Model profile
Evidence summary
Safety. GPT 5.6 Luna has an estimated Safety rank of #22; its 90% source-sensitivity interval is #19–#156. Its behavior-only rank is #28; company governance moves the combined estimate to #22. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #1 of 248); its weakest is GPT-5.6 system card (gore_not_unsafe, #7 of 7).
Freedom. GPT 5.6 Luna has an estimated Freedom rank of #532; its 90% source-sensitivity interval is #337–#575. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is GPT-5.6 system card (gore_not_unsafe, #1 of 7); its weakest is Adversarial Poetry Refusal (AHB self-run) (intellectual_property, #8 of 8).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5-6-luna
- OpenRouter ↗openai/gpt-5.6-luna
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #143 / 345 | ↓0.75 | Source ↗official | |
| Adversarial Poetry Refusal (AHB self-run)child_sexual_exploitation | #1 / 8 | ↓1.449 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)defamation | #5 / 8 | ↓9.42 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)hate | #3 / 8 | ↓5.797 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)indiscriminate_weapons_cbrne | #1 / 8 | ↓0 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)intellectual_property | #1 / 8 | ↓0 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)non_violent_crimes | #1 / 8 | ↓0.7246 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)privacy | #1 / 8 | ↓5.797 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)sex_related_crimes | #2 / 8 | ↓4.348 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)sexual_content | #3 / 8 | ↓5.303 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)specialized_advice | #1 / 8 | ↓2.333 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)suicide_self_harm | #1 / 8 | ↓1.515 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)violent_crimes | #1 / 8 | ↓2.273 | Source ↗self run | |
| ANIMAscore | #2 / 22 | ↑0.7494 | Source ↗self run | |
| BullshitBench v2clear_pushback_rate | #47 / 117 | ↑0.39 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #19 / 49 | ↓64.2 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #32 / 54 | ↓68.8 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #30 / 55 | ↓55.7 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #26 / 51 | ↓87.9 | Source ↗official | |
| CAIS Risk Indexmask | #10 / 57 | ↓7.3 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #18 / 48 | ↓44.7 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #47 / 54 | ↓23.8 | Source ↗official | |
| Claude Fable 5.1 card — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #9 / 11 | ↓50 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #80 / 248 | ↑21.96 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #208 / 248 | ↑77.83 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #1 / 248 | ↑100 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #175 / 246 | ↑93.82 | Source ↗official | |
| Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #12 / 15 | ↓50 | Source ↗official | |
| GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_base_pct | #4 / 4 | ↓19.7 | Source ↗official | |
| GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_confirmation_pct | #3 / 4 | ↓7.2 | Source ↗official | |
| GPT-5.6 system cardconnectors_injection_resistance | #4 / 7 | ↑0.999 | Source ↗official | |
| GPT-5.6 system cardemotional_reliance | #3 / 7 | ↑0.957 | Source ↗official | |
| GPT-5.6 system cardextremism_not_unsafe | #4 / 7 | ↑0.981 | Source ↗official | |
| GPT-5.6 system cardgore_not_unsafe | #7 / 7 | ↑0.585 | Source ↗official | |
| GPT-5.6 system cardharm_overall_pct | #1 / 7 | ↓0.61 | Source ↗official | |
| GPT-5.6 system cardhate_not_unsafe | #1 / 7 | ↑1 | Source ↗official | |
| GPT-5.6 system cardmental_health | #2 / 7 | ↑0.989 | Source ↗official | |
| GPT-5.6 system cardnonviolent_illicit_not_unsafe | #2 / 7 | ↑0.993 | Source ↗official | |
| GPT-5.6 system cardsearch_function_calling_injection_resistance | #3 / 6 | ↑0.897 | Source ↗official | |
| GPT-5.6 system cardself_harm | #4 / 7 | ↑0.905 | Source ↗official | |
| GPT-5.6 system cardself_harm_not_unsafe | #4 / 7 | ↑0.954 | Source ↗official | |
| GPT-5.6 system cardsexual_minors_not_unsafe | #1 / 7 | ↑0.974 | Source ↗official | |
| GPT-5.6 system cardsexual_not_unsafe | #3 / 7 | ↑0.944 | Source ↗official | |
