GPT-5-Codex System Card Addendum
A system card addendum by OpenAI about GPT-5-Codex, published 15 Sep 2025. We recorded 21 values from it.
- Developer
- OpenAI
- Type
- System card addendum
- Model covered
- GPT-5-Codex
- Published
- 15 Sep 2025
- Archived copy
- No archived copy yet
- Changelog
- Not known
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Versions
One version is on record: the copy we retrieved on 26 Sep 2026. We know of no other.
26 Sep 2026
Date retrieved
Copy retrieved 26 Sep 2026
No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).
Revisions
No revisions are recorded for this document. We know of only one version of it.
Values
Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 1 of the 21 has been blind-verified: a second reader found the same value without seeing ours.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M7 Harmful compliance and over-refusal
13 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5-Codex | Production BenchmarksExtremism | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksHarassment/threatening | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksHate/threatening | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksIllicit/non-violent | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksIllicit/violent | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksNon-violent hate | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksPersonal data | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksSelf-harm/instructions | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksSelf-harm/intent | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksSexual/exploitative | None stated | Table 1 | Unverified | |
| GPT-5-Codex | Production BenchmarksSexual/minors | None stated | Table 1 | Unverified | |
| codex-1 | Malware refusals (golden set)Refusal rate | None stated | Table 3 | Unverified | |
| GPT-5-Codex | Malware refusals (golden set)Refusal rate | None stated | Table 3 | Unverified |
M8 Jailbreak robustness
4 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5-Codex | StrongRejectAbuse/disinformation/hate | None stated | Table 2 | Unverified | |
| GPT-5-Codex | StrongRejectIllicit/non-violent crime | None stated | Table 2 | Verified | |
| GPT-5-Codex | StrongRejectSexual content | None stated | Table 2 | Unverified | |
| GPT-5-Codex | StrongRejectViolence | None stated | Table 2 | Unverified |
M9 Prompt injection
2 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| codex-1 | Prompt injection (Codex env)Attacks successfully ignored | None stated | Table 4 | Unverified | |
| GPT-5-Codex | Prompt injection (Codex env)Attacks successfully ignored | None stated | Table 4 | Unverified |
M10 Dangerous capabilities and risk determinations
2 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| GPT-5-Codex | Preparedness Framework determinationBiological and chemical | None stated | Preparedness | Unverified | |
| GPT-5-Codex | Preparedness Framework determinationCybersecurity | None stated | Preparedness | Unverified |
Extraction coverage
What we read of this document, and where each value was read.
Our note We have not written a coverage note for this document yet.
All 21 values were read in the document itself.
All 21 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).