CarryOnBench - Harmfulness (Oracle Intent): leaderboard

Metric: Harmfulness (1-5): GPT-5.2 rates each response for harmful or policy-violating content (4 or more is harmful); a conversation scores its worst turn, averaged over conversations, over a single turn in which the query states the full benign intent, on CarryOnBench (398 seemingly harmful SORRY-Bench queries with a benign underlying intent; user turns simulated by Gemini-3-Flash); lower is better. Source: arxiv.org. Saturation forecast: Not forecast. 14 models tracked.

Top models

#ModelScore
1Claude Haiku 4.51.5
2GPT-5.41.6
3GPT-OSS-120B1.6
4GPT-5 Mini1.6
5Olmo 3.1 32B Instruct1.6
6Qwen 3 235B A22B1.9
7OLMo 3 7B Instruct1.9
8Claude Sonnet 42.1
9Qwen 3 Next 80B A3B Instruct2.3
10Gemini 3.1 Pro (Preview)2.4
11Llama 4 Maverick2.4
12Mixtral 8x7B Instruct (v0.1)2.6
13Qwen 3 32B2.8
14DeepSeek V3.12.9

Interactive version: theaggregate.ai/benchmark?slug=carryonbench-harmfulness-oracle-intent · How It Works · Data refreshed daily, snapshot 2026-10-07.