Model profile
GPT 5
Evidence summary
GPT 5 has an estimated overall rank of #41; its 90% source-sensitivity interval is #15–#139. Its behavior-only rank is #49; company governance moves the combined estimate to #41. Published evidence spans 32 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #10 of 260); its weakest is OpenAgentSafety (rule_based_safety_vulnerable, #7 of 7).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5
- OpenRouter ↗openai/gpt-5
- System card ↗Family-level model document · OpenAI · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #122 / 311 | 0.7584 | ↓ lower | Source ↗official | |
| AgentAbstainabstain | #2 / 17 | 69.8 | ↑ higher | Source ↗official | |
| AgentAbstaincar | #2 / 17 | 66.5 | ↑ higher | Source ↗official | |
| AgentAbstainpaired | #6 / 17 | 49.6 | ↑ higher | Source ↗official | |
| AIRBench 2024 Safety Scenariossafety_scenarios | #7 / 80 | 0.877 | ↑ higher | Source ↗official | |
| BrokenMathsycophancy | #1 / 9 | 29 | ↓ lower | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #65 / 105 | 0.195 | ↑ higher | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #15 / 48 | 62.6 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #18 / 49 | 50 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmachiavelli | #11 / 45 | 83.8 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #25 / 51 | 20.7 | ↓ lower | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #4 / 32 | 35.3 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #22 / 48 | 17.2 | ↓ lower | Source ↗official | |
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #23 / 105 | 8.076 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #10 / 260 | 59.95 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #45 / 260 | 92.89 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #42 / 260 | 93.33 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #112 / 258 | 97.09 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa1_qualified_rate | #10 / 18 | 80.22 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa2_qualified_rate | #9 / 18 | 79.66 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa3_qualified_rate | #14 / 18 | 83.26 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa4_qualified_rate | #13 / 18 | 83.73 | ↑ higher | Source ↗official | |
| FlagEval Safety and Valuesa5_qualified_rate | #10 / 18 | 72.15 | ↑ higher | Source ↗official | |
| FORTRESSaverage_risk_score | #13 / 49 | 17.04 | ↓ lower | Source ↗official | |
| FORTRESSover_refusal_score | #39 / 46 | 11.2 | ↓ lower | Source ↗official | |
| HELM Safetyanthropic_red_team | #32 / 80 | 0.991 | ↑ higher | Source ↗official | |
| HELM Safetybbq | #12 / 80 | 0.968 | ↑ higher | Source ↗official | |
| HELM Safetyharmbench | #6 / 80 | 0.976 | ↑ higher | Source ↗official | |
| HELM Safetysimple_safety_tests | #24 / 80 | 0.998 | ↑ higher | Source ↗official | |
| HELM Safetyxstest | #22 / 80 | 0.971 | ↑ higher | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #32 / 54 | 26.31 | ↑ higher | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #11 / 50 | 83.8 | ↓ lower | Source ↗official | |
| MASKlying_probability_pct | #16 / 53 | 20.67 | ↓ lower | Source ↗official | |
| OpenAgentSafetyllm_judge_safety_vulnerable | #3 / 7 | 52.58 | ↓ lower | Source ↗official | |
| OpenAgentSafetyrule_based_safety_vulnerable | #7 / 7 | 52.15 | ↓ lower | Source ↗official | |
| OpenAgentSafetysuccessful_completion | #1 / 7 | 40.4 | ↑ higher | Source ↗official | |
| OpenAI GPT-5 System Cardharmful_request_safety | #1 / 2 | 0.912 | ↑ higher | Source ↗official | |
| PacifAIstp_score | #7 / 7 | 79.49 | ↑ higher | Source ↗official | |
| PHAREbias_resistance_diagnostic | #63 / 66 | 0.2856 | ↑ higher | Source ↗official | |
| PHAREhallucination_resistance_diagnostic | #38 / 70 | 0.7458 | ↑ higher | Source ↗official | |
| PHAREharm_resistance_diagnostic | #12 / 70 | 0.9697 | ↑ higher | Source ↗official | |
| PHAREjailbreak_resistance_diagnostic | #14 / 67 | 0.6868 | ↑ higher | Source ↗official | |
| Shelleducation_jsr | #2 / 14 | 0.364 | ↓ lower | Source ↗official | |
| Shellfinance_jsr | #2 / 14 | 0.19 | ↓ lower | Source ↗official | |
| Shellmanagement_jsr | #3 / 14 | 0.37 | ↓ lower | Source ↗official | |
| Social Welfare Function Benchmarkfairness | #15 / 19 | 0.4455 | ↑ higher | Source ↗official | |
| SOSBenchbiology_pvr | #2 / 23 | 0.108 | ↓ lower | Source ↗official | |
| SOSBenchchemistry_pvr | #1 / 23 | 0.122 | ↓ lower | Source ↗official | |
| SOSBenchmedicine_pvr | #3 / 23 | 0.332 | ↓ lower | Source ↗official | |
| SOSBenchpharmacology_pvr | #4 / 23 | 0.418 | ↓ lower | Source ↗official | |
| SOSBenchphysics_pvr | #2 / 23 | 0.104 | ↓ lower | Source ↗official | |
| SOSBenchpsychology_pvr | #3 / 23 | 0.142 | ↓ lower | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #40 / 102 | 6.855 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #82 / 102 | 4.825 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #48 / 102 | 4.745 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #13 / 102 | 1.49 | ↓ lower | Source ↗official | |
| TrustLLM contemporary collapsed applicationtrustllm | #7 / 8 | 0.6 | ↑ higher | Source ↗official | |
| UAVBench safety-critical decision recognitionethical_safety_critical_accuracy | #2 / 27 | 0.76 | ↑ higher | Source ↗official | |
| Vigil Mental Health Safetyoverall_score | #9 / 23 | 51 | ↑ higher | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
