safety benchmark
XSTest is a test suite for identifying exaggerated safety behaviours in large language models.
Updated Sep 5, 2026
Higher score ranks better on this benchmark.
Rank | Model | Score | Percentile | Participants | Evidence | Evaluated |
|---|
| Rank01 | ModelGO | Score98.80% | Percentile100.00% | Participants4 | EvidenceC | Evaluated |
| Rank02 | ModelGO | Score97.00% | Percentile66.67% | Participants4 | EvidenceC | Evaluated |
| Rank03 | ModelMA | Score94.60% | Percentile33.33% | Participants4 | EvidenceC | Evaluated |
| Rank04 | ModelGO | Score92.60% | Percentile0.00% | Participants4 | EvidenceC | Evaluated |
The leading models and scores on this benchmark.
A closer view of the leading scores on this benchmark.
The first five results on this benchmark, with official price and output speed added where the model identity can be matched.
What XSTest measures and how its scores work.
XSTest comprises 450 prompts: 250 safe prompts across ten prompt types that well-calibrated models should not refuse to comply with, and 200 unsafe prompts that models should refuse.
It measures whether models refuse to respond to clearly safe prompts due to overly cautious safety mechanisms, using the Score metric reported as a ratio.
Scores are shown in ratio. This benchmark is not independently verified and has an evidence level of B.
LLM Stats. Benchmark scores retain their original unit. Overall score eligibility is shown separately.
Common questions about XSTest.
Gemini 1.5 Pro is currently ranked first with 98.80%.
The current leaders are Gemini 1.5 Pro (98.80%), Gemini 1.5 Flash (97.00%), and Shieldstral 1.0 (3B) (94.60%).
No matched official input price is currently available.
The fastest matched records are Gemini 1.5 Flash (150.00 tok/s via Google), Gemini 1.5 Flash 8B (150.00 tok/s via Google), and Gemini 1.5 Pro (85.00 tok/s via Google).
No. This benchmark measures one defined capability or task. The overall LLMBoard score uses a separate aggregation across eligible benchmark evidence.
It measures whether models refuse to respond to clearly safe prompts due to overly cautious safety mechanisms, using the Score metric reported as a ratio.
Yes. Higher values rank better for this benchmark.
4 model results are currently shown.
No. This benchmark is shown for reference but does not contribute to the overall score.
Ranking basisThis xstest AI model leaderboard uses descending score in the benchmark original unit. The leaderboard ranking keeps matched price and speed data separate from benchmark evidence.
Selection summary
Gemini 1.5 Pro currently leads XSTest with 98.80%. It is the top model on this specific benchmark, while the best LLM for the broader task should also be checked against other benchmarks, price, and runtime.
Use this leaderboard with the supporting benchmark results and coverage details above. A leaderboard position summarizes the selected ranking signal; it does not replace workload-specific testing.