| GPT-5.6 system cardviolent_illicit_not_unsafe | #5 / 7 | ↑0.94 | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #11 / 13 | ↓43.9 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #31 / 54 | ↑26.33 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #2 / 10 | ↑97.8 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #3 / 10 | ↑83.8 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #4 / 10 | ↑98.7 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #22 / 50 | ↓87.9 | Source ↗official | |
| Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns | #1 / 24 | ↓0 | Source ↗official | |
| Opposite-Narrator Sycophancysycophancy_rate_pct | #6 / 24 | ↓1 | Source ↗official | |
| Pokee-Isaac model card — DTAPbenign_task_success_rate | #1 / 6 | ↑0.851 | Source ↗official | |
| Pokee-Isaac model card — DTAPcombined_attack_success_rate | #3 / 6 | ↓0.501 | Source ↗official | |
| SM-Benchadversarial | #21 / 84 | ↑85.85 | Source ↗official | |
| SM-Benchambiguous_interpretation | #58 / 84 | ↑82.14 | Source ↗official | |
| SM-Benchanti_hallucination | #61 / 84 | ↑87.17 | Source ↗official | |
| SM-Bencheq_boundaries | #57 / 84 | ↑58.71 | Source ↗official | |
| SM-Benchoverfit | #69 / 84 | ↑47.81 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #37 / 123 | ↑6.9 | Source ↗official | |
| SpeciEvalland_animal_4ns | #12 / 123 | ↓4.15 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #5 / 123 | ↓4.175 | Source ↗official | |
| SpeciEvalspeciesism | #79 / 123 | ↓2.16 | Source ↗official | |
| TACbase_welfare_rate | #86 / 87 | ↑13.46 | Source ↗self run | |
| Vals AI Cheating Auditbiomystery_bench_cheating_attempt_rate_pct | #1 / 9 | ↓2.963 | Source ↗official | |
| Vals AI Cheating Auditswebench_verified_cheating_attempt_rate_pct | #5 / 6 | ↓78.8 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| Adversarial Poetry Refusal (AHB self-run)child_sexual_exploitation | #6 / 8 | ↑1.449 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)defamation | #4 / 8 | ↑9.42 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)hate | #4 / 8 | ↑5.797 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)indiscriminate_weapons_cbrne | #7 / 8 | ↑0 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)intellectual_property | #8 / 8 | ↑0 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)non_violent_crimes | #8 / 8 | ↑0.7246 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)privacy | #8 / 8 | ↑5.797 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)sex_related_crimes | #6 / 8 | ↑4.348 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)sexual_content | #6 / 8 | ↑5.303 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)specialized_advice | #7 / 8 | ↑2.333 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)suicide_self_harm | #8 / 8 | ↑1.515 | Source ↗self run | |
| Adversarial Poetry Refusal (AHB self-run)violent_crimes | #7 / 8 | ↑2.273 | Source ↗self run | |
| CAIS Risk Indexbioweapons_assistance | #23 / 54 | ↑68.8 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #41 / 248 | ↓77.83 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #243 / 248 | ↓100 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #70 / 246 | ↓93.82 | Source ↗official | |
| GPT-5.6 system cardemotional_reliance | #5 / 7 | ↓0.957 | Source ↗official | |
| GPT-5.6 system cardextremism_not_unsafe | #3 / 7 | ↓0.981 | Source ↗official | |
| GPT-5.6 system cardgore_not_unsafe | #1 / 7 | ↓0.585 | Source ↗official | |
| GPT-5.6 system cardhate_not_unsafe | #5 / 7 | ↓1 | Source ↗official | |
| GPT-5.6 system cardmental_health | #6 / 7 | ↓0.989 | Source ↗official | |
| GPT-5.6 system cardnonviolent_illicit_not_unsafe | #5 / 7 | ↓0.993 | Source ↗official | |
| GPT-5.6 system cardself_harm | #4 / 7 | ↓0.905 | Source ↗official | |
| GPT-5.6 system cardself_harm_not_unsafe | #4 / 7 | ↓0.954 | Source ↗official | |
| GPT-5.6 system cardsexual_minors_not_unsafe | #6 / 7 | ↓0.974 | Source ↗official | |
| GPT-5.6 system cardsexual_not_unsafe | #4 / 7 | ↓0.944 | Source ↗official | |
| GPT-5.6 system cardviolent_illicit_not_unsafe | #2 / 7 | ↓0.94 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #2 / 10 | ↑97.8 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #8 / 10 | ↓83.8 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #6 / 10 | ↓98.7 | Source ↗official | |
| SM-Benchadversarial | #62 / 84 | ↓85.85 | Source ↗official | |
| SM-Bencheq_boundaries | #57 / 84 | ↑58.71 | Source ↗official | |
| SM-Benchoverfit | #69 / 84 | ↑47.81 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #103 / 181 | ↑52.4 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #77 / 156 | ↑3.2 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
