PolicyShiftBench - Shift Split: leaderboard
Metric: F1 of the block decision (%; policy-conditioned image guardrailing: decide whether an image violates the supplied runtime policy bundle (one policy variant per risk category, seven categories); Shift split, 1,000 instances over 152 images under 12 held-out policy definitions; mean of three evaluations). Source: arxiv.org. Saturation forecast: Around December 2026. 19 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Gemini 3 Flash (Preview) | 74.2 |
| 2 | GPT-5.4 | 57.8 |
| 3 | Qwen 3.5 35B A3B (Thinking) | 41.3 |
| 4 | Qwen 3.5 4B (Non-reasoning) | 35.7 |
| 5 | Qwen 3.5 35B A3B (Non-reasoning) | 32.5 |
| 6 | Claude Sonnet 4.6 | 27 |
| 7 | Qwen 3.5 4B (Thinking) | 25.3 |
| 8 | Qwen 2.5 VL 7B | 12.1 |
| 9 | Qwen 3.5 0.8B (Non-reasoning) | 4.3 |
| 10 | Qwen 3.5 2B (Non-reasoning) | 0 |
Interactive version: theaggregate.ai/benchmark?slug=policyshiftbench-shift-split · How It Works · Data refreshed daily, snapshot 2026-09-29.