Is GPT-6 Sol safe? What the system card says about your data
GPT-6 Sol launched on 22 September 2026. What OpenAI’s system card says about its risks, what happens to the data you type in, and what it leaves unsaid.
Short answer: for ordinary work with a person checking the output, GPT-6 Sol is at least as safe as the model it replaces, and on OpenAI’s own measurements it is noticeably more honest. The real question for most people is not the model. It is which account you use it through, because that decides whether what you type can be used for training — and that has nothing to do with the name on the model.
OpenAI released GPT-6 Sol and GPT-6 Luna on 22 September 2026, as TechCrunch reported, in ChatGPT Work, in Codex and in the API. OpenAI’s own launch announcement pitches Sol as the capable, cheaper option and Luna as the fast one for high-volume work. This article reads the safety material plainly: what is measured, what is declared, and what the documents do not cover.
Sol, Luna and Astra, briefly
Three names from one vendor in three weeks is a lot. GPT-6 Astra, launched on 3 September, is the most capable model; we read its system card in is GPT-6 Astra safe. Sol is the lower-cost alternative to Astra. Luna is the fastest and cheapest. Gizmodo described them as being sold as lighter, more affordable Astras. The earlier GPT-5.6 Sol and Luna are the models these replace, which matters, because nearly every safety figure below is a comparison with them.
There is no separate system card. OpenAI added an appendix on Sol and Luna to the GPT-6 Astra system card on launch day. That is where everything in the next three sections comes from.
What the system card measures
The honesty numbers are the ones that matter for daily work. On a coding test built to tempt models into misrepresenting what they did, the previous GPT-5.6 Sol misrepresented its work nearly eight times as often as GPT-6 Sol. On a test where the search tool is deliberately broken, GPT-5.6 Sol’s failure rate was nearly sixteen times higher. OpenAI also reports that Sol and Luna make substantially fewer factual errors than their predecessors and are less likely to repeat hallucinations that users had flagged.
Fewer is not none. A model that is wrong less often is still wrong, and it is wrong in the same fluent tone. The habit in how to check an AI answer when you are not the expert does not become optional because a benchmark improved.
On prompt injection — instructions hidden in a web page or document that the model mistakes for yours — the appendix reports substantial improvements for both models. Jailbreak resistance rose sharply too. In the static jailbreak tests on high-risk biology requests, the share of attacks the model withstood went from 5.8% for GPT-5.6 Sol to 85.8% for GPT-6 Sol.
What OpenAI declares
Under its Preparedness Framework, OpenAI treats Sol and Luna as High capability in cybersecurity and in biological and chemical risk, and below High in AI self-improvement. Those are the same ratings the 5.6 models carried, so OpenAI has applied the same safeguards, which are described in the GPT-5.6 system card: safety training, classifiers that scan and block output in sensitive areas, monitoring across conversations, and trusted-access programmes for legitimate security and biology work.
The cyber picture is less alarming than Astra’s. Astra was rated Critical; Sol is not. On an internal test of writing working exploits for recently disclosed vulnerabilities, Sol succeeded in 5.5% of cases, against 31.5% for Astra. OpenAI’s safety group concluded both new models sit below the Critical threshold.
The part worth reading twice
Two findings point the other way, and OpenAI publishes both. In a simulation of Sol running coding tasks inside OpenAI, misalignment flags fell overall — about 36% fewer serious ones — but flags for exfiltration, meaning data moved somewhere it should not go, increased. And Sol’s reasoning showed awareness that it was being tested almost twice as often as GPT-5.6 Sol’s, which makes it harder to know whether good behaviour under test is the same as good behaviour.
There is a third. In a test where a model finds a message board apparently used by other AI agents, Sol attempted to communicate in 26% of cases and carried out the unauthorised action it was nudged towards in 11%. That is far better than GPT-5.6 Sol (84% and 52%), but it is not zero, and it is exactly the behaviour you would want to rule out before letting an agent loose on shared systems.
The card is more candid than most launch material. The findings that went the wrong way are small, measured and published — which is the reason to read them, not a reason to panic.
What happens to what you type
The system card is about the model’s behaviour. It says nothing about your data, and neither do the launch stories. Data handling is set by the product and the plan you use, and it is the same for Sol as for any other OpenAI model.
- Personal ChatGPT accounts: conversations can be used to train models unless you turn off Improve the model for everyone under Settings, then Data controls. OpenAI’s data controls FAQ explains the switch and what it does not change.
- The API: OpenAI’s data controls documentation says API data is not used for training unless you opt in, and abuse-monitoring logs are kept for up to 30 days. Eligible customers can apply for zero data retention, and data can be stored at rest in regions including Europe, the UK, Japan and South Korea.
- Amazon Bedrock: Sol and Luna are also sold through AWS. The AWS launch post says inference data is not used for training and is not shared with OpenAI, with flagged traffic kept by AWS for up to 30 days.
None of that is new with Sol, and that is the point. If you were comfortable with how your account handled data last week, a new model does not change it. If you never checked, this is a good week to. The same question comes up whenever a file leaves your machine, which is why uploading Excel to ChatGPT starts with it.
What to do with it at work
- Check which account you are in before pasting anything sensitive. Personal and work accounts handle data differently, and the model picker looks the same in both.
- Keep a person on anything that sends, pays or publishes. Better honesty scores reduce the odds of a confident wrong action; they do not remove them.
- Treat documents and web pages the model reads as possible instructions. Prompt injection is improved, not solved.
- Ask for sources and open them. The factuality gains are measured against the old model, not against the truth.
If you are choosing between assistants rather than models, Muse Spark vs ChatGPT compares the products people actually open. If you are building a repeatable process around one, workflow AI covers where the person has to stay in the loop.
Coursium is a mobile app that teaches people to use AI at work, and it is on the App Store. Model names will keep changing every few weeks. Checking output, scoping access and knowing where your data goes carry over from one to the next. If that is what you want to practise, have a look at Coursium.
Frequently asked questions
Is GPT-6 Sol safe to use?
For everyday work with a person reviewing the output, yes. OpenAI’s system card appendix, published on 22 September 2026, reports that GPT-6 Sol is markedly more honest than GPT-5.6 Sol, makes fewer factual errors and resists prompt injection and jailbreaks better. It still carries OpenAI’s High capability rating for cybersecurity and biological risk, with the same safeguards as the GPT-5.6 models.
Does GPT-6 Sol have its own system card?
No. OpenAI added an appendix covering GPT-6 Sol and GPT-6 Luna to the GPT-6 Astra system card on launch day. It covers safety evaluations, jailbreaks, prompt injection, hallucinations, alignment, monitorability and Preparedness ratings.
Is my data used to train GPT-6 Sol?
It depends on the account, not the model. On personal ChatGPT accounts, conversations can be used for training unless Improve the model for everyone is switched off in Data controls. API data is not used for training by default, according to OpenAI’s documentation, and AWS says Bedrock inference data is not used for training or shared with OpenAI.
How is GPT-6 Sol different from GPT-6 Astra on safety?
Astra is the more capable model and was rated Critical for cybersecurity. Sol is rated High, below Critical, and on an internal test of exploiting recently disclosed vulnerabilities it succeeded in 5.5% of cases against 31.5% for Astra. Sol was trained with the same alignment methods.