Revisions

Each change we have recorded between two versions: the old and the new text, whether the document's changelog explains it, how we know, and whether we have checked it. A revision is not in itself evidence of wrongdoing; most are corrections (Methodology §7).

  1. Value changed · 9 Jul 2026 to 19 Aug 2026

    GPT-5.5 hard-negative protein-binding prediction, pass@4

    M10 · Dangerous capabilities and risk determinations

    0.4%1.5%

    Explained — earlier figure was the pass@1 score

    New value:

    How we know Changelog read 26 Sep 2026; same entry also appears in the GPT-5.6 Preview card changelog

    Checked Confirmed from changelog

  2. Added · 9 Jul 2026 to 3 Aug 2026

    GPT-Red instruction-hierarchy (direct prompt injection) attack success rate added, GPT-5.6 Sol

    M9 · Prompt injection

    0.051%

    Explained — The changelog says the GPT-Red prompt-injection results were added.

    New value:

    How we know From the document's changelog, as summarised in our source registry.

    Checked Not yet checked

  3. Added · 9 Jul 2026 to 3 Aug 2026

    GPT-Red indirect prompt injection attack success rate added, GPT-5.6 Sol

    M9 · Prompt injection

    3.77%

    Explained — The changelog says the GPT-Red prompt-injection results were added.

    New value:

    How we know From the document's changelog, as summarised in our source registry.

    Checked Not yet checked

Versions

Five versions are on record, oldest first. We hold a copy of one; the others are known only by their date.

  1. 27 Jun 2026

    Revision

    Date from
    the document's changelog
    Copy
    Known from the changelog; no copy held

    What changed metagaming plots re-aggregated

    This date is earlier than the document's recorded publication date, 9 Jul 2026. We have not yet established which is right.

  2. 9 Jul 2026

    First published version

    Date from
    our source registry
    Copy
    Known to exist; no copy held
  3. 3 Aug 2026

    Revision

    Date from
    the document's changelog
    Copy
    Known from the changelog; no copy held
    Values
    2 values recorded from this version

    What changed 2 changes recorded as revisions. See them in redline

  4. 19 Aug 2026

    Revision

    Date from
    the document's changelog
    Copy
    Known from the changelog; no copy held

    What changed 1 change recorded as a revision. See it in redline

  5. 26 Sep 2026

    Date retrieved

    Copy retrieved 26 Sep 2026

    Date from
    the date we retrieved it; the copy states no version date
    Copy
    Copy retrieved on 26 Sep 2026
    Values
    49 values recorded from this version

No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).

Values

Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 9 of the 51 have been blind-verified: a second reader found the same value without seeing ours.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M1 Evaluation awareness

1 value

M1 Evaluation awareness: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolVerbalized metagamingMetagaming vs GPT-5.5None stated7.4 Metagaming (Fig 17-20)Unverified

M2 Reward hacking

1 value

M2 Reward hacking: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolChatGPT deployment simulationObserved calculator hackingNone stated7.1 Deployment simulation (ChatGPT)Unverified

M4 Misalignment audits

7 values

M4 Misalignment audits: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolDeployment simulation (internal Codex traffic)Severity-3 actions vs GPT-5.5None stated7.2 Deployment simulation (internal)Unverified
GPT-5.5Destructive action avoidanceAvoidanceNone statedDestructive actions tableVerified
GPT-5.5Destructive action avoidanceAvoidance + correctnessNone statedDestructive actions tableUnverified
GPT-5.6 LunaDestructive action avoidanceAvoidanceNone statedDestructive actions tableVerified
GPT-5.6 LunaDestructive action avoidanceAvoidance + correctnessNone statedDestructive actions tableUnverified
GPT-5.6 SolDestructive action avoidanceAvoidanceNone statedDestructive actions tableVerified
GPT-5.6 SolDestructive action avoidanceAvoidance + correctnessNone statedDestructive actions tableUnverified

M5 Honesty and hallucination

2 values

M5 Honesty and hallucination: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolChatGPT deployment simulationMisrepresenting work completion vs GPT-5.5None stated7.1 Deployment simulation (ChatGPT)Unverified
GPT-5.6 SolHallucinationsFactual errors vs GPT-5.5 (user-flagged cases)None statedHallucinations (Fig 4)Unverified

M7 Harmful compliance and over-refusal

11 values

M7 Harmful compliance and over-refusal: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.5 ThinkingProduction BenchmarksGoreNone statedDisallowed content tableUnverified
GPT-5.6 LunaProduction BenchmarksGoreNone statedDisallowed content tableVerified
GPT-5.6 SolProduction BenchmarksExtremismNone statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksGoreNone statedDisallowed content tableVerified
GPT-5.6 SolProduction BenchmarksHateNone statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksNonviolent illicit behaviorNone statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksSelf-harm (standard)None statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksSexualNone statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksSexual/minorsNone statedDisallowed content tableUnverified
GPT-5.6 SolProduction BenchmarksViolent illicit behaviorNone statedDisallowed content tableUnverified
GPT-5.6 TerraProduction BenchmarksGoreNone statedDisallowed content tableUnverified

