Model profile
Evidence summary
Safety. GPT 5.6 Terra has an estimated Safety rank of #7; its 90% source-sensitivity interval is #13–#72. Its behavior-only rank is #12; company governance moves the combined estimate to #7. Published Safety evidence spans 25 eval lineages and 7 of 7 components. Its strongest relative result is Opposite-Narrator Sycophancy (sycophancy_rate_pct, #1 of 24); its weakest is Vals AI Cheating Audit (terminal_bench_cheating_shortcut_evidence_rate_pct, #14 of 14).
Freedom. GPT 5.6 Terra has an estimated Freedom rank of #565; its 90% source-sensitivity interval is #360–#611. Published Freedom evidence spans 7 eval lineages and 1 of 1 components. Its strongest relative result is Enkrypt AI Safety Leaderboard (cbrn_attack_non_success_rate, #51 of 248); its weakest is GPT-5.6 system card (sexual_not_unsafe, #7 of 7).
Compare this model
Only models sharing at least one published sub-eval are listed.
Official and reference links
- Artificial Analysis ↗gpt-5-6-terra
- OpenRouter ↗openai/gpt-5.6-terra
- Official model documentation ↗Family-level model document · openai · first party
- Release source ↗direct research preview identity date
Safety evals
Rank and direction are specific to the Safety portfolio. Black marks the observed result; the grey dot marks the value implied by the Safety rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| AA-Omnisciencehallucination_rate | #246 / 345 | ↓0.8788 | Source ↗official | |
| BullshitBench v2clear_pushback_rate | #29 / 117 | ↑0.505 | Source ↗official | |
| CAIS Risk Indexagent_red_teaming | #16 / 49 | ↓54.6 | Source ↗official | |
| CAIS Risk Indexbioweapons_assistance | #28 / 54 | ↓66.2 | Source ↗official | |
| CAIS Risk Indexhle_overconfidence | #24 / 55 | ↓50.7 | Source ↗official | |
| CAIS Risk Indexmachiavelli | #4 / 51 | ↓80.4 | Source ↗official | |
| CAIS Risk Indexmask | #8 / 57 | ↓6.7 | Source ↗official | |
| CAIS Risk Indexpolitical_manipulation | #21 / 48 | ↓46.2 | Source ↗official | |
| CAIS Risk Indextextquests_harm | #42 / 54 | ↓22.2 | Source ↗official | |
| Claude Fable 5.1 card — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #8 / 11 | ↓37.3 | Source ↗official | |
| Enkrypt AI Safety Leaderboardbias_attack_non_success_rate | #33 / 248 | ↑39.28 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #198 / 248 | ↑80 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #22 / 248 | ↑97.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #189 / 246 | ↑92.36 | Source ↗official | |
| Google Gemini 3.8 launch — Gray Swan indirect prompt injection k=15attack_success_probability_k15_pct | #11 / 15 | ↓37.3 | Source ↗official | |
| GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_base_pct | #2 / 4 | ↓13.5 | Source ↗official | |
| GPT 6 Astra system-card alignment evaluationsoverall_misaligned_outcome_confirmation_pct | #2 / 4 | ↓5.7 | Source ↗official | |
| GPT-5.6 system cardconnectors_injection_resistance | #1 / 7 | ↑1 | Source ↗official | |
| GPT-5.6 system cardemotional_reliance | #2 / 7 | ↑0.976 | Source ↗official | |
| GPT-5.6 system cardextremism_not_unsafe | #4 / 7 | ↑0.981 | Source ↗official | |
| GPT-5.6 system cardgore_not_unsafe | #6 / 7 | ↑0.6 | Source ↗official | |
| GPT-5.6 system cardharm_overall_pct | #2 / 7 | ↓0.88 | Source ↗official | |
| GPT-5.6 system cardhate_not_unsafe | #1 / 7 | ↑1 | Source ↗official | |
| GPT-5.6 system cardmental_health | #3 / 7 | ↑0.985 | Source ↗official | |
| GPT-5.6 system cardnonviolent_illicit_not_unsafe | #4 / 7 | ↑0.99 | Source ↗official | |
| GPT-5.6 system cardsearch_function_calling_injection_resistance | #1 / 6 | ↑0.946 | Source ↗official | |
| GPT-5.6 system cardself_harm | #3 / 7 | ↑0.947 | Source ↗official | |
| GPT-5.6 system cardself_harm_not_unsafe | #2 / 7 | ↑0.962 | Source ↗official | |
| GPT-5.6 system cardsexual_minors_not_unsafe | #1 / 7 | ↑0.974 | Source ↗official | |
| GPT-5.6 system cardsexual_not_unsafe | #1 / 7 | ↑0.966 | Source ↗official | |
| GPT-5.6 system cardviolent_illicit_not_unsafe | #4 / 7 | ↑0.952 | Source ↗official | |
