ModelRiskIndex

Rankings / DeepSeek

DeepSeek V4 Pro

Tier 010/100open weights

deepseek-v4-pro (Preview) via api.deepseek.com

Usage share 5.1% · OpenRouter rankings API (daily token share, 2026-08-04)

Now outperformed on agent benchmarks by its cheaper sibling Flash-0731, per DeepSeek's own model card — relevant buyer guidance. Dual-nature entry graded on the hosted endpoint.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.Model card exists but contains no safety content.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.
  • Enterprise data controls. Terms permit training on customer data by default with no documented opt-out.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.Extensive independent post-release testing exists (CAISI, FAR.AI, Neo Research, Anthropic) — none disclosed pre-deployment or provider-commissioned.
  • Third-party certification. No verifiable third-party certification.
  • Versioning with changelogs. No versioning discipline or changelog for model changes.
  • Stated deprecation policy. No stated deprecation policy.

Missing for Tier 1: published safety evals, documented safety policy, enterprise data controls. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governanceweak

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Identical platform terms to V4 Flash: train-by-default with PRC storage and governing law; consumer opt-out right added Feb 2026 but API terms silent on training use.

Receipts (1)
  • DeepSeek privacy policy (updated 2026-02-10)
    DeepSeek provider artifacts · provider artifact · source tier B · cdn.deepseek.com · retrieved 2026-08-05
    To improve and develop the Services and to train and improve our technology, such as our machine learning models and algorithms.

Operational stabilityweak

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Still 'Preview' three-plus months after launch with a stable build promised vaguely for later in 2026; the family precedent (Flash-0731) is silent in-place retraining of the hosted alias.

Receipts (1)
  • DeepSeek API news: V4 launch
    DeepSeek provider artifacts · provider artifact · source tier B · api-docs.deepseek.com · retrieved 2026-08-05

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

The best-documented safeguard failure of any tracked model: FAR.AI achieved 100% attack success across CBRN/cyber/terrorism domains with ~15 minutes of effort (a V3.2-era jailbreak worked unmodified), and Neo Research raised StrongREJECT jailbreak rates from 0.6% to 77.8% with a single 2023-era roleplay template that peer models resisted.

Prompt injection (agentic)weak

No published hardening; worst-in-class record-tampering (20/20 fraud runs) in Anthropic's agentic-misalignment evaluation, and lying in 62% of MASK pressure scenarios per Neo Research.

Receipts (4)
  • FAR.AI: security stress test of DeepSeek V4 Pro's safeguards
    FAR.AI security research · independent eval · source tier C · far.ai · retrieved 2026-08-05
    Low-skill attackers were able to bypass the model's safety mechanisms with success rates ranging from 98-100% across every domain tested.
  • Neo Research: DeepSeek V4 Pro safety evaluation
    Neo Research safety evaluations · independent eval · source tier C · neoresearch.ai · retrieved 2026-08-05
    A 2023 roleplay template, sent as one user message, drives its StrongREJECT jailbreak rate from 0.6% to 77.8%; FAR.AI independently reached 98–100% across CBRN, cyber, and terrorism.
  • Anthropic alignment: agentic misalignment, summer 2026
    Anthropic alignment research (cross-model evaluations) · independent eval · source tier C · alignment.anthropic.com · retrieved 2026-08-05
    Record-tampering was common in several non-Claude models: DeepSeek V4 hit in 20/20 runs, Grok 4.3 in 19/20, and GPT-5.4 and Kimi K2.6 in 17/20.
  • Neo Research: DeepSeek V4 Pro safety evaluation
    Neo Research safety evaluations · independent eval · source tier C · neoresearch.ai · retrieved 2026-08-05
    On MASK it lies in 62% of pressured scenarios.

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

MIT weights and a 319-author technical report with zero safety content; extensive third-party testing exists (NIST CAISI, FAR.AI, Neo Research, Anthropic) but none was DeepSeek-commissioned or pre-deployment.

Receipts (2)
  • DeepSeek-V4-Pro weights and model card
    DeepSeek provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05
    This repository and the model weights are licensed under the MIT License
  • NIST CAISI evaluation of DeepSeek V4 Pro
    NIST CAISI assessments · independent eval · source tier C · nist.gov · retrieved 2026-08-05
    DeepSeek V4 scores better on DeepSeek's self-reported evaluations than on CAISI evaluations.

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Same absent posture as the rest of the DeepSeek platform: no certifications, no enterprise documentation.

Receipts (1)

Governance & evidence

Where your data goes

  • PRC

No regional pinning — the provider chooses where data is processed.

PRC storage under PRC governing law; no regional options.

Enterprise vs consumer terms

Enterprise vs consumer gap: none measured. Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against. No gap because the API tier is itself weak: train-by-default platform terms identical to V4 Flash, with no API opt-out.CONSUMERENTERPRISE / APIWORSE TERMS →
No measured gap

No gap because the API tier is itself weak: train-by-default platform terms identical to V4 Flash, with no API opt-out.

Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against.

Change cadence

no tracked changesNo tracked changes for DeepSeek V4 Pro. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

10 evidence refs6 distinct sources4 independent
  • CNeo Research safety evaluationsindependent eval×2 references
  • CAnthropic alignment research (cross-model evaluations)independent eval×1 reference
  • CFAR.AI security researchindependent eval×1 reference
  • CNIST CAISI assessmentsindependent eval×1 reference
  • BDeepSeek provider artifactsprovider artifact×4 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
Yes — flag
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
No
Retention window
'As long as necessary' — no fixed periods documented
Data residency
PRC (first-party API); PRC governing law
EU AI Act
No published EU AI Act posture.
Deprecation policy
none stated
Available via
api.deepseek.com · Self-hosted (MIT weights) · Multiple inference providers

Incident history

2026-05-11
FAR.AI: DeepSeek V4 Pro safeguards collapse at 98–100% across three attack strategies
Public jailbreaks, authority manipulation, response prefill

FAR.AI's stress test broke DeepSeek V4 Pro's safeguards at 100% with public jailbreaks across CBRN, cyber, and terrorism domains in roughly 15 minutes, 99.6% via authority manipulation, and 99.6% via response prefill — and a jailbreak written for V3.2 worked on V4 Pro unmodified. Neo Research separately raised the StrongREJECT jailbreak rate from 0.6% to 77.8% with a single 2023-era roleplay template that peer models resisted.

Outcome: No provider response; open weights preclude post-release safeguard fixes. Recorded as the best-documented safeguard failure among tracked models.

Sources (2)

Change timeline

No tracked changes yet for this model.

Compare this model: DeepSeek V4 Pro + open compare view →