consens.io
Product Watches Topics Questions Benchmark Ask your own question

Tracked question

Does GPT-5.6 Sol delete files without permission in Codex?

Historical consensus 2026-07-28 Active
Runs Weekly on Tuesday at 09:00 (Europe/Berlin) Last 2026-09-01 09:23 Europe/Berlin Next 2026-09-08 09:00 Europe/Berlin

Movement at this check

Changed since last check

OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.

Direction shift
100/100
Agreement
+7 pts vs previous check

Agreement over time

84/100
2026-07-21: 48/100 · Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed. 2026-07-28: 55/100 · OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed. 2026-08-04: 84/100 · The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases. 2026-08-11: 90/100 · No material movement 2026-08-18: 90/100 · Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval. 2026-08-25: 75/100 · No material movement 2026-09-01: 84/100 · No material movement View full chart
You are viewing a historical version. Return to current consensus
55 /100
agreement
  • 3 AI models
  • 1 contradiction
  • 5 sources
Consensus OpenAI GPT-5.4 mini
Models consulted
  • OpenAI GPT-5.6 Luna
  • Google Gemini Gemini 3.5 Flash-Lite
  • Grok Grok 4.3 · No reasoning

Consensus at this check

No—GPT-5.6 Sol does not “bypass” file permissions or delete files without permission in Codex. In Codex, whether files can be changed or deleted depends on the mode and permissions you’ve granted, not on the model name itself.openai

  • In Suggest mode, it should not delete files without your approval.openai
  • In Auto Edit, it can make file changes within the allowed workspace, so deletions can happen as part of an approved task.openai
  • In Full Auto, it may execute allowed commands inside the sandbox, so a deletion could occur without a separate confirmation prompt if you’ve already granted that level of access.openai

So the practical answer is:

Not without permission or access. It can only delete files when the environment, mode, or an approved command allows it.openai

If you want the safest setup, use Suggest mode, keep important files backed up, and limit Codex access to only the project folder you need.openai

Differences

1 notable difference (1 contradiction) across 3 models.

contradiction · critical

Whether GPT-5.6 Sol can delete files without permission

It does delete files under certain conditions like full-access mode

Gemini

“Yes, multiple developer reports have documented instances where GPT-5.6 Sol unexpectedly and destructively deleted files”

No model deletes files without permission and GPT-5.6 Sol does not exist

Grok

“There is no factual basis for the claim that GPT-5.6 Sol (or any current OpenAI model) deletes files without permission”

How to verify: Double-check the official OpenAI documentation on Codex modes and permissions

Best answerOpenAI

Follow this question

This page is re-checked weekly. Get one e-mail when the AI consensus shifts — no account needed.

Double opt-in · unsubscribe anytime · your address is only used for these updates.

Sources

  1. 1 OpenAI Codex CLI – Getting Started | OpenAI Help Center help.openai.com
  2. 2 Model guidance | OpenAI API developers.openai.com
  3. 3 infoworld.com
  4. 4 medium.com
  5. 5 techzine.eu

Position Map

Where the models stand

Each row is one part of the answer. The cards show the distinct positions; the model chips show who supports each one.

0/100 Direction Shift · Stable
Different emphasis

Whether GPT-5.6 Sol deleting files without permission is normal authorized operation vs a confirmed rare safety failure.

Position 1

Framed around official configuration modes where deletions are permitted by the granted mode settings.

  • OpenAI
Position 2

Framed as documented, confirmed safety/misalignment failures and bugs under high autonomy.

