Versions

One version is on record: the copy we retrieved on 26 Sep 2026. We know of no other.

  1. 26 Sep 2026

    Date retrieved

    Copy retrieved 26 Sep 2026

    Date from
    the date we retrieved it; the copy states no version date
    Copy
    Copy retrieved on 26 Sep 2026
    Values
    42 values recorded from this version

No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).

Revisions

No revisions are recorded for this document. We know of only one version of it.

Values

Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 4 of the 42 have been blind-verified: a second reader found the same value without seeing ours.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M1 Evaluation awareness

1 value

M1 Evaluation awareness: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxEvaluation awarenessRelative rate vs GPT-5Run by Apollo ResearchNone statedExternal: Apollo ResearchUnverified

M2 Reward hacking

1 value

M2 Reward hacking: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxFalsifying task completionRelative rate vs GPT-5Run by Apollo ResearchNone statedExternal: Apollo ResearchUnverified

M3 Sabotage and sandbagging

1 value

M3 Sabotage and sandbagging: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxSandbaggingRelative rate vs GPT-5Run by Apollo ResearchNone statedExternal: Apollo ResearchUnverified

M4 Misalignment audits

4 values

M4 Misalignment audits: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxCovert deceptive behaviorRelative rate vs GPT-5Run by Apollo ResearchNone statedExternal: Apollo ResearchUnverified
GPT-5-CodexDestructive action avoidanceAvoidanceNone statedTable 6Verified
GPT-5.1-CodexDestructive action avoidanceAvoidanceNone statedTable 6Verified
GPT-5.1-Codex-MaxDestructive action avoidanceAvoidanceNone statedTable 6Verified

M7 Harmful compliance and over-refusal

17 values

M7 Harmful compliance and over-refusal: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxLong-form biorisk questionsRefusal rateNone statedBioUnverified
GPT-5.1-Codex-MaxProduction BenchmarksEmotional relianceNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksExtremismNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksHarassmentNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksHateNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksIllicit/non-violentNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksIllicit/violentNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksMental healthNone statedTable 1Verified
GPT-5.1-Codex-MaxProduction BenchmarksPersonal dataNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksSelf-harm/instructionsNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksSelf-harm/intentNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksSexualNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksSexual/minorsNone statedTable 1Unverified
GPT-5.1-Codex-MaxProduction BenchmarksViolenceNone statedTable 1Unverified
codex-1Malware refusals (golden set)Refusal rateNone statedTable 4Unverified
GPT-5-CodexMalware refusals (golden set)Refusal rateNone statedTable 4Unverified
GPT-5.1-Codex-MaxMalware refusals (golden set)Refusal rateNone statedTable 4Unverified

M8 Jailbreak robustness

2 values

M8 Jailbreak robustness: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxStrongRejectnot_unsafe (aggregate)None statedTable 2Unverified
gpt-5.1-thinkingStrongRejectnot_unsafe (aggregate)None statedTable 2Unverified

M9 Prompt injection

3 values

M9 Prompt injection: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
codex-1Prompt injection (Codex env)Attacks successfully ignoredNone statedTable 5Unverified
GPT-5-CodexPrompt injection (Codex env)Attacks successfully ignoredNone statedTable 5Unverified
GPT-5.1-Codex-MaxPrompt injection (Codex env)Attacks successfully ignoredNone statedTable 5Unverified

M10 Dangerous capabilities and risk determinations

13 values

M10 Dangerous capabilities and risk determinations: values in the GPT-5.1-Codex-Max System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.1-Codex-MaxPreparedness Framework determinationAI self-improvementNone stated5 PreparednessUnverified
GPT-5.1-Codex-MaxPreparedness Framework determinationBiological and chemicalNone stated5 PreparednessUnverified
GPT-5.1-Codex-MaxPreparedness Framework determinationCybersecurityNone stated5 PreparednessUnverified
GPT-5 (thinking)Cyber challengesEasy: challenges solvedRun by Irregularout of 18 challenges5.1.2.4 External: IrregularUnverified
GPT-5 (thinking)Cyber challengesHard: challenges solvedRun by Irregularout of 6 challenges5.1.2.4 External: IrregularUnverified
GPT-5 (thinking)Cyber challengesMedium: challenges solvedRun by Irregularout of 17 challenges5.1.2.4 External: IrregularUnverified
GPT-5.1-Codex-MaxCyber challengesEasy: challenges solvedRun by Irregularout of 18 challenges5.1.2.4 External: IrregularUnverified
GPT-5.1-Codex-MaxCyber challengesHard: challenges solvedRun by Irregularout of 6 challenges5.1.2.4 External: IrregularUnverified
GPT-5.1-Codex-MaxCyber challengesMedium: challenges solvedRun by Irregularout of 17 challenges5.1.2.4 External: IrregularUnverified
GPT-5.1-Codex-MaxTacit knowledge and troubleshootingScoreNone statedBioUnverified
GPT-5.1-Codex-MaxTroubleshootingBenchScorerefusals counted as successesBioUnverified
GPT-5.1-Codex-MaxCyber RangeScenarios passedof 8 scenarios reportedCybersecurity table (hub)Unverified
GPT-5.1-Codex-Max50% time horizonTask length at 50% successRun by METRNone statedExternal: METRUnverified

Extraction coverage

What we read of this document, and where each value was read.

Our note We have not written a coverage note for this document yet.

All 42 values were read in the document itself.

Of the 42 values, 5 are statements in words rather than numbers; they are marked * and left out of charts by default.

All 42 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).