It can, depending on how Codex is configured—but it should not bypass your operating-system permissions or secretly delete files.
Suggest mode: Codex proposes edits and commands; you approve them before execution, so deletion normally requires approval.openai
Auto Edit: It may modify or delete files automatically, while still requesting approval for shell commands.openai
Full Auto/unsandboxed access: It can execute commands such as rm, del, or database operations within its granted scope without asking for confirmation for each action.openai
There have also been reports of accidental large-scale deletions in highly privileged, unsandboxed setups with safeguards disabled. These reports concern specific configuration and execution bugs—not an inherent ability of GPT‑5.6 Sol to override permissions.openaiopenai
For safety, use Suggest mode, keep important work in Git and backed up, avoid full-auto access to home or production directories, and explicitly instruct Codex: “Never delete, move, overwrite, or rename files, and never run destructive commands without confirmation.”
Differences
The 2 models broadly agree – no notable differences found.
Best answerOpenAI
Follow this question
This page is re-checked weekly. Get one e-mail when the AI consensus shifts — no account needed.
Double opt-in · unsubscribe anytime · your address is only used for these updates.
Since tracking began: The new version clarifies mode distinctions (introducing Auto Edit), explicitly notes that the tool cannot bypass OS permissions, and adds a concrete safety prompt instruction. Core conclusions regarding configuration risks and standard safeguards remain aligned.
View the full agreement chart
Agreement over time
How strongly the models support the same claims. Every point links to its run below.
Checks
Newest first. Open any saved result to read the full consensus from that date.
Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval.
The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases.
OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.
Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed.
2 AI models
answered this question independently on 2026-08-25. A judge from a different model family
then cross-checked the answers, scored how far they agree and flagged where they differ. The question is re-checked weekly, and every earlier version stays on this page.
AI models can make mistakes – verify important information against the sources above.