The AI arena is free today

Open Superagent

XSTest

Paper

Progress Over Time

Interactive timeline showing model performance evolution on XSTest

State-of-the-art frontier
Open
Proprietary

XSTest Leaderboard

4 models
ContextCostLicense
1
2
33B
48B
Notice missing or incorrect data?
About this benchmark

What is XSTest?

XSTest is a test suite designed to identify exaggerated safety behaviours in large language models. It comprises 450 prompts: 250 safe prompts across ten prompt types that well-calibrated models should not refuse to comply with, and 200 unsafe prompts as contrasts that models should refuse. The benchmark systematically evaluates whether models refuse to respond to clearly safe prompts due to overly cautious safety mechanisms.

XSTest is a text benchmark evaluating models on safety tasks. LLM Stats tracks 4 models on this benchmark, scored on a 0–1 scale. The current average is 1.0, with the leader at 1.0.

Compare leaders on the best AI for safety leaderboards.

Current leaders

Gemini 1.5 Pro from Google currently leads the XSTest leaderboard with a score of 0.988 across 4 evaluated AI models.

1Gemini 1.5 ProGoogle98.8%
2Gemini 1.5 FlashGoogle97.0%
3Shieldstral 1.0 (3B)Mistral AI94.6%

Source paper

Title
XSTest: A Test Suite for Identifying Exaggerated Safety Behaviours in Large Language Models
Authors
Paul Röttger, Hannah Rose Kirk, Bertie Vidgen, Giuseppe Attanasio, and 2 others
Published
Abstract

Without proper safeguards, large language models will readily follow malicious instructions and generate toxic content. This risk motivates safety efforts such as red-teaming and large-scale feedback learning, which aim to make models both helpful and harmless. However, there is a tension between these two objectives, since harmlessness requires models to refuse to comply with unsafe prompts, and thus not be helpful. Recent anecdotal evidence suggests that some models may have struck a poor balance, so that even clearly safe prompts are refused if they use similar language to unsafe prompts or mention sensitive topics. In this paper, we introduce a new test suite called XSTest to identify such eXaggerated Safety behaviours in a systematic way. XSTest comprises 250 safe prompts across ten prompt types that well-calibrated models should not refuse to comply with, and 200 unsafe prompts as contrasts that models, for most applications, should refuse. We describe XSTest's creation and composition, and then use the test suite to highlight systematic failure modes in state-of-the-art language models as well as more general challenges in building safer language models.

FAQ

Common questions about the XSTest benchmark and leaderboard.

What is the XSTest benchmark?

XSTest is a test suite designed to identify exaggerated safety behaviours in large language models. It comprises 450 prompts: 250 safe prompts across ten prompt types that well-calibrated models should not refuse to comply with, and 200 unsafe prompts as contrasts that models should refuse. The benchmark systematically evaluates whether models refuse to respond to clearly safe prompts due to overly cautious safety mechanisms.

What is the XSTest leaderboard?

The XSTest leaderboard ranks 4 AI models based on their performance on this benchmark. Currently, Gemini 1.5 Pro by Google leads with a score of 0.988. The average score across all models is 0.958.

What is the highest XSTest score?

The highest XSTest score is 0.988, achieved by Gemini 1.5 Pro from Google.

How many models are evaluated on XSTest?

4 models have been evaluated on the XSTest benchmark, with 0 verified results and 4 self-reported results.

Where can I find the XSTest paper?

The XSTest paper is available at https://arxiv.org/abs/2308.01263. The paper details the methodology, dataset construction, and evaluation criteria.

What categories does XSTest cover?

XSTest is categorized under safety. The benchmark evaluates text models.

What is the best open-source model on XSTest?

Shieldstral 1.0 (3B) by Mistral AI is the top-ranked open-source model on XSTest, with a score of 0.946 (rank #3).

How recent are the XSTest leaderboard results?

The XSTest leaderboard was last updated in August 2026 and currently includes 4 evaluated models.