Versions

Four versions are on record, oldest first. We hold a copy of one; the others are known only by their date.

  1. 7 Aug 2025

    First published version

    Date from
    our source registry
    Copy
    Known to exist; no copy held
  2. 13 Aug 2025

    Revision

    Date from
    our source registry
    Copy
    Known to exist; no copy held

    What changed PDF of 2025-08-07 replaced by 2025-08-13 version without changelog

  3. 24 Apr 2026

    Revision

    Date from
    the document's changelog
    Copy
    Known from the changelog; no copy held
    Values
    2 values recorded from this version

    What changed hub added chain-of-thought evaluations

  4. 26 Sep 2026

    Date retrieved

    Copy retrieved 26 Sep 2026

    Date from
    the date we retrieved it; the copy states no version date
    Copy
    Copy retrieved on 26 Sep 2026
    Values
    116 values recorded from this version

No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).

Revisions

No revisions are recorded for this document. Without copies of the earlier versions, changes between them are not recorded value by value; what we know of each version is listed below.

Values

Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 4 of the 118 have been blind-verified: a second reader found the same value without seeing ours.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M1 Evaluation awareness

4 values

M1 Evaluation awareness: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
gpt-5-thinkingEvaluation awarenessVerbalized eval awareness, broadRun by Apollo Researchall samplesExternal: Apollo ResearchVerified
gpt-5-thinkingEvaluation awarenessVerbalized eval awareness, broadRun by Apollo Researchscheming samplesExternal: Apollo ResearchUnverified
gpt-5-thinkingEvaluation awarenessVerbalized eval awareness, strictRun by Apollo Researchall samplesExternal: Apollo ResearchUnverified
gpt-5-thinkingEvaluation awarenessVerbalized eval awareness, strictRun by Apollo Researchscheming samplesExternal: Apollo ResearchUnverified

M3 Sabotage and sandbagging

1 value

M3 Sabotage and sandbagging: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
gpt-5-thinkingSandbagging reviewClear evidence of sandbaggingRun by METRNone statedExternal: METR / SandbaggingUnverified

M4 Misalignment audits

5 values

M4 Misalignment audits: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
gpt-5-thinkingCovert deceptive behaviorShare of trajectories with deceptive actionRun by Apollo ResearchApollo scheming suiteExternal: Apollo ResearchUnverified
gpt-5-thinkingLog falsificationCovert action rateRun by Apollo Researchstrong goal nudgeExternal: Apollo ResearchUnverified
gpt-5-thinkingLog falsificationCovert action rateRun by Apollo Researchweak goal nudgeExternal: Apollo ResearchUnverified
gpt-5-thinking-helpful-onlyCovert deceptive behaviorShare of trajectories with deceptive actionRun by Apollo ResearchApollo scheming suiteExternal: Apollo ResearchUnverified
o3Covert deceptive behaviorShare of trajectories with deceptive actionRun by Apollo ResearchApollo scheming suiteExternal: Apollo ResearchUnverified

M5 Honesty and hallucination

21 values

M5 Honesty and hallucination: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
GPT-4oSimpleQAHallucination rateno browsing3.7 Table 8Unverified
gpt-5-mainSimpleQAHallucination rateno browsing3.7 Table 8Unverified
gpt-5-thinkingSimpleQAHallucination rateno browsing3.7 Table 8Unverified
gpt-5-thinking-miniSimpleQAHallucination rateno browsing3.7 Table 8Unverified
gpt-5-thinking-nanoSimpleQAHallucination rateno browsing3.7 Table 8Unverified
o3SimpleQAHallucination rateno browsing3.7 Table 8Unverified
o4-miniSimpleQAHallucination rateno browsing3.7 Table 8Unverified
gpt-5-mainProduction-traffic factualityClaim-level hallucination rate reduction vs GPT-4owith browsing; production prompts3.7 textUnverified
gpt-5-mainProduction-traffic factualityReduction in responses with 1+ major error vs GPT-4owith browsing; production prompts3.7 textUnverified
gpt-5-thinkingProduction-traffic factualityClaim-level hallucination rate reduction vs o3with browsing; production prompts3.7 textUnverified
gpt-5-thinkingProduction-traffic factualityReduction in responses with 1+ major error vs o3with browsing; production prompts3.7 textUnverified
gpt-5-thinkingAbstentionBenchRecall (appropriate abstention)None stated3.8 Table 9Unverified
gpt-5-thinkingDeception evalAgentic coding (impossible tasks)None stated3.8 Table 9Unverified
gpt-5-thinkingDeception evalBrowsing broken toolsNone stated3.8 Table 9Unverified
gpt-5-thinkingDeception evalCharXiv missing imageNone stated3.8 Table 9Unverified
o3AbstentionBenchRecall (appropriate abstention)None stated3.8 Table 9Unverified
o3Deception evalAgentic coding (impossible tasks)None stated3.8 Table 9Unverified
o3Deception evalBrowsing broken toolsNone stated3.8 Table 9Unverified
o3Deception evalCharXiv missing imageNone stated3.8 Table 9Unverified
gpt-5-thinkingProduction CoT deception monitorShare of responses flagged deceptiverepresentative production traffic3.8.1Verified
o3Production CoT deception monitorShare of responses flagged deceptiverepresentative production traffic3.8.1Verified

