Overview
Revisions
Changes developers made to their documents after publishing them, newest first. Each change is shown as the two versions print it, with whether the document's own changelog explains it. A revision is not in itself evidence of wrongdoing; most are corrections.
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Summary
The ledger records 15 revisions to 9 documents by Anthropic, Google DeepMind, OpenAI and xAI, dated between Dec 2025 and 9 Sep 2026. Of these, the document's own changelog explains 7, partly explains 3 and does not explain 2; 3 are in documents that keep no changelog. In 3 of them, a document was marked updated and there is no record of what changed.
| Explanation | Revisions | Developers |
|---|---|---|
| ExplainedThe document's changelog describes the change. | 7 — show the revisions marked Explained | Anthropic, OpenAI |
| Partly explainedThe changelog mentions the change, but not in full or without a reason. | 3 — show the revisions marked Partly explained | xAI |
| Not explainedChanged without an explanation in the document's changelog. | 2 — show the revisions marked Not explained | xAI |
| No changelogThe document keeps no changelog. | 3 — show the revisions marked No changelog | Google DeepMind |
| All statuses | 15 | Anthropic, Google DeepMind, OpenAI, xAI |
The ledger holds the revisions recorded so far. Developers' changelogs also date 25 later versions of documents whose changes are not recorded in the ledger; each document's page lists its versions.
Every revision, newest first
Grouped by the revision of a document they belong to, and dated by the later version as the document states it, not by when we read it. Select a value for its source and its checks.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
Showing all 15 revisions.
GPT-6 Astra System Card
- Earlier version
- 3 Sep 2026, dated by our source registry. Known to exist; no copy held
- Later version
- 9 Sep 2026, dated by the document's changelog. Known from the changelog; no copy held
Wording changed
Alignment section clarified and its limitations expanded; section on verbalized metagaming and oversight gaming renamed and revised
Explained — changelog describes the changes
How we know Re-read from the change log of the copy retrieved on 27 Sep 2026: two entries dated 9 Sep. The change log gives only the section's current title. An extraction note on m-001261 says the section was titled 'Metagaming and Alignment Faking' before; we cannot confirm that without a copy of the version of 3 Sep.
How it was checked Confirmed from changelog
GPT-5.6 Preview System Card
- Earlier version
- 25 Jun 2026, dated by our source registry. Known to exist; no copy held
- Later version
- 19 Aug 2026, dated by the document's changelog. Known from the changelog; no copy held
Value changed
GPT-5.5 hard-negative protein-binding prediction, pass@4
0.4%1.5%Explained — earlier figure was the pass@1 score
How we know Changelog read 26 Sep 2026 (no v0 value row in this document)
How it was checked Confirmed from changelog
GPT-5.6 System Card
- Earlier version
- 9 Jul 2026, dated by our source registry. Known to exist; no copy held
- Later version
- 19 Aug 2026, dated by the document's changelog. Known from the changelog; no copy held
Value changedM10 · Dangerous capabilities and risk determinations
GPT-5.5 hard-negative protein-binding prediction, pass@4
0.4%1.5%Explained — earlier figure was the pass@1 score
New value
How we know Changelog read 26 Sep 2026; same entry also appears in the GPT-5.6 Preview card changelog
How it was checked Confirmed from changelog
Grok 4.6 Model Card
- Earlier version
- 12 Aug 2026, dated by our source registry. Version of 12 Aug 2026 (opens an external site) · an earlier copy, hosted elsewhere
- Later version
- 17 Aug 2026, dated by the document's changelog. Version of 17 Aug 2026 (opens an external site) · retrieved 26 Sep 2026
Value changedM7 · Harmful compliance and over-refusal
HackerBench v0.2 harmful/dual-use compliance, Grok 4.6 (high)
16.7%6.9%Partly explained — changelog lists "corrected eval results" for this eval; no reason
Old value New value
How we know The old value was read in the earlier copy and the new one in the later copy. Blind check 26 Sep 2026 (both versions)
How it was checked Blind-verified
Value changedM5 · Honesty and hallucination
MASK dishonesty, Grok 4.6 (high)
3.8%1.90%Partly explained — listed as corrected; no reason
Old value New value
How we know The old value was read in the earlier copy and the new one in the later copy. Blind check 26 Sep 2026 (both versions)
How it was checked Blind-verified
Value changedM7 · Harmful compliance and over-refusal
Self-harm compliance, Grok 4.6 (high)
3.7%0.84%Partly explained — listed as corrected; no reason
Old value New value
How we know The old value was read in the earlier copy and the new one in the later copy. Blind check 26 Sep 2026 (both versions)
How it was checked Blind-verified
AddedM7 · Harmful compliance and over-refusal
FORTRESS-RN R/N refusal accuracy added, Grok 4.6 (high)
Not in the earlier version97.9%
Not explained — Added without a changelog note.
