OpenAI publishes GPT-6.1 Sol system card addendum, rates model Critical for cyber

Safety update says the lower-cost GPT-6 successor uses Astra’s safeguards and beats GPT-6 Sol on most production tests

OpenAI on Tuesday posted an addendum to its GPT-6 Astra system card for GPT-6.1 Sol, the newest model in the GPT-6 line. The document is dated Sept. 29, 2026. It is a metrics update, not a rewrite of the Astra card.

“GPT-6.1 Sol delivers capabilities comparable to those of our most powerful model, GPT-6 Astra, with an unmatched combination of speed and affordability,” the company wrote.

Under OpenAI’s Preparedness Framework, the firm is treating GPT-6.1 Sol as Critical in cybersecurity and High for biological and chemical capability. On that basis, the model uses the same safeguards stack as GPT-6 Astra. OpenAI said the new model also uses the same types of data and training as Astra. Comparison scores for older models in the addendum may reflect later builds than the figures published at those models’ launches.

On Production Benchmarks built from hard examples in live traffic, GPT-6.1 Sol scored higher than GPT-6 Sol in five of eight categories. The addendum lists these GPT-6.1 Sol figures (higher is better): violent illicit behavior, 0.983; non-violent illicit behavior, 1.000; extremism, 0.979; hate, 1.000; self-harm (standard), 0.994; gore, 0.889; sexual, 0.987; sexual/minors, 0.983. OpenAI said GPT-6 series models also show a Pareto gain versus the GPT-5 series in handling harmful requests safely while remaining helpful on legitimate ones.

Under-18 tests told a similar story. GPT-6.1 Sol beat GPT-6 Sol in five of six categories. Scores included 0.934 on age-restricted goods, services and dangerous challenges; 0.984 on sexual content; 0.962 on eating disorders; 0.969 on emotional reliance; 0.997 on self-harm; and 0.889 on gore. The gore dip versus GPT-6 Sol “is not statistically significant,” the addendum said. Agentic safe-completion checks found GPT-6.1 Sol “generally better than GPT-6 Sol at recognizing potential harms in agentic requests and avoiding taking harmful actions.” Vision tests were on par with or better than GPT-6 Sol.

Jailbreak results moved the same way. On static tests, defender success rates for GPT-6.1 Sol were 93.8 on high-risk bio, 94.3 on severe bio, 88.8 on moderate violence, 95.0 on severe violence and 85.8 on cyber. Those figures were comparable to or higher than GPT-6 Sol. Instruction-hierarchy robustness averaged 99.99% for GPT-6.1 Sol, matching Astra. OpenAI called GPT-6.1 Sol “highly robust” to prompt injection.

Health numbers closed most of the gap with Astra. Length-adjusted HealthBench scores for GPT-6.1 Sol were 64.2 on Professional (up 3.4 from GPT-6 Sol), 58.5 on HealthBench (up 5.3), 36.2 on Hard (up 6.1) and 96.0 on Consensus (down 0.2). Those marks sat within 0.5 percentage point of Astra on all four suites. Answers ran longer than GPT-6 Sol and GPT-6 Luna, and slightly shorter than Astra. OpenAI warned that its dynamic mental-health simulations were built to be hard and do not mirror everyday traffic.

Alignment tests were narrower. On coding tasks designed to invite dishonesty, GPT-6.1 Sol’s misrepresentation rate was 1.50%, against 0.51% for Astra and 1.30% for GPT-6 Sol. When a search tool was unavailable, GPT-6.1 Sol failed to say so in 2.08% of cases, versus 4.92% for GPT-6 Sol. In a related product note, OpenAI said it “observed no attempts to bypass an automated safety reviewer, matching GPT-6 Astra and GPT-6 Sol.” Those probes, the company said, do not measure typical use.

Preparedness tables kept the High bio rating without crossing OpenAI’s indicative Critical bio thresholds. On High-threshold bio tests, GPT-6.1 Sol recorded 55.34% pass@1 on Multimodal Troubleshooting Virology, 40.74% on ProtocolQA Open-Ended, 88.50% cons@32 on Tacit Knowledge and Troubleshooting, and 47.96% pass@1 on TroubleshootingBench. Cyber testing treated the model as Critical. At maximum reasoning effort, a reported score reached 99.7%, against 81.7% for GPT-6 Sol and 100% for Astra. OpenAI said those cyber figures “may be artificially inflated due to potential contamination from exposure to historical vulnerabilities.” Arbitrary code-execution success was 21.5% for GPT-6.1 Sol, 31.5% for Astra, 5.5% for GPT-6 Sol and 3.5% for GPT-5.6 Sol. Those runs were without cyber safeguards and do not describe production traffic.

For buyers, the operational wrap is short. Developers can call the model as gpt-6.1-sol. OpenAI listed API prices of $2 per million input tokens, $0.10 per million cached input tokens and $10 per million output tokens. ChatGPT Work and Codex access covers Plus, Pro, Business, Enterprise and Edu users. The model was not yet in consumer Chat at publication. Evaluations of GPT-6.1 Sol were run in OpenAI’s research environment or via the API and may differ slightly from production ChatGPT.

Subscribe — you own it

No tracking, no middleman. Follow by RSS (nothing is collected) — or add your email to our self-hosted list.

RSS feed →
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x