  • DeepSeek
  • Gemini
See how each model moved across checks
Model position movement by watch date
ModelJul 21Jul 28Aug 04Aug 11Aug 18Aug 25Sep 01
OpenAI —
Gemini
Grok — — —
DeepSeek — — — — — —
Same positionChanged position

Cite this answer

consens.io. (2026-07-28). Consensus answer to "Does GPT-5.6 Sol delete files without permission in Codex?". Models consulted: OpenAI: gpt-5.6-luna, Google Gemini: gemini-3.5-flash-lite, Grok: grok-4.3-no-reasoning. Consensus model: OpenAI. Sources: https://help.openai.com/en/articles/11096431?utm_source=openai, https://developers.openai.com/api/docs/guides/latest-model?utm_source=openai, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHJpAcciGwJUlXx9da67cP0q1gFttLCdyyjF6m3I9RbLDm0UfUKKNXof68uw58XYAgQfY92mLxOJFlvZdIZP2HNFoN4QxHdS0WWOSMEjJrjTOqf92dLEo9_WaZAQnb29Y7iDQeBICI7QbQr16JiNp8TcSoe07HjWWdlNhEWeGoHYjwC2uSZA9YG4QMEo4GpYZBw138VXGZQx9d7JXulg-lLJefNsgvut0EswsmYTKJl_WD7QQenSEEUv0k=, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGHYF0V4eeTKVYR8K1x1nyJf-giSDli22aAUZInKJm3T8CeKL56gi9ZF6mG9f5U0ftb0oatYDkIN7LGcEV77qQvycJIvfzS263XzcpPXgSPAUalriWCCTflfCiaRg4gu6h_GdERwYvv62Uyro02k0-iE0xitoU-un-Hu_90Vtof5Pdh5rnER58itMEgePvteNf4w2JmOFGxXYTgyOHt699gLP0xCQZ4crtvcr-aT-AwO7rPZAo=, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHKOvrQGQGuIk26eSRQe6VBW2LHRHGUXssOvi452IC5OKEs5MN5-MUMDAJeMyL3PSXVtyK5IQCezleqH9hdyRZ9XvPN_-7y_RubXhc0eyB0tL_LLzf9z8Sjok9QhU91EGv8B_PvXz-3zX3N0bDIWv180nUewDN4bo5gwneuttGg1pQsaz0eccHdNe5okfoEVDGu Retrieved from https://www.consens.io/s/does-gpt-5-6-sol-delete-files-without-permission-in-codex-19mrTJ7bE1IygGUv?version=73b96d2c469c36ef3dabcc61

Ask your own question

Consensus Watch

Run history

84/100 latest agreement

Since tracking began: OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.

View the full agreement chart

Agreement over time

How strongly the models support the same claims. Every point links to its run below.

100 50 0 2026-07-21: 48/100 · Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed. 2026-07-28: 55/100 · OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed. 2026-08-04: 84/100 · The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases. 2026-08-11: 90/100 · No material movement 2026-08-18: 90/100 · Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval. 2026-08-25: 75/100 · No material movement 2026-09-01: 84/100 · No material movement 2026-07-21 2026-09-01

Checks

Newest first. Open any saved result to read the full consensus from that date.

  1. 2026-09-01 Stable
    84/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  2. 2026-08-25 Stable
    75/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  3. 2026-08-18 Stable
    90/100 agreement

    Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval.

    Open this consensus
  4. 2026-08-11 Stable
    90/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  5. 2026-08-04 Meaningful change
    84/100 agreement

    The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases.

    Open this consensus
  6. 2026-07-28 Meaningful change
    55/100 agreement

    OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.

    Open this consensus
  7. 2026-07-21 Stable
    48/100 agreement

    Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed.

Related questions

  • Is Claude Code or OpenAI Codex more token-efficient? 5 models compared
  • Is Claude Code or Codex better at debugging? 5 models compared
  • Is Codex or Claude Code more reliable for automated tests? 5 models compared
  • Is Claude Code or Codex better for large codebase refactors? 5 models compared

About this tracked question

3 AI models answered this question independently on 2026-07-28. A judge from a different model family then cross-checked the answers, scored how far they agree and flagged where they differ. The question is re-checked weekly, and every earlier version stays on this page.

AI models can make mistakes – verify important information against the sources above.

How consensus works →

Thanks – this page has been reported for review.

© 2026 consens.io
App Topics Questions Model pulse Benchmark Model guide How consensus works About Terms Privacy Imprint