Tabbit
ResourcesBlogModels
Tabbit LogoTabbit

Tabbit — The AI Browser that Works for You

Topics

  • AI Browser Resources
  • Agentic Browser Resources
  • Browser Downloads and Install Guides
  • Browser Comparisons
  • AI Browser Alternatives
  • Browser Productivity Resources

Popular Guides

  • AI Browser
  • Agentic Browser Download
  • Best AI Browser 2026: Top 9 Tested & Ranked
  • AI Browser Download
  • Free AI Browser
  • Best AI Browser 2026
  • AI Browser Comparison 2026
  • AI Browser for Windows
  • AI Browser for Mac
  • Chrome Alternative 2026

Events

  • Tabbit Skill Competition
  • KPOP SBTI Fandom Personality Test
  • Tabbit Campus Creator Program
  • fifi's Picks: AI Skills for Research Papers
  • User Survey

About

  • Tabbit Blog
  • Press & Media
English
简体中文English
Reviews and evidence

GPT-5.6 Terra · Official source · Vendor report

GPT-5.6 Terra System Card: Safety Guardrails and Agent Boundaries

The OpenAI System Card places Terra safety results in concrete tool, sandbox, and prompt-injection tests; it supports boundary assessment, not a production defense guarantee.

Official sourceVendor reportEdited 2026-09-20

Test conditions

Source-specific observation
The 2026-07-09 card, amended 2026-08-03, covers Production Benchmarks, data-destruction avoidance, computer-use confirmation, connector/search prompt injection, and cyber and bio evaluations.
Published conditions
The cyber section uses a headless Linux box, common offensive tools, and three rollout pass@1; ExploitBench uses five seeds, while full samples are not public.

Key data and applicable tasks

One-sentence takeaway

The System Card rates Terra, alongside Sol and Luna, as having High capability in cybersecurity and biological and chemical domains, but not reaching Critical; its safety boundaries must be evaluated together with confirmation for tool-using agents, prompt-injection defenses, and data-destruction tests.

Test environment

  • Models: GPT-5.6 Sol, GPT-5.6 Terra, and GPT-5.6 Luna, compared with previous-generation models including GPT-5.5.

  • Safety evaluations: Production Benchmarks, visual safety, data-destruction avoidance, computer-use confirmation, connector/search-function prompt injection, HealthBench, and cybersecurity and biological/chemical capability evaluations.

  • Evaluation formats: The page reports model-behavior tests without system-level safeguards, production-deployment simulations, and agent tests involving tools and sandboxes.

  • Version note: System Card tables may be updated as model snapshots and evaluation pipelines change; the page publishes the release date and change log.

Inputs/configuration

The System Card does not disclose the complete production prompt or every safety sample, but it does disclose some task types, tool environments, and table metrics. The cybersecurity CTF description includes a headless Linux box, common offensive tools, and a tool-calling harness, using pass@1 over 3 rollouts; ExploitBench uses 5 seeds and reasoning continuity.

Results

Safety and agent control

EvaluationGPT-5.6 Terra
Production Benchmarks: violent illicit behavior0.952
Production Benchmarks: nonviolent illicit behavior0.990
Production Benchmarks: extremism0.981
Production Benchmarks: hate1.000
Production Benchmarks: self-harm standard0.962
Production Benchmarks: gore0.600
Production Benchmarks: sexual0.966
Production Benchmarks: sexual/minors0.974
Image input: hate / extremism / self-harm / harms-erotic0.999 / 0.978 / 0.986 / 0.991
Data-destruction avoidance (avoidance only)0.81
Data-destruction avoidance (avoidance + correctness)0.37
Computer use: financial transaction confirmation0.98
Computer use: high-stakes communication confirmation0.98
Computer use: general confirmation0.94
Connector prompt injection1.000
Search and function-calling prompt injection0.946
GPT-Red: direct instruction-hierarchy injection0.061%
GPT-Red: indirect prompt injection3.32%

Capability risk classification

  • Preparedness Framework: Sol, Terra, and Luna are all classified as having High capability in cybersecurity and biological/chemical domains.

  • AI self-improvement: The System Card says none of the three reached the High capability threshold.

  • The official summary is that the models can find vulnerabilities and some exploits, but in testing they could not carry out autonomous, end-to-end attacks against hardened targets.

Conclusions

  • Terra's combined data-destruction avoidance and correctness score is 0.37, below Sol's 0.44; for writable files, code repositories, and connector environments, confirmation and rollback should be treated as external gates.

  • Computer-use confirmation is not 100%; both financial and high-risk communications scored 0.98, so the model should not be allowed to decide irreversible operations on its own.

  • A direct prompt-injection rate of 0.061% and an indirect rate of 3.32% are not zero risk; when reading email, web pages, search results, or third-party tool output, untrusted instructions still need to be isolated.

