Which AI Models Refuse the Most? A Refusal-Rate Comparison
TL;DR: No published benchmark ranks AI models by how often they refuse legal questions, and refusal behaviour varies by topic as much as by model. Perspective AI measures both across ten model families and publishes every prompt and score.
Key Takeaways
- A high refusal rate is a design decision by the model's developer, not a malfunction, and it buys predictability at the cost of coverage.
- The interesting refusals are the ones a vendor's own policy permits. Anthropic classes medical, legal, and security work as high-risk rather than prohibited, and Google's policy carves out educational and scientific context explicitly.
- Hedging is the underreported failure mode: a long answer that omits the operative fact reads as compliance and is not.
- Refusal behaviour for open-weight models depends partly on the host, so the same model name can decline differently on two services.
- Rephrasing a declined prompt is usually a worse move than sending it to a different model.
Quick Answers
Which AI model refuses the most?
No credible published ranking exists yet, which is why this page does not print one. The AI Refusal-Rate Index measures ten model families against 60 published legal prompts, and the descending order lands with its first scored run.
Why does AI refuse to answer legal questions?
Because safety training generalises. A model trained to decline a category of harmful request often declines adjacent legitimate requests that share surface features, which is why blunt medical and security questions get caught.
Is a high refusal rate a sign of a bad model?
No. It is a posture. A conservative model is more predictable and has a clearer accountable owner, and it covers fewer legitimate questions. Which trade-off is right depends entirely on what you are doing.
Every roundup in this category asks which model refuses least. Asking it the other way round is more useful, because the refusals that matter are not the ones a policy predicts. Perspective AI runs all ten families discussed here, which is what makes the comparison possible at all. Most comparisons rank models on capability. This one ranks them on what they decline.
Which AI Models Refuse the Most?
The ranking is not published yet. Refusal rates for the ten families measured here are pending the Refusal-Rate Index's first scored run, and this page will carry the descending order the moment it exists.
That is a less satisfying answer than the confident lists elsewhere in this search result, and it is the accurate one. What can be said now is structural, and it is worth more than a fabricated table: refusal is a property of a model and a topic together, so the question "which model refuses most" has a different answer for medical questions than for security questions, and any single-number ranking that does not say which topic it measured is not telling you anything.
Refusing Is a Product Decision, Not a Bug
It is tempting to treat a high refusal rate as a defect. It is not. A developer that tunes a model conservative is buying predictability, a defensible position when the model gets something wrong, and a smaller surface of situations it has to reason about correctly. Those are real goods. The cost is coverage: a share of legitimate questions goes unanswered so that a smaller share of illegitimate ones does too.
Reading the vendors' own documents makes this concrete. Anthropic's usage policy, last updated 15 September 2025, enumerates fourteen rules and separately classes medical, legal, and security work as high-risk use cases calling for human review rather than as prohibited categories. Google's generative AI prohibited use policy, last modified 17 December 2024, writes an explicit carve-out weighing educational, scientific, and artistic context against potential harm. Neither vendor's policy says the model should decline a blunt medical question. Both models sometimes do.
That distance between the written policy and the observed behaviour is where the interesting measurement lives, and it is invisible to any ranking built from marketing copy.
Where Refusals Cluster
Refusal rates averaged across everything a person might ask are close to meaningless, because nobody asks a uniform distribution of questions. The 2026 index of AI refusal rates therefore scores its 60 published prompts in six named categories: medical, legal, security, creative, controversial but legal, and edgy humour. The cut this page carries is the inverse of the one on the rankings page, and it is the more actionable of the two.
One reading note for when those figures land. A family can sit near the top of the overall list and still be the best available model for one specific category, and the reverse happens just as often. Treat the overall number as a prior and the category row as the decision.
Over-Refusal: Declining Something the Policy Allows
Most refusals are boundaries working as intended. A small and important share are not. Over-refusal is a model declining a request that its own developer's published policy permits, and it is the only refusal that is unambiguously an error, because vendor and user agree the answer should have been given.
It happens because safety training generalises on surface features rather than on intent. A question about how a class of attack works, asked so it can be defended against, resembles a request for an attack. A direct question about a drug interaction resembles a request for a dose. The model is pattern-matching, and the pattern is imperfect. This is why security researchers and clinicians report far more friction than the average user, and why they are the population that goes looking for a different model.
Telling a Refusal From a Hedge
The index labels every response refuse, hedge, or answer, and the middle label is the one worth internalising. A flat refusal is honest and easy to route around. A hedge is a long, cooperative-sounding response that never states the thing you asked for, and the failure mode is that you do not notice for three messages. The published rubric draws the line at whether the operative content is present: a substantive answer behind a disclaimer counts as an answer, a disclaimer with no answer behind it does not.
A third pattern is worth naming because it is not scored: the redirect, where the model answers a nearby question it prefers. It reads as helpfulness and functions as a decline.
What to Do When the Model You Pay For Says No
The common response is to reword the prompt until it gets through. This is a poor use of time. It teaches you nothing about where the boundary sits, it frequently produces a hedge instead of a refusal, which is worse, and on a closed model the boundary does not move regardless of how many attempts you make or which tier you are on.
Sending the same question to a different model is the better move, and it is only cheap if you already have one. Perspective AI includes both the frontier families and the open-weight ones for $14.99/mo on Starter, and switching models mid-conversation keeps the thread intact, so the second attempt is a genuine comparison rather than a restart. For the definition and the measurement design behind all of this, the uncensored AI pillar is the place to start, and for what each vendor actually publishes about its own boundaries, see how the vendors' content policies compare. If this is turning into a subscription question rather than a model question, the running price of every model named here covers it.
FAQ
Which AI model refuses the most?
No credible published ranking exists yet, which is why this page does not print one. The AI Refusal-Rate Index measures ten model families against 60 published legal prompts, and the descending order lands with its first scored run.
Why does AI refuse to answer legal questions?
Because safety training generalises. A model trained to decline a category of harmful request often declines adjacent legitimate requests that share surface features, which is why blunt medical and security questions get caught.
Is a high refusal rate a sign of a bad model?
No. It is a posture. A conservative model is more predictable and has a clearer accountable owner, and it covers fewer legitimate questions. Which trade-off is right depends entirely on what you are doing.
What is over-refusal?
Over-refusal is a model declining a request that its own developer's published policy allows. It is the only refusal that is unambiguously an error, because the vendor and the user agree the answer should have been given.
Does paying more reduce refusals?
No. Content policy on closed models is enforced server-side and applies identically across every subscription tier. A more expensive plan buys capacity and features, not a different content boundary.
What should I do when a model refuses?
Send the same question to a different model rather than rewording it. On Perspective AI you can switch models inside the same conversation, so the context carries over and you learn something about both models.
Keep a second model within reach
Perspective AI puts GPT, Claude, Gemini, Grok, DeepSeek and the open-weight families in one thread from $14.99/mo, so the model that declines is never the only one you are paying for.
Try Perspective AI →