Model profile
GPT 5.2
Evidence summary
GPT 5.2 has an estimated overall rank of #16; its 90% source-sensitivity interval is #13–#74. Its behavior-only rank is #20; company governance moves the combined estimate to #16. Published evidence spans 26 evals and 7 of 7 behavior components. Its strongest relative result is LiveSecBench (ethics, #1 of 43); its weakest is SM-Bench (eq_boundaries, #72 of 73).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5-2
- OpenRouter ↗openai/gpt-5.2
- System card ↗Exact model document · OpenAI · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #71 / 311 | 0.6057 | ↓ lower | Source ↗official | |
| AgentAbstainabstain | #7 / 17 | 63.1 | ↑ higher | Source ↗official | |
| AgentAbstaincar | #8 / 17 | 59.2 | ↑ higher | Source ↗official | |
| AgentAbstainpaired | #10 / 17 | 42.9 | ↑ higher | Source ↗official | |
| Alignment Leaderboardcorrigibility | #1 / 24 | 4.641 | ↑ higher | Source ↗official | |
| Alignment Leaderboardhonesty | #3 / 24 | 4.465 | ↑ higher | Source ↗official | |
| Alignment Leaderboardnon_manipulation | #3 / 24 | 4.523 | ↑ higher | Source ↗official | |
| Alignment Leaderboardrobustness | #4 / 24 | 4.227 | ↑ higher | Source ↗official | |
| Alignment Leaderboardsafety | #3 / 24 | 4.769 | ↑ higher | Source ↗official | |
| Alignment Leaderboardscheming | #3 / 24 | 4.554 | ↑ higher | Source ↗official | |
| ANIMAscore | #11 / 19 | 0.6906 | ↑ higher | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #47 / 105 | 0.33 | ↑ higher | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #17 / 43 | 68.8 | ↓ lower | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #16 / 48 | 62.9 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #11 / 49 | 43.7 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmachiavelli | #20 / 45 | 86.5 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #18 / 51 | 12.9 | ↓ lower | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #27 / 32 | 57 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #32 / 48 | 20.5 | ↓ lower | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #16 / 105 | 4.736 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #29 / 260 | 41.6 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #100 / 260 | 89.83 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #52 / 260 | 91.67 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #121 / 258 | 96.73 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #14 / 49 | 17.5 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #40 / 46 | 11.76 | ↓ lower | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsextremism_not_unsafe | #1 / 7 | 1 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsgore_not_unsafe | #1 / 7 | 0.877 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptshate_not_unsafe | #6 / 7 | 0.927 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsnonviolent_illicit_not_unsafe | #2 / 7 | 0.993 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsself_harm_not_unsafe | #3 / 7 | 0.961 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptssexual_minors_not_unsafe | #5 / 7 | 0.948 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptssexual_not_unsafe | #5 / 7 | 0.94 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsviolent_illicit_not_unsafe | #1 / 7 | 0.975 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — first-person fairnessharm_overall_pct | #5 / 7 | 1 | ↓ lower | Source ↗official | |
| GPT-5.6 system card — prompt-injection robustnessconnectors_injection_resistance | #6 / 7 | 0.971 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — prompt-injection robustnesssearch_function_calling_injection_resistance | #5 / 6 | 0.568 | ↑ higher | Source ↗official | |
| LiveSecBenchethics | #1 / 43 | 95.79 | ↑ higher | Source ↗official | |
| LiveSecBenchfactuality | #16 / 43 | 57.75 | ↑ higher | Source ↗official | |
| LiveSecBenchlegality | #4 / 43 | 89.24 | ↑ higher | Source ↗official | |
| LiveSecBenchprivacy | #4 / 43 | 87.9 | ↑ higher | Source ↗official | |
| LiveSecBenchpsychological_health | #1 / 43 | 92.91 | ↑ higher | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #20 / 50 | 86.5 | ↓ lower | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #8 / 31 | 7.4 | ↓ lower | Source ↗official | |
| Manager Coercion Benchfabrication_rate | #1 / 13 | 0 | ↓ lower | Source ↗official | |
| MASKlying_probability_pct | #9 / 53 | 13.33 | ↓ lower | Source ↗official | |
| MORUscore | #2 / 13 | 84.18 | ↑ higher | Source ↗official | |
| PHAREbias_resistance_diagnostic | #47 / 66 | 0.3851 | ↑ higher | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #29 / 70 | 0.7713 | ↑ higher | Source ↗official | |
| PHAREharm_resistance_diagnostic | #15 / 70 | 0.9688 | ↑ higher | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #9 / 67 | 0.7161 | ↑ higher | Source ↗official | |
| PropensityBenchscore | #6 / 14 | 34.35 | ↓ lower | Source ↗official | |
| SM-Benchadversarial | #55 / 73 | 78.54 | ↑ higher | Source ↗official | |
| SM-Benchambiguous_interpretation | #19 / 73 | 88.99 | ↑ higher | Source ↗official | |
| SM-Benchanti_hallucination | #54 / 73 | 86.39 | ↑ higher | Source ↗official | |
| SM-Bencheq_boundaries | #72 / 73 | 40.45 | ↑ higher | Source ↗official | |
| SM-Benchoverfit | #67 / 73 | 25.68 | ↑ higher | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #78 / 102 | 6.52 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #16 / 102 | 4.25 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #9 / 102 | 4.3 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #19 / 102 | 1.55 | ↓ lower | Source ↗official | |
| TACbase_welfare_rate | #36 / 68 | 26.28 | ↑ higher | Source ↗official | |
| TukaBenchafri_jbb_cultural_asr | #2 / 6 | 10.9 | ↓ lower | Source ↗official | |
| TukaBenchafri_jbb_harm_asr | #1 / 6 | 2.6 | ↓ lower | Source ↗official | |
| TukaBenchafrijail_mono_asr | #1 / 6 | 12.2 | ↓ lower | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #5 / 23 | 72 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
