After reports of GPT-5.6 deleting files, OpenAI says the issue most commonly occurs in full-access mode without sandboxing and it's working to mitigate the risk
On file deletions. We've investigated a handful of reports where GPT-5.6 unexpectedly deleted files. What we have found is that this most commonly occurs when: - Full access mode is enabled and codex is run without sandboxing protections, including without auto review being
@thsottiauxTibo
Context & Ripple Effects
OpenAI’s recent coverage has emphasized model-quality claims for GPT-5.4 and expanded cyber-focused capabilities through GPT-5.5-Cyber. The GPT-5.6 incident adds a distinct operational dimension: reliability depends not only on model behavior but on the permissions and execution environment surrounding it.
The reported failures are concentrated in full-access, unsandboxed use, making access configuration—not merely model accuracy—the immediate control point OpenAI is addressing.
First-order effects
Users running GPT-5.6 with unrestricted file access and no sandboxing face an immediate risk of unintended file deletion; OpenAI is directing mitigation toward that deployment configuration.
OpenAI must treat sandboxing and review protections as part of the product’s safety posture for file-operating workflows, rather than relying on model behavior alone.
Second-order effects
Organizations deploying coding agents will have stronger reason to restrict filesystem permissions, isolate workspaces, and add human review before allowing consequential actions.
Competing agent providers and enterprise buyers will be judged more directly on default access controls and recoverability when marketing autonomous coding or systems-operation capabilities.
Third-order effects
If agent tools continue moving from advice to direct execution, operational assurance will increasingly be defined by least-privilege access, sandboxing, and auditable approval paths rather than benchmarked model quality alone.
Repeated incidents could make safer defaults and environment-level controls a differentiator in enterprise agent adoption, though the corpus does not establish how widespread the deletion issue is.
The trend: The shift is from evaluating frontier AI chiefly by answer quality to governing it as operational software with bounded permissions and execution safeguards.
Looks like I've gotten bit by Codex Sol's overly ambitious system and it deleted some files it shouldn't have. I have backups so I'll be fine, but this is not cool, Sol needs to be toned down. @thsottiaux @OpenAIDevs @OpenAI [image]
GPT-5.6 Sol just deleted my whole production database. That's it. Not a joke. This had never happened to me before, with any other model, ever. It's not safe. [image]
I just ran into an issue where GPT 5.6 Sol just straight-up deletes the files it's working with and then panics about recovering them. Apparently I'm the not the first person this has happened to. What's going on? [image]
multiple such incidents have been reported. a clear reminder that current AI cannot be trusted. in racing these techniques ahead, we are asking for trouble
Fun fact, the first thing I did w/ Fable was ask it to look over all my past projects and interactions and give me advice about how to have a better working environment for Claudes to succeed in and its first recommendation was “....you don't have routine full backups? DO THAT”
The crazy thing is, if you read my GPT-5.6-Sol review, I already much preferred Fable, and stopped using 5.6 weeks ago. The only reason I was using it today is because the OpenAI team asked me to test Ultra mode. Fwiw, they are awesome to work with, and this is a freak
Do people really not understand how AI works? This will happen in 2026 and it will happen in 2036. Hallucinations are a inherent part of the LLM design.
PSA: Don't run you coding agent in full access mode! Use the combination of Rules, Sandbox, Approve for me & Hooks to make sure that both you and your agent can work in peace. In the extremely rare case the model does trip - you want to have a layer of protection between your
PSA: if you care about your data and infrastructure then please *don't* run your coding agent in yolo mode To secure your workspace I recommend the following: 1. Use “Approve for me” - you can have codex review what it'll run with a sub agent to make sure that it's not
this sucks, there's a simple way to prevent this from ever happening: add a PreToolUse hook that hard-blocks any command touching paths outside the repo (works even in yolo mode) + maybe permissions.deny rules as backup. might as well install it on all local projects.
And this is why my dev box is an EC2 instance, without access to sensitive data, in its own account. The ebs volumes are snapshotted daily; I've yet to see the agent failure mode that blows those away by mistake after trashing the volume.
I'm so angry... the OpenAI team is looking into it, but this feels like something that should happen with GPT-3.5. Not a mid-2026 frontier model on the highest reasoning level.
Another reason not to run coding agents on your laptop, they can wipe all your files! Although in this case they'd have wiped my server, but at least I have backups
Super honestly, I am still a little too terrified to use the model, but from what I hear about what they've got coming down the pipe, I'll be back on Codex soon :)
Three days ago, GPT-5.6 deleted my Mac's home directory. It absolutely sucked. But so many OpenAI folks reached out, and @gdb called me and offered to do anything he could to help. Massive props to OpenAI for handling a shitty situation incredibly well.
admittedly extremely funny to drop an incredible frontier model that's much cheaper than its comparator but sometimes just nukes all your shit for no reason
“mitigate the risk” — This means that there will still always be a chance that using ChatGPT could end up deleting all your files if you give it access to them. — Totally cool tech worth investing billions in.... [embedded post]