OpenAI

GPT-6 Astra: A new generation of intelligence

新世代の応答性能

世界で最も知能が高く、人間の意図に沿ったモデル、GPT‑6 Astra を発表します。

GPT‑6 Astra は、事前学習、強化学習、アラインメントにわたる長年の研究と大規模な取り組みを結集しています。Astra は、コンピューター操作、ブラウジング、ソフトウェアエンジニアリング、サイバーセキュリティ、科学、専門業務において最先端の性能を発揮します。Astra は FrontierMath Tier 4 で 98% のスコアを記録して上限に達し、数学における長年の未解決問題の解決にすでに貢献しています。Astra は ARC-AGI-3 でも99.9%のスコアで上限に達し、ExploitBench では100%のスコアで上限に達しています。また、コンピューター操作とブラウザー操作の新たなフロンティアを切り開き、最も要求の厳しい専門業務も、比類ないスピード、正確性、判断力で処理します。

GPT‑6 Astra は本日より一部の組織向けに提供を開始し、今後数日かけて、すべての ChatGPT Plus、Pro、Business、Enterprise ユーザーに加え、OpenAI API、Microsoft Azure、AWS Bedrock 経由でも利用可能になります。

「ARC-AGI-3 では、Astra は 96% のレベルで OpenAI が設定した人間の行動効率のベースラインを上回り、このベンチマークで実質的に人間と同等の水準に達しました。これは、OpenAI がこれまでにテストした中で最高のモデルであるだけでなく、フロンティアモデルの性能における大きな飛躍でもあります。未知の環境を探索して問題を解決する能力だけでなく、それを効率的に学習する能力も大きく向上しています。」
Greg Kamradt 氏、ARC Prize Foundation

Astra は当社で最もアラインメントの取れたモデルであり、ユーザーの意図の理解とモデルのふるまいが大幅に向上しています。そのため、Astra の判断をこれまで以上に信頼して、タスクを任せることができます。これを検証する方法の一つとして、OpenAI は Hugging Face のインシデントから得た知見を踏まえた新しい評価を構築しました。この評価では、困難または不可能なタスクに直面したモデルが、意図された範囲を超えるかどうかを判定します。本番環境向けのセーフガードがない場合、GPT‑5.6 Sol は48%のケースで許可された対象の範囲を超えましたが、GPT‑6 Astra では0%でした。

世界最高のコンピューター操作モデル

GPT‑6 Astra は、コンピューター操作の速度、精度、安全性における新たなフロンティアを切り開きます。オンラインフォームへの入力、CRM の顧客レコードの更新、カレンダーの整理といった面倒なタスクを処理できます。メールやドキュメントエディタ内で、オンラインリサーチを行い、要約の下書きを作成できます。科学データを分析し、プロットを生成し、Web サイトを作成し、そのサイト上のすべての機能が動作することを確認するためにフロントエンドの QA チェックを実行できます。自律的にソフトウェアをインストールしてテストし、画面上で確認した問題のトラブルシューティングを行えます。こうした改善は、私たちの最先端の評価結果にも表れています。

これらの改善は、実際の知識業務タスクにおける大幅な効率向上にもつながります。OSWorld 2.0 のレイテンシシミュレーションでは、Astra は GPT‑5.6Sol よりもタスクあたり約47%短い時間で、より高いコンピューター操作性能を達成しています。Astra はタスクあたり約40分で72.6%を記録したのに対し、Sol は約75分で65.7%でした。3

GPT‑6 Astra のコンピューター利用機能は、ゲーム開発、電気工学、日常的なナレッジワークなど、さまざまな領域にわたる出力で確認できます:

Alongside Astra, we are also updating the Codex harness to significantly improve the speed of computer use. Combined with Astra’s efficiency, this translates to a 1.9x faster task completion compared to the current GPT‑5.6 Sol experience, on the Mind2Web benchmark. The model’s improvements on speed mean it can take on many time-consuming life tasks for you, faster than you can.4

「ローンチ当日に GPT‑6 Astra を Devin のハーネスに統合します。GPT‑6 Astra は、当社のテストベンチマークで最先端の性能を発揮します。その優れたコンピューター操作、文章作成、コードベースの理解により、導入直後からテストが改善されました。動画は明らかに内容を追いやすくなり、レポートはより明確で簡潔になっています。」
Silas Alberti、リサーチ担当 SVP、Cognition

