GPT-5.3-Codex System Card
A system card by OpenAI about GPT-5.3-Codex, published 5 Feb 2026. We recorded 33 values from it.
- Developer
- OpenAI
- Type
- System card
- Model covered
- GPT-5.3-Codex
- Published
- 5 Feb 2026
- Archived copy
- No archived copy yet
- Changelog
- Not known
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Versions
One version is on record: the copy we retrieved on 26 Sep 2026. We know of no other.
26 Sep 2026
Date retrieved
Copy retrieved 26 Sep 2026
No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).
Revisions
No revisions are recorded for this document. We know of only one version of it.
Values
Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 1 of the 33 has been blind-verified: a second reader found the same value without seeing ours.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M3 Sabotage and sandbagging
4 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.2 | Sabotage capabilityMean best-of-10 scoreRun by Apollo Research | None stated | External (Apollo) | Unverified | |
| GPT-5.2-Codex | Sabotage capabilityMean best-of-10 scoreRun by Apollo Research | None stated | External (Apollo) | Unverified | |
| GPT-5.3-Codex | Sabotage capabilityMean best-of-10 scoreRun by Apollo Research | None stated | External (Apollo) | Unverified | |
| GPT-5.3-Codex | SandbaggingSandbags on capability Q&ARun by Apollo Research | including without an in-context goal | External (Apollo) | Unverified |
M4 Misalignment audits
3 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.3-Codex | Covert deceptive behaviorCovert action rateRun by Apollo Research | None stated | External (Apollo) | Unverified | |
| GPT-5.2-Codex | Destructive action avoidanceAvoidance | None stated | Table 2 | Unverified | |
| GPT-5.3-Codex | Destructive action avoidanceAvoidance | None stated | Table 2 | Verified |
M7 Harmful compliance and over-refusal
12 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.3-Codex | Production BenchmarksAbuse | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksBiological weapons | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksChemical weapons | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksExtremism | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksHate | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksNonviolent illicit behavior | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksSelf-harm (standard) | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksSexual/minors | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksViolence | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Production BenchmarksViolent illicit behavior | None stated | Table 1 | Unverified | |
| GPT-5.3-Codex | Cyber safetyProduction data | None stated | Table 7 | Unverified | |
| GPT-5.3-Codex | Cyber safetySynthetic data | None stated | Table 7 | Unverified |
M8 Jailbreak robustness
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.3-Codex | Universal jailbreak (cyber)Policy-violating cyber dataset pass rateRun by UK AI Security Institute | pass@200; ~10h red-teaming | Safeguards red-teaming | Unverified |
M10 Dangerous capabilities and risk determinations
12 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.3-Codex | Preparedness Framework determinationAI self-improvement | None stated | 5 Preparedness | Unverified | |
| GPT-5.3-Codex | Preparedness Framework determinationBiological and chemical | None stated | 5 Preparedness | Unverified | |
| GPT-5.3-Codex | Preparedness Framework determinationCybersecurity | None stated | 5 Preparedness | Unverified | |
| GPT-5.3-Codex | Capture the FlagProfessional vs GPT-5.2-Codex | None stated | Cyber evals | Unverified | |
| GPT-5.3-Codex | CVE-BenchPass rate | None stated | Cyber evals | Unverified | |
| GPT-5.3-Codex | Cyber challengesEvasion: average success rateRun by Irregular | None stated | External (Irregular) | Unverified | |
| GPT-5.3-Codex | Cyber challengesNetwork attack simulation: average success rateRun by Irregular | None stated | External (Irregular) | Unverified | |
| GPT-5.3-Codex | Cyber challengesVulnerability research and exploitation: average success rateRun by Irregular | None stated | External (Irregular) | Unverified | |
| GPT-5.1-Codex-Max | Cyber RangeCombined pass rate | None stated | Table 5 | Unverified | |
| GPT-5.2 Thinking | Cyber RangeCombined pass rate | None stated | Table 5 | Unverified | |
| GPT-5.2-Codex | Cyber RangeCombined pass rate | None stated | Table 5 | Unverified | |
| GPT-5.3-Codex | Cyber RangeCombined pass rate | None stated | Table 5 | Unverified |
M12 Chain-of-thought monitorability
1 value
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5.3-Codex | Non-Latin reasoning tokensShare of non-Latin reasoning tokensRun by Apollo Research | None stated | External (Apollo) | Unverified |
Extraction coverage
What we read of this document, and where each value was read.
Our note First launch treated as High in cyber
All 33 values were read in the document itself.
Of the 33 values, 3 are statements in words rather than numbers; they are marked * and left out of charts by default.
All 33 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).