Search arXivSearch

arXiv · 2503.05731

AILuminate: Introducing v1.0 of the AI Risk and Reliability Benchmark from MLCommons

Shaona Ghosh·Heather Frase·Adina Williams·Sarah Luger·Paul Röttger·Fazl Barez·Sean McGregor·Kenneth Fricklas·Mala Kumar·Quentin Feuillade--Montixi·Kurt Bollacker·Felix Friedrich·Ryan Tsang·Bertie Vidgen·Alicia Parrish·Chris Knotz·Eleonora Presani·Jonathan Bennion·Marisa Ferrara Boston·Mike Kuniavsky·Wiebke Hutiri·James Ezick·Malek Ben Salem·Rajat Sahay·Sujata Goswami·Usman Gohar·Ben Huang·Supheakmungkol Sarin·Elie Alhajjar·Canyu Chen·Roman Eng·Kashyap Ramanandula Manjusha·Virendra Mehta·Eileen Long·Murali Emani·Natan Vidra·Benjamin Rukundo·Abolfazl Shahbazi·Kongtao Chen·Rajat Ghosh·Vithursan Thangarasa·Pierre Peigné·Abhinav Singh·Max Bartolo·Satyapriya Krishna·Mubashara Akhtar·Rafael Gold·Cody Coleman·Luis Oala·Vassil Tashev·Joseph Marvin Imperial·Amy Russ·Sasidhar Kunapuli·Nicolas Miailhe·Julien Delaunay·Bhaktipriya Radharapu·Rajat Shinde·Tuesday·Debojyoti Dutta·Declan Grabb·Ananya Gangavarapu·Saurav Sahay·Agasthya Gangavarapu·Patrick Schramowski·Stephen Singam·Tom David·Xudong Han·Priyanka Mary Mammen·Tarunima Prabhakar·Venelin Kovatchev·Rebecca Weiss·Ahmed Ahmed·Kelvin N. Manyeki·Sandeep Madireddy·Foutse Khomh·Fedor Zhdanov·Joachim Baumann·Nina Vasan·Xianjun Yang·Carlos Mougn·Jibin Rajan Varghese·Hussain Chinoy·Seshakrishna Jitendar·Manil Maskey·Claire V. Hardgrove·Tianhao Li·Aakash Gupta·Emil Joswin·Yifan Mai·Shachi H Kumar·Cigdem Patlak·Kevin Lu·Vincent Alessi·Sree Bhargavi Balija·Chenhe Gu·Robert Sullivan·James Gealy·Matt Lavrisa·James Goel·Peter Mattson

Abstract

The rapid advancement and deployment of AI systems have created an urgent need for standard safety-evaluation frameworks. This paper introduces AILuminate v1.0, the first comprehensive industry-standard benchmark for assessing AI-product risk and reliability. Its development employed an open process that included participants from multiple fields. The benchmark evaluates an AI system's resistance to prompts designed to elicit dangerous, illegal, or undesirable behavior in 12 hazard categories, including violent crimes, nonviolent crimes, sex-related crimes, child sexual exploitation, indiscriminate weapons, suicide and self-harm, intellectual property, privacy, defamation, hate, sexual content, and specialized advice (election, financial, health, legal). Our method incorporates a complete assessment standard, extensive prompt datasets, a novel evaluation framework, a grading and reporting system, and the technical as well as organizational infrastructure for long-term support and evolution. In particular, the benchmark employs an understandable five-tier grading scale (Poor to Excellent) and incorporates an innovative entropy-based system-response evaluation. In addition to unveiling the benchmark, this report also identifies limitations of our method and of building safety benchmarks generally, including evaluator uncertainty and the constraints of single-turn interactions. This work represents a crucial step toward establishing global standards for AI risk and reliability evaluation while acknowledging the need for continued development in areas such as multiturn interactions, multimodal understanding, coverage of additional languages, and emerging hazard categories. Our findings provide valuable insights for model developers, system integrators, and policymakers working to promote safer AI deployment.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Shaona Ghosh, Heather Frase, Adina Williams, Sarah Luger, Paul Röttger, Fazl Barez, Sean McGregor, Kenneth Fricklas, Mala Kumar, Quentin Feuillade--Montixi, Kurt Bollacker, Felix Friedrich, Ryan Tsang, Bertie Vidgen, Alicia Parrish, Chris Knotz, Eleonora Presani, Jonathan Bennion, Marisa Ferrara Boston, Mike Kuniavsky, Wiebke Hutiri, James Ezick, Malek Ben Salem, Rajat Sahay, Sujata Goswami, Usman Gohar, Ben Huang, Supheakmungkol Sarin, Elie Alhajjar, Canyu Chen, Roman Eng, Kashyap Ramanandula Manjusha, Virendra Mehta, Eileen Long, Murali Emani, Natan Vidra, Benjamin Rukundo, Abolfazl Shahbazi, Kongtao Chen, Rajat Ghosh, Vithursan Thangarasa, Pierre Peigné, Abhinav Singh, Max Bartolo, Satyapriya Krishna, Mubashara Akhtar, Rafael Gold, Cody Coleman, Luis Oala, Vassil Tashev, Joseph Marvin Imperial, Amy Russ, Sasidhar Kunapuli, Nicolas Miailhe, Julien Delaunay, Bhaktipriya Radharapu, Rajat Shinde, Tuesday, Debojyoti Dutta, Declan Grabb, Ananya Gangavarapu, Saurav Sahay, Agasthya Gangavarapu, Patrick Schramowski, Stephen Singam, Tom David, Xudong Han, Priyanka Mary Mammen, Tarunima Prabhakar, Venelin Kovatchev, Rebecca Weiss, Ahmed Ahmed, Kelvin N. Manyeki, Sandeep Madireddy, Foutse Khomh, Fedor Zhdanov, Joachim Baumann, Nina Vasan, Xianjun Yang, Carlos Mougn, Jibin Rajan Varghese, Hussain Chinoy, Seshakrishna Jitendar, Manil Maskey, Claire V. Hardgrove, Tianhao Li, Aakash Gupta, Emil Joswin, Yifan Mai, Shachi H Kumar, Cigdem Patlak, Kevin Lu, Vincent Alessi, Sree Bhargavi Balija, Chenhe Gu, Robert Sullivan, James Gealy, Matt Lavrisa, James Goel, Peter Mattson. 2025-04-18. AILuminate: Introducing v1.0 of the AI Risk and Reliability Benchmark from MLCommons. https://arxiv.org/abs/2503.05731

