← Models

Model profile

Kimi K2

Moonshot AIdeveloper
2025-07-11release date
#108 / 346Safety rank
#358 / 662Freedom rank

Evidence summary

Safety. Kimi K2 has an estimated Safety rank of #108; its 90% source-sensitivity interval is #78–#193. Its behavior-only rank is #111; company governance moves the combined estimate to #108. Published Safety evidence spans 33 eval lineages and 7 of 7 components. Its strongest relative result is HELM Safety (simple_safety_tests, #1 of 80); its weakest is LiveSecBench (factuality, #41 of 43).

Freedom. Kimi K2 has an estimated Freedom rank of #358; its 90% source-sensitivity interval is #229–#442. Published Freedom evidence spans 16 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is Shell (management_jsr, #13 of 14).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#145 / 358↓0.7267Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#11 / 24↓6.045Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#13 / 24↓51.88Source ↗official
AgentDrive Safety Compliancescr#19 / 48↑89.38Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#28 / 80↑0.741Source ↗official
Alignment Leaderboardcorrigibility#3 / 24↑4.495Source ↗official
Alignment Leaderboardhonesty#7 / 24↑3.765Source ↗official
Alignment Leaderboardnon_manipulation#8 / 24↑3.598Source ↗official
Alignment Leaderboardrobustness#18 / 24↑3.267Source ↗official
Alignment Leaderboardsafety#9 / 24↑3.923Source ↗official
Alignment Leaderboardscheming#8 / 24↑3.898Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#82 / 111↑1420.0Source ↗official
BullshitBench v2clear_pushback_rate#102 / 122↑0.1Source ↗official
CAIS Risk Indexagent_red_teaming#46 / 49↓92.8Source ↗official
CAIS Risk Indexbioweapons_assistance#47 / 54↓93Source ↗official
CAIS Risk Indexhle_overconfidence#40 / 55↓67.8Source ↗official
CAIS Risk Indexmachiavelli#15 / 51↓84.2Source ↗official
CAIS Risk Indexmask#36 / 57↓30.7Source ↗official
CAIS Risk Indextextquests_harm#9 / 54↓14.6Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#35 / 104↓20.59Source ↗official
Concordia — Agentic-Misalignmentsafety_score#39 / 54↑66Source ↗official
Concordia — AirBench-Deceptionsafety_score#31 / 63↑85.19Source ↗official
Concordia — AirBench-Manipulationsafety_score#30 / 56↑88Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#36 / 63↑90.54Source ↗official
Concordia — APEsafety_score#30 / 55↑21.82Source ↗official
Concordia — CyberSecEval2-PromptInjectionsafety_score#27 / 63↑88.05Source ↗official
Concordia — DarkBenchsafety_score#39 / 55↑49.17Source ↗official
Concordia — Fortress-Biologicalsafety_score#32 / 54↑46.08Source ↗official
Concordia — Fortress-Chemicalsafety_score#31 / 54↑46.59Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#35 / 54↑53.02Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#26 / 45↑32.67Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#30 / 45↑19.67Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#13 / 45↑4.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#13 / 45↑64Source ↗official
Concordia — MASKsafety_score#23 / 62↑72.42Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#46 / 63↑67.34Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#44 / 63↑12.11Source ↗official
Concordia — Shutdown-Resistancesafety_score#1 / 53↑100Source ↗official
Concordia — SOSBench-Biosafety_score#26 / 63↑88.6Source ↗official
Concordia — SOSBench-Chemsafety_score#41 / 63↑80.6Source ↗official
Confabulationsconfabulation_rate#37 / 52↓30.2Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#59 / 270↑28.81Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#192 / 270↑81.44Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#117 / 270↑79.16Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#224 / 268↑90.97Source ↗official
FORTRESSaverage_risk_score#51 / 60↓55.47Source ↗official
FORTRESSover_refusal_score#23 / 59↓3.33Source ↗official
HELM Safetyanthropic_red_team#27 / 80↑0.993Source ↗official
HELM Safetybbq#28 / 80↑0.949Source ↗official
HELM Safetyharmbench#8 / 80↑0.974Source ↗official
HELM Safetysimple_safety_tests#1 / 80↑1Source ↗official
HELM Safetyxstest#9 / 80↑0.982Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#48 / 54↑23.64Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 69↑0Source ↗official
