Values by metric family

Each value as the document printed it. Select a value for its source, its checks and its history. Values from other documents are listed after the model’s own, each marked as the first report of that measure or as a restatement.

KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.

M1 · Evaluation awareness 2 values

M1 Evaluation awareness: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
Evaluation awarenessSamples with moderate-or-higher eval awarenessRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026
From other documents
Evaluation awarenessSamples with verbalized eval awarenessCondition: xhighRun by Apollo ResearchGPT-6 Astra System Card3 Sep 2026First reportedGPT-6 Astra System Card3 Sep 2026First reported

M3 · Sabotage and sandbagging 2 values

M3 Sabotage and sandbagging: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
Sabotage capabilityMean score across task/difficultyRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026
SandbaggingAccuracy when incentivized <50%Run by Apollo ResearchGPT-5.5 System Card23 Apr 2026

M4 · Misalignment audits 7 values

M4 Misalignment audits: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
ChatGPT deployment simulationSeverity-3 misalignment rateGPT-5.5 System Card23 Apr 2026
Covert deceptive behaviorCovert action rateRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026
Destructive action avoidanceAvoidanceGPT-5.5 System Card23 Apr 2026
Destructive action avoidancePerfect reversionGPT-5.5 System Card23 Apr 2026
Destructive action avoidanceUser work preservedGPT-5.5 System Card23 Apr 2026
From other documents
Destructive action avoidanceAvoidanceGPT-5.6 System Card9 Jul 2026First reportedGPT-5.6 System Card9 Jul 2026First reported
Destructive action avoidanceAvoidance + correctnessGPT-5.6 System Card9 Jul 2026First reportedGPT-5.6 System Card9 Jul 2026First reported

M5 · Honesty and hallucination 2 values

M5 Honesty and hallucination: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
HallucinationsResponses with factual error vs GPT-5.4 ThinkingGPT-5.5 System Card23 Apr 2026
Impossible Coding TaskSamples lying about completing taskRun by Apollo ResearchGPT-5.5 System Card23 Apr 2026

M7 · Harmful compliance and over-refusal 11 values

M7 Harmful compliance and over-refusal: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
Production BenchmarksExtremismGPT-5.5 System Card23 Apr 2026
Production BenchmarksHarassmentGPT-5.5 System Card23 Apr 2026
Production BenchmarksHateGPT-5.5 System Card23 Apr 2026
Production BenchmarksNonviolent illicit behaviorGPT-5.5 System Card23 Apr 2026
Production BenchmarksSelf-harm (standard)GPT-5.5 System Card23 Apr 2026
Production BenchmarksSexualGPT-5.5 System Card23 Apr 2026
Production BenchmarksSexual/minorsGPT-5.5 System Card23 Apr 2026
Production BenchmarksViolenceGPT-5.5 System Card23 Apr 2026
Production BenchmarksViolent illicit behaviorGPT-5.5 System Card23 Apr 2026
From other documents
Production BenchmarksGoreGPT-5.6 System Card9 Jul 2026First reportedGPT-5.6 System Card9 Jul 2026First reported
HackerBenchCompliance on harmful/dual-use cyber tasksCondition: xhighGrok 4.5 Model Card14 Jul 2026Reported by xAIFirst reportedGrok 4.5 Model Card14 Jul 2026Reported by xAIFirst reported

M8 · Jailbreak robustness 2 values

M8 Jailbreak robustness: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
JailbreaksWorst-case defender successGPT-5.5 System Card23 Apr 2026
From other documents
Static jailbreakCyberGPT-6 Astra System Card3 Sep 2026First reportedGPT-6 Astra System Card3 Sep 2026First reported

M9 · Prompt injection 2 values

M9 Prompt injection: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
Prompt injectionConnectorsRestated later: compare with the later valueGPT-5.5 System Card23 Apr 2026Restated later: compare with the later value
From other documents
Prompt injectionConnectorsGPT-5.6 System Card9 Jul 2026Restated: compare with the earlier valueGPT-5.6 System Card9 Jul 2026Restated: compare with the earlier value