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Who Should Be Generated? Justifying Demographic Targets in Open-Ended Generation

Fairness evaluation concerns not only what a model produces, but also what its outputs ought to be compared against. When a model generates "a CEO in the United States," the prompt leaves demographic realization to the model. Existing group fairness definitions assume that sensitive attributes are given on the input side. Generative audits instead examine output-side demographic composition, yet the targets they compare it against are typically supplied rather than justified. The upstream question is what the target distribution should be. We formalize this missing-target problem for demographic-value-unspecified generation and decompose target construction into four commitments: the evaluative object, prior admissibility, allocation, and operationalization. In this framework, we admit the geographic prior under a geographic-membership interpretation for the declared public-world use. The occupational prior, under an incumbency interpretation, requires an independently defended objective such as workforce-composition fidelity. Instantiating this construction in AP-Bench, we find substantial distribution divergence from geography-derived targets, ranging from 0.508 to 0.606 on a 0-to-1 scale. Replacing each geography-derived target with an equal-category comparator, while holding generations and measurement fixed, produces model-specific mean absolute cell-level $\mathrm{JSD}_2$ changes ranging from 0.279 to 0.355. Target construction is therefore not a preliminary to fairness evaluation but a component of it. What we supply is not a universal target, but a framework that makes explicit the justification required before a distribution can serve as a fairness standard.

cs.CY

Anticipatory Human Oversight of Agentic AI: A Philosophical Account

Human oversight is widely held to mitigate the risks of AI systems. Even for systems that produce discrete outputs at identifiable decision points, the realisation of human oversight as a reactive measure is empirically fragile, yet increasingly well understood. However, for agentic AI -- systems that plan, decompose goals, and execute multi-step actions over extended horizons -- reactive oversight reaches its structural limits: intervention on individual actions defeats the autonomy that motivates the deployment, while intervention on aggregate patterns is too coarse for harms whose cumulative consequences only become legible after the fact. This paper argues that reactive oversight must be complemented by an anticipatory mode: oversight exercised before the agent acts, by specifying the normative agenda that structures the space of permissible action and refining it iteratively through specification, runtime, and inspection. The two are complements -- the agenda's escalation conditions specify when reactive intervention is invoked. Drawing on Meaningful Human Control, we read anticipatory oversight as the operationalisation of distal-reason tracking. In addition, we argue that the proposed framework yields a specific responsibility architecture by design: occupying the anticipatory mode is the discharge of a role-grounded prospective obligation, and backward-looking responsibility takes the form of strict moral answerability -- rationalistic, relational, and holding regardless of fault, in virtue of the principal's prior opportunity for precaution. We develop bridging failure modes, address objections including moral luck and the illusion of control, and close with regulatory, architectural, and empirical implications

cs.CY

Critical Data Studies in the Anthropocene

This chapter introduces the concept of the Anthropocene into critical data studies, a field that has, for the past decade, explored the entanglements between datafication and politics. With the scaling up of contemporary datafication alongside generative computing, it is essential to expand these debates, both theoretically and methodologically, to consider the logics of extraction and exploitation inherent in the politics of artificial intelligence. Critical data scholars are called to interrogate how dominant narratives around the materiality of contemporary datafication either obscure or reveal its environmental impacts, along other key questions such as who benefits from these logics. To illustrate this, this chapter brings two case studies from Spain and Chile and explores how the infrastructure of contemporary datafication intersects with existing power structures, influencing which social and environmental consequences are recognized, addressed, and neglected. Finally, it invites critical data scholars to keep exploring the politics of data, infrastructure, and the Anthropocene by blending discipline boundaries between science and technology studies, media, geography, and political ecology.

cs.CY