GPT-5.1-Codex-Max System Card
A system card by OpenAI about GPT-5.1-Codex-Max, published 18 Nov 2025. We recorded 42 values from it.
- Developer
- OpenAI
- Type
- System card
- Model covered
- GPT-5.1-Codex-Max
- Published
- 18 Nov 2025
- Archived copy
- No archived copy yet
- Changelog
- Not known
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Versions
One version is on record: the copy we retrieved on 26 Sep 2026. We know of no other.
26 Sep 2026
Date retrieved
Copy retrieved 26 Sep 2026
No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).
Revisions
No revisions are recorded for this document. We know of only one version of it.
Values
Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 4 of the 42 have been blind-verified: a second reader found the same value without seeing ours.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M1 Evaluation awareness
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | Evaluation awarenessRelative rate vs GPT-5Run by Apollo Research | None stated | External: Apollo Research | Unverified |
M2 Reward hacking
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | Falsifying task completionRelative rate vs GPT-5Run by Apollo Research | None stated | External: Apollo Research | Unverified |
M3 Sabotage and sandbagging
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | SandbaggingRelative rate vs GPT-5Run by Apollo Research | None stated | External: Apollo Research | Unverified |
M4 Misalignment audits
4 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | Covert deceptive behaviorRelative rate vs GPT-5Run by Apollo Research | None stated | External: Apollo Research | Unverified | |
| GPT-5-Codex | Destructive action avoidanceAvoidance | None stated | Table 6 | Verified | |
| GPT-5.1-Codex | Destructive action avoidanceAvoidance | None stated | Table 6 | Verified | |
| GPT-5.1-Codex-Max | Destructive action avoidanceAvoidance | None stated | Table 6 | Verified |
M7 Harmful compliance and over-refusal
17 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | Long-form biorisk questionsRefusal rate | None stated | Bio | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksEmotional reliance | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksExtremism | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksHarassment | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksHate | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksIllicit/non-violent | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksIllicit/violent | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksMental health | None stated | Table 1 | Verified | |
| GPT-5.1-Codex-Max | Production BenchmarksPersonal data | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksSelf-harm/instructions | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksSelf-harm/intent | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksSexual | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksSexual/minors | None stated | Table 1 | Unverified | |
| GPT-5.1-Codex-Max | Production BenchmarksViolence | None stated | Table 1 | Unverified | |
| codex-1 | Malware refusals (golden set)Refusal rate | None stated | Table 4 | Unverified | |
| GPT-5-Codex | Malware refusals (golden set)Refusal rate | None stated | Table 4 | Unverified | |
| GPT-5.1-Codex-Max | Malware refusals (golden set)Refusal rate | None stated | Table 4 | Unverified |
M8 Jailbreak robustness
2 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | StrongRejectnot_unsafe (aggregate) | None stated | Table 2 | Unverified | |
| gpt-5.1-thinking | StrongRejectnot_unsafe (aggregate) | None stated | Table 2 | Unverified |
M9 Prompt injection
3 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| codex-1 | Prompt injection (Codex env)Attacks successfully ignored | None stated | Table 5 | Unverified | |
| GPT-5-Codex | Prompt injection (Codex env)Attacks successfully ignored | None stated | Table 5 | Unverified | |
| GPT-5.1-Codex-Max | Prompt injection (Codex env)Attacks successfully ignored | None stated | Table 5 | Unverified |
M10 Dangerous capabilities and risk determinations
13 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.1-Codex-Max | Preparedness Framework determinationAI self-improvement | None stated | 5 Preparedness | Unverified | |
| GPT-5.1-Codex-Max | Preparedness Framework determinationBiological and chemical | None stated | 5 Preparedness | Unverified | |
| GPT-5.1-Codex-Max | Preparedness Framework determinationCybersecurity | None stated | 5 Preparedness | Unverified | |
| GPT-5 (thinking) | Cyber challengesEasy: challenges solvedRun by Irregular | out of 18 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5 (thinking) | Cyber challengesHard: challenges solvedRun by Irregular | out of 6 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5 (thinking) | Cyber challengesMedium: challenges solvedRun by Irregular | out of 17 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5.1-Codex-Max | Cyber challengesEasy: challenges solvedRun by Irregular | out of 18 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5.1-Codex-Max | Cyber challengesHard: challenges solvedRun by Irregular | out of 6 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5.1-Codex-Max | Cyber challengesMedium: challenges solvedRun by Irregular | out of 17 challenges | 5.1.2.4 External: Irregular | Unverified | |
| GPT-5.1-Codex-Max | Tacit knowledge and troubleshootingScore | None stated | Bio | Unverified | |
| GPT-5.1-Codex-Max | TroubleshootingBenchScore | refusals counted as successes | Bio | Unverified | |
| GPT-5.1-Codex-Max | Cyber RangeScenarios passed | of 8 scenarios reported | Cybersecurity table (hub) | Unverified | |
| GPT-5.1-Codex-Max | 50% time horizonTask length at 50% successRun by METR | None stated | External: METR | Unverified |
Extraction coverage
What we read of this document, and where each value was read.
Our note We have not written a coverage note for this document yet.
All 42 values were read in the document itself.
Of the 42 values, 5 are statements in words rather than numbers; they are marked * and left out of charts by default.
All 42 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).