GPT-6 Sol and GPT-6 Luna, now available in ChatGPT for free and paid users, carry the same rating as the GPT-5.6 models they replace, and OpenAI is applying the same safeguards.
In a safety report published Oct. 7, OpenAI rated both versions of its new GPT-6 model, GPT-6 Sol and GPT-6 Luna, as “High” risk for cyberattacks and biological and chemical weapons attacks. By OpenAI’s definition, a model at that level could carry out an attack on well-protected computer systems largely on its own, or give someone with only basic scientific training real help in making a known biological or chemical weapon. OpenAI’s stated worry is more cyberattacks and more terror attacks. The company released both models to ChatGPT users on free and paid plans worldwide the same day.
The rating matches the one OpenAI gave GPT-5.6 Sol and GPT-5.6 Luna, the models GPT-6 now replaces in ChatGPT. OpenAI said it gave the new models the same safeguards it described in its earlier safety report on the GPT-5.6 models.
What OpenAI’s High rating means
OpenAI rates its models under its own internal risk rules, which it calls the Preparedness Framework. The rules set two danger levels. “High” covers abilities that could help people cause serious harm in ways already known. “Critical” covers abilities that could create new ways to cause harm. OpenAI’s rules say it will not release a model rated High until its safeguards “sufficiently minimize” the risk of severe harm. A group of OpenAI’s own safety leaders decides case by case. It looks for evidence that the model refuses dangerous requests and resists attempts to trick it, and that OpenAI’s monitoring would catch misuse before it causes large-scale harm. OpenAI’s leadership makes the final call.
GPT-6 tested at OpenAI’s High level but below Critical
On OpenAI’s automated hacking tests, GPT-6 Sol performed about the same as GPT-5.6 Sol, with no clear improvement, and GPT-6 Luna showed less hacking ability than Sol. In one test, Sol turned known software flaws into working attacks 82.6% of the time, against 44.7% for Luna. OpenAI said the score may be inflated because the flaws are public and the model may have seen them before.
In biology, both models scored above OpenAI’s High bar on a test that asks a model to work out why a virology lab experiment went wrong. OpenAI counts any score above 31% on that test as High-level ability. GPT-6 Sol scored 51.7% and GPT-6 Luna 48.1%.
Both models scored below OpenAI’s Critical bar on all three of its harder biology tests, which include predicting what a protein does from its makeup.
OpenAI reused the safeguards it built for GPT-5.6
OpenAI said it gave GPT-6 Sol and Luna “the same set of safeguards” as their GPT-5.6 counterparts. The new report does not list them. It says the details are in an internal report that OpenAI keeps private because the details could help attackers. OpenAI’s Safety Advisory Group, a team of its own safety leaders, and the company’s leadership concluded the safeguards are enough for a public launch.
One safeguard the report does give numbers for is built into the model itself: OpenAI trains each model to turn down dangerous requests. To measure it, OpenAI switched off its other protections and counted how often each model’s answers to dangerous requests stayed within OpenAI’s safety rules. On the most dangerous biology questions, GPT-6 Sol stayed within the safety rules 98% of the time, up from 95.4% for GPT-5.6 Sol. On cybersecurity requests, GPT-6 Sol did so 97.3% of the time, against 98.2% for GPT-5.6 Sol, which OpenAI called broadly comparable. GPT-6 Luna’s scores moved the same way.
The ratings put GPT-6 Sol and Luna one level below GPT-6 Astra, a separate OpenAI model that the company rated Critical for cybersecurity in September, the first at that level. Under OpenAI’s rules, a Critical rating requires stronger safeguards while a model is still being built, not only before release.