M10 · Dangerous capabilities and risk determinations 11 values

M10 Dangerous capabilities and risk determinations: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
Cyber RangeCombined pass rateGPT-5.5 System Card23 Apr 2026
Cyber tasksPass rateCondition: pass@5Run by UK AI Security InstituteGPT-5.5 System Card23 Apr 2026
CyScenarioBenchAverage success rateRun by IrregularGPT-5.5 System Card23 Apr 2026
DNA sequence designScoreCondition: pass@1GPT-5.5 System Card23 Apr 2026
Hard-negative protein bindingScoreCondition: pass@4Restated later: compare with the later valueGPT-5.5 System Card23 Apr 2026Restated later: compare with the later value
Internal Research DebuggingMedian scoreGPT-5.5 System Card23 Apr 2026
Preparedness Framework determinationAI self-improvementGPT-5.5 System Card23 Apr 2026
Preparedness Framework determinationBiological and chemicalGPT-5.5 System Card23 Apr 2026
Preparedness Framework determinationCybersecurityGPT-5.5 System Card23 Apr 2026
From other documents
Expert CTFPass rateRun by UK AI Security InstituteGPT-5.6 System Card9 Jul 2026First reportedGPT-5.6 System Card9 Jul 2026First reported
Hard-negative protein bindingScoreCondition: pass@4GPT-5.6 System Card9 Jul 2026Restated: compare with the earlier valueGPT-5.6 System Card9 Jul 2026Restated: compare with the earlier value

M12 · Chain-of-thought monitorability 3 values

M12 Chain-of-thought monitorability: values about GPT-5.5
Evaluation and metricValueDocument
From its own documentGPT-5.5 System Card · 23 Apr 2026
CoT controllabilityCoTs successfully controlledCondition: 50k-character CoTsGPT-5.5 System Card23 Apr 2026
Misalignment monitor recallRecall flagging severity 3+GPT-5.5 System Card23 Apr 2026
From other documents
CoT controllabilityCoTs successfully controlledCondition: ~5k-token CoTsGPT-5.6 System Card9 Jul 2026First reportedGPT-5.6 System Card9 Jul 2026First reported

Restated in later documents

A later document reported values about GPT-5.5 again. Each pair is shown side by side: both values are kept with their own documents, and the later one does not replace the earlier.

Values about GPT-5.5 restated in later documents
Earlier valueLater value
M9 · Prompt injection
Prompt injectionConnectors
GPT-5.5 System Card23 Apr 2026 · its own documentGPT-5.6 System Card9 Jul 2026No reason stated
M10 · Dangerous capabilities and risk determinations
Hard-negative protein bindingScoreCondition: pass@4
GPT-5.5 System Card23 Apr 2026 · its own documentGPT-5.6 System Card9 Jul 2026Reason stated: corrected in the later card's changelog from a pass@1 figure

Risk determinations

The developer's formal decisions about GPT-5.5 under its framework, as printed. Levels from different frameworks do not map onto one another.

Risk determinations about GPT-5.5
DomainLevel as printedFramework and document
Bio/chemhigh code, not the printed wording Preparedness Framework GPT-5.5 System Card · 23 Apr 2026Preparedness Framework GPT-5.5 System Card · 23 Apr 2026
Cyberhigh code, not the printed wording Preparedness Framework GPT-5.5 System Card · 23 Apr 2026Preparedness Framework GPT-5.5 System Card · 23 Apr 2026
AI R&D / autonomybelow_high code, not the printed wording Preparedness Framework GPT-5.5 System Card · 23 Apr 2026Preparedness Framework GPT-5.5 System Card · 23 Apr 2026

“Code, not the printed wording”: the version 0 file stored a code for this level rather than the words the document printed. The wording will be read again from the source.

Revisions

Changes made to a document after it was published that change a value about GPT-5.5.

  1. OpenAI · 9 Jul 2026 to 19 Aug 2026

    GPT-5.6 System Card

    GPT-5.5 hard-negative protein-binding prediction, pass@4

    M10 · Dangerous capabilities and risk determinations

    0.4%1.5%

    Explained — earlier figure was the pass@1 score

    New value:

    How we know Changelog read 26 Sep 2026; same entry also appears in the GPT-5.6 Preview card changelog

    Checked Confirmed from changelog