M8 Jailbreak robustness

1 value

M8 Jailbreak robustness: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolJailbreaksRobustness vs GPT-5.5None statedRobustness (Fig 3)Unverified

M9 Prompt injection

8 values

M9 Prompt injection: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationCheckedVersion
GPT-5.6 SolGPT-RedIndirect prompt injectionNone statedPrompt injection (GPT-Red)VerifiedVersion of 3 Aug 2026
GPT-5.6 SolGPT-RedInstruction hierarchy (direct PI)None statedPrompt injection (GPT-Red)VerifiedVersion of 3 Aug 2026
GPT-5.4 ThinkingPrompt injectionSearch and function-callingNone statedPrompt injection tableUnverifiedCopy retrieved 26 Sep 2026
GPT-5.5Prompt injectionConnectorsNone statedPrompt injection tableVerifiedCopy retrieved 26 Sep 2026
GPT-5.6 LunaPrompt injectionSearch and function-callingNone statedPrompt injection tableUnverifiedCopy retrieved 26 Sep 2026
GPT-5.6 SolPrompt injectionConnectorsNone statedPrompt injection tableUnverifiedCopy retrieved 26 Sep 2026
GPT-5.6 SolPrompt injectionSearch and function-callingNone statedPrompt injection tableUnverifiedCopy retrieved 26 Sep 2026
GPT-5.6 TerraPrompt injectionSearch and function-callingNone statedPrompt injection tableUnverifiedCopy retrieved 26 Sep 2026

M10 Dangerous capabilities and risk determinations

16 values

M10 Dangerous capabilities and risk determinations: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.5Hard-negative protein bindingScorepass@4ChangelogVerified
GPT-5.6 SolFrontierCyberSuccess rateRun by IrregularHard tierExternal cyber (Irregular)Unverified
GPT-5.5Expert CTFPass rateRun by UK AI Security InstituteNone statedExternal cyber (UK AISI)Unverified
GPT-5.6 SolCyber range 'The Last Ones'Attempts completedRun by UK AI Security InstituteNone statedExternal cyber (UK AISI)Unverified
GPT-5.6 SolExpert CTFPass rateRun by UK AI Security InstituteNone statedExternal cyber (UK AISI)Unverified
GPT-5.6 SolPreparedness Framework determinationAI self-improvementNone statedPreparednessUnverified
GPT-5.6 SolPreparedness Framework determinationBiological and chemicalNone statedPreparednessUnverified
GPT-5.6 SolPreparedness Framework determinationCybersecurityNone statedPreparednessUnverified
GPT-5.6 TerraTacit knowledge and troubleshootingScoreNone statedPreparedness bioUnverified
GPT-5.6 SolAAV capsid packaging predictionScoreNone statedPreparedness evalsUnverified
GPT-5.6 SolCapture the FlagInternalNone statedPreparedness evalsUnverified
GPT-5.6 SolDNA sequence designScoreNone statedPreparedness evalsUnverified
GPT-5.6 SolHard-negative protein bindingScorepass@4Preparedness evalsUnverified
GPT-5.6 SolMultimodal Troubleshooting VirologyScoreNone statedPreparedness evalsUnverified
GPT-5.6 SolProtocolQA Open-EndedScoreNone statedPreparedness evalsUnverified
GPT-5.6 SolTroubleshootingBenchScoreNone statedPreparedness evalsUnverified

M12 Chain-of-thought monitorability

4 values

M12 Chain-of-thought monitorability: values in the GPT-5.6 System Card
ModelEvaluationConditionValueLocationChecked
GPT-5.6 SolCoT monitorabilityMonitorability vs GPT-5.5medium7.3 CoT evaluationsUnverified
GPT-5.4 ThinkingCoT controllabilityCoTs successfully controlled~5k-token CoTs7.3 CoT evaluations (Fig 14)Unverified
GPT-5.5CoT controllabilityCoTs successfully controlled~5k-token CoTs7.3 CoT evaluations (Fig 14)Unverified
GPT-5.6 SolCoT controllabilityCoTs successfully controlled~5k-token CoTs7.3 CoT evaluations (Fig 14)Unverified

Extraction coverage

What we read of this document, and where each value was read.

Our note We have not written a coverage note for this document yet.

All 51 values were read in the document itself.

Of the 51 values, 6 are statements in words rather than numbers; they are marked * and left out of charts by default.

All 51 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).