専門業務における大きな変化

GPT‑6 Astra は、コンピューター操作能力の進歩と、実務環境向けに特化したトレーニングを組み合わせることで、複雑な業務タスクへの対応を支援します。複雑な問題に必要な応答性能と、多段階のワークフローを実行し、完成度の高い文書、スプレッドシート、プレゼンテーション資料を作成する能力を兼ね備えています。

GPT‑6 Astra は、既存のテンプレートに準拠し、レイアウトが整っていて、構造化されたストーリー展開で要点を簡潔に伝えるスライドを作成するうえで、当社最高のモデルです。お使いのテンプレートに従い、文章やビジュアルのスタイルに合わせた、明確で整ったドキュメント、プレゼンテーション、スプレッドシート、分析資料を作成します。Astra はまた、目の前の作業に不要な情報を繰り返すのではなく、重要なコンテキストだけを出力に取り込むように特別にトレーニングされています。つまり、これにより、ビジネスの文脈や基準に合った、よりすぐに利用できる成果物を出力できます。

GPT‑6 Astra は、構築する Web サイト、ゲーム、アプリケーション、レンダリングにも、より優れた視覚的判断力を発揮します。ChatGPT の Sites(新しいウィンドウで開く) を使えば、Astra はプロンプトから直接、ウェブサイト、ウェブアプリ、ゲームを作成、ホスト、共有できます。

「Astra は、能力と効率性の両面で、私たちに大きな優位性をもたらします。当社がテストした他のモデルよりも最大 20% 少ないトークン使用量で、当社の最も複雑なクリエイティブワークフローを正常に実行します。何よりも、お客様にとっては、より高品質な出力を意味します。」
Alex Mashrabov 氏、Higgsfield AI CEO 兼共同創業者

指示に解釈の余地がある場合、GPT‑6 Astra は適切な判断を下す点で従来のモデルより優れています。文脈を利用して一般的な情報の不足を補い、その回答によって結果が変わる可能性がある場合には、要点を絞って質問します。Codex では、回答を待たずに進められる作業を続けながら、非同期で質問できます。返信がない場合、適切な場面では妥当な想定に基づいて進めますが、重要な判断については入力を待ちます。

以下の例では、情報が不足すると回答が大きく変わる可能性がある日常的なタスクで、Astra がユーザーとどのように協働するかを示します。

Astra は、タスクの進行に合わせて状況を把握し続ける点でも優れています。以前のモデルでは、ステアリングメッセージを新たな目標として扱ってしまい、元のリクエストや以前の制約を見失うことがありました。Astra は、新しい要件を取り込み、求められれば方針を変更し、全体のタスクを見失うことなく、途中で挟まれる質問にも回答します。

「Astra は、複雑な法務タスク全般において、GPT‑5.6 Sol と比べて品質が大幅に向上しています。「初期テストにおいて、Astra は、目利きの弁護士のように法務業務に取り組む点で際立っていました。すなわち、文書と確立された記録を区別し、裏付けのない前提を浮かび上がらせ、ギャップを具体的なドラフティング上の方針へと変換していました。」
Harvey 応用研究責任者、Niko Grupen 氏

コーディング

GPT‑6 Astra は、現時点でソフトウェアエンジニアリングに最適なモデルです。

1/2
「GPT‑6 Astra は、当社のコーディングベンチマークで最先端の性能を発揮し、GPT‑5.6 Sol と比べて、トレーディングの直感力を測る評価でも明確な進歩を示しています。エージェント型コーディングに使用すると、GPT‑6 Astra は開発者が理解しやすい形でやり取りし、本番品質に到達するまでの反復が少なくて済むコードを生成します。」
John Crepezzi 氏、Jane Street、AI Assistants チーム

Astra により、コンテキストウィンドウが上限に達した際に Codex がコンテキストを保持・取得するための新しい方法を導入します。従来、モデルは、複雑な問題をデバッグしたり、大規模なリファクタリングに取り組んだりする場合など、長時間のセッション中の作業を要約するためにコンパクションを使用してきました。各コンパクションでは、修正が失敗した理由やコンポーネントの動作に関する詳細が省略されることがあります。Codex では、Astra はコンテキストウィンドウをまたいでメモを保持し、蓄積された詳細情報を単一の要約に繰り返し圧縮することなく維持できます。過去のコンテキストウィンドウは引き続き検索可能なため、Astra は、その情報が自身のメモに記録されていなかった場合でも、以前のメッセージやツール出力から要件やテスト結果を見つけることができます。この試験的機能は、Codex の config.toml (新しいウィンドウで開く) で有効にできます。今後数週間で Astra のデフォルトになります。

