Stanford CRFM leaderboard that scores a model by averaging its results across five existing safety benchmarks into one 0-1 number.
unassessed
| Category | safety |
|---|---|
| Page status | active |
| Metric | Mean score (unweighted average of five normalized per-scenario scores) |
| Direction | higher_is_better |
| Unit | 0-1 scale |
| Publisher | Stanford Center for Research on Foundation Models (CRFM) |
HELM Safety is a Stanford CRFM leaderboard that scores a model's refusal and bias behaviour across five existing safety datasets: BBQ, SimpleSafetyTests, HarmBench, AnthropicRedTeam, and XSTest. Together they probe six risk categories CRFM drew from AI developers' acceptable-use policies: violence, fraud, discrimination, sexual content, harassment, and deception. A model sees single-turn prompts ranging from overtly unsafe requests, through red-teamed jailbreak attempts meant to bypass guardrails, to sensitive-sounding but benign questions; BBQ instead asks multiple-choice questions testing whether the model leans on a social stereotype when context does not support one.
Single-turn prompts; graded by exact-match accuracy (BBQ) or a two-model LLM-judge harmfulness/helpfulness rating (the other four scenarios).
| Model | Provider | Score | Card as of |
|---|---|---|---|
| Llama Guard 3 8B | Meta | 95.2 | 2026-04 |
| Llama Guard 3 8B INT8 | Meta | 95.2 | 2026-04 |
| shieldgemma 27B | Google DeepMind | 94.5 | 2026-04 |
| shieldgemma 9B | Google DeepMind | 93.2 | 2026-04 |
| Llama Guard 3 1B | Meta | 92.8 | 2026-04 |
| Claude Opus 4 | Anthropic | 92.5 | 2026-04 |
| Claude Opus 4.6 | Anthropic | 92.5 | 2026-04 |
| Claude Sonnet 4 | Anthropic | 91.8 | 2026-04 |
| Claude Sonnet 4.5 | Anthropic | 91.8 | 2026-04 |
| Claude Sonnet 4.5 (latest) | Anthropic | 91.8 | 2026-04 |
| Claude Sonnet 3.5 | Anthropic | 91.5 | 2026-04 |
| Claude Sonnet 3.5 v2 | Anthropic | 91.5 | 2026-04 |
| Claude Opus 3 | Anthropic | 90.8 | 2026-04 |
| GPT-4 | OpenAI | 90.5 | 2026-04 |
| GPT-4.1 | OpenAI | 90.5 | 2026-04 |
| GPT-4.1 mini | OpenAI | 90.5 | 2026-04 |
| GPT-4.1 nano | OpenAI | 90.5 | 2026-04 |
| Claude Haiku 3.5 | Anthropic | 89.8 | 2026-04 |
| Claude Haiku 3.5 (latest) | Anthropic | 89.8 | 2026-04 |
| Claude Sonnet 3 | Anthropic | 89.5 | 2026-04 |
| GPT-4 Turbo | OpenAI | 89.5 | 2026-04 |
| GPT-4o | OpenAI | 89.2 | 2026-04 |
| GPT-4o (2024-05-13) | OpenAI | 89.2 | 2026-04 |
| GPT-4o (2024-08-06) | OpenAI | 89.2 | 2026-04 |
| GPT-4o (2024-11-20) | OpenAI | 89.2 | 2026-04 |
| GPT-4o mini | OpenAI | 89.2 | 2026-04 |
| Gemini 2.5 Pro | Google DeepMind | 88.5 | 2026-04 |
| Gemini 2.5 Pro Preview 05-06 | Google DeepMind | 88.5 | 2026-04 |
| Gemini 2.5 Pro Preview 06-05 | Google DeepMind | 88.5 | 2026-04 |
| Gemini 2.5 Pro Preview TTS | Google DeepMind | 88.5 | 2026-04 |
| Claude Haiku 3 | Anthropic | 88.2 | 2026-04 |
| Gemini 2.0 Flash | Google DeepMind | 87.8 | 2026-04 |
| Gemini 1.5 Pro | Google DeepMind | 87.5 | 2026-04 |
| Pixtral Large (latest) | Mistral AI | 86.8 | 2026-04 |
| Llama 4 Maverick 17B 128E Instruct | Meta | 86.5 | 2026-04 |
| Llama-4-Maverick-17B-128E-Instruct-FP8 | Meta | 86.5 | 2026-04 |
| Gemini 1.5 Flash | Google DeepMind | 86.2 | 2026-04 |
| Gemini 1.5 Flash-8B | Google DeepMind | 86.2 | 2026-04 |
| Gemini 2.0 Flash Lite | Google DeepMind | 85.5 | 2026-04 |
| Llama 4 Scout 17B 16E | Meta | 85.2 | 2026-04 |
| Llama 4 Scout 17B 16E Instruct | Meta | 85.2 | 2026-04 |
| Llama-4-Scout-17B-16E-Instruct-FP8 | Meta | 85.2 | 2026-04 |
| Llama 3.2 90B Vision | Meta | 84.5 | 2026-04 |
| Llama 3.2 90B Vision Instruct | Meta | 84.5 | 2026-04 |
| Llama 3.3 70B Instruct NVFP4 | NVIDIA | 84.2 | 2026-04 |
| Llama-3.3-70B-Instruct | Meta | 84.2 | 2026-04 |
| Qwen2.5-VL 72B Instruct | Alibaba / Qwen Team | 84.2 | 2026-04 |
| Command R+ | Cohere | 83.5 | 2026-04 |
| Pixtral 12B | Mistral AI | 83.5 | 2026-04 |
| Mistral Large (latest) | Mistral AI | 82.8 | 2026-04 |
| Mistral Large 2.1 | Mistral AI | 82.8 | 2026-04 |
| Mistral Large 3 | Mistral AI | 82.8 | 2026-04 |
| Llama 3.1 70B | Meta | 82.5 | 2026-04 |
| Llama 3.1 70B Instruct | Meta | 82.5 | 2026-04 |
| Llama 3.2 11B Vision | Meta | 82.5 | 2026-04 |
| Llama 3.2 11B Vision Instruct | Meta | 82.5 | 2026-04 |
| Qwen2.5 72B Instruct | Alibaba / Qwen Team | 80.5 | 2026-04 |
| Llama 3.1 8B | Meta | 78.5 | 2026-04 |
| Llama 3.1 8B Instruct | Meta | 78.5 | 2026-04 |
| Llama 3.1 8B Instruct | Unsloth | 78.5 | 2026-04 |
| Llama 3.1 8B Instruct FP8 | NVIDIA | 78.5 | 2026-04 |
| Llama 3.1 8B Instruct NVFP4 | NVIDIA | 78.5 | 2026-04 |
| DeepSeek Chat | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V2 | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V2 Lite | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V2 Lite Chat | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V3 | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V3 0324 | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V3.1 | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V3.2 | DeepSeek | 78.2 | 2026-04 |
| DeepSeek V3.2 Exp | DeepSeek | 78.2 | 2026-04 |