Does GPT-5.6 Sol delete files without permission in Codex?
Historical consensus 2026-07-28Active
Runs Weekly on Tuesday at 09:00 (Europe/Berlin)LastNext
Movement at this check
Changed since last check
OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.
No—GPT-5.6 Sol does not “bypass” file permissions or delete files without permission in Codex. In Codex, whether files can be changed or deleted depends on the mode and permissions you’ve granted, not on the model name itself.openai
In Suggest mode, it should not delete files without your approval.openai
In Auto Edit, it can make file changes within the allowed workspace, so deletions can happen as part of an approved task.openai
In Full Auto, it may execute allowed commands inside the sandbox, so a deletion could occur without a separate confirmation prompt if you’ve already granted that level of access.openai
So the practical answer is:
Not without permission or access. It can only delete files when the environment, mode, or an approved command allows it.openai
If you want the safest setup, use Suggest mode, keep important files backed up, and limit Codex access to only the project folder you need.openai
Differences
1 notable difference (1 contradiction)
across 3 models.
contradiction · critical
Whether GPT-5.6 Sol can delete files without permission
It does delete files under certain conditions like full-access mode
Gemini
“Yes, multiple developer reports have documented instances where GPT-5.6 Sol unexpectedly and destructively deleted files”
No model deletes files without permission and GPT-5.6 Sol does not exist
Grok
“There is no factual basis for the claim that GPT-5.6 Sol (or any current OpenAI model) deletes files without permission”
How to verify: Double-check the official OpenAI documentation on Codex modes and permissions
Best answerOpenAI
Follow this question
This page is re-checked weekly. Get one e-mail when the AI consensus shifts — no account needed.
Double opt-in · unsubscribe anytime · your address is only used for these updates.
Since tracking began: OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.
View the full agreement chart
Agreement over time
How strongly the models support the same claims. Every point links to its run below.
Checks
Newest first. Open any saved result to read the full consensus from that date.
Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval.
The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases.
OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.
Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed.
3 AI models
answered this question independently on 2026-07-28. A judge from a different model family
then cross-checked the answers, scored how far they agree and flagged where they differ. The question is re-checked weekly, and every earlier version stays on this page.
AI models can make mistakes – verify important information against the sources above.