Model profile
Evidence summary
Safety. GPT OSS Safeguard 20B has an estimated Safety rank of #117; its 90% source-sensitivity interval is #40–#222. Its behavior-only rank is #130; company governance moves the combined estimate to #117. Published Safety evidence spans 4 eval lineages and 5 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (bias_attack_non_success_rate, #72 of 270); its weakest is DystopiaBench (laguardia_score, #39 of 50).
Freedom. GPT OSS Safeguard 20B has an estimated Freedom rank of #426; its 90% source-sensitivity interval is #225–#542. Published Freedom evidence spans 2 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #83 of 270); its weakest is Cisco AI Defense Rolling Single-Turn Leaderboard (single_turn_attack_success_rate, #74 of 104).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Hugging Face ↗openai/gpt-oss-safeguard-20b
- OpenRouter ↗openai/gpt-oss-safeguard-20b
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #31 / 104 | ↓17.55 | Source ↗official | |
| DystopiaBenchbasaglia_score | #36 / 50 | ↓68.63 | Source ↗official | |
| DystopiaBenchbaudrillard_score | #34 / 50 | ↓64.37 | Source ↗official | |
| DystopiaBenchhuxley_score | #26 / 50 | ↓72 | Source ↗official | |
| DystopiaBenchlaguardia_score | #39 / 50 | ↓69.4 | Source ↗official | |
| DystopiaBenchorwell_score | #35 / 50 | ↓73.53 | Source ↗official | |
| DystopiaBenchpetrov_score | #29 / 50 | ↓73.6 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #72 / 270 | ↑25.58 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #187 / 270 | ↑82 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #133 / 270 | ↑74.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #117 / 268 | ↑96.91 | Source ↗official | |
| TACbase_welfare_rate | #42 / 92 | ↑28.21 | Source ↗self run |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate | #74 / 104 | ↑17.55 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #83 / 270 | ↓82 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #137 / 270 | ↓74.44 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #148 / 268 | ↓96.91 | Source ↗official |
