← Models

Model profile

o3

OpenAIdeveloper
2025-04-16release date
#109 / 346Safety rank
#510 / 662Freedom rank

Evidence summary

Safety. o3 has an estimated Safety rank of #109; its 90% source-sensitivity interval is #23–#202. Its behavior-only rank is #122; company governance moves the combined estimate to #109. Published Safety evidence spans 30 eval lineages and 6 of 7 components. Its strongest relative result is HELM Safety (harmbench, #3 of 80); its weakest is Arena Factuality — Search Arena (factuality-only weighting) (factuality_bt_rating, #30 of 30).

Freedom. o3 has an estimated Freedom rank of #510; its 90% source-sensitivity interval is #348–#594. Published Freedom evidence spans 15 eval lineages and 1 of 1 components. Its strongest relative result is Human Pathogen Capabilities Test (HPCT) — overall refusal (refusal_rate_pct, #1 of 69); its weakest is OpenAI o3 and o4-mini System Card (harmful_request_safety, #2 of 2).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#264 / 358↓0.8809Source ↗official
AIRBench 2024 Safety Scenariossafety_scenarios#14 / 80↑0.845Source ↗official
Arena Factuality — Search Arena (factuality-only weighting)factuality_bt_rating#30 / 30↑1082.0Source ↗official
Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating#102 / 111↑1394.0Source ↗official
BioTIERpermit_compliance_pct#44 / 52↑95.3Source ↗official
BioTIERrefuse_compliance_pct#13 / 52↑73.1Source ↗official
BullshitBench v2clear_pushback_rate#73 / 122↑0.26Source ↗official
CAIS Risk Indexbioweapons_assistance#11 / 54↓47.7Source ↗official
CAIS Risk Indexmask#23 / 57↓15.5Source ↗official
CAIS Risk Indexpolitical_manipulation#10 / 51↓39Source ↗official
CAIS Risk Indextextquests_harm#28 / 54↓18.7Source ↗official
Confabulationsconfabulation_rate#27 / 52↓24.75Source ↗official
Emergent Collusionhigh_illegality_game_rate#9 / 13↓0.51Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#81 / 270↑23Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#77 / 270↑90.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#55 / 270↑93.89Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#177 / 268↑95.05Source ↗official
FlagEval Safety and Valuesa1_qualified_rate#5 / 18↑82.67Source ↗official
FlagEval Safety and Valuesa2_qualified_rate#1 / 18↑82.84Source ↗official
FlagEval Safety and Valuesa3_qualified_rate#5 / 18↑88.64Source ↗official
FlagEval Safety and Valuesa4_qualified_rate#5 / 18↑89.98Source ↗official
FlagEval Safety and Valuesa5_qualified_rate#8 / 18↑72.58Source ↗official
FORTRESSaverage_risk_score#13 / 60↓16.01Source ↗official
FORTRESSover_refusal_score#40 / 59↓7.42Source ↗official
HELM Safetyanthropic_red_team#50 / 80↑0.983Source ↗official
HELM Safetybbq#5 / 80↑0.979Source ↗official
HELM Safetyharmbench#3 / 80↑0.984Source ↗official
HELM Safetysimple_safety_tests#32 / 80↑0.99Source ↗official
HELM Safetyxstest#19 / 80↑0.973Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#34 / 54↑26.3Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#27 / 69↑0Source ↗official
Humanity's Last Exam RMS calibration error (Scale Labs)calibrationError#2 / 42↓36.5Source ↗official
MASKlying_probability_pct#13 / 53↓16.46Source ↗official
MonitoringBench Full-Trajectory Monitorfull_trajectory_catch_rate_at_1pct_fpr_percent#5 / 13↑31.8Source ↗official
OpenAI o3 and o4-mini System Cardharmful_request_safety#1 / 2↑0.92Source ↗official
OpenAI o3 and o4-mini System Cardjailbreak_resistance#1 / 2↑0.97Source ↗official
PropensityBenchscore#1 / 14↓10.5Source ↗official
Reward Hacking Benchmarkintegrity_score#12 / 13↑88.2Source ↗official
Shelleducation_jsr#7 / 14↓0.608Source ↗official
Shellfinance_jsr#5 / 14↓0.328Source ↗official
Shellmanagement_jsr#4 / 14↓0.482Source ↗official
SimpleQA Verifiedf1_score#3 / 13↑51.9Source ↗official
Social Welfare Function Benchmarkfairness#19 / 19↑0.433Source ↗official
SOSBenchbiology_pvr#4 / 23↓0.156Source ↗official
SOSBenchchemistry_pvr#3 / 23↓0.152Source ↗official
SOSBenchmedicine_pvr#5 / 23↓0.372Source ↗official
SOSBenchpharmacology_pvr#5 / 23↓0.424Source ↗official
SOSBenchphysics_pvr#3 / 23↓0.114Source ↗official
SOSBenchpsychology_pvr#5 / 23↓0.196Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AIRBench 2024 Safety Scenariossafety_scenarios#67 / 80↓0.845Source ↗official
BioTIERpermit_compliance_pct#44 / 52↑95.3Source ↗official
BioTIERrefuse_compliance_pct#40 / 52↓73.1Source ↗official
CAIS Risk Indexbioweapons_assistance#44 / 54↑47.7Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#189 / 270↓90.33Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#214 / 270↓93.89Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#91 / 268↓95.05Source ↗official
FORTRESSaverage_risk_score#48 / 60↑16.01Source ↗official
FORTRESSover_refusal_score#40 / 59↓7.42Source ↗official
HELM Safetyanthropic_red_team#28 / 80↓0.983Source ↗official
HELM Safetyharmbench#77 / 80↓0.984Source ↗official
HELM Safetysimple_safety_tests#42 / 80↓0.99Source ↗official
HELM Safetyxstest#19 / 80↑0.973Source ↗official
Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct#1 / 69↓0Source ↗official
OpenAI o3 and o4-mini System Cardharmful_request_safety#2 / 2↓0.92Source ↗official
OpenAI o3 and o4-mini System Cardjailbreak_resistance#2 / 2↓0.97Source ↗official
Shelleducation_jsr#8 / 14↑0.608Source ↗official
Shellfinance_jsr#10 / 14↑0.328Source ↗official
Shellmanagement_jsr#11 / 14↑0.482Source ↗official
SOSBenchbiology_pvr#20 / 23↑0.156Source ↗official
SOSBenchchemistry_pvr#21 / 23↑0.152Source ↗official
SOSBenchmedicine_pvr#19 / 23↑0.372Source ↗official
SOSBenchpharmacology_pvr#19 / 23↑0.424Source ↗official
SOSBenchphysics_pvr#21 / 23↑0.114Source ↗official
SOSBenchpsychology_pvr#19 / 23↑0.196Source ↗official
SpeechMap model completioncomplete_pct#89 / 181↑60.2Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 156↑1.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#109 / 156↑2.333Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-20.6
Government48.4
Diplomacy66.5
Economy44.8
Society60