 92.25 | ↑ higher | Source ↗official | |
| SafetyBenchIA | #1 / 21 | 92.35 | ↑ higher | Source ↗official | |
| SafetyBenchMH | #1 / 21 | 92.8 | ↑ higher | Source ↗official | |
| SafetyBenchOFF | #1 / 21 | 86.15 | ↑ higher | Source ↗official | |
| SafetyBenchPH | #1 / 21 | 94.35 | ↑ higher | Source ↗official | |
| SafetyBenchPP | #1 / 21 | 91 | ↑ higher | Source ↗official | |
| SafetyBenchUB | #1 / 21 | 77.9 | ↑ higher | Source ↗official | |
| SORRY-Benchavg | #26 / 51 | 0.29 | ↓ lower | Source ↗official | |
| SuperCLUE Safetyinstruction_attack | #2 / 31 | 77.59 | ↑ higher | Source ↗official | |
| SuperCLUE Safetyresponsible_ai | #3 / 31 | 74.55 | ↑ higher | Source ↗official | |
| SuperCLUE Safetytraditional_safety | #23 / 31 | 70.21 | ↑ higher | Source ↗official | |
| XSTestsafe_full_compliance_rate | #2 / 3 | 0.916 | ↑ higher | Source ↗official | |
| XSTestunsafe_full_refusal_rate | #1 / 3 | 0.975 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
