News confirmed medium confidence

OpenAI Rates October GPT-6 Sol and Luna High in Cyber and Bio Capability

The new ChatGPT versions remain below critical capability thresholds but show several disclosed safety-evaluation regressions alongside stronger results in other tests.

Edited by Tyronne Panaino

OpenAI published a deployment-safety update on October 7 for the October versions of GPT-6 Sol and GPT-6 Luna entering ChatGPT. The company classifies both models as high capability in cybersecurity and in biological and chemical domains, while saying they remain below its critical thresholds and do not reach its high threshold for AI self-improvement.

The document matters because the October models are not simply the same releases already used elsewhere. OpenAI says the GPT-6 Sol and Luna versions in Codex and ChatGPT Work remain the previously released September variants. The new system card therefore describes a distinct ChatGPT deployment line with its own evaluation record.

Two model generations now share the GPT-6 names

OpenAI says the October models are being launched across free and paid ChatGPT plans globally. At the same time, Codex and ChatGPT Work continue to use the September versions. Readers comparing product behavior or safety results need to distinguish the month-specific variants rather than treat every product carrying the GPT-6 Sol or Luna name as identical.

That distinction is especially important for evaluation claims. OpenAI says earlier comparison values can reflect later model versions and may differ from numbers published at launch. It also says its production benchmark sets were deliberately designed around challenging cases where earlier systems did not give ideal responses, so their error rates are not estimates of normal production traffic.

High capability does not mean the critical threshold was crossed

Under OpenAI's Preparedness Framework, the company treats both October models as high capability in cybersecurity and biological or chemical work. For biological and chemical capability, OpenAI reports that GPT-6 Sol did not cross its indicative critical thresholds; Luna scored below the comparison that would have required separate critical testing.

For cybersecurity, OpenAI says both models fall below the critical threshold. It reports that Sol performed comparably to GPT-5.6 Sol without a clear capability improvement, while Luna underperformed the October Sol model. These are the developer's own classifications and test interpretations, not an independent audit of real-world offensive capability.

Safety results include both progress and regressions

The standard safety evaluations were mixed. OpenAI reports a statistically significant regression for GPT-6 Sol on standard self-harm prompts. For GPT-6 Luna, it reports statistically significant regressions on standard self-harm, gore and sexual-content prompts. The company says its manual review found the violations generally low severity, and it notes that those tests exclude system-level interventions used in the deployed product.

The under-18 evaluations also surfaced regressions. OpenAI reports statistically significant declines for both models on age-restricted content, sexual content and emotional reliance, with Luna also declining on gore. It says an additional classifier block for self-harm, sexual content and gore is applied in deployment but is not included in the model-level results.

Adaptive jailbreak testing produced another qualified result. The October models had slightly lower point estimates than their September counterparts, but the reported 95% confidence intervals broadly overlapped. In a separate prompt-injection evaluation, OpenAI reports robustness of 99.99% for Sol and 99.79% for Luna.

What the evidence does not establish

The system card is useful because it discloses regressions, deployment mitigations and threshold decisions in one place. It is still a first-party evaluation. OpenAI itself says there are legitimate questions about how some alignment tests translate to real-world behavior, and several results come from deliberately difficult benchmarks run without the full deployed safeguard stack.

Independent reproduction, post-deployment incident data and stable cross-version methodology would be needed to judge how the October models behave at population scale. Until then, the supported conclusion is narrower: OpenAI has released a new ChatGPT-specific GPT-6 line, classified it as high capability in two risk domains, kept it below critical thresholds, and disclosed material areas where evaluation performance regressed.

Status

Confirmed. OpenAI's official system card establishes the release distinction, internal capability classifications and reported evaluation outcomes. Internal confidence is medium because the evidence is vendor-produced, the benchmarks are not measures of typical traffic, and no independent reproduction was fetched.

Sources

Update note: Last reviewed 2026-10-08. We will revise this post if independent testing, incident evidence or a later system-card update materially changes the assessment.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More News coverage