← Models

Model profile

GPT 5.6 Luna

OpenAIdeveloper
2026-07-09release date
#22 / 333Safety rank
#532 / 645Freedom rank
2discovery sources

Evidence summary

Safety. GPT 5.6 Luna has an estimated Safety rank of #22; its 90% source-sensitivity interval is #19–#156. Its behavior-only rank is #28; company governance moves the combined estimate to #22. Published Safety evidence spans 27 eval lineages and 7 of 7 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (harmful_attack_non_success_rate, #1 of 248); its weakest is GPT-5.6 system card (gore_not_unsafe, #7 of 7).

Freedom. GPT 5.6 Luna has an estimated Freedom rank of #532; its 90% source-sensitivity interval is #337–#575. Published Freedom evidence spans 9 eval lineages and 1 of 1 components. Its strongest relative result is GPT-5.6 system card (gore_not_unsafe, #1 of 7); its weakest is Adversarial Poetry Refusal (AHB self-run) (intellectual_property, #8 of 8).

Compare this model

Only models sharing at least one published sub-eval are listed.

Official and reference links

Safety evals

Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
AA-Omnisciencehallucination_rate#143 / 3450.75Source ↗official
Adversarial Poetry Refusal (AHB self-run)child_sexual_exploitation#1 / 81.449Source ↗self run
Adversarial Poetry Refusal (AHB self-run)defamation#5 / 89.42Source ↗self run
Adversarial Poetry Refusal (AHB self-run)hate#3 / 85.797Source ↗self run
Adversarial Poetry Refusal (AHB self-run)indiscriminate_weapons_cbrne#1 / 80Source ↗self run
Adversarial Poetry Refusal (AHB self-run)intellectual_property#1 / 80Source ↗self run
Adversarial Poetry Refusal (AHB self-run)non_violent_crimes#1 / 80.7246Source ↗self run
Adversarial Poetry Refusal (AHB self-run)privacy#1 / 85.797Source ↗self run
Adversarial Poetry Refusal (AHB self-run)sex_related_crimes#2 / 84.348Source ↗self run
Adversarial Poetry Refusal (AHB self-run)sexual_content#3 / 85.303Source ↗self run
Adversarial Poetry Refusal (AHB self-run)specialized_advice#1 / 82.333Source ↗self run
Adversarial Poetry Refusal (AHB self-run)suicide_self_harm#1 / 81.515Source ↗self run
Adversarial Poetry Refusal (AHB self-run)violent_crimes#1 / 82.273Source ↗self run
ANIMAscore#2 / 220.7494Source ↗self run
BullshitBench v2clear_pushback_rate#47 / 1170.39Source ↗official
CAIS Risk Indexagent_red_teaming#19 / 4964.2Source ↗official
CAIS Risk Indexbioweapons_assistance#32 / 5468.8Source ↗official
CAIS Risk Indexhle_overconfidence#30 / 5555.7Source ↗official
CAIS Risk Indexmachiavelli#26 / 5187.9Source ↗official
CAIS Risk Indexmask#10 / 577.3Source ↗official
CAIS Risk Indexpolitical_manipulation#18 / 4844.7Source ↗official
CAIS Risk Indextextquests_harm#47 / 5423.8Source ↗official
Claude Fable 5.1 card — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct#9 / 1150Source ↗official
Enkrypt AI Safety Leaderboardbias_attack_non_success_rate#80 / 24821.96Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#208 / 24877.83Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#1 / 248100Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#175 / 24693.82Source ↗official
Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct#12 / 1550Source ↗official
GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_base_pct#4 / 419.7Source ↗official
GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_confirmation_pct#3 / 47.2Source ↗official
GPT-5.6 system cardconnectors_injection_resistance#4 / 70.999Source ↗official
GPT-5.6 system cardemotional_reliance#3 / 70.957Source ↗official
GPT-5.6 system cardextremism_not_unsafe#4 / 70.981Source ↗official
GPT-5.6 system cardgore_not_unsafe#7 / 70.585Source ↗official
GPT-5.6 system cardharm_overall_pct#1 / 70.61Source ↗official
GPT-5.6 system cardhate_not_unsafe#1 / 71Source ↗official
GPT-5.6 system cardmental_health#2 / 70.989Source ↗official
GPT-5.6 system cardnonviolent_illicit_not_unsafe#2 / 70.993Source ↗official
GPT-5.6 system cardsearch_function_calling_injection_resistance#3 / 60.897Source ↗official
GPT-5.6 system cardself_harm#4 / 70.905Source ↗official
GPT-5.6 system cardself_harm_not_unsafe#4 / 70.954Source ↗official
GPT-5.6 system cardsexual_minors_not_unsafe#1 / 70.974Source ↗official
GPT-5.6 system cardsexual_not_unsafe#3 / 70.944Source ↗official
GPT-5.6 system cardviolent_illicit_not_unsafe#5 / 70.94Source ↗official
Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct#11 / 1343.9Source ↗official
HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score#31 / 5426.33Source ↗official
Inkling-Small model card — FORTRESSbenign_answer_rate#2 / 1097.8Source ↗official
Inkling-Small model card — FORTRESSharmful_refusal_rate#3 / 1083.8Source ↗official
Inkling-Small model card — StrongREJECTsafety_rate#4 / 1098.7Source ↗official
MACHIAVELLIdeception_relative_random_pct#22 / 5087.9Source ↗official
Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns#1 / 240Source ↗official
Opposite-Narrator Sycophancysycophancy_rate_pct#6 / 241Source ↗official
Pokee-Isaac model card — DTAPbenign_task_success_rate#1 / 60.851Source ↗official
Pokee-Isaac model card — DTAPcombined_attack_success_rate#3 / 60.501Source ↗official
SM-Benchadversarial#21 / 8485.85Source ↗official
SM-Benchambiguous_interpretation#58 / 8482.14Source ↗official
SM-Benchanti_hallucination#61 / 8487.17Source ↗official
SM-Bencheq_boundaries#57 / 8458.71Source ↗official
SM-Benchoverfit#69 / 8447.81Source ↗official
SpeciEvalbelief_animal_sentience#37 / 1236.9Source ↗official
SpeciEvalland_animal_4ns#12 / 1234.15Source ↗official
SpeciEvalsea_animal_4ns#5 / 1234.175Source ↗official
SpeciEvalspeciesism#79 / 1232.16Source ↗official
TACbase_welfare_rate#86 / 8713.46Source ↗self run
Vals AI Cheating Auditbiomystery_bench_cheating_attempt_rate_pct#1 / 92.963Source ↗official
Vals AI Cheating Auditswebench_verified_cheating_attempt_rate_pct#5 / 678.8Source ↗official