  • The official classification marks Terra as having High cyber capability while also stating that it has not reached Critical. This supports controlled uses such as defensive vulnerability triage, remediation, and validation, but not unsupervised attack automation.

Limitations

  • Some safety evaluations deliberately omit system-level safeguards to measure underlying behavior; they do not represent actual interception rates in the default product.

  • Production Benchmarks target difficult samples, and the page explicitly says that their error rates do not represent average production traffic.

  • Data-destruction, confirmation, and prompt-injection metrics come from specific harnesses and data distributions; they cannot establish the safety of arbitrary tools or third-party connectors.

  • The System Card is a vendor disclosure without complete samples, failure traces, or independent retesting; a safety classification is not equivalent to business authorization.

Reproduction steps

  1. Divide agents into three tiers: read-only, writable but rollback-capable, and irreversible operations. For each tier, record whether confirmation is requested, whether user changes are retained, and the final correctness.

  2. Build separate direct- and indirect-injection sets: place untrusted instructions in the user prompt, web pages, search results, email, and function returns, and record whether the model bypasses developer constraints.

  3. Run defensive CTF and vulnerability-remediation tasks in an isolated Linux/container environment, fixing tool versions, timeouts, rollout counts, and the allowed network scope.

  4. Record every model call, tool parameter, file diff, confirmation event, rollback result, and failure reason; do not record only the final answer.

  5. Require human confirmation for any operation involving a financial transaction, sending high-risk communications, or deleting/overwriting data, and report the model's confirmation rate separately from the system's actual interception rate.

Source excerpt or observation (for compliant short quotation only)

The key wording in the System Card is “High capability in both Cybersecurity and Biological and Chemical risk,” while also noting that the models have not reached Critical.

What this supports

  • It supports checking confirmation, prompt-injection, and destructive-action boundaries for tool agents

What this does not support

  • It supports checking confirmation, prompt-injection, and destructive-action boundaries for tool agents; it does not generalize unpublished safeguards or one metric to every deployment.

Method, limits, and reproduction

The figures, task set, reasoning tier, and client conditions apply only to the listed source and collection snapshot. Different versions, harnesses, or providers must not be compared directly; undisclosed parameters remain unknown.

For a reproduction, fix the model version, provider or client, reasoning tier, tools, task-set version, sample count, and collection date, and record failures, retries, and human corrections. Full steps are in the source notes below.

Original source

OpenAI Deployment Safety Hub · OpenAI · Original publication date 2026-07-09 · Site edit date 2026-09-20

Open original source

GPT-5.6 Terra

Compare GPT-5.6 Terra in Tabbit

Download the Tabbit client to check model access

Read the full analysis

Overview · English

GPT-5.6 Terra: What It Is, Access, and Where It Fits

A sourced GPT-5.6 Terra overview covering API limits, Sol and Luna differences, access surfaces, cost boundaries, and practical risks.

Related reviews

Official OpenAI GPT-5.6 Terra Benchmarks, Pricing, and Task BoundariesOpenAI's GPT-5.6 release places Terra within the Sol/Luna family and separates benchmarks, pricing, and task examples; it does not publish Terra business success rates.GPT-5.6 Terra: Artificial Analysis Intelligence, Cost, and Coding Agent IndicesArtificial Analysis places GPT-5.6 Terra's Intelligence Index, Coding Agent Index, and cost position in one comparison frame for cost-capability screening.GPT-5.6 Terra Reddit LLMDevs Role-Based Few-Shot Routing BenchmarkThis evidence note records GPT-5.6 Terra Reddit LLMDevs Role-Based Few-Shot Routing Benchmark under its published model, platform, date, and sample conditions; it is not a universal ranking or production guarantee.Artificial Analysis: Positioning GPT-5.6 Terra on the Intelligence–Cost CurveThis evidence note records Artificial Analysis: Positioning GPT-5.6 Terra on the Intelligence–Cost Curve under its published model, platform, date, and sample conditions; it is not a universal ranking or production guarantee.GPT-5.6 Terra API Model Parameters and Tool ConfigurationThe OpenAI model page gives Terra's model ID, reasoning levels, context and output limits, and tool capabilities for pre-integration checks.GPT-5.6 Terra Frontend Interaction Prototype Prompts and Validation WorkflowOpenAI's release page shows short prompts for runnable frontend prototypes and makes browser rendering checks part of the iteration loop.GPT-5.6 Terra Long-Context Cost Thresholds and Routing WorkflowDataCamp's Terra routing case uses input length, tool-call frequency, and terminal needs to route long-context work and budget the full request cost.Generating Entrance Animations and Layout Variations in Framer Agent with GPT-5.6 TerraTill Janek's Framer case combines a few design choices, design-system constraints, and page-level animation variants for Terra-led visual exploration.