M6 Sycophancy

5 values

M6 Sycophancy: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
GPT-4oSycophancy offline evalSycophancy scoreoffline3.3 Table 4Unverified
gpt-5-mainSycophancy offline evalSycophancy scoreoffline3.3 Table 4Unverified
gpt-5-mainSycophancy online prevalence (A/B)Relative change vs GPT-4ofree users3.3 Table 4Unverified
gpt-5-mainSycophancy online prevalence (A/B)Relative change vs GPT-4opaid users3.3 Table 4Unverified
gpt-5-thinkingSycophancy offline evalSycophancy scoreoffline3.3 Table 4Unverified

M7 Harmful compliance and over-refusal

44 values

M7 Harmful compliance and over-refusal: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
GPT-4oProduction BenchmarksExtremismNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksHarassment/threateningNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksHate/threateningNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksIllicit/non-violentNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksIllicit/violentNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksNon-violent hateNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksPersonal dataNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksSelf-harm/instructionsNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksSelf-harm/intentNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksSexual/exploitativeNone stated3.2 Table 3Unverified
GPT-4oProduction BenchmarksSexual/minorsNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksExtremismNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksHarassment/threateningNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksHate/threateningNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksIllicit/non-violentNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksIllicit/violentNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksNon-violent hateNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksPersonal dataNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksSelf-harm/instructionsNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksSelf-harm/intentNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksSexual/exploitativeNone stated3.2 Table 3Unverified
gpt-5-mainProduction BenchmarksSexual/minorsNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksExtremismNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksHarassment/threateningNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksHate/threateningNone stated3.2 Table 3Verified
gpt-5-thinkingProduction BenchmarksIllicit/non-violentNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksIllicit/violentNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksNon-violent hateNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksPersonal dataNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksSelf-harm/instructionsNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksSelf-harm/intentNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksSexual/exploitativeNone stated3.2 Table 3Unverified
gpt-5-thinkingProduction BenchmarksSexual/minorsNone stated3.2 Table 3Unverified
o3Production BenchmarksExtremismNone stated3.2 Table 3Unverified
o3Production BenchmarksHarassment/threateningNone stated3.2 Table 3Unverified
o3Production BenchmarksHate/threateningNone stated3.2 Table 3Unverified
o3Production BenchmarksIllicit/non-violentNone stated3.2 Table 3Unverified
o3Production BenchmarksIllicit/violentNone stated3.2 Table 3Unverified
o3Production BenchmarksNon-violent hateNone stated3.2 Table 3Unverified
o3Production BenchmarksPersonal dataNone stated3.2 Table 3Unverified
o3Production BenchmarksSelf-harm/instructionsNone stated3.2 Table 3Unverified
o3Production BenchmarksSelf-harm/intentNone stated3.2 Table 3Unverified
o3Production BenchmarksSexual/exploitativeNone stated3.2 Table 3Unverified
o3Production BenchmarksSexual/minorsNone stated3.2 Table 3Unverified

