CarryOnBench - Harmfulness (Oracle Intent): leaderboard
Metric: Harmfulness (1-5): GPT-5.2 rates each response for harmful or policy-violating content (4 or more is harmful); a conversation scores its worst turn, averaged over conversations, over a single turn in which the query states the full benign intent, on CarryOnBench (398 seemingly harmful SORRY-Bench queries with a benign underlying intent; user turns simulated by Gemini-3-Flash); lower is better. Source: arxiv.org. Saturation forecast: Not forecast. 14 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Haiku 4.5 | 1.5 |
| 2 | GPT-5.4 | 1.6 |
| 3 | GPT-OSS-120B | 1.6 |
| 4 | GPT-5 Mini | 1.6 |
| 5 | Olmo 3.1 32B Instruct | 1.6 |
| 6 | Qwen 3 235B A22B | 1.9 |
| 7 | OLMo 3 7B Instruct | 1.9 |
| 8 | Claude Sonnet 4 | 2.1 |
| 9 | Qwen 3 Next 80B A3B Instruct | 2.3 |
| 10 | Gemini 3.1 Pro (Preview) | 2.4 |
| 11 | Llama 4 Maverick | 2.4 |
| 12 | Mixtral 8x7B Instruct (v0.1) | 2.6 |
| 13 | Qwen 3 32B | 2.8 |
| 14 | DeepSeek V3.1 | 2.9 |
Interactive version: theaggregate.ai/benchmark?slug=carryonbench-harmfulness-oracle-intent · How It Works · Data refreshed daily, snapshot 2026-10-07.