ModelRiskIndex

Rankings / MiniMax

MiniMax M3

Tier 020/100open weights

minimax-m3 (open weights, community license) via api.minimax.io / self-hosted

Usage share 3.2% · OpenRouter rankings API (daily token share, 2026-08-04)

Dual-nature entry graded on the hosted first-party endpoint, DeepSeek-style: the tier reflects api.minimax.io's train-by-default terms and absent safety disclosure. Self-hosted deployments of the weights escape the data-handling failure but inherit the ungraded safety posture.

Tier assessment

Fails one or more Tier 1 requirements: no published model card or safety evals, or terms that permit training on customer API data by default with no opt-out.

Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. No safety evaluations are published for this model.
  • Documented safety policy. No documented safety or acceptable-use policy exists.
  • Enterprise data controls. Terms permit training on customer data by default with no documented opt-out.
Tier 2 requirements
  • External pre-deployment testing. No disclosed external pre-deployment testing.
  • Third-party certification. No verifiable third-party certification.
  • Versioning with changelogs. No versioning discipline or changelog for model changes.Dated slugs exist only at aggregators; first-party repo is rolling with no changelog.
  • Stated deprecation policy. No stated deprecation policy.

Missing for Tier 1: published safety evals, documented safety policy, enterprise data controls. The tier is computed from this checklist — satisfying these requirements moves the badge, automatically.

Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governanceweak

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Platform terms permit using inputs and outputs to develop and improve services, with no general no-training promise, no documented opt-out, and no stated retention window. The operating entity is Singapore-domiciled but reporting indicates processing likely occurs in the PRC — corporate domicile is not data residency. Self-hosting the weights avoids all of this.

Receipts (1)
  • MiniMax platform terms of service
    MiniMax provider artifacts · provider artifact · source tier B · platform.minimax.io · retrieved 2026-08-05
    We may use the input and generated content to provide, maintain, develop, and improve our Services, comply with applicable law, enforce our terms and policies, and keep our Services safe.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Aggregator-level dated snapshots and stable pricing across the M-series, but a rolling first-party weights repo, no changelog, and no stated deprecation policy for the hosted API.

Receipts (1)

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistanceweak

No developer safety evals exist; a public DAN-style jailbreak landed within a month of release, and the family's track record on F5's board is volatile — predecessor M2.5 collapsed 29 CASI points in a single month. M3 itself has no standalone third-party score yet.

Prompt injection (agentic)weak

Heavily marketed for agentic coding, with no published injection hardening or agent red-teaming results of any kind.

Receipts (3)

Transparencypartial

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Open weights and a genuine architecture paper (MiniMax Sparse Attention), but zero safety disclosure: no safety section, no evals, no external testing — notable for a company that IPO'd on the HKEX in January 2026.

Receipts (2)
  • MiniMax M3 weights and model card
    MiniMax provider artifacts · provider artifact · source tier B · huggingface.co · retrieved 2026-08-05
  • MiniMax Sparse Attention technical report
    Peer-reviewed / preprint research · independent eval · source tier C · arxiv.org · retrieved 2026-08-05
    We introduce MiniMax Sparse Attention (MSA), a blockwise sparse attention built upon Grouped Query Attention (GQA).

Compliance postureweak

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

No SOC 2, ISO, or equivalent certifications published for the API despite the public listing; the IPO prospectus remains the unchecked place such claims would live.

Receipts (1)

Governance & evidence

Where your data goes

  • PRC

No regional pinning — the provider chooses where data is processed.

Singapore-domiciled operator; processing likely PRC — corporate domicile is not data residency.

Enterprise vs consumer terms

Enterprise vs consumer gap: none measured. Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against. No gap because the API tier is itself weak: platform terms permit using inputs and outputs to improve services with no opt-out.CONSUMERENTERPRISE / APIWORSE TERMS →
No measured gap

No gap because the API tier is itself weak: platform terms permit using inputs and outputs to improve services with no opt-out.

Level tiers can mean both are clean, or that the API tier is itself weak with nothing better to compare against.

Change cadence

no tracked changesNo tracked changes for MiniMax M3. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

9 evidence refs5 distinct sources2 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • CPeer-reviewed / preprint researchindependent eval×1 reference
  • BMiniMax provider artifactsprovider artifact×5 references
  • EOpenRouter model rankingsusage data×1 reference
  • FInjectPrompt jailbreak disclosuresreporting×1 reference

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
Yes — flag
SOC 2
not verified
ISO/IEC 42001
not verified
HIPAA eligible
not verified
Retention window
Not documented
Data residency
Singapore-domiciled operator; processing likely PRC (unresolved residency paradox)
EU AI Act
No published EU AI Act posture.
Deprecation policy
none stated
Available via
api.minimax.io · Self-hosted (community license) · Multiple inference providers

Change timeline

No tracked changes yet for this model.

Compare this model: MiniMax M3 + open compare view →