Values by metric family

Each value as the document printed it. Select a value for its source, its checks and its history. Values from other documents are listed after the model’s own, each marked as the first report of that measure or as a restatement.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M1 · Evaluation awareness 1 value

M1 Evaluation awareness: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From other documents
Evaluation awarenessSamples with moderate-or-higher eval awarenessRun by Apollo ResearchSnapshot: pre-releaseGPT-5.5 System Card23 Apr 2026First reportedGPT-5.5 System Card23 Apr 2026First reported

M3 · Sabotage and sandbagging 2 values

M3 Sabotage and sandbagging: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Sabotage capabilityMean best-of-10 scoreRun by Apollo ResearchGPT-5.3-Codex System Card5 Feb 2026
SandbaggingSandbags on capability Q&ACondition: including without an in-context goalRun by Apollo ResearchGPT-5.3-Codex System Card5 Feb 2026

M4 · Misalignment audits 2 values

M4 Misalignment audits: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Covert deceptive behaviorCovert action rateRun by Apollo ResearchGPT-5.3-Codex System Card5 Feb 2026
Destructive action avoidanceAvoidanceGPT-5.3-Codex System Card5 Feb 2026

M5 · Honesty and hallucination 1 value

M5 Honesty and hallucination: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From other documents
Impossible Coding TaskSamples lying about completing taskRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026First reportedGPT-5.5 System Card23 Apr 2026First reported

M7 · Harmful compliance and over-refusal 12 values

M7 Harmful compliance and over-refusal: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Cyber safetyProduction dataGPT-5.3-Codex System Card5 Feb 2026
Cyber safetySynthetic dataGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksAbuseGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksBiological weaponsGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksChemical weaponsGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksExtremismGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksHateGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksNonviolent illicit behaviorGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksSelf-harm (standard)GPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksSexual/minorsGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksViolenceGPT-5.3-Codex System Card5 Feb 2026
Production BenchmarksViolent illicit behaviorGPT-5.3-Codex System Card5 Feb 2026

M8 · Jailbreak robustness 1 value

M8 Jailbreak robustness: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Universal jailbreak (cyber)Policy-violating cyber dataset pass rateCondition: pass@200; ~10h red-teamingRun by UK AI Security InstituteGPT-5.3-Codex System Card5 Feb 2026

M10 · Dangerous capabilities and risk determinations 10 values

M10 Dangerous capabilities and risk determinations: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Capture the FlagProfessional vs GPT-5.2-CodexGPT-5.3-Codex System Card5 Feb 2026
CVE-BenchPass rateGPT-5.3-Codex System Card5 Feb 2026
Cyber challengesEvasion: average success rateRun by IrregularGPT-5.3-Codex System Card5 Feb 2026
Cyber challengesNetwork attack simulation: average success rateRun by IrregularGPT-5.3-Codex System Card5 Feb 2026
Cyber challengesVulnerability research and exploitation: average success rateRun by IrregularGPT-5.3-Codex System Card5 Feb 2026
Cyber RangeCombined pass rateRestated later: compare with the later valueGPT-5.3-Codex System Card5 Feb 2026Restated later: compare with the later value
Preparedness Framework determinationAI self-improvementGPT-5.3-Codex System Card5 Feb 2026
Preparedness Framework determinationBiological and chemicalGPT-5.3-Codex System Card5 Feb 2026
Preparedness Framework determinationCybersecurityGPT-5.3-Codex System Card5 Feb 2026
From other documents
Cyber RangeCombined pass rateGPT-5.4 Thinking System Card5 Mar 2026Restated: compare with the earlier valueGPT-5.4 Thinking System Card5 Mar 2026Restated: compare with the earlier value

M12 · Chain-of-thought monitorability 1 value

M12 Chain-of-thought monitorability: values about GPT-5.3-Codex
Evaluation and metricValueDocument
From its own documentGPT-5.3-Codex System Card · 5 Feb 2026
Non-Latin reasoning tokensShare of non-Latin reasoning tokensRun by Apollo ResearchGPT-5.3-Codex System Card5 Feb 2026

Restated in later documents

A later document reported a value about GPT-5.3-Codex again. Each pair is shown side by side: both values are kept with their own documents, and the later one does not replace the earlier.

Values about GPT-5.3-Codex restated in later documents
Earlier valueLater value
M10 · Dangerous capabilities and risk determinations
Cyber RangeCombined pass rate
GPT-5.3-Codex System Card5 Feb 2026 · its own documentGPT-5.4 Thinking System Card5 Mar 2026No reason stated

Risk determinations

The developer's formal decisions about GPT-5.3-Codex under its framework, as printed. Levels from different frameworks do not map onto one another.

Risk determinations about GPT-5.3-Codex
DomainLevel as printedFramework and document
Bio/chemhigh code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026
Cyberhigh code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026
AI R&D / autonomybelow_high code, not the printed wording Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026Preparedness Framework GPT-5.3-Codex System Card · 5 Feb 2026

“Code, not the printed wording”: the version 0 file stored a code for this level rather than the words the document printed. The wording will be read again from the source.