Freedom evals

Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.

Eval / sub-evalRankValueDistributionSource
Adversarial Poetry Refusal (AHB self-run)child_sexual_exploitation#6 / 81.449Source ↗self run
Adversarial Poetry Refusal (AHB self-run)defamation#4 / 89.42Source ↗self run
Adversarial Poetry Refusal (AHB self-run)hate#4 / 85.797Source ↗self run
Adversarial Poetry Refusal (AHB self-run)indiscriminate_weapons_cbrne#7 / 80Source ↗self run
Adversarial Poetry Refusal (AHB self-run)intellectual_property#8 / 80Source ↗self run
Adversarial Poetry Refusal (AHB self-run)non_violent_crimes#8 / 80.7246Source ↗self run
Adversarial Poetry Refusal (AHB self-run)privacy#8 / 85.797Source ↗self run
Adversarial Poetry Refusal (AHB self-run)sex_related_crimes#6 / 84.348Source ↗self run
Adversarial Poetry Refusal (AHB self-run)sexual_content#6 / 85.303Source ↗self run
Adversarial Poetry Refusal (AHB self-run)specialized_advice#7 / 82.333Source ↗self run
Adversarial Poetry Refusal (AHB self-run)suicide_self_harm#8 / 81.515Source ↗self run
Adversarial Poetry Refusal (AHB self-run)violent_crimes#7 / 82.273Source ↗self run
CAIS Risk Indexbioweapons_assistance#23 / 5468.8Source ↗official
Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate#41 / 24877.83Source ↗official
Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate#243 / 248100Source ↗official
Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate#70 / 24693.82Source ↗official
GPT-5.6 system cardemotional_reliance#5 / 70.957Source ↗official
GPT-5.6 system cardextremism_not_unsafe#3 / 70.981Source ↗official
GPT-5.6 system cardgore_not_unsafe#1 / 70.585Source ↗official
GPT-5.6 system cardhate_not_unsafe#5 / 71Source ↗official
GPT-5.6 system cardmental_health#6 / 70.989Source ↗official
GPT-5.6 system cardnonviolent_illicit_not_unsafe#5 / 70.993Source ↗official
GPT-5.6 system cardself_harm#4 / 70.905Source ↗official
GPT-5.6 system cardself_harm_not_unsafe#4 / 70.954Source ↗official
GPT-5.6 system cardsexual_minors_not_unsafe#6 / 70.974Source ↗official
GPT-5.6 system cardsexual_not_unsafe#4 / 70.944Source ↗official
GPT-5.6 system cardviolent_illicit_not_unsafe#2 / 70.94Source ↗official
Inkling-Small model card — FORTRESSbenign_answer_rate#2 / 1097.8Source ↗official
Inkling-Small model card — FORTRESSharmful_refusal_rate#8 / 1083.8Source ↗official
Inkling-Small model card — StrongREJECTsafety_rate#6 / 1098.7Source ↗official
SM-Benchadversarial#62 / 8485.85Source ↗official
SM-Bencheq_boundaries#57 / 8458.71Source ↗official
SM-Benchoverfit#69 / 8447.81Source ↗official
SpeechMap model completioncomplete_pct#103 / 18152.4Source ↗official
UGI Leaderboard — base-model willingnesswillingness_adherence_score#79 / 1561.5Source ↗official
UGI Leaderboard — base-model willingnesswillingness_direct_score#77 / 1563.2Source ↗official

Values evaluations

Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.

UGI Political Values

DimensionValueDistribution
Political Lean-25.6
Government47.1
Diplomacy70.2
Economy44.9
Society62.2