CarryOnBench - Harmfulness (Turn 1): leaderboard
Metric: Harmfulness (1-5): GPT-5.2 rates each response for harmful or policy-violating content (4 or more is harmful); a conversation scores its worst turn, averaged over conversations, over the first response to the bare query, on CarryOnBench (398 seemingly harmful SORRY-Bench queries with a benign underlying intent; user turns simulated by Gemini-3-Flash); lower is better. Source: arxiv.org. Saturation forecast: Not forecast. 14 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Olmo 3.1 32B Instruct | 1.3 |
| 2 | GPT-5.4 | 1.4 |
| 3 | GPT-OSS-120B | 1.4 |
| 4 | GPT-5 Mini | 1.5 |
| 5 | Claude Haiku 4.5 | 1.5 |
| 6 | Claude Sonnet 4 | 1.5 |
| 7 | Qwen 3 Next 80B A3B Instruct | 1.5 |
| 8 | Qwen 3 235B A22B | 1.5 |
| 9 | OLMo 3 7B Instruct | 1.5 |
| 10 | Llama 4 Maverick | 1.8 |
| 11 | Gemini 3.1 Pro (Preview) | 2 |
| 12 | DeepSeek V3.1 | 2.2 |
| 13 | Qwen 3 32B | 2.3 |
| 14 | Mixtral 8x7B Instruct (v0.1) | 2.8 |
Interactive version: theaggregate.ai/benchmark?slug=carryonbench-harmfulness-turn-1 · How It Works · Data refreshed daily, snapshot 2026-10-07.