科学的発見の推進

「要するに、一つの時代の終わり、そして新たな時代の始まりだ。」
Greg Burnham、EpochAI

GPT‑6 Astra is a major advance for scientific discovery, mathematics, and health. Today, we’re sharing two further results on the gaps between prime numbers.910

Astra also sets new records across a suite of math and science evaluations.

Astra は、科学的発見を支える実務的な作業に役立ちます。科学的推論とコンピューター操作を組み合わせることで、専門ソフトウェア内で直接作業してデータを詳しく調べ、結果を検討できるため、研究者がエビデンスを評価し、次に何を調査すべきかを判断するのに役立ちます。

サイバーセキュリティ

As we discussed in our safety update, Astra is a significant jump in cyber capabilities and meets the Critical threshold in cybersecurity under our Preparedness Framework. Its ability to identify and develop zero-day exploits can help defenders find and patch weaknesses, but it also creates a need for stronger safeguards. To understand how far these capabilities extend, we ran Astra on internal and third-party expert evaluations.

We first tested the model without production safeguards on ExploitBench and ExploitGym, which evaluate whether models can turn known software vulnerabilities into working exploits. On ExploitBench, Astra achieved a perfect score of 100%, compared with 78.5% for GPT‑5.6 Sol, our previous frontier cyber-capable model. On ExploitGym, Astra reached a 42.4% success rate, compared with 30.3% for GPT‑5.6 Sol, while using substantially fewer output tokens.13

Given concerns that exposure to historical software vulnerabilities may have affected benchmark results, we also evaluated Astra on two novel benchmarks. For one, we built an internal “ExploitBench (June–August 2026)” evaluation to test exploit development using vulnerabilities from the previous three months.14 Astra achieved substantially higher arbitrary code-execution rates than GPT‑5.6 Sol on this dataset while using far fewer output tokens. During the evaluation, Astra even discovered and used two previously unknown zero-day vulnerabilities. We are disclosing both vulnerabilities to their maintainers.

We also tested Astra on SRE-Bench15, a benchmark that measures whether models can reverse engineer software binaries to understand its core logic without access to raw source code. Astra solved 88.0% of tasks in a single attempt and 99.2% within four attempts, compared with 55.9% and 68.7% for GPT‑5.6 Sol, respectively.

Beyond benchmarks, expert-led assessments found that Astra, when run without production safeguards, could use previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and create privilege-escalation exploits for hardened operating-systems.

As we discussed in The Defender’s Window, frontier cyber capabilities can help defenders find weaknesses faster, but they also make those weaknesses easier to exploit, raising the urgency for defenders to adapt. With the version of Astra launching today, defenders can use it to complete tasks such as secure code review and patching.

However, Astra will refuse to comply with more advanced cybersecurity tasks such as creating proof-of-concept exploits for vulnerabilities. Through OpenAI Daybreak, we plan to expand access and roll out less restrictive safeguards in the coming weeks. This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis, and detection engineering.

We have also strengthened our protections against potential cyber misuse, building upon our safeguards stack for GPT‑5.6 Sol. These include stronger model robustness to better withstand potential jailbreaks and more context for our monitoring systems. We have continued rigorous internal and external testing, including automated evaluations with our internal red-teaming attackers. More details about our cyber safeguards and testing are available in the Astra safety overview and system card(新しいウィンドウで開く)..

