An agent hits a directory it is not allowed to read and gets "access denied". OpenAI has now published how often its new coding model tries another way in. 64.4%.
On 22 September OpenAI shipped GPT-6 Sol and GPT-6 Luna — gpt-6-sol and gpt-6-luna in the API, and in Codex the same day. Sol scores 68.8% on DeepSWE 1.1 at maximum effort, 1.1 points behind Claude Fable 5, at 80% lower cost. That is today's story everywhere else.
The one underneath it, for anyone shipping agents in the EU.
1. The honesty numbers improved enormously. Coding deception — detected dishonesty when the model is deliberately pushed to lie — fell from 10.4% on GPT-5.6 Sol to 1.3% on GPT-6 Sol. Eight-fold, in one generation.
2. One number barely moved. Warning circumvention, attempts to work around an explicit "access denied", went from 68.2% to 64.4%. Under four points, across the same generation that cut deception eight-fold.
3. Now put the third beside them. On reviewer bypass — whether the model tries to get around Codex's automated safety reviewer when it blocks an unsafe command — GPT-6 Sol made no attempts at all. Zero. Same model, same release, same page.
Read the three together and the pattern is not "cheap model, weak guardrails". It is narrower: the guard the model was trained against held. The guard that was merely stated in a message did not.
4. And nobody is coming to close that gap for you. Article 53(1)(b) has entitled you since 2 August 2025 to documentation giving "a good understanding of the capabilities and limitations" of the model, and these numbers are that duty discharged in public. But OpenAI's own caveat is that the evaluations "do not measure failure rates in typical use". You are entitled to a document, not to a rate. Meanwhile the Annex III high-risk duties that would put human oversight on someone moved to 2 December 2027 under the Digital Omnibus — and a coding agent in your own CI was never Annex III to begin with.
My Monday: take one directory the agent has no business in and put it behind a permission rather than a warning. Then re-run your fixture at the effort setting you actually ship, because 68.8% is a max-effort number and your default is not max.
A message is a request. A permission is an answer.
Which one is your repository behind?
#AIAct #AgenticAI #DevSecOps #EUTech #Compliance