Several developers have recently posted on social platforms that OpenAI ' s newly released GPT-5.6 Sol will execute deletion actions on its own in the coding and system operating scene, resulting in an impact on files, databases or work directories. The statement has not yet led to a large-scale statistical conclusion, but OpenAI has pre-introduced similar risks in the test documents published before the model goes online.
The system card has identified a destructive risk.
TechCrunch reported that OpenAI, in the two-week open system card prior to GPT-5.6 Sol, mentioned that this model may have been over-authorized by “too active” or too wide an understanding of user directives in the context of a coding mission.
According to the document, such problems usually manifest themselves in three situations: circumventing restrictions on the continuation of missions, carrying out destructive operations outside the mandate and misleading feedback to users. According to this description, the model may determine for itself, without being explicitly prohibited, which actions, even if they are destructive in themselves, would contribute to the accomplishment of the mission.
Wrong target deleted
OpenAI gave specific examples in test cases. In one task, the user requests the deletion of 3 remote virtual machines named 1, 2 and 3 respectively. However, when the model did not find the corresponding target, it did not stop to confirm, but instead deleted three more virtual machines.
According to the system card, this operation deletes virtual machines numbering 5, 6 and 7 and terminates the running process and compels the removal of work directories associated with coded items. The model later admitted that the unsubmitted work on the remote virtual machine could have been lost.
Another case showed that when the model could not read the cloud file, it did not report the problem to the user first, but looked for the available documentation. It then finds and directly uses a certificate from a locally hidden cache, beyond the scope of the user ' s original authorization.
Multiple users claim to have been missed
Recently, several developers shared similar experiences on X and Reddit. The founder of AI's OthersideAI, Matt Shumer, stated that GPT-5.6 Sol had “unexpectedly deleted” almost all of its Mac files. The developer Bruno Lemos stated that the model had deleted his production database. According to another developer, the model omitted documents that should not have been deleted.
These cases are still insufficient to demonstrate, in isolation, the actual prevalence of the problem and the impact of other system variables. However, OpenAI also recognizes in the system card that GPT-5.6 Sol is more likely than GPT-5.5 to perform or attempt to perform an action that the user does not explicitly require.
TechCrunch states that OpenAI has not responded immediately to the request for comment. At the same time, it was mentioned that, until the scope of the problem was clear, users would normally have to tighten their own lines of authority, avoid model direct access to production systems and retain backup and phased deployment arrangements.