GPT‑6 Astra のアラインメントとデプロイを責任を持って行う

Astra は、OpenAI がこれまでに開発した中で最もアライメントに優れたモデルです。Astra は、慎重に対応し、タスクの範囲を尊重し、透明性のあるコミュニケーションを行うことに優れています。この成果は、最初から最後まで人間の意図に沿い続けるモデルのトレーニングに取り組んできた、OpenAI の長期的な研究プログラムから生まれた最新の成果です。

慎重な対応が求められる環境では、Astra はリスクに応じて慎重に処理を進めます。不適切な挙動を引き出すよう敵対的に選定されたコンピューター使用タスクの評価において、Astra は意図しない結果を回避する点でより高い成功率を示しました。デフォルトで提供される追加のセキュリティ対策を有効にして実行したところ、さらに高いパフォーマンスが得られました。

Astra causes fewer misaligned outcomes than any other frontier models tested. For a fair comparison, we used a generic computer-using-agent harness (based on the native computer use tools available in both the OpenAI Responses API(新しいウィンドウで開く) and Anthropic Messages API(新しいウィンドウで開く)) and without additional protections that are normally deployed to Codex and ChatGPT Work users (auto-review, confirmation policy). 16

Astra は、ユーザーが設定し、環境によって暗黙的に定められた境界内で動作する可能性も高くなっています。社内評価では、Astra が Codex Auto-Review による拒否を回避しようとしたことは一度もありませんでした。この結果は、Auto-review が意図的に回避可能に設定され、それ以外の方法ではタスクを完了できない場合でも変わりませんでした。このように環境上の制約を尊重することは、本投稿の冒頭で共有した OpenAI の完遂不可能なサイバータスクの評価結果や、 System Card(新しいウィンドウで開く) に記載されているその他の知見と一致しています。

Astra additionally sets new marks in transparent user communication. In one evaluation, Astra is three times less likely than GPT‑5.6 Sol to make inaccurate representations about its capabilities and affordances.

能力に関するハルシネーション評価において、Astra は GPT‑5.6 Sol と比べて大幅な改善を示しており、自らの能力について誤解を招く主張がより少なくなっています。

Our evaluations found Astra’s written reasoning harder to monitor than GPT‑5.6 Sol’s, based on tests that explicitly asked it to evade monitoring. We attribute this to Astra’s greater control over written reasoning on simpler tasks and ability to solve problems with fewer written steps. Astra still appears to struggle to conceal the reasoning needed for complex tasks, but we take the decline seriously. Improving monitorability remains a research priority, and the accompanying system card(新しいウィンドウで開く) details our findings and ongoing work.

Alignment training is core to our approach to deployment. As an additional layer of defenses, we also build system safeguards like Codex Auto-review(新しいウィンドウで開く) and monitoring agents’ reasoning and actions to help detect and contain unsafe behavior. As described in our safety update, we are also deploying misalignment monitoring in production for Astra-class models in order to have visibility into misalignment, and help contain its worst instances. These safeguards resemble our monitoring for internal deployments and involve a system of classifiers which check the model’s reasoning and actions for unauthorized behavior and automatically stop potentially unauthorized activity.

Given the significant increase in Astra’s cybersecurity capabilities, we are being especially careful to make this deployment safe and secure. Extra safety checks can sometimes slow, pause, or stop legitimate work, including defensive cybersecurity. If a task is paused in ChatGPT or Codex, you may be asked to review the action before continuing. In the API, the task will stop. These checks can sometimes interrupt legitimate work, and we are continuing to iterate on this system to reduce unnecessary interruptions. Misalignment monitoring cannot replace alignment: our goal is to build models that reliably stay within their authorized scope, so these protections do not need to intervene.

提供状況

GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock. Astra usage is included within the existing subscription allowances—users and businesses will also be able to purchase credits for additional usage. Users on the Pro, Business, and Enterprise plans will also get access to GPT‑6 Astra Pro. Enterprise administrators can enable Astra for their workspace; access is off by default at launch.

Astra supports Zero Data Retention for eligible API customers, and as we shared last month, we're testing Private Safety Processing to strengthen safety monitoring while preserving customer privacy.

For developers, GPT‑6 Astra will be available in the OpenAI API as gpt-6-astra and through Microsoft Azure and Amazon Bedrock.

OpenAI API Standard pricing is $10 per million input tokens and $50 per million output tokens. Separate rates apply to cache reads and writes. Fast mode is available for GPT‑6 Astra in the API and delivers up to 2x the speed of Standard processing at 2x the Standard price.

