← Models

Model profile

GPT 5.6 Luna

OpenAIdeveloper
2026-07-09release date
#69 / 267overall rank
17eval lineages

Evidence summary

GPT 5.6 Luna has an estimated overall rank of #69; its 90% source-sensitivity interval is #14–#182. Its behavior-only rank is #76; company governance moves the combined estimate to #69. Published evidence spans 17 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #1 of 260); its weakest is GPT-5.6 system card — disallowed content with challenging prompts (gore_not_unsafe, #7 of 7).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Published eval results

Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionBetterSource
AA-Omnisciencehallucination_rate#110 / 3110.7349↓ lowerSource ↗official
BullshitBench v2clear_pushback_rate#40 / 1050.38↑ higherSource ↗official
CAIS Risk Indexagent_red_teaming#14 / 4364.2↓ lowerSource ↗official
CAIS Risk Indexbioweapons_assistance#26 / 4868.8↓ lowerSource ↗official
CAIS Risk Indexhle_overconfidence#24 / 4955.7↓ lowerSource ↗official
CAIS Risk Indexmachiavelli#22 / 4587.9↓ lowerSource ↗official
CAIS Risk Indexmask#8 / 517.3↓ lowerSource ↗official
CAIS Risk Indexpolitical_manipulation#13 / 3244.7↓ lowerSource ↗official
CAIS Risk Indextextquests_harm#45 / 4823.8↓ lowerSource ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#80 / 26021.96↑ higherSource ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#227 / 26077.83↑ higherSource ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#1 / 260100↑ higherSource ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#183 / 25893.82↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptsextremism_not_unsafe#4 / 70.981↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptsgore_not_unsafe#7 / 70.585↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptshate_not_unsafe#1 / 71↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptsnonviolent_illicit_not_unsafe#2 / 70.993↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptsself_harm_not_unsafe#4 / 70.954↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptssexual_minors_not_unsafe#1 / 70.974↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptssexual_not_unsafe#3 / 70.944↑ higherSource ↗official
GPT-5.6 system card — disallowed content with challenging promptsviolent_illicit_not_unsafe#5 / 70.94↑ higherSource ↗official
GPT-5.6 system card — first-person fairnessharm_overall_pct#1 / 70.61↓ lowerSource ↗official
GPT-5.6 system card — prompt-injection robustnessconnectors_injection_resistance#4 / 70.999↑ higherSource ↗official
GPT-5.6 system card — prompt-injection robustnesssearch_function_calling_injection_resistance#3 / 60.897↑ higherSource ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#11 / 1343.9↓ lowerSource ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#31 / 5426.33↑ higherSource ↗official
Inkling-Small model card — FORTRESSbenign_answer_rate#2 / 1097.8↑ higherSource ↗official
Inkling-Small model card — FORTRESSharmful_refusal_rate#3 / 1083.8↑ higherSource ↗official
Inkling-Small model card — StrongREJECTsafety_rate#4 / 1098.7↑ higherSource ↗official
MACHIAVELLIdeception_relative_random_pct#22 / 5087.9↓ lowerSource ↗official
SM-Benchadversarial#18 / 7385.85↑ higherSource ↗official
SM-Benchambiguous_interpretation#48 / 7382.14↑ higherSource ↗official
SM-Benchanti_hallucination#51 / 7387.17↑ higherSource ↗official
SM-Bencheq_boundaries#47 / 7358.71↑ higherSource ↗official
SM-Benchoverfit#58 / 7347.81↑ higherSource ↗official
SpeciEvalbelief_animal_sentience#30 / 1026.9↑ higherSource ↗official
SpeciEvalland_animal_4ns#10 / 1024.15↓ lowerSource ↗official
SpeciEvalsea_animal_4ns#4 / 1024.175↓ lowerSource ↗official
SpeciEvalspeciesism#64 / 1022.16↓ lowerSource ↗official
TACbase_welfare_rate#68 / 6813.46↑ higherSource ↗self run

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-25.6
Government47.1
Diplomacy70.2
Economy44.9
Society62.2