SafePyramid: leaderboard
Metric: Rule matching rate (%) over SafePyramid's 3,000 cases (1,000 conversations in 10 domains, each with an L0, L1 and L2 policy): per case (a multi-turn conversation plus an in-context safety policy), the predicted set of violated rules matches the ground-truth set when neither false positives nor false negatives exceed (1 - tau) of the true violations; averaged over tau = 0.7, 0.8, 0.9 and 1.0; per-policy evaluation, refused cases excluded; higher is better. Source: arxiv.org. Saturation forecast: Around April 2028. 12 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.5 (xHigh) | 54.2 |
| 2 | Claude Opus 4.7 (Max) | 52.9 |
| 3 | DeepSeek V4 Pro (Max) | 52.2 |
| 4 | Seed 2.0 Pro (High) | 50 |
| 5 | Gemini 3.5 Flash (High) | 49.6 |
| 6 | Hy3-preview (High) | 49.1 |
| 7 | Qwen 3.6 Max (Preview) (Thinking) | 47.4 |
| 8 | Grok 4.3 (High) | 40.6 |
| 9 | gpt-oss-safeguard-20B | 22.5 |
Interactive version: theaggregate.ai/benchmark?slug=safepyramid · How It Works · Data refreshed daily, snapshot 2026-09-29.