ModelRiskIndex

Rankings / Meta

Llama 4 Maverick

Tier 150/100open weights

Llama-4-Maverick-17B-128E-Instruct (open weights, self-hosted reference)

Usage share 0.06% · OpenRouter rankings API (daily token share, 2026-08-04)

Graded as the self-hosted reference deployment. The Mistral objection to company-level safety indexes applies here with full force: the deployer controls fine-tuning, guardrails, and data handling. Vectors that are deployer properties are marked as such.

Tier assessment
Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. Safety evaluations for this model are published.Safety section in the model card is thin but present; Llama Protections documentation supplements it.
  • Documented safety policy. A documented safety, usage, or acceptable-use policy governs the model.
  • Enterprise data controls. Not applicable to this artifact.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.No certification pathway currently exists for open weights — an open methodology question, not a gap unique to this provider.
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Immutable published checkpoints are the strongest possible versioning discipline.
  • Stated deprecation policy. A deprecation policy with notice windows is published.Weights remain available once released; hosted-provider availability varies.

Missing for Tier 2: external pre-deployment testing, third-party certification. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancen/a — deployer

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Deployer property, not a property of the weights: in the self-hosted reference deployment, prompts and outputs never leave deployer infrastructure. Hosted providers' terms vary and are not graded here.

Receipts (1)

Operational stabilitystrong

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Published immutable weights are the strongest possible versioning discipline: a given checkpoint cannot change silently, ever. Releases are explicit and diffable.

Receipts (1)
  • Llama 4 release announcement
    Meta / Llama provider artifacts · provider artifact · source tier B · ai.meta.com · retrieved 2026-08-03
    We're making Llama 4 Scout and Llama 4 Maverick available for download today on llama.com and Hugging Face so everyone can continue to build new experiences using our latest technology.

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

The bare model jailbreaks readily in independent testing. Meta ships Llama Guard and Prompt Guard as separate optional layers, but the graded artifact — the weights as released — carries little built-in resistance.

Prompt injection (agentic)weak

No built-in agentic injection hardening; Prompt Guard exists as an add-on classifier but is off by default and trivially omitted by deployers.

Receipts (3)
  • F5 Labs CASI leaderboard
    F5 Labs CASI/ARS leaderboard · independent eval · source tier C · f5.com · retrieved 2026-08-03
    Bottom-quartile composite security index among tracked frontier models.
  • Llama Protections (Llama Guard, Prompt Guard)
    Meta / Llama provider artifacts · provider artifact · source tier B · llama.com · retrieved 2026-08-03
    Our comprehensive system-level protections framework proactively identifies and mitigates potential risks, empowering developers to more easily deploy generative AI responsibly.
  • Llama Protections (Llama Guard, Prompt Guard)
    Meta / Llama provider artifacts · provider artifact · source tier B · llama.com · retrieved 2026-08-03
    LlamaFirewall can orchestrate across guard models and work with our suite of protection tools to detect and prevent risks such as prompt injection, insecure code and risky tool interactions.

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Model card and benchmark disclosures exist, but no external pre-deployment testing, and the launch-time LM Arena benchmark episode (an experimental variant submitted to the public leaderboard) damaged disclosure credibility.

Receipts (1)
  • Llama 4 model card
    Meta / Llama provider artifacts · provider artifact · source tier B · github.com · retrieved 2026-08-03
    Capability evaluations measure vulnerabilities of Llama models inherent to specific capabilities, for which were crafted dedicated benchmarks including long context, multilingual, coding or memorization.

Compliance posturen/a — deployer

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Deployer property: no certification attaches to open weights; compliance posture is entirely inherited from whichever deployer or host runs the model.

Receipts (1)

Governance & evidence

Where your data goes

  • SELF

No regional pinning — the provider chooses where data is processed.

Self-hosted reference deployment: data never leaves deployer infrastructure; hosted providers' terms vary and are not graded here.

Enterprise vs consumer terms

Enterprise vs consumer gap: none measured. Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against. No consumer tier exists for the self-hosted reference deployment; data handling is deployer-controlled.CONSUMERENTERPRISE / APIWORSE TERMS →
No measured gap

No consumer tier exists for the self-hosted reference deployment; data handling is deployer-controlled.

Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against.

Change cadence

insufficient history1 tracked change · last 2026-08-04 · 1d since Insufficient history to estimate a cadence.1d

One tracked change, on 2026-08-04 — 1 days before the as-of date (2026-08-05). A single event cannot establish a cadence, so days-since is shown without a baseline.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

8 evidence refs3 distinct sources1 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • BMeta / Llama provider artifactsprovider artifact×6 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-03 — 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
not verified
Retention window
Deployer-controlled
Data residency
Deployer-controlled
EU AI Act
Open-weight GPAI models have reduced obligations under the EU AI Act; deployer obligations apply.
Deprecation policy
Weights remain available once released; hosted-provider availability varies
Available via
Self-hosted · AWS Bedrock · Google Vertex AI · Azure AI Foundry · Multiple inference providers

Incident history

2025-04-08
Llama 4 Maverick LM Arena submission used unreleased experimental variant
Benchmark presentation (not an attack)

Meta's leaderboard submission was an experimental chat-tuned variant, not the released weights, inflating public perception of the released model. Recorded under transparency: disclosure practices are part of the risk surface buyers rely on.

Outcome: LM Arena updated its policies; Meta acknowledged the variant difference.

Sources (1)
  • LMSYS statement
    LMArena leaderboard statements · independent eval · source tier C · lmarena.ai · retrieved 2026-08-03

Change timeline

2026-08-04
Methodology v0.2: computed tiers and first-class N/A grades
methodologynotice

Tiers are now derived from a per-requirement checklist rather than assigned, and not-applicable / under-review became first-class grade states excluded from the composite score. Deployer-property vectors on open-weight models (data handling, compliance) moved from graded to not-applicable, changing the composite scores of the tagged models.

Evidence (1)

Compare this model: Llama 4 Maverick + open compare view →