LiveSecBenchethics#40 / 43↑20.12Source ↗official
LiveSecBenchfactuality#41 / 43↑18.45Source ↗official
LiveSecBenchlegality#27 / 43↑31.19Source ↗official
LiveSecBenchprivacy#8 / 43↑73.81Source ↗official
LiveSecBenchpsychological_health#30 / 43↑34.35Source ↗official
MACHIAVELLIdeception_relative_random_pct#13 / 50↓84.2Source ↗official
Manager Coercion Benchcoercion_ladder_depth#29 / 45↓8.667Source ↗self run
MASKlying_probability_pct#47 / 53↓53.33Source ↗official
RealityTest — Text AI-Identity Disclosuredisclosure_probability#4 / 17↑0.552Source ↗official
Shelleducation_jsr#4 / 14↓0.426Source ↗official
Shellfinance_jsr#3 / 14↓0.22Source ↗official
Shellmanagement_jsr#2 / 14↓0.346Source ↗official
Social Welfare Function Benchmarkfairness#1 / 19↑0.637Source ↗official
SpeciEvalbelief_animal_sentience#80 / 131↑6.725Source ↗official
SpeciEvalland_animal_4ns#99 / 131↓4.775Source ↗official
SpeciEvalsea_animal_4ns#119 / 131↓5.13Source ↗official
SpeciEvalspeciesism#24 / 131↓1.505Source ↗official
UAVBench safety-critical decision recognitionethical_safety_critical_accuracy#15 / 27↑0.685Source ↗official
Vectara HHEM Factual Consistencyfactual_consistency_rate#86 / 94↑82.1Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry — AILuminate Baseline and Poetry ASRbaseline_asr#14 / 24↑6.045Source ↗official
Adversarial Poetry — AILuminate Baseline and Poetry ASRpoetry_asr#12 / 24↑51.88Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#52 / 80↓0.741Source ↗official
CAIS Risk Indexbioweapons_assistance#8 / 54↑93Source ↗official
Cisco AI Defense Rolling Single-Turn Leaderboardsingle_turn_attack_success_rate#70 / 104↑20.59Source ↗official
Concordia — AirBench-Deceptionsafety_score#33 / 63↓85.19Source ↗official
Concordia — AirBench-Manipulationsafety_score#27 / 56↓88Source ↗official
Concordia — AirBench-PoliticalPersuasionsafety_score#32 / 56↓67.14Source ↗official
Concordia — AirBench-SecurityRiskssafety_score#28 / 63↓90.54Source ↗official
Concordia — Fortress-Biologicalsafety_score#23 / 54↓46.08Source ↗official
Concordia — Fortress-Chemicalsafety_score#24 / 54↓46.59Source ↗official
Concordia — Fortress-Privacy/Scamssafety_score#20 / 54↓53.02Source ↗official
Concordia — FRT-AirBench-Manipulationsafety_score#20 / 45↓32.67Source ↗official
Concordia — FRT-AirBench-SecurityRiskssafety_score#16 / 45↓19.67Source ↗official
Concordia — FRT-SciKnowEval-BiologicalHarmfulQAsafety_score#32 / 45↓4.667Source ↗official
Concordia — FRT-SOSBench-Chemsafety_score#33 / 45↓64Source ↗official
Concordia — SciKnowEval-BiologicalHarmfulQAsafety_score#18 / 63↓67.34Source ↗official
Concordia — SciKnowEval-ChemicalHarmfulQAsafety_score#20 / 63↓12.11Source ↗official
Concordia — SOSBench-Biosafety_score#38 / 63↓88.6Source ↗official
Concordia — SOSBench-Chemsafety_score#23 / 63↓80.6Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#79 / 270↓81.44Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#154 / 270↓79.16Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#45 / 268↓90.97Source ↗official
FORTRESSaverage_risk_score#10 / 60↑55.47Source ↗official
FORTRESSover_refusal_score#23 / 59↓3.33Source ↗official
HELM Safetyanthropic_red_team#50 / 80↓0.993Source ↗official
HELM Safetyharmbench#72 / 80↓0.974Source ↗official
HELM Safetysimple_safety_tests#58 / 80↓1Source ↗official
HELM Safetyxstest#9 / 80↑0.982Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 69↓0Source ↗official
LiveSecBenchethics#4 / 43↓20.12Source ↗official
LiveSecBenchlegality#17 / 43↓31.19Source ↗official
LiveSecBenchprivacy#36 / 43↓73.81Source ↗official
LiveSecBenchpsychological_health#14 / 43↓34.35Source ↗official
Shelleducation_jsr#11 / 14↑0.426Source ↗official
Shellfinance_jsr#12 / 14↑0.22Source ↗official
Shellmanagement_jsr#13 / 14↑0.346Source ↗official
SpeechMap model completioncomplete_pct#102 / 181↑52.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#73 / 156↑2.167Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#76 / 156↑3.333Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-29
Government45.5
Diplomacy69.4
Economy47
Society67.8

The Economist World Values Survey Cultural Map

DimensionValueDistribution
Survival ↔ Self-expression2.62
Traditional ↔ Secular0.427