Model profile
Evidence summary
Safety. Qwen3.5 397B A17B has an estimated Safety rank of #53; its 90% source-sensitivity interval is #51–#116. Its behavior-only rank is #32; company governance moves the combined estimate to #53. Published Safety evidence spans 13 eval lineages and 7 of 7 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is DelusionEval (discourages_harm_prevalence_pct, #15 of 16).
Freedom. Qwen3.5 397B A17B has an estimated Freedom rank of #526; its 90% source-sensitivity interval is #308–#594. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is BioTIER (permit_compliance_pct, #1 of 52); its weakest is LiveSecBench (ethics, #42 of 43).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗qwen3-5-397b-a17b
- Hugging Face ↗Qwen/Qwen3.5-397B-A17B
- OpenRouter ↗qwen/qwen3.5-397b-a17b
- Official model page ↗Exact model document · Reviewed official Hugging Face owner · official repository
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #211 / 358 | ↓0.8269 | Source ↗official | |
| Arena Factuality — Text Arena (factuality-only weighting)factuality_bt_rating | #52 / 111 | ↑1439.0 | Source ↗official | |
| BioTIERpermit_compliance_pct | #1 / 52 | ↑100 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #32 / 52 | ↑29.5 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #9 / 122 | ↑0.735 | Source ↗official | |
| DelusionEvaldelusional_prevalence_pct | #7 / 16 | ↓28.65 | Source ↗official | |
| DelusionEvaldiscourages_harm_prevalence_pct | #15 / 16 | ↑12.55 | Source ↗official | |
| DelusionEvalfacilitates_harm_prevalence_pct | #5 / 16 | ↓1.15 | Source ↗official | |
| DelusionEvalrelationship_prevalence_pct | #6 / 16 | ↓21.1 | Source ↗official | |
| DelusionEvalsycophancy_prevalence_pct | #4 / 16 | ↓19.9 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #21 / 270 | ↑50.39 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #216 / 270 | ↑75.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #41 / 270 | ↑97.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #95 / 268 | ↑97.45 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #23 / 69 | ↑0.3 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #6 / 10 | ↑95.4 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #6 / 10 | ↑77.3 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #1 / 10 | ↑99.4 | Source ↗official | |
| LiveSecBenchethics | #2 / 43 | ↑89.63 | Source ↗official | |
| LiveSecBenchfactuality | #8 / 43 | ↑72.1 | Source ↗official | |
| LiveSecBenchlegality | #16 / 43 | ↑62.2 | Source ↗official | |
| LiveSecBenchprivacy | #2 / 43 | ↑94.2 | Source ↗official | |
| LiveSecBenchpsychological_health | #3 / 43 | ↑89.45 | Source ↗official | |
| SABERoverall_safety_rate | #5 / 13 | ↑26.58 | Source ↗official | |
| SABERscenario_a_safety_rate | #5 / 13 | ↑30.62 | Source ↗official | |
| SABERscenario_b_safety_rate | #4 / 13 | ↑36 | Source ↗official | |
| SABERscenario_c_safety_rate | #7 / 13 | ↑15.02 | Source ↗official | |
| SM-Benchadversarial | #55 / 92 | ↑80.49 | Source ↗official | |
| SM-Benchambiguous_interpretation | #71 / 92 | ↑79.76 | Source ↗official | |
| SM-Benchanti_hallucination | #19 / 92 | ↑98.43 | Source ↗official | |
| SM-Bencheq_boundaries | #68 / 92 | ↑58.43 | Source ↗official | |
| SM-Benchoverfit | #68 / 92 | ↑56.83 | Source ↗official | |
| TACbase_welfare_rate | #42 / 92 | ↑28.21 | Source ↗self run | |
| WildClawBench Safety & Alignment (OpenClaw harness)safety_alignment_score_pct | #9 / 24 | ↑40.53 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| BioTIERpermit_compliance_pct | #1 / 52 | ↑100 | Source ↗official | |
| BioTIERrefuse_compliance_pct | #21 / 52 | ↓29.5 | Source ↗official | |
| DelusionEvaldiscourages_harm_prevalence_pct | #2 / 16 | ↓12.55 | Source ↗official | |
| DelusionEvalfacilitates_harm_prevalence_pct | #12 / 16 | ↑1.15 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #55 / 270 | ↓75.5 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #229 / 270 | ↓97.22 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #170 / 268 | ↓97.45 | Source ↗official | |
| Human Pathogen Capabilities Test (HPCT) — overall refusalrefusal_rate_pct | #45 / 69 | ↓0.3 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #6 / 10 | ↑95.4 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #5 / 10 | ↓77.3 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #9 / 10 | ↓99.4 | Source ↗official | |
| LiveSecBenchethics | #42 / 43 | ↓89.63 | Source ↗official | |
| LiveSecBenchlegality | #28 / 43 | ↓62.2 | Source ↗official | |
| LiveSecBenchprivacy | #42 / 43 | ↓94.2 | Source ↗official | |
| LiveSecBenchpsychological_health | #41 / 43 | ↓89.45 | Source ↗official | |
| SM-Benchadversarial | #35 / 92 | ↓80.49 | Source ↗official | |
| SM-Bencheq_boundaries | #68 / 92 | ↑58.43 | Source ↗official | |
| SM-Benchoverfit | #68 / 92 | ↑56.83 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #149 / 181 | ↑37.4 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #113 / 156 | ↑2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
UGI Political Values
CCPBench political narrative alignment
| Dimension | Value | Distribution |
|---|---|---|
| CCP-narrative alignment — all questions | 3.21 | |
| CCP-narrative alignment — China topics | 3.87 | |
| CCP-narrative alignment — non-China controls | 1.22 |
Agent-ValueBench Moral Foundations (MFT08)
Agent-ValueBench HEXACO
| Dimension | Value | Distribution |
|---|---|---|
| Openness to experience | 6.5 | |
| Honesty-humility | 5.1 | |
| Extraversion | 6.3 | |
| Agreeableness | 6.7 | |
| Conscientiousness | 7.8 |