GPT-5.2 System Card (update to GPT-5 card)
A system card by OpenAI about gpt-5.2-thinking and gpt-5.2-instant, published 11 Dec 2025. We recorded 94 values from it.
- Developer
- OpenAI
- Type
- System card
- Models covered
- gpt-5.2-thinking, gpt-5.2-instant
- Published
- 11 Dec 2025
- Archived copy
- No archived copy yet
- Changelog
- Partial changelog
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Versions
Three versions are on record, oldest first. We hold a copy of one; the others are known only by their date.
11 Dec 2025
First published version
24 Apr 2026
Revision
What changed hub added CoT monitorability/controllability and sandbagging sections (not in PDF)
26 Sep 2026
Date retrieved
Copy retrieved 26 Sep 2026
No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).
Revisions
No revisions are recorded for this document. Without copies of the earlier versions, changes between them are not recorded value by value; what we know of each version is listed below.
Values
Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 3 of the 94 have been blind-verified: a second reader found the same value without seeing ours.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M3 Sabotage and sandbagging
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.2-thinking | SabotageSabotage observedRun by Apollo Research | None stated | Sandbagging / Apollo | Unverified |
M4 Misalignment audits
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.2-thinking | Covert deceptive behaviorRate vs peersRun by Apollo Research | None stated | Sandbagging / Apollo | Unverified |
M5 Honesty and hallucination
13 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.2-thinking | Factuality (5 domains)Hallucination rate | with browsing | 3.5 text | Unverified | |
| gpt-5.1-thinking | Deception evalBrowsing broken tools | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.1-thinking | Deception evalCharXiv missing image (lenient output) | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.1-thinking | Deception evalCharXiv missing image (strict output) | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.1-thinking | Deception evalCoding deception | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.1-thinking | Deception evalProduction deception - adversarial | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.1-thinking | Deception evalProduction traffic | None stated | 3.7 Table 6 | Verified | |
| gpt-5.2-thinking | Deception evalBrowsing broken tools | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.2-thinking | Deception evalCharXiv missing image (lenient output) | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.2-thinking | Deception evalCharXiv missing image (strict output) | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.2-thinking | Deception evalCoding deception | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.2-thinking | Deception evalProduction deception - adversarial | None stated | 3.7 Table 6 | Unverified | |
| gpt-5.2-thinking | Deception evalProduction traffic | None stated | 3.7 Table 6 | Verified |
M7 Harmful compliance and over-refusal
50 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.1-instant | Production BenchmarksEmotional reliance | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksExtremism | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksHarassment | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksHate | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksIllicit/non-violent | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksMental health | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksPersonal data | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksSelf-harm | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksSexual | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksSexual/minors | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-instant | Production BenchmarksViolence | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksEmotional reliance | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksExtremism | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksHarassment | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksHate | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksIllicit/non-violent | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksMental health | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksPersonal data | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksSelf-harm | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksSexual | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksSexual/minors | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.1-thinking | Production BenchmarksViolence | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksEmotional reliance | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksExtremism | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksHarassment | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksHate | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksIllicit/non-violent | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksMental health | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksPersonal data | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksSelf-harm | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksSexual | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksSexual/minors | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-instant | Production BenchmarksViolence | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksEmotional reliance | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksExtremism | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksHarassment | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksHate | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksIllicit/non-violent | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksMental health | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksPersonal data | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksSelf-harm | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksSexual | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksSexual/minors | None stated | 3.1 Table 1 | Unverified | |
