CarryOnBench - Harmfulness (Turn 1): leaderboard

Metric: Harmfulness (1-5): GPT-5.2 rates each response for harmful or policy-violating content (4 or more is harmful); a conversation scores its worst turn, averaged over conversations, over the first response to the bare query, on CarryOnBench (398 seemingly harmful SORRY-Bench queries with a benign underlying intent; user turns simulated by Gemini-3-Flash); lower is better. Source: arxiv.org. Saturation forecast: Not forecast. 14 models tracked.

Top models

#ModelScore
1Olmo 3.1 32B Instruct1.3
2GPT-5.41.4
3GPT-OSS-120B1.4
4GPT-5 Mini1.5
5Claude Haiku 4.51.5
6Claude Sonnet 41.5
7Qwen 3 Next 80B A3B Instruct1.5
8Qwen 3 235B A22B1.5
9OLMo 3 7B Instruct1.5
10Llama 4 Maverick1.8
11Gemini 3.1 Pro (Preview)2
12DeepSeek V3.12.2
13Qwen 3 32B2.3
14Mixtral 8x7B Instruct (v0.1)2.8

Interactive version: theaggregate.ai/benchmark?slug=carryonbench-harmfulness-turn-1 · How It Works · Data refreshed daily, snapshot 2026-10-07.