Skip to content
Menu
Menu

OpenAI Rates New GPT-6 Models High Risk For Cyberattacks And Biological Weapons

GPT-6 Sol and GPT-6 Luna, now available in ChatGPT for free and paid users, carry the same rating as the GPT-5.6 models they replace, and OpenAI is applying the same safeguards.

 

In a safety report published Oct. 7, OpenAI rated both versions of its new GPT-6 model, GPT-6 Sol and GPT-6 Luna, as “High” risk for cyberattacks and biological and chemical weapons attacks. By OpenAI’s definition, a model at that level could carry out an attack on well-protected computer systems largely on its own, or give someone with only basic scientific training real help in making a known biological or chemical weapon. OpenAI’s stated worry is more cyberattacks and more terror attacks. The company released both models to ChatGPT users on free and paid plans worldwide the same day.

The rating matches the one OpenAI gave GPT-5.6 Sol and GPT-5.6 Luna, the models GPT-6 now replaces in ChatGPT. OpenAI said it gave the new models the same safeguards it described in its earlier safety report on the GPT-5.6 models.

What OpenAI’s High rating means

OpenAI rates its models under its own internal risk rules, which it calls the Preparedness Framework. The rules set two danger levels. “High” covers abilities that could help people cause serious harm in ways already known. “Critical” covers abilities that could create new ways to cause harm. OpenAI’s rules say it will not release a model rated High until its safeguards “sufficiently minimize” the risk of severe harm. A group of OpenAI’s own safety leaders decides case by case. It looks for evidence that the model refuses dangerous requests and resists attempts to trick it, and that OpenAI’s monitoring would catch misuse before it causes large-scale harm. OpenAI’s leadership makes the final call.

GPT-6 tested at OpenAI’s High level but below Critical

On OpenAI’s automated hacking tests, GPT-6 Sol performed about the same as GPT-5.6 Sol, with no clear improvement, and GPT-6 Luna showed less hacking ability than Sol. In one test, Sol turned known software flaws into working attacks 82.6% of the time, against 44.7% for Luna. OpenAI said the score may be inflated because the flaws are public and the model may have seen them before.

In biology, both models scored above OpenAI’s High bar on a test that asks a model to work out why a virology lab experiment went wrong. OpenAI counts any score above 31% on that test as High-level ability. GPT-6 Sol scored 51.7% and GPT-6 Luna 48.1%.

Both models scored below OpenAI’s Critical bar on all three of its harder biology tests, which include predicting what a protein does from its makeup.

OpenAI reused the safeguards it built for GPT-5.6

OpenAI said it gave GPT-6 Sol and Luna “the same set of safeguards” as their GPT-5.6 counterparts. The new report does not list them. It says the details are in an internal report that OpenAI keeps private because the details could help attackers. OpenAI’s Safety Advisory Group, a team of its own safety leaders, and the company’s leadership concluded the safeguards are enough for a public launch.

One safeguard the report does give numbers for is built into the model itself: OpenAI trains each model to turn down dangerous requests. To measure it, OpenAI switched off its other protections and counted how often each model’s answers to dangerous requests stayed within OpenAI’s safety rules. On the most dangerous biology questions, GPT-6 Sol stayed within the safety rules 98% of the time, up from 95.4% for GPT-5.6 Sol. On cybersecurity requests, GPT-6 Sol did so 97.3% of the time, against 98.2% for GPT-5.6 Sol, which OpenAI called broadly comparable. GPT-6 Luna’s scores moved the same way.

The ratings put GPT-6 Sol and Luna one level below GPT-6 Astra, a separate OpenAI model that the company rated Critical for cybersecurity in September, the first at that level. Under OpenAI’s rules, a Critical rating requires stronger safeguards while a model is still being built, not only before release.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!