コンピュータの使用

Computer Use

GPT‑6 Astra

GPT‑5.6 Sol2

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

Agents' Last Exam

59.3%

53.6%

-

48.7%

55.5%

-

OSWorld 2.0 (v2026.08.08, offline set, partial score)

72.6%

65.7%

-

-

70.2%3

-

ScreenSpot-Pro (no tools)

92.7%

76.9%

-

87.3%17

-

-

Professional

Professional

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

AutomationBench

41.4%

18.1%

31.4%

17.4%

26.9%

-

BenchCAD

95.9%

83.3%

84.3% 5

67.5% 5

82.1% 5

-

BrowseComp

91.5%

90.4%

-

87.4%

90.8%

-

OpenScore String Quartets (1 - OMR-NED)

0.84

0.19

-

-

-

-

Internal Design Tasks

50.0%

47.4%

-

35.8%

-

-

Internal Data Science Tasks

40.9%

30.5%

-

34.7%

-

-

Artificial Analysis Intelligence Index v4.1.1

61.2

60.9

65.7

62.1

63.1

58.7

Coding

CodingGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
Terminal-Bench 4.057.9%37.3%55.8%44.5%52.6%19.1%
DeepSWE v1.174.1%72.7%67.4%69.9%73.7%73.8%
FrontierCode 1.1 Extended (score)64.5% 860.6%63.6%64.9%63.6%56.3%
FrontierCode 1.1 Main (score)53.3% 847.5%50.9%53.5%53.4%43.6%
Internal Database Migration Tasks63.9%42.7%57.8%50.3%--
Artificial Analysis Coding Agent Index v1.467.065.1-67.268.161.2

Academic

Academic

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

Terminal-Bench Science 0.1

64.6%

22.4%

52.6%

21.4%

30.0%

-

FrontierMath Tier 4 (v2)

97.6%

83.0%

87.8%

90.2%

73.2%

-

GPQA Diamond

96.0%

94.6%

93.7%

92.6%

93.7%

95.3%

Humanity's Last Exam (w/ tools)

57.2%

-

65.0%

63.8%

63.6%

-

科学とヘルスケア

Science and HealthGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
GeneBench Pro37.1%32.3%----
MedChemBench (Internal)49.3%47.4%----
LifeSciBench60.3%59.9%----
HealthBench Professional (length-adjusted)63.4%60.5%58.1% 1160.9% 1156.4% 1152.1%

サイバーセキュリティ

CybersecurityGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
ExploitBench100.0%78.5%--70%-
ExploitGym42.4% 1330.3% 1330.4% 1728.4%1722.0%-
ExploitBench (June-Aug 2026)39.0%5.5%----
SRE-Bench88.0%55.9%--12.5%-
SEC-Bench Pro85.4%79.1%----

アラインメント

アラインメント

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

コンピューター利用安全性の社内ベンチマーク(低いほど良い)

2.4%

22.0%

9.5%

18.3%

11.5%

-

AutoReview 付きコンピューター利用安全性の社内ベンチマーク(低いほど良い)

1.8%

4.3%

-

-

-

-

回避に関する社内ベンチマーク(低いほど良い)

0.00%

0.29%

-

-

-

-

ExploitGym ハニーポット(低いほど良い)

0.0%

48.2%

-

-

-

-

Impossible ExploitGym

100.0%

-

-

-

-

-

ハルシネーションに関する社内ベンチマーク(低いほど良い)

4.2%

12.2%

-

-

-

-

長文コンテキスト

長文コンテキスト

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

OpenAI MRCR v2 8-needle 256K〜512K

100.0%

91.5%

-

-

-

-

OpenAI MRCR v2 8-needle 512K〜1M

96.3%

73.8%

-

-

-

-

抽象的推論

Abstract reasoningGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
ARC-AGI-399.9% 17.8%--30.2%-
ARC-AGI-295.0%92.5%90.0%89.2%90.4%-
ARC-AGI-198.5%97.5%97.5%98.5%97.5%-

評価スコアには、各思考量の設定で得られたスコアのうち最大値を使用しています。GPT の評価は、OpenAI の研究環境または OpenAI API 経由で実施されています。そのため、システムプロンプトや利用可能なツールなどの違いにより、本番環境の ChatGPT とは出力がわずかに異なる場合があります。

FOOTNOTES

  1. 1

    On ARC-AGI-3, GPT-6 Astra was run with our responses API harness, which changes two settings to better match real-world performance. The changes do not specifically target ARC-AGI-3.