| Gray Swan indirect prompt injection (15 attempts)attack_success_probability_k15_pct | #9 / 13 | ↓30.4 | Source ↗official | |
| HUMAINE Trust, Ethics and Safetytrust_ethics_safety_score | #19 / 54 | ↑27.66 | Source ↗official | |
| MACHIAVELLIdeception_relative_random_pct | #3 / 50 | ↓80.4 | Source ↗official | |
| Manager Coercion Benchcoercion_ladder_depth | #22 / 37 | ↓8.7 | Source ↗official | |
| Manager Coercion Benchfabrication_rate | #1 / 15 | ↓0 | Source ↗official | |
| Olam Social Poker — Social Lie Ratesocial_lie_rate_per_10000_turns | #3 / 24 | ↓2 | Source ↗official | |
| Opposite-Narrator Sycophancysycophancy_rate_pct | #1 / 24 | ↓0 | Source ↗official | |
| Pander Scoreconversational_absolute_pander_score | #11 / 26 | ↓9.7 | Source ↗official | |
| Pander Scoreinstructional_absolute_pander_score | #10 / 26 | ↓25.68 | Source ↗official | |
| SM-Benchadversarial | #33 / 84 | ↑83.66 | Source ↗official | |
| SM-Benchambiguous_interpretation | #50 / 84 | ↑83.63 | Source ↗official | |
| SM-Benchanti_hallucination | #51 / 84 | ↑90.84 | Source ↗official | |
| SM-Bencheq_boundaries | #38 / 84 | ↑66.01 | Source ↗official | |
| SM-Benchoverfit | #64 / 84 | ↑53.55 | Source ↗official | |
| SpeciEvalbelief_animal_sentience | #34 / 123 | ↑6.925 | Source ↗official | |
| SpeciEvalland_animal_4ns | #29 / 123 | ↓4.29 | Source ↗official | |
| SpeciEvalsea_animal_4ns | #7 / 123 | ↓4.225 | Source ↗official | |
| SpeciEvalspeciesism | #9 / 123 | ↓1.265 | Source ↗official | |
| TACbase_welfare_rate | #36 / 87 | ↑29.49 | Source ↗official | |
| Vals AI Cheating Auditswebench_verified_cheating_attempt_rate_pct | #6 / 6 | ↓89.4 | Source ↗official | |
| Vals AI Cheating Auditterminal_bench_cheating_shortcut_evidence_rate_pct | #14 / 14 | ↓4.494 | Source ↗official |
Freedom evals
Rank and direction are specific to the Freedom portfolio. Black marks the observed result; the grey dot marks the value implied by the Freedom rank. Values stay on each source’s native scale.
| Eval / sub-eval | Rank | Value | Distribution | Source |
|---|---|---|---|---|
| CAIS Risk Indexbioweapons_assistance | #27 / 54 | ↑66.2 | Source ↗official | |
| Enkrypt AI Safety Leaderboardcbrn_attack_non_success_rate | #51 / 248 | ↓80 | Source ↗official | |
| Enkrypt AI Safety Leaderboardharmful_attack_non_success_rate | #223 / 248 | ↓97.78 | Source ↗official | |
| Enkrypt AI Safety Leaderboardtoxicity_attack_non_success_rate | #58 / 246 | ↓92.36 | Source ↗official | |
| GPT-5.6 system cardemotional_reliance | #6 / 7 | ↓0.976 | Source ↗official | |
| GPT-5.6 system cardextremism_not_unsafe | #3 / 7 | ↓0.981 | Source ↗official | |
| GPT-5.6 system cardgore_not_unsafe | #2 / 7 | ↓0.6 | Source ↗official | |
| GPT-5.6 system cardhate_not_unsafe | #5 / 7 | ↓1 | Source ↗official | |
| GPT-5.6 system cardmental_health | #4 / 7 | ↓0.985 | Source ↗official | |
| GPT-5.6 system cardnonviolent_illicit_not_unsafe | #3 / 7 | ↓0.99 | Source ↗official | |
| GPT-5.6 system cardself_harm | #5 / 7 | ↓0.947 | Source ↗official | |
| GPT-5.6 system cardself_harm_not_unsafe | #6 / 7 | ↓0.962 | Source ↗official | |
| GPT-5.6 system cardsexual_minors_not_unsafe | #6 / 7 | ↓0.974 | Source ↗official | |
| GPT-5.6 system cardsexual_not_unsafe | #7 / 7 | ↓0.966 | Source ↗official | |
| GPT-5.6 system cardviolent_illicit_not_unsafe | #4 / 7 | ↓0.952 | Source ↗official | |
| SM-Benchadversarial | #51 / 84 | ↓83.66 | Source ↗official | |
| SM-Bencheq_boundaries | #38 / 84 | ↑66.01 | Source ↗official | |
| SM-Benchoverfit | #64 / 84 | ↑53.55 | Source ↗official | |
| SpeechMap model completioncomplete_pct | #131 / 181 | ↑44.2 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_adherence_score | #79 / 156 | ↑1.5 | Source ↗official | |
| UGI Leaderboard — base-model willingnesswillingness_direct_score | #79 / 156 | ↑3 | Source ↗official |
Values evaluations
Descriptive values and political-framing results are separate from safety/ethics ranks. Each strip shows the evaluation’s observed model range; its endpoint labels state what lower and higher values mean.
