Model profile
GPT 5.6 Luna
Evidence summary
GPT 5.6 Luna has an estimated overall rank of #69; its 90% source-sensitivity interval is #14–#182. Its behavior-only rank is #76; company governance moves the combined estimate to #69. Published evidence spans 17 evals and 7 of 7 behavior components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #1 of 260); its weakest is GPT-5.6 system card — disallowed content with challenging prompts (gore_not_unsafe, #7 of 7).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5-6-luna
- OpenRouter ↗openai/gpt-5.6-luna
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Published eval results
Rank is within that sub-eval. Black marks the observed result; the grey dot marks the value implied by the global rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Better | Source |
|---|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #110 / 311 | 0.7349 | ↓ lower | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #40 / 105 | 0.38 | ↑ higher | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #14 / 43 | 64.2 | ↓ lower | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #26 / 48 | 68.8 | ↓ lower | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #24 / 49 | 55.7 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmachiavelli | #22 / 45 | 87.9 | ↓ lower | Source ↗official | |
| CAIS Risk Indexmask | #8 / 51 | 7.3 | ↓ lower | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #13 / 32 | 44.7 | ↓ lower | Source ↗official | |
| CAIS Risk Indextextquests_harm | #45 / 48 | 23.8 | ↓ lower | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #80 / 260 | 21.96 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #227 / 260 | 77.83 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #1 / 260 | 100 | ↑ higher | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #183 / 258 | 93.82 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsextremism_not_unsafe | #4 / 7 | 0.981 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsgore_not_unsafe | #7 / 7 | 0.585 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptshate_not_unsafe | #1 / 7 | 1 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsnonviolent_illicit_not_unsafe | #2 / 7 | 0.993 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsself_harm_not_unsafe | #4 / 7 | 0.954 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptssexual_minors_not_unsafe | #1 / 7 | 0.974 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptssexual_not_unsafe | #3 / 7 | 0.944 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — disallowed content with challenging promptsviolent_illicit_not_unsafe | #5 / 7 | 0.94 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — first-person fairnessharm_overall_pct | #1 / 7 | 0.61 | ↓ lower | Source ↗official | |
| GPT-5.6 system card — prompt-injection robustnessconnectors_injection_resistance | #4 / 7 | 0.999 | ↑ higher | Source ↗official | |
| GPT-5.6 system card — prompt-injection robustnesssearch_function_calling_injection_resistance | #3 / 6 | 0.897 | ↑ higher | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #11 / 13 | 43.9 | ↓ lower | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #31 / 54 | 26.33 | ↑ higher | Source ↗official | |
| Inkling-Small model card — FORTRESSbenign_answer_rate | #2 / 10 | 97.8 | ↑ higher | Source ↗official | |
| Inkling-Small model card — FORTRESSharmful_refusal_rate | #3 / 10 | 83.8 | ↑ higher | Source ↗official | |
| Inkling-Small model card — StrongREJECTsafety_rate | #4 / 10 | 98.7 | ↑ higher | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #22 / 50 | 87.9 | ↓ lower | Source ↗official | |
| SM-Benchadversarial | #18 / 73 | 85.85 | ↑ higher | Source ↗official | |
| SM-Benchambiguous_interpretation | #48 / 73 | 82.14 | ↑ higher | Source ↗official | |
| SM-Benchanti_hallucination | #51 / 73 | 87.17 | ↑ higher | Source ↗official | |
| SM-Bencheq_boundaries | #47 / 73 | 58.71 | ↑ higher | Source ↗official | |
| SM-Benchoverfit | #58 / 73 | 47.81 | ↑ higher | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #30 / 102 | 6.9 | ↑ higher | Source ↗official | |
| SpeciEvalland_animal_4ns | #10 / 102 | 4.15 | ↓ lower | Source ↗official | |
| SpeciEvalsea_animal_4ns | #4 / 102 | 4.175 | ↓ lower | Source ↗official | |
| SpeciEvalspeciesism | #64 / 102 | 2.16 | ↓ lower | Source ↗official | |
| TACbase_welfare_rate | #68 / 68 | 13.46 | ↑ higher | Source ↗self run |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
