UK AISI → OpenAI
Directly documented interface
Evaluation
Named evaluator performed a model-specific exercise.
evaluator → provider. Evaluator → developer of model actually tested. No inference of joint model development.
Displayed claim → analysis (if present) → coded attributes → interface / instrument → atomic evidence → source version
Instrument and timeline
- Instrument
- GPT-5.6 Sol July cyber-range evaluation
- Bindingness
- Not applicable to historical event
- Announced
- Unknown
- Observed by
- 2026-07-28 · event observed by day; full evaluation period unknown
- Effective period
- Unknown → Unknown
- Event
- Conducted
- Status at cutoff
- historical event only
- Last confirmation
- 2026-07-28
The incident halted related activity; this qualifies evaluation continuity, not the occurrence of the tests.
- Model-specific historical exercise; current access and agreement terms unresolved.
Status investigation
Checked 2026-09-12; assessed as of 2026-09-12. Last confirmation does not establish uninterrupted continuity.
- amendments
- No change to historical event established
- expiry
- Historical event, not an access term
- termination
- Related evaluations halted after incident
- restrictions
- Non-public configurations and incident-specific response
- succession
- Same UK AISI unit; no transfer of historical US agreement
- conflicts
- Reports distinguish incidents from ordinary public deployment
Search queries
- site.aisi.gov.uk "OpenAI" "2026" evaluation
- UK AISI Anthropic Fable evaluation 2026 suspension status before:2026-09-13
Analytical assessment
No reviewed analytical conclusion is attached. This does not establish independence or absence of an institutional constraint.
Coded attributes
evaluation-capacity: substantial-access-constrained
Ability to design and execute a substantive assessment independently, conditional on access.
Evaluator × evaluation exercise or programme × date. Claude 3.5 Sonnet 2024 pre-deployment exercise; assessed 2024-11-19.
Completed independent tests establish capacity; explicit limited testing access narrows conclusions. Independently run assessments counters inference of provider-directed findings.
Supporting evidence: independent-tests access-limits . Counterevidence: independent-tests
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- absent
- Affirmative evidence of no ability to perform this assessment.
- nascent
- Initial methods/team with no completed substantive assessment.
- substantial-access-constrained
- Completed independent assessment with documented access or time constraints materially limiting conclusions.
- substantial-durable-access
- Completed assessment and enforceable/reproducible access sufficient for the task over its defined period.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
public-authority: limited
Institutionally authorized power to make decisions binding in the specified context.
Institution × legal/operational context × assessed date. February 2024 stated evaluation and advisory remit; assessed 2024-02-09.
Self-described supplementary evaluation and policy-advice remit supports advisory anchor. It does not code the powers of DSIT or UK government as a whole.
Supporting evidence: aisi-remit . Counterevidence:
- Historical institutional remit. Later capacity, legislative changes or government powers require separate evidence. Limited denotes advisory remit here, not limited binding authority.
Published rubric anchors
- absent
- Affirmative remit excludes binding public decisions in this context.
- limited
- Advisory or delegated bounded public decisions.
- substantial
- Binding decisions over a significant but bounded function.
- binding-operational
- Documented binding decision and ability to carry it into operation in the defined function.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
information-access: unresolved
Ability to obtain non-public model information independently of provider consent.
Institution × information category × jurisdiction/date. Compulsion of access to non-public frontier checkpoints; assessed 2026-09-12.
A limited voluntary exercise cannot prove absence of all compulsory authority. No jurisdiction-wide classification from this evidence.
Supporting evidence: access-limits . Counterevidence: independent-tests
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- absent
- Affirmative evidence excludes access in this context.
- voluntary-provider-controlled
- Access obtained through provider permission or negotiated instrument.
- partial-compulsory
- Specific compulsory information powers apply to some requested information.
- broad-compulsory
- Applicable legal powers reach the information needed for this defined task, subject to stated safeguards.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
Atomic evidence and exact sources
The evaluation had a limited access and testing period.
- Source
- Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
- Version
- 2024-11-19; retrieved 2026-09-12
- Exact locator
- Section 2.1, printed pages 1–2
- Limit
- Applies to this exercise; does not identify who caused the limits.
Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903
The institutes each ran independent tests and worked together on methodology and interpretation of findings.
- Source
- Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
- Version
- 2024-11-19; retrieved 2026-09-12
- Exact locator
- Section 1, printed page 1
- Limit
- Independence of tests does not establish durable model access.
Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903
In its February 2024 approach document, AISI describes itself as a secondary check rather than a regulator.
- Source
- AI Safety Institute approach to evaluations · DSIT / AI Safety Institute
- Version
- published-2024-02-09; retrieved 2026-09-12
- Exact locator
- A note on evaluations, final paragraph
- Limit
- Historical stated remit; not an assessment of every governmental power or all powers at September 2026.
Retrieved bytes SHA-256: 3cf1fee953c6819e009c82b58e5340b7e67737a824477c3ceced9ca636be981c
AISI identifies GPT-5.6 Sol as a model it tested in its July 2026 cyber-range exercise.
- Source
- Incident Report: unsanctioned agent behaviour during cyber testing · UK AI Security Institute
- Version
- consulted-2026-09-12; retrieved 2026-09-12
- Exact locator
- Paragraphs beginning The incident stemmed and Almost all of this behaviour
- Limit
- Specific non-public testing configurations; not ordinary deployed behavior or proven real-world harm.
Retrieved bytes SHA-256: d877ecd7c74dcf9b667aadb79c49e784e11f4a87eda89f287089038b8584350c
OpenAI reports AISI stopped related evaluations and isolated relevant machines after July28 incident detection.
- Source
- Third-party cyber evaluations involving OpenAI models · OpenAI
- Version
- consulted-2026-09-12; retrieved 2026-09-12
- Exact locator
- UK AISI section, paragraph beginning UK AISI identified the activity
- Limit
- Specific exercise response; not termination of all developer–institute relations.
Supporting and conflicting evidence
Interface support: uk-openai-july-tested. Counterevidence: july-evaluation-halted
Substantive review
evidence/access-limits: approved · agent reviewer codex-research-checker · 2026-09-12
Full joint report section 2.1 explicitly limits access and the testing window. It does not identify the institution responsible for either constraint. Checked locator: Section 2.1, printed pages 1–2. Source version: 2024-11-19.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/uk-openai-july-tested: approved · agent reviewer codex-research-checker · 2026-09-12
AISI incident report names GPT-5.6 Sol, actual cyber-range runs and July28 detection; non-public configurations and unknown full testing period remain explicit. Checked locator: Paragraphs beginning The incident stemmed and Almost all of this behaviour. Source version: consulted-2026-09-12.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/july-evaluation-halted: approved · agent reviewer codex-research-checker · 2026-09-12
OpenAI August4 UK AISI section corroborates stopping the related evaluations and isolating machines following July28 detection; no universal agreement termination inferred. Checked locator: UK AISI section, paragraph beginning UK AISI identified the activity. Source version: consulted-2026-09-12.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
instruments/uk-openai-july-evaluation-event: approved · agent reviewer codex-research-checker · 2026-09-12
AISI report plus OpenAI corroboration establish the named historical cyber-range test event and subsequent halt.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
relationships/uk-openai-july-evaluation: approved · agent reviewer codex-research-checker · 2026-09-12
AISI names actual GPT-5.6 Sol testing; evaluator-to-developer direction and historical event status are correct. July halt counterevidence qualifies continuity rather than test occurrence.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-sonnet-capacity: approved · agent reviewer codex-research-checker · 2026-09-12
Checked evaluation-capacity rubric against report sections1/2.1: completed independently run assessments plus explicit access/time constraints satisfy the context-bound substantial-access-constrained anchor. Corrected reasoning no longer claims independently designed methodology. No contemporary UK institution-wide ranking follows.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-information: approved · agent reviewer codex-research-checker · 2026-09-12
Unresolved is warranted: limited voluntary testing does not prove absence of statutory powers or distinguish compulsory-access anchors across the UK jurisdiction. Reviewed uncertainty is not a finding of absent authority.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/independent-tests: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/aisi-remit: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-public-remit: approved · agent reviewer codex-primary · 2026-09-12
Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a