Model profile
Evidence summary
GPT 5.6 Luna has an estimated overall rank of #27; its 90% source-sensitivity interval is #5–#169. Its behavior-only rank is #29; company governance moves the combined estimate to #27. Published evidence spans 22 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #1 of 241); its weakest is GPT-5.6 system card (gore_not_unsafe, #7 of 7).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5-6-luna
- OpenRouter ↗openai/gpt-5.6-luna
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #125 / 330 | ↓0.75 | Source ↗official | |
| ANIMAscore | #2 / 22 | ↑0.7494 | Source ↗self run | |
| BullshitBench v2clear_pushback_rate | #40 / 106 | ↑0.38 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #16 / 45 | ↓64.2 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #28 / 50 | ↓68.8 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #26 / 51 | ↓55.7 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #23 / 47 | ↓87.9 | Source ↗official | |
| CAIS Risk Indexmask | #9 / 53 | ↓7.3 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #14 / 34 | ↓44.7 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #46 / 50 | ↓23.8 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #76 / 241 | ↑21.96 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #208 / 241 | ↑77.83 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #1 / 241 | ↑100 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #166 / 239 | ↑93.82 | Source ↗official | |
| GPT-5.6 system cardconnectors_injection_resistance | #4 / 7 | ↑0.999 | Source ↗official | |
| GPT-5.6 system cardemotional_reliance | #3 / 7 | ↑0.957 | Source ↗official | |
| GPT-5.6 system cardextremism_not_unsafe | #4 / 7 | ↑0.981 | Source ↗official | |
| GPT-5.6 system cardgore_not_unsafe | #7 / 7 | ↑0.585 | Source ↗official | |
| GPT-5.6 system cardharm_overall_pct | #1 / 7 | ↓0.61 | Source ↗official | |
| GPT-5.6 system cardhate_not_unsafe | #1 / 7 | ↑1 | Source ↗official | |
| GPT-5.6 system cardmental_health | #2 / 7 | ↑0.989 | Source ↗official | |
| GPT-5.6 system cardnonviolent_illicit_not_unsafe | #2 / 7 | ↑0.993 | Source ↗official | |
| GPT-5.6 system cardsearch_function_calling_injection_resistance | #3 / 6 | ↑0.897 | Source ↗official | |
| GPT-5.6 system cardself_harm | #4 / 7 | ↑0.905 | Source ↗official | |
| GPT-5.6 system cardself_harm_not_unsafe | #4 / 7 | ↑0.954 | Source ↗official | |
| GPT-5.6 system cardsexual_minors_not_unsafe | #1 / 7 | ↑0.974 | Source ↗official | |
| GPT-5.6 system cardsexual_not_unsafe | #3 / 7 | ↑0.944 | Source ↗official | |
| GPT-5.6 system cardviolent_illicit_not_unsafe | #5 / 7 | ↑0.94 | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #11 / 13 | ↓43.9 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #31 / 54 | ↑26.33 | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #2 / 10 | ↑97.8 | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #3 / 10 | ↑83.8 | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #4 / 10 | ↑98.7 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #22 / 50 | ↓87.9 | Source ↗official | |
| Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns | #1 / 19 | ↓0 | Source ↗official | |
| Opposite-Narrator Sycophancysycophancy_rate_pct | #6 / 24 | ↓1 | Source ↗official | |
| Pokee-Isaac model card — DTAPbenign_task_success_rate | #1 / 6 | ↑0.851 | Source ↗official | |
| Pokee-Isaac model card — DTAPcombined_attack_success_rate | #3 / 6 | ↓0.501 | Source ↗official | |
| SM-Benchadversarial | #19 / 79 | ↑85.85 | Source ↗official | |
| SM-Benchambiguous_interpretation | #53 / 79 | ↑82.14 | Source ↗official | |
| SM-Benchanti_hallucination | #56 / 79 | ↑87.17 | Source ↗official | |
| SM-Bencheq_boundaries | #52 / 79 | ↑58.71 | Source ↗official | |
| SM-Benchoverfit | #64 / 79 | ↑47.81 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #34 / 113 | ↑6.9 | Source ↗official | |
| SpeciEvalland_animal_4ns | #12 / 113 | ↓4.15 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #5 / 113 | ↓4.175 | Source ↗official | |
| SpeciEvalspeciesism | #72 / 113 | ↓2.16 | Source ↗official | |
| TACbase_welfare_rate | #75 / 76 | ↑13.46 | Source ↗self run |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