M8 Jailbreak robustness

16 values

M8 Jailbreak robustness: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
GPT-4oStrongRejectAbuse/disinformation/hateNone stated3.4 Table 5Unverified
GPT-4oStrongRejectIllicit/non-violent crimeNone stated3.4 Table 5Unverified
GPT-4oStrongRejectSexual contentNone stated3.4 Table 5Unverified
GPT-4oStrongRejectViolenceNone stated3.4 Table 5Unverified
gpt-5-mainStrongRejectAbuse/disinformation/hateNone stated3.4 Table 5Unverified
gpt-5-mainStrongRejectIllicit/non-violent crimeNone stated3.4 Table 5Unverified
gpt-5-mainStrongRejectSexual contentNone stated3.4 Table 5Unverified
gpt-5-mainStrongRejectViolenceNone stated3.4 Table 5Unverified
gpt-5-thinkingStrongRejectAbuse/disinformation/hateNone stated3.4 Table 5Unverified
gpt-5-thinkingStrongRejectIllicit/non-violent crimeNone stated3.4 Table 5Unverified
gpt-5-thinkingStrongRejectSexual contentNone stated3.4 Table 5Unverified
gpt-5-thinkingStrongRejectViolenceNone stated3.4 Table 5Unverified
o3StrongRejectAbuse/disinformation/hateNone stated3.4 Table 5Unverified
o3StrongRejectIllicit/non-violent crimeNone stated3.4 Table 5Unverified
o3StrongRejectSexual contentNone stated3.4 Table 5Unverified
o3StrongRejectViolenceNone stated3.4 Table 5Unverified

M9 Prompt injection

6 values

M9 Prompt injection: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
gpt-5-thinkingPrompt injectionBrowsingNone stated3.6 Table 7Unverified
gpt-5-thinkingPrompt injectionCodingNone stated3.6 Table 7Unverified
gpt-5-thinkingPrompt injectionTool callingNone stated3.6 Table 7Unverified
o3Prompt injectionBrowsingNone stated3.6 Table 7Unverified
o3Prompt injectionCodingNone stated3.6 Table 7Unverified
o3Prompt injectionTool callingNone stated3.6 Table 7Unverified

M10 Dangerous capabilities and risk determinations

14 values

M10 Dangerous capabilities and risk determinations: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationChecked
ChatGPT agentMLE-BenchMedal rateNone stated5 AI Self-improvementUnverified
gpt-5-thinkingOpenAI-Proof Q&APass rateNone stated5 AI Self-improvementUnverified
gpt-5-thinkingTroubleshootingBenchDifference vs o3None stated5 BioUnverified
gpt-5-thinkingPreparedness Framework determinationAI self-improvementNone stated5 PreparednessUnverified
gpt-5-thinkingPreparedness Framework determinationBiological and chemicalNone stated5 PreparednessUnverified
gpt-5-thinkingPreparedness Framework determinationCybersecurityNone stated5 PreparednessUnverified
gpt-5-thinking50% time horizonTask length at 50% successRun by METRNone statedExternal: METRUnverified
o350% time horizonTask length at 50% successRun by METRNone statedExternal: METRUnverified
gpt-5-thinkingCyber challengesEasy: challenges solvedRun by Irregularout of 18 challengesExternal: Pattern LabsUnverified
gpt-5-thinkingCyber challengesEvasion: average success rateRun by IrregularNone statedExternal: Pattern LabsUnverified
gpt-5-thinkingCyber challengesHard: challenges solvedRun by Irregularout of 4 challengesExternal: Pattern LabsUnverified
gpt-5-thinkingCyber challengesMedium: challenges solvedRun by Irregularout of 14 challengesExternal: Pattern LabsUnverified
gpt-5-thinkingCyber challengesNetwork attack simulation: average success rateRun by IrregularNone statedExternal: Pattern LabsUnverified
gpt-5-thinkingCyber challengesVulnerability discovery and exploitation: average success rateRun by IrregularNone statedExternal: Pattern LabsUnverified

M12 Chain-of-thought monitorability

2 values

M12 Chain-of-thought monitorability: values in the GPT-5 System Card
ModelEvaluationConditionValueLocationCheckedVersion
gpt-5-thinkingCoT controllabilityAbility to control CoT contentNone statedCoT Evaluations (hub)UnverifiedVersion of 24 Apr 2026
gpt-5-thinkingCoT monitorabilityMonitorability vs o3None statedCoT Evaluations (hub)UnverifiedVersion of 24 Apr 2026

Extraction coverage

What we read of this document, and where each value was read.

Our note Many Preparedness numbers are chart-only (excluded)

All 118 values were read in the document itself.

Of the 118 values, 4 are statements in words rather than numbers; they are marked * and left out of charts by default.

All 118 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).