ModelRiskIndex

Rankings / Tencent

Tencent Hunyuan HY3

Tier 033/100open weights

hy3 (open weights, Apache 2.0) via TokenHub / multiple hosts

Usage share 8.6% · OpenRouter rankings API (daily token share, 2026-08-04)

Three of six vectors are under review — the honest description of a month-old model with ~8.6% share and no security evidence in either direction. That gap is itself the finding: usage arrived (via a free tier) far ahead of any safety scrutiny.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.Apache 2.0 weights carry no acceptable-use policy; hosted-API policy unverified in English.
  • Enterprise data controls. Terms permit training on customer data by default with no documented opt-out.TokenHub terms unlocatable in English; treated as unsatisfied pending verification.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.Platform-level Tencent Cloud ISO 27001 exists; TokenHub scope unverified.
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Dated preview/GA releases with separate IDs; no formal changelog.
  • Stated deprecation policy. No stated deprecation policy.

Missing for Tier 1: published safety evals, documented safety policy, enterprise data controls. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governanceunder review

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

English-language training-default, retention, and residency terms for the first-party TokenHub API could not be located; third-party analyses flag GDPR concerns and recommend self-hosting for sensitive data. The Apache 2.0 weights make self-hosting fully deployer-controlled.

Receipts (1)

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Distinct dated releases (preview April, GA July) with separate IDs — better discipline than most peers — but no changelog, no deprecation policy, and an opaque preview-period serving history.

Receipts (1)
  • HY3 preview repository (dated release lineage)
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · github.com · retrieved 2026-08-05
    [2026-04-23] 🔥 We open-source Hy3 preview model weights on Hugging Face , ModelScope , and GitCode

Adversarial resistanceunder review

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceunder review

Not yet assessable: no independent security testing exists (absent from F5's board as of July 2026 — likely too new), and Tencent publishes no safety evals — only internal reliability metrics like hallucination rates. A ~8.6%-share model with zero security evidence either way.

Prompt injection (agentic)under review

Marketed on stable tool-calling across agent scaffoldings, with no published injection results from Tencent or any third party.

Receipts (3)
  • HY3 model card (reliability metrics only, no safety evals)
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05
    In internal evaluations based on real-world scenarios, Hy3's hallucination rate dropped from 12.5% to 5.4%, and commonsense error rates fell from 25.4% to 12.7%.
  • F5 Labs CASI/ARS leaderboards (HY3 not yet listed)
    F5 Labs CASI/ARS leaderboard · independent eval · source tier C · f5.com · retrieved 2026-08-05
  • HY3 repository (agentic claims, no injection results)
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · github.com · retrieved 2026-08-05
    Stability of tool calls and output formats : We fixed multiple baseline reliability issues, bringing the model to production-grade standards across tool configurations and output constraints.

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Apache 2.0 weights (a license loosening from the preview's community license) with benchmark-rich model card and repo — but no technical report, no safety section, and no external testing.

Receipts (2)
  • HY3 weights and model card
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05
    Hy3 is released under the Apache License 2.0
  • Tencent HY3 official release announcement
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · tencent.com · retrieved 2026-08-05
    On the open-source front, Hy3 is available under the commercially friendly Apache 2.0 license, allowing developers worldwide to download and use it.

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Tencent Cloud holds platform-level ISO 27001:2022, but whether it scopes TokenHub is unverified, and nothing model- or service-specific is published.

Receipts (1)
  • Tencent Cloud compliance documentation
    Tencent Hunyuan provider artifacts · provider artifact · source tier B · tencentcloud.com · retrieved 2026-08-05
    Tencent Cloud has obtained certification for the upgraded ISO27001:2022 information security management system standard.

Governance & evidence

Where your data goes

  • PRC

No regional pinning — the provider chooses where data is processed.

Unverified: PRC processing presumed by third-party analyses of Tencent's TokenHub; no first-party residency statement located in English.

Enterprise vs consumer terms

Enterprise vs consumer gap: not assessed. Not yet assessed. Absence of assessment is not absence of a gap.NOT ASSESSEDENTERPRISE / APICONSUMER
Not assessed

Not yet assessed. Absence of assessment is not absence of a gap.

Change cadence

insufficient history1 tracked change · last 2026-07-06 · 30d since Insufficient history to estimate a cadence.30d

One tracked change, on 2026-07-06 — 30 days before the as-of date (2026-08-05). A single event cannot establish a cadence, so days-since is shown without a baseline.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

9 evidence refs3 distinct sources1 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • BTencent Hunyuan provider artifactsprovider artifact×7 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
not verified
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
not verified
Retention window
Unverified
Data residency
Unverified; Tencent (PRC) processing presumed by third-party analyses
EU AI Act
No published EU AI Act posture; third-party analyses flag GDPR concerns for hosted use.
Deprecation policy
none stated
Available via
Tencent Cloud TokenHub · Self-hosted (Apache 2.0 weights) · Multiple inference providers

Change timeline

2026-07-06
Tencent HY3 GA: license loosened to Apache 2.0, free tier drives #1 weekly usage
versionnotice

Official release relicensed the weights from the preview's community license to Apache 2.0, and a two-week free OpenRouter tier pushed HY3 to #1 by weekly usage (6.13T tokens) — a ~8.6% share model with, at time of entry, zero independent security testing in either direction.

Evidence (1)

Compare this model: Tencent Hunyuan HY3 + open compare view →