GPT-5.3-Codex
30 values about GPT-5.3-Codex from 3 documents, in 8 metric families. In each family, values from its own document come first.
- Developer
- OpenAI
- Release date
- 5 Feb 2026The date of its first card in the dataset, the GPT-5.3-Codex System Card.
- Availability
- Public
- Also printed as
- GPT-5.3-Codex (pre-release)
- Snapshot
- pre-releaseValues about a snapshot are marked in the tables; they are not a separate model.
- Its own document
- GPT-5.3-Codex System Card · 5 Feb 2026
- Also reported in
- GPT-5.4 Thinking System Card · 5 Mar 2026
- GPT-5.5 System Card · 23 Apr 2026
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Values by metric family
Each value as the document printed it. Select a value for its source, its checks and its history. Values from other documents are listed after the model’s own, each marked as the first report of that measure or as a restatement.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M1 · Evaluation awareness 1 value
| Evaluation and metric | Value | Document |
|---|---|---|
| From other documents | ||
| Evaluation awarenessSamples with moderate-or-higher eval awarenessRun by Apollo ResearchSnapshot: pre-releaseGPT-5.5 System Card23 Apr 2026First reported | GPT-5.5 System Card23 Apr 2026First reported | |
M3 · Sabotage and sandbagging 2 values
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Sabotage capabilityMean best-of-10 scoreRun by Apollo Research | GPT-5.3-Codex System Card5 Feb 2026 | |
| SandbaggingSandbags on capability Q&ACondition: including without an in-context goalRun by Apollo Research | GPT-5.3-Codex System Card5 Feb 2026 | |
M4 · Misalignment audits 2 values
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Covert deceptive behaviorCovert action rateRun by Apollo Research | GPT-5.3-Codex System Card5 Feb 2026 | |
| Destructive action avoidanceAvoidance | GPT-5.3-Codex System Card5 Feb 2026 | |
M5 · Honesty and hallucination 1 value
| Evaluation and metric | Value | Document |
|---|---|---|
| From other documents | ||
| Impossible Coding TaskSamples lying about completing taskRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026First reported | GPT-5.5 System Card23 Apr 2026First reported | |
M7 · Harmful compliance and over-refusal 12 values
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Cyber safetyProduction data | GPT-5.3-Codex System Card5 Feb 2026 | |
| Cyber safetySynthetic data | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksAbuse | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksBiological weapons | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksChemical weapons | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksExtremism | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksHate | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksNonviolent illicit behavior | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksSelf-harm (standard) | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksSexual/minors | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksViolence | GPT-5.3-Codex System Card5 Feb 2026 | |
| Production BenchmarksViolent illicit behavior | GPT-5.3-Codex System Card5 Feb 2026 | |
M8 · Jailbreak robustness 1 value
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Universal jailbreak (cyber)Policy-violating cyber dataset pass rateCondition: pass@200; ~10h red-teamingRun by UK AI Security Institute | GPT-5.3-Codex System Card5 Feb 2026 | |
M10 · Dangerous capabilities and risk determinations 10 values
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Capture the FlagProfessional vs GPT-5.2-Codex | GPT-5.3-Codex System Card5 Feb 2026 | |
| CVE-BenchPass rate | GPT-5.3-Codex System Card5 Feb 2026 | |
| Cyber challengesEvasion: average success rateRun by Irregular | GPT-5.3-Codex System Card5 Feb 2026 | |
| Cyber challengesNetwork attack simulation: average success rateRun by Irregular | GPT-5.3-Codex System Card5 Feb 2026 | |
| Cyber challengesVulnerability research and exploitation: average success rateRun by Irregular | GPT-5.3-Codex System Card5 Feb 2026 | |
| Cyber RangeCombined pass rateRestated later: compare with the later value | GPT-5.3-Codex System Card5 Feb 2026Restated later: compare with the later value | |
| Preparedness Framework determinationAI self-improvement | GPT-5.3-Codex System Card5 Feb 2026 | |
| Preparedness Framework determinationBiological and chemical | GPT-5.3-Codex System Card5 Feb 2026 | |
| Preparedness Framework determinationCybersecurity | GPT-5.3-Codex System Card5 Feb 2026 | |
| From other documents | ||
| Cyber RangeCombined pass rateGPT-5.4 Thinking System Card5 Mar 2026Restated: compare with the earlier value | GPT-5.4 Thinking System Card5 Mar 2026Restated: compare with the earlier value | |
M12 · Chain-of-thought monitorability 1 value
| Evaluation and metric | Value | Document |
|---|---|---|
| From its own documentGPT-5.3-Codex System Card · 5 Feb 2026 | ||
| Non-Latin reasoning tokensShare of non-Latin reasoning tokensRun by Apollo Research | GPT-5.3-Codex System Card5 Feb 2026 | |
Restated in later documents
A later document reported a value about GPT-5.3-Codex again. Each pair is shown side by side: both values are kept with their own documents, and the later one does not replace the earlier.
| Earlier value | Later value |
|---|---|
| M10 · Dangerous capabilities and risk determinations | |
| Cyber RangeCombined pass rate | |
| GPT-5.3-Codex System Card5 Feb 2026 · its own document | GPT-5.4 Thinking System Card5 Mar 2026No reason stated |
Risk determinations
The developer's formal decisions about GPT-5.3-Codex under its framework, as printed. Levels from different frameworks do not map onto one another.
| Domain | Level as printed | Framework and document |
|---|---|---|
| Bio/chem | high code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 | Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 |
| Cyber | high code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 | Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 |
| AI R&D / autonomy | below_high code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 | Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026 |
“Code, not the printed wording”: the version 0 file stored a code for this level rather than the words the document printed. The wording will be read again from the source.