New value
How we know The value was read in the later copy; the earlier copy does not have it.
How it was checked Not yet checked
Wording changedM10 · Dangerous capabilities and risk determinations
Bio capability lift statement relative to Grok 4.5, Grok 4.6
no appreciable liftnoted in the biological domain but is limitedNot explained — The changelog does not mention this change.
Old value New value
How we know The old value was read in the earlier copy and the new one in the later copy. The FORTRESS-RN addition in the same revision is recorded separately.
How it was checked Not yet checked
GPT-5.6 System Card
- Earlier version
- 9 Jul 2026, dated by our source registry. Known to exist; no copy held
- Later version
- 3 Aug 2026, dated by the document's changelog. Known from the changelog; no copy held
GPT-Red indirect prompt injection attack success rate added, GPT-5.6 Sol
Not in the earlier version3.77%
Explained — The changelog says the GPT-Red prompt-injection results were added.
New value
How we know From the document's changelog, as summarised in our source registry.
How it was checked Not yet checked
GPT-Red instruction-hierarchy (direct prompt injection) attack success rate added, GPT-5.6 Sol
Not in the earlier version0.051%
Explained — The changelog says the GPT-Red prompt-injection results were added.
New value
How we know From the document's changelog, as summarised in our source registry.
How it was checked Not yet checked
Claude Fable 5 & Claude Mythos 5 System Card
- Earlier version
- 11 Jun 2026, dated by the document's changelog. Known from the changelog; no copy held
- Later version
- 25 Jun 2026, dated by the document's changelog. Known from the changelog; no copy held
Wording changed
Alignment risk in executive summary
lowvery lowExplained — corrected to match §2.4
How we know Changelog read 26 Sep 2026
How it was checked Confirmed from changelog
Claude Opus 4.8 System Card
- Earlier version
- 3 Jun 2026, dated by the document's changelog. Known from the changelog; no copy held
- Later version
- 17 Jun 2026, dated by the document's changelog. Known from the changelog; no copy held
Value changedM10 · Dangerous capabilities and risk determinations
Long-form virology task 2 end-to-end score, Claude Opus 4.8
0.890.90Explained — The changelog lists the corrected score.
New value
How we know Old and new text as the source registry quotes the changelog entry of 17 Jun 2026; v0 row 350 records the corrected value. The changelog has not been re-read by us, so the revision is unverified.
How it was checked Not yet checked
Gemini 3 Pro Model Card
- Earlier version
- 18 Nov 2025, dated by our source registry. Known to exist; no copy held
- Later version
- May 2026, dated by the document header. Version of May 2026 (opens an external site) · retrieved 26 Sep 2026
Marked updated
Card marked "Last updated May 2026"
The document was marked updated. There is no record of what changed.
No changelog
How we know Header read by extraction pass
How it was checked Not yet checked
Gemini 3.1 Flash-Lite Model Card
- Earlier version
- 3 Mar 2026, dated by our source registry. Known to exist; no copy held
- Later version
- May 2026, dated by the document header. Version of May 2026 (opens an external site) · retrieved 26 Sep 2026
Marked updated
Card marked updated May 2026
The document was marked updated. There is no record of what changed.
No changelog
How we know Header read by extraction pass
How it was checked Not yet checked
Gemini 2.5 Flash Model Card
- Earlier version
- 26 Sep 2025, dated by our source registry. Known to exist; no copy held
- Later version
- Dec 2025, dated by the document header. Version of Dec 2025 (opens an external site) · retrieved 26 Sep 2026
Marked updated
Card marked updated Dec 2025
The document was marked updated. There is no record of what changed.
No changelog
How we know Header read by extraction pass
How it was checked Not yet checked
Source: Safety Card Ledger v0.1 · Data from developer system cards · CC BY 4.0