Versions

One version is on record: the copy we retrieved on 26 Sep 2026. We know of no other.

  1. 26 Sep 2026

    Date retrieved

    Copy retrieved 26 Sep 2026

    Date from
    the date we retrieved it; the copy states no version date
    Copy
    Copy retrieved on 26 Sep 2026
    Values
    33 values recorded from this version

No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).

Revisions

No revisions are recorded for this document. We know of only one version of it.

Values

Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 1 of the 33 has been blind-verified: a second reader found the same value without seeing ours.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M3 Sabotage and sandbagging

4 values

M3 Sabotage and sandbagging: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.2Sabotage capabilityMean best-of-10 scoreRun by Apollo ResearchNone statedExternal (Apollo)Unverified
GPT-5.2-CodexSabotage capabilityMean best-of-10 scoreRun by Apollo ResearchNone statedExternal (Apollo)Unverified
GPT-5.3-CodexSabotage capabilityMean best-of-10 scoreRun by Apollo ResearchNone statedExternal (Apollo)Unverified
GPT-5.3-CodexSandbaggingSandbags on capability Q&ARun by Apollo Researchincluding without an in-context goalExternal (Apollo)Unverified

M4 Misalignment audits

3 values

M4 Misalignment audits: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.3-CodexCovert deceptive behaviorCovert action rateRun by Apollo ResearchNone statedExternal (Apollo)Unverified
GPT-5.2-CodexDestructive action avoidanceAvoidanceNone statedTable 2Unverified
GPT-5.3-CodexDestructive action avoidanceAvoidanceNone statedTable 2Verified

M7 Harmful compliance and over-refusal

12 values

M7 Harmful compliance and over-refusal: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.3-CodexProduction BenchmarksAbuseNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksBiological weaponsNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksChemical weaponsNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksExtremismNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksHateNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksNonviolent illicit behaviorNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksSelf-harm (standard)None statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksSexual/minorsNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksViolenceNone statedTable 1Unverified
GPT-5.3-CodexProduction BenchmarksViolent illicit behaviorNone statedTable 1Unverified
GPT-5.3-CodexCyber safetyProduction dataNone statedTable 7Unverified
GPT-5.3-CodexCyber safetySynthetic dataNone statedTable 7Unverified

M8 Jailbreak robustness

1 value

M8 Jailbreak robustness: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.3-CodexUniversal jailbreak (cyber)Policy-violating cyber dataset pass rateRun by UK AI Security Institutepass@200; ~10h red-teamingSafeguards red-teamingUnverified

M10 Dangerous capabilities and risk determinations

12 values

M10 Dangerous capabilities and risk determinations: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.3-CodexPreparedness Framework determinationAI self-improvementNone stated5 PreparednessUnverified
GPT-5.3-CodexPreparedness Framework determinationBiological and chemicalNone stated5 PreparednessUnverified
GPT-5.3-CodexPreparedness Framework determinationCybersecurityNone stated5 PreparednessUnverified
GPT-5.3-CodexCapture the FlagProfessional vs GPT-5.2-CodexNone statedCyber evalsUnverified
GPT-5.3-CodexCVE-BenchPass rateNone statedCyber evalsUnverified
GPT-5.3-CodexCyber challengesEvasion: average success rateRun by IrregularNone statedExternal (Irregular)Unverified
GPT-5.3-CodexCyber challengesNetwork attack simulation: average success rateRun by IrregularNone statedExternal (Irregular)Unverified
GPT-5.3-CodexCyber challengesVulnerability research and exploitation: average success rateRun by IrregularNone statedExternal (Irregular)Unverified
GPT-5.1-Codex-MaxCyber RangeCombined pass rateNone statedTable 5Unverified
GPT-5.2 ThinkingCyber RangeCombined pass rateNone statedTable 5Unverified
GPT-5.2-CodexCyber RangeCombined pass rateNone statedTable 5Unverified
GPT-5.3-CodexCyber RangeCombined pass rateNone statedTable 5Unverified

M12 Chain-of-thought monitorability

1 value

M12 Chain-of-thought monitorability: values in the GPT-5.3-Codex System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.3-CodexNon-Latin reasoning tokensShare of non-Latin reasoning tokensRun by Apollo ResearchNone statedExternal (Apollo)Unverified

Extraction coverage

What we read of this document, and where each value was read.

Our note First launch treated as High in cyber

All 33 values were read in the document itself.

Of the 33 values, 3 are statements in words rather than numbers; they are marked * and left out of charts by default.

All 33 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).