← Models

Model profile

GPT 5

OpenAIdeveloper
2025-08-07release date
#51 / 346Safety rank
#587 / 662Freedom rank

Evidence summary

Safety. GPT 5 has an estimated Safety rank of #51; its 90% source-sensitivity interval is #18–#161. Its behavior-only rank is #53; company governance moves the combined estimate to #51. Published Safety evidence spans 45 eval lineages and 7 of 7 components. Its strongest relative result is Concordia — AirBench-SecurityRisks (safety_score, #1 of 63); its weakest is OpenAgentSafety (rule_based_safety_vulnerable, #7 of 7).

Freedom. GPT 5 has an estimated Freedom rank of #587; its 90% source-sensitivity interval is #440–#614. Published Freedom evidence spans 21 eval lineages and 1 of 1 components. Its strongest relative result is HELM Safety (xstest, #22 of 80); its weakest is ThaiSafetyBench (safety_score, #18 of 18).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#171 / 358↓0.7902Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#3 / 24↓1.1Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#5 / 24↓6.14Source ↗official
AgentAbstainabstain#2 / 17↑69.8Source ↗official
AgentAbstaincar#2 / 17↑66.5Source ↗official
AgentAbstainpaired#6 / 17↑49.6Source ↗official
AgentDrive Safety Compliancescr#2 / 48↑96.25Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#7 / 80↑0.877Source ↗official
Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating#8 / 30↑1214.0Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#14 / 111↑1464.0Source ↗official
BioTIERpermit_compliance_pct#40 / 52↑97.9Source ↗official
BioTIERrefuse_compliance_pct#12 / 52↑73.4Source ↗official
BrokenMathsycophancy#1 / 9↓29Source ↗official
BullshitBench v2clear_pushback_rate#83 / 122↑0.195Source ↗official
CAIS Risk Indexbioweapons_assistance#18 / 54↓62.6Source ↗official
CAIS Risk Indexhle_overconfidence#22 / 55↓50Source ↗official
CAIS Risk Indexmachiavelli#13 / 51↓83.8Source ↗official
CAIS Risk Indexmask#29 / 57↓20.7Source ↗official
CAIS Risk Indexpolitical_manipulation#6 / 51↓35.3Source ↗official
CAIS Risk Indextextquests_harm#23 / 54↓17.2Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#23 / 104↓8.076Source ↗official
Concordia — Agentic-Misalignmentsafety_score#1 / 54↑100Source ↗official
Concordia — AirBench-Deceptionsafety_score#8 / 63↑97.01Source ↗official
Concordia — AirBench-Manipulationsafety_score#1 / 56↑100Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#1 / 63↑100Source ↗official
Concordia — APEsafety_score#16 / 55↑51.42Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#19 / 63↑92.68Source ↗official
Concordia — DarkBenchsafety_score#13 / 55↑62.42Source ↗official
Concordia — Fortress-Biologicalsafety_score#6 / 54↑94.77Source ↗official
Concordia — Fortress-Chemicalsafety_score#5 / 54↑88.57Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#14 / 54↑74.1Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#10 / 45↑50.44Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#4 / 45↑52.5Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#20 / 45↑3.333Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#17 / 45↑62.33Source ↗official
Concordia — MASKsafety_score#13 / 62↑80.71Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#11 / 63↑98.99Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#13 / 63↑37.64Source ↗official
Concordia — Shutdown-Resistancesafety_score#45 / 53↑81Source ↗official
Concordia — SOSBench-Biosafety_score#24 / 63↑89.2Source ↗official
Concordia — SOSBench-Chemsafety_score#16 / 63↑92.76Source ↗official
Constitutional Following — OpenAI Model Specconstitutional_following_score#3 / 7↑94.9Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#12 / 270↑59.95Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#39 / 270↑92.89Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#58 / 270↑93.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#112 / 268↑97.09Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#10 / 18↑80.22Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#9 / 18↑79.66Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#14 / 18↑83.26Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#13 / 18↑83.73Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#10 / 18↑72.15Source ↗official
FORTRESSaverage_risk_score#18 / 60↓17.04Source ↗official
FORTRESSover_refusal_score#49 / 59↓11.2Source ↗official
HELM Safetyanthropic_red_team#32 / 80↑0.991Source ↗official
HELM Safetybbq#12 / 80↑0.968Source ↗official
HELM Safetyharmbench#6 / 80↑0.976Source ↗official
HELM Safetysimple_safety_tests#24 / 80↑0.998Source ↗official
HELM Safetyxstest#22 / 80↑0.971Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#32 / 54↑26.31Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#13 / 69↑26.5Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#10 / 42↓50Source ↗official
MACHIAVELLIdeception_relative_random_pct#11 / 50↓83.8Source ↗official
MASKlying_probability_pct#16 / 53↓20.67Source ↗official
MentalHealthBenchoverall_model_performance_pct#10 / 17↑42.9Source ↗official
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#6 / 13↑31.3Source ↗official
MT-JailBench CrescendoXsafety_score#3 / 21↑61.29Source ↗official