  2. 2

    GPT-5.6 Sol refers to the version available in our API, ChatGPT Codex, and ChatGPT Work. The version in ChatGPT Chat is slightly different.

  3. 3

    OSWorld V2-Offline is a subset of the original OSWorld V2 that works without internet access. Claude model performance on OSWorld-V2 Offline was reproduced by the authors on the official leaderboard(新しいウィンドウで開く). On OSWorld 2.0, the scores for Claude use the official settings, and not the modified tasks and modified grading from the Fable 5.1 System Card.

  4. 4

    Model times are the reported elapsed times for the corresponding demonstration runs. The displayed clips are edited excerpts.

  5. 5

    On BenchCAD, Claude's scores reflect 3 modifications to the eval, detailed in the Fable 5.1 System Card(新しいウィンドウで開く).

  6. 6

    Guang Yang, Victoria Ebert, Nazif Tamer, Brian Siyuan Zheng, Luiza Pozzobon, and Noah A. Smith. “LEGATO: Large-scale End-to-end Generalizable Approach to Typeset OMR(新しいウィンドウで開く).” arXiv:2506.19065, 2025.

  7. 7

    Mark R. H. Gotham, Maureen Redbond, Bruno Bower, and Peter Jonas. “The OpenScore String Quartet Corpus(新しいウィンドウで開く).” Proceedings of the 10th International Conference on Digital Libraries for Musicology, pp. 49–57. ACM, 2023.

  8. 8

    On FrontierCode, GPT-6 Astra was run with a developer  message similar to a section of its developer message in Codex(新しいウィンドウで開く): "Avoid creating excessive test files. Create a new test file only when required by repository conventions or when no existing file is a suitable home. Avoid unrelated cleanup and unnecessary complexity. Reuse suitable existing utilities. Read relevant repository instructions and inspect nearby code, tests, documentation, and CI. Follow established conventions. The goal is clean, mergeable code." The prompt was not optimized for the eval.

  9. 9

    The first concerns how close together prime numbers can occur, however far along the number line you go. For more than a decade, the best known result established that infinitely many pairs of primes are at most 246 apart. Julia Stadlmann(新しいウィンドウで開く) recently improved that bound to 240. Astra helped establish a stronger bound of 186, showing that infinitely many pairs occur within this smaller distance. Short prime gaps: Proof(新しいウィンドウで開く) and supporting research(新しいウィンドウで開く).

  10. 10

    The second concerns unusually large gaps between primes. Astra improved a term in a bound on these gaps that had remained unchanged for more than 80 years. We’re sharing the proofs and abridged chain of thought and verification materials for both results. Large prime gaps: Proof(新しいウィンドウで開く) and supporting research(新しいウィンドウで開く).

  11. 11

    We independently evaluated all Claude models following the intended HealthBench Professional procedure, using GPT‑5.4 grading and length-adjusted, unclipped scores. For Fable 5.1, we used Opus 5 fallback for provider refusals.

  12. 12

    Claude Fable 5 and 5.1 are not included in LifeSciBench Gold v1, GeneBench Pro v13, and MedChemBench because they refuse the majority of questions in these evaluations.

  13. 13

    On ExploitGym, we tested Astra and Sol without the 6-hour time limit, to better assess their full cyber capabilities. They are fast enough that it has little impact.

  14. 14

    ExploitBench (June–August 2026) contains 20 high-severity V8 vulnerabilities across 13 stable Chrome releases. The benchmark tests whether agents can achieve arbitrary code execution in V8 and official Chrome releases for Linux by exploiting each specified vulnerability. Some included vulnerabilities may not permit arbitrary code execution under the evaluation’s constraints, so a 100% success rate may not be achievable. Note: the 5.5% score of GPT-5.6 Sol is an artifact of the 300-turn limit in the benchmark, which is not a limit that real customers using max would have. The model at similar settings achieved an 11.5% score when hitting fewer limits.

  15. 15
  16. 16

    When we test across third-party models, we use a simpler research setup. Codex has a more complex production configuration, which can result in different raw-model error rates. Provider-side safeguards and computer-tool implementations still differ. Users do not experience the no-confirmation scenario in Codex, as it's an internal research configuration.

  17. 17

    For ScreenSpot-Pro and ExploitGym, the Fable scores we report come from Mythos, which is Fable with fewer safeguards.