Dynamic adversarial user simulations
Does the model follow the publisher's safety policy under challenging prompts?
Safety4 ranked models6 reported values1 reportsHigher is better
Top rankings
One row per model, using its best reported score across effort settings.
| Rank | Model | Best score | Best reported setting |
|---|---|---|---|
| 1 | GPT-5.5OpenAI | 0.989 | Reported configurationOpenAI report3 values · 1 reportAug 6, 2026 · source |
| 2 | GPT-5.3 InstantOpenAI | 0.987 | Reported configurationOpenAI report1 value · 1 reportAug 6, 2026 · source |
| 3 | GPT-5.6 LunaOpenAI | 0.965 | Reported configurationOpenAI report1 value · 1 reportAug 6, 2026 · source |
| 4 | GPT-5.6 SolOpenAI | 0.961 | Reported configurationOpenAI report1 value · 1 reportAug 6, 2026 · source |
Effort curve
Every sourced cost-linked effort value for this exact version. Lines connect complete sweeps only.
No cost-linked effort sweep for this version.
Definition and comparison boundarylimited methodology
Does the model follow the publisher's safety policy under challenging prompts?
Publisher-defined safety behavior, robustness, or preparedness evaluations under the stated test protocol. Higher is better. Raw not_unsafe share in the publisher's [0,1] scale.
Harness, tools, prompts, attempt count, and benchmark version can materially change the result. Compare within one reporting context.
Dynamic multi-turn evaluation; metric is the share of assistant messages that do not violate safety policies.
Method / source