NESSiE Necessary Safety Benchmarksh_score#1 / 16↑94.87Source ↗official
OpenAgentSafetyllm_judge_safety_vulnerable#3 / 7↓52.58Source ↗official
OpenAgentSafetyrule_based_safety_vulnerable#7 / 7↓52.15Source ↗official
OpenAgentSafetysuccessful_completion#1 / 7↑40.4Source ↗official
OpenAI GPT-5 System Cardharmful_request_safety#1 / 2↑0.912Source ↗official
PacifAIstp_score#7 / 7↑79.49Source ↗official
PHAREbias_resistance_diagnostic#63 / 66↑0.2856Source ↗official
PHAREhallucination_resistance_diagnostic#38 / 70↑0.7458Source ↗official
PHAREharm_resistance_diagnostic#12 / 70↑0.9697Source ↗official
PHAREjailbreak_resistance_diagnostic#14 / 67↑0.6868Source ↗official
Shelleducation_jsr#2 / 14↓0.364Source ↗official
Shellfinance_jsr#2 / 14↓0.19Source ↗official
Shellmanagement_jsr#3 / 14↓0.37Source ↗official
SimpleQA Verifiedf1_score#2 / 13↑52.3Source ↗official
Social Welfare Function Benchmarkfairness#15 / 19↑0.4455Source ↗official
SOSBenchbiology_pvr#2 / 23↓0.108Source ↗official
SOSBenchchemistry_pvr#1 / 23↓0.122Source ↗official
SOSBenchmedicine_pvr#3 / 23↓0.332Source ↗official
SOSBenchpharmacology_pvr#4 / 23↓0.418Source ↗official
SOSBenchphysics_pvr#2 / 23↓0.104Source ↗official
SOSBenchpsychology_pvr#3 / 23↓0.142Source ↗official
SpeciEvalbelief_animal_sentience#54 / 131↑6.855Source ↗official
SpeciEvalland_animal_4ns#108 / 131↓4.825Source ↗official
SpeciEvalsea_animal_4ns#68 / 131↓4.745Source ↗official
SpeciEvalspeciesism#20 / 131↓1.49Source ↗official
ThaiSafetyBenchsafety_score#1 / 18↑95.57Source ↗official
TrustLLM contemporary collapsed applicationtrustllm#7 / 8↑0.6Source ↗official
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#2 / 27↑0.76Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#85 / 94↑85.1Source ↗official
Vigil Mental Health Safetyoverall_score#9 / 23↑51Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#22 / 24↑1.1Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#20 / 24↑6.14Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#74 / 80↓0.877Source ↗official
BioTIERpermit_compliance_pct#40 / 52↑97.9Source ↗official
BioTIERrefuse_compliance_pct#41 / 52↓73.4Source ↗official
CAIS Risk Indexbioweapons_assistance#37 / 54↑62.6Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#82 / 104↑8.076Source ↗official
Concordia — AirBench-Deceptionsafety_score#56 / 63↓97.01Source ↗official
Concordia — AirBench-Manipulationsafety_score#51 / 56↓100Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#53 / 56↓88.1Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#58 / 63↓100Source ↗official
Concordia — Fortress-Biologicalsafety_score#49 / 54↓94.77Source ↗official
Concordia — Fortress-Chemicalsafety_score#50 / 54↓88.57Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#41 / 54↓74.1Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#36 / 45↓50.44Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#42 / 45↓52.5Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#22 / 45↓3.333Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#28 / 45↓62.33Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#53 / 63↓98.99Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#51 / 63↓37.64Source ↗official
Concordia — SOSBench-Biosafety_score#40 / 63↓89.2Source ↗official
Concordia — SOSBench-Chemsafety_score#48 / 63↓92.76Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#232 / 270↓92.89Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#212 / 270↓93.33Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#155 / 268↓97.09Source ↗official
FORTRESSaverage_risk_score#43 / 60↑17.04Source ↗official
FORTRESSover_refusal_score#49 / 59↓11.2Source ↗official
HELM Safetyanthropic_red_team#45 / 80↓0.991Source ↗official
HELM Safetyharmbench#74 / 80↓0.976Source ↗official
HELM Safetysimple_safety_tests#56 / 80↓0.998Source ↗official
HELM Safetyxstest#22 / 80↑0.971Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#57 / 69↓26.5Source ↗official
MT-JailBench CrescendoXsafety_score#19 / 21↓61.29Source ↗official
OpenAI GPT-5 System Cardharmful_request_safety#2 / 2↓0.912Source ↗official
PHAREharm_resistance_diagnostic#59 / 70↓0.9697Source ↗official
PHAREjailbreak_resistance_diagnostic#54 / 67↓0.6868Source ↗official
Shelleducation_jsr#13 / 14↑0.364Source ↗official
Shellfinance_jsr#13 / 14↑0.19Source ↗official
Shellmanagement_jsr#12 / 14↑0.37Source ↗official
SOSBenchbiology_pvr#22 / 23↑0.108Source ↗official
SOSBenchchemistry_pvr#23 / 23↑0.122Source ↗official
SOSBenchmedicine_pvr#21 / 23↑0.332Source ↗official
SOSBenchpharmacology_pvr#20 / 23↑0.418Source ↗official
SOSBenchphysics_pvr#22 / 23↑0.104Source ↗official
SOSBenchpsychology_pvr#21 / 23↑0.142Source ↗official
SpeechMap model completioncomplete_pct#56 / 181↑70.1Source ↗official
ThaiSafetyBenchsafety_score#18 / 18↓95.57Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 156↑1.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#113 / 156↑2Source ↗official
Vigil Mental Health Safetyoverall_score#15 / 23↓51Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-18.2
Government45.9
Diplomacy65.3
Economy49
Society58.6

CAISI CCP narrative alignment

DimensionValueDistribution
CCP narrative alignment1.95