| gpt-5.2-thinking | Production BenchmarksViolence | None stated | 3.1 Table 1 | Unverified | |
| gpt-5-thinking | Cyber safetyProduction data | None stated | 3.8 Table 7 | Unverified | |
| gpt-5-thinking | Cyber safetySynthetic data | None stated | 3.8 Table 7 | Unverified | |
| gpt-5.1-thinking | Cyber safetyProduction data | None stated | 3.8 Table 7 | Unverified | |
| gpt-5.1-thinking | Cyber safetySynthetic data | None stated | 3.8 Table 7 | Unverified | |
| gpt-5.2-thinking | Cyber safetyProduction data | None stated | 3.8 Table 7 | Unverified | |
| gpt-5.2-thinking | Cyber safetySynthetic data | None stated | 3.8 Table 7 | Unverified |
M8 Jailbreak robustness
5 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5-instant-oct3oct3 | StrongRejectnot_unsafe (aggregate) | None stated | 3.2 Table 2 | Unverified | |
| gpt-5.1-instant | StrongRejectnot_unsafe (aggregate) | None stated | 3.2 Table 2 | Unverified | |
| gpt-5.1-thinking | StrongRejectnot_unsafe (aggregate) | None stated | 3.2 Table 2 | Unverified | |
| gpt-5.2-instant | StrongRejectnot_unsafe (aggregate) | None stated | 3.2 Table 2 | Unverified | |
| gpt-5.2-thinking | StrongRejectnot_unsafe (aggregate) | None stated | 3.2 Table 2 | Unverified |
M9 Prompt injection
8 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.1-instant | Prompt injectionAgent JSK | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.1-instant | Prompt injectionPlugInject | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.1-thinking | Prompt injectionAgent JSK | None stated | 3.3 Table 3 | Verified | |
| gpt-5.1-thinking | Prompt injectionPlugInject | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.2-instant | Prompt injectionAgent JSK | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.2-instant | Prompt injectionPlugInject | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.2-thinking | Prompt injectionAgent JSK | None stated | 3.3 Table 3 | Unverified | |
| gpt-5.2-thinking | Prompt injectionPlugInject | None stated | 3.3 Table 3 | Unverified |
M10 Dangerous capabilities and risk determinations
13 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.2-thinking | Preparedness Framework determinationAI self-improvement | None stated | 4 Preparedness | Unverified | |
| gpt-5.2-thinking | Preparedness Framework determinationBiological and chemical | None stated | 4 Preparedness | Unverified | |
| gpt-5.2-thinking | Preparedness Framework determinationCybersecurity | None stated | 4 Preparedness | Unverified | |
| GPT-5.1-Codex-Max | OpenAI-Proof Q&APass rate | None stated | AI Self-improvement | Unverified | |
| gpt-5.2-thinking | PaperBenchDifference vs GPT-5.1-Codex-Max | None stated | AI Self-improvement | Unverified | |
| gpt-5.2-thinking | TroubleshootingBenchDifference vs GPT-5.1 Thinking | refusals not counted | Bio | Unverified | |
| gpt-5.2-thinking | CVE-BenchDifference vs GPT-5.1 Thinking | None stated | Cybersecurity | Unverified | |
| gpt-5.2-thinking | CVE-BenchDifference vs GPT-5.1-Codex-Max | None stated | Cybersecurity | Unverified | |
| GPT-5.1-Codex-Max | Cyber RangeScenarios passed | of 9 scenarios | Cybersecurity table | Unverified | |
| gpt-5.2-thinking | Cyber RangeScenarios passed | of 9 scenarios | Cybersecurity table | Unverified | |
| gpt-5.2-thinking | Cyber challengesEvasion: average success rateRun by Irregular | v1 atomic challenge suite | External: Irregular | Unverified | |
| gpt-5.2-thinking | Cyber challengesNetwork attack simulation: average success rateRun by Irregular | v1 atomic challenge suite | External: Irregular | Unverified | |
| gpt-5.2-thinking | Cyber challengesVulnerability research and exploitation: average success rateRun by Irregular | v1 atomic challenge suite | External: Irregular | Unverified |
M11 Self-preservation
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| gpt-5.2-thinking | Self-preservationSelf-preservation behavior observedRun by Apollo Research | None stated | Sandbagging / Apollo | Unverified |
M12 Chain-of-thought monitorability
2 values
| Model | Evaluation | Condition | Value | Location | Checked | Version |
|---|---|---|---|---|---|---|
| gpt-5.2-thinking | CoT controllabilityControllability vs GPT-5/5.1 Thinking | None stated | CoT Evaluations (hub) | Unverified | Version of 24 Apr 2026 | |
| gpt-5.2-thinking | CoT monitorabilitySandbagging eval TPR vs GPT-5 Thinking | None stated | CoT Evaluations (hub) | Unverified | Version of 24 Apr 2026 |
Extraction coverage
What we read of this document, and where each value was read.
Our note We have not written a coverage note for this document yet.
All 94 values were read in the document itself.
Of the 94 values, 5 are statements in words rather than numbers; they are marked * and left out of charts by default.
All 94 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).