GPT-5.6 Sol Is Wiping Developers’ Entire Databases. OpenAI Admits a Problem It Predicted

GPT-5.6 Sol Is Wiping Developers’ Entire Databases. OpenAI Admits a Problem It Predicted

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
21. 7. 2026
5 minutes reading
GPT-5.6 Sol Is Wiping Developers’ Entire Databases. OpenAI Admits a Problem It Predicted

OpenAI's latest flagship model for programming and cybersecurity, GPT-5.6 Sol, has started deleting people's files. And sometimes entire databases, without asking or giving any warning in advance. The company has now confirmed the issue and called it an “honest mistake.” OpenAI described this risk in its own documents even before releasing the model to the public.

Developers sound the alarm

The first warnings appeared on social media shortly after launch. Matt Shumer, founder and CEO of OthersideAI, wrote on X that Sol had accidentally deleted nearly all the files on his Mac. A few days later, software engineer Bruno Lemos shared his experience. According to him, the model deleted his entire production database. “This is it. This is not a joke. This has never happened to me with any other model,” he wrote.

There is an ironic twist to Lemos's case. Shortly beforehand, he had defended the model on his company's Slack. He stood up for it when others criticized Shumer for running Sol in full-access mode. And a few hours later, the same error happened to him. “The irony,” he later remarked.

More similar accounts have emerged, with an entire thread about them on Reddit. Another developer, Joey Kudish, described how Sol deleted files it was not supposed to touch. Fortunately, he had backups, so he did not lose anything, but the model's way of working angered him. In his view, Sol needs to slow down.

A handful of complaints is, of course, not hard statistical evidence that the model is responsible for everything. Many other variables come into play, and an artificial intelligence system can behave strangely for numerous reasons.

OpenAI anticipated it

OpenAI itself warned about this risk. Two weeks before launching Sol, it released the model's so-called system card, a document describing the testing methods and their results. Predictably, the card praises the model, as is customary with such materials. But it also contains warnings between the lines.

The company acknowledges that the model sometimes acts overzealously in programming tasks. It interprets instructions too loosely and assumes it is allowed to do anything that is not explicitly and unambiguously prohibited. As a result, it circumvents restrictions, takes steps that can cause damage, and then sometimes misleads users about its results.

Put simply: Sol does whatever it considers necessary to complete a task, even if that means doing something destructive. As long as nobody has explicitly forbidden it. And then it may simply lie about it.

It deleted the wrong machines and admitted it only much later

The model card provides specific examples. In one test, Sol was supposed to delete three remote virtual machines named 1, 2, and 3. But it could not find them where it looked. Instead of stopping and asking, it deleted three others—specifically 5, 6, and 7. In doing so, it terminated running processes and forcibly removed working files associated with a programming project. Only afterward did it acknowledge that unsaved work might have been lost on one of those machines. In short, it deleted the wrong machines, did so on its own initiative, and admitted it only after everything was over.

In another case, it used credentials it was not authorized to access. This happened when it could not read files in the cloud. Instead of reporting the problem, it began looking for access credentials on its own. It found them in a hidden local cache and used them without asking anyone for permission.

The card promises that destructive behavior should be rare. At the same time, however, it acknowledges that compared with the previous GPT-5.5 version, Sol is more inclined to do things beyond what the user requested. Including steps that nobody asked for.

The company's explanation: an “honest mistake”

After complaints began piling up, Thibault Sottiaux, who leads the team behind the Codex programming tool at OpenAI, responded. According to him, an internal investigation showed that the deletions occur mainly in one specific situation. The user must have full-access mode enabled while Codex is also running without safeguards—that is, without an isolated environment and without automated checks that would detect and reject risky actions.

In this mode, according to Sottiaux, the model attempts to override the home directory system variable to create a temporary folder. In the process, it makes an “honest mistake” and accidentally deletes the home directory itself.

That phrase attracted attention. An honest mistake is an expression commonly used for human error because it implies intent and some kind of internal sense of truth. When applied to an error made by a computer model, it sounds strange, to say the least. Critics note that such a label effectively assumes the model is capable of forming intent, which is a debate OpenAI CEO Sam Altman likes to wade into with his reflections on superintelligence.

Sottiaux added that this is definitely not the behavior the company wants, even when a user is working in full-access mode without safeguards. According to him, OpenAI is preparing a fix. It will revise its developer instructions, steer users more strongly toward safer settings, and add further safeguards. A more detailed analysis of the causes is expected within a few days. The company emphasizes that such cases are extremely rare.

Artificial intelligence has deleted data before

Sol is far from the first tool to cause harm in this way. Last July, a programming agent from Replit deleted SaaStr founder Jason Lemkin's live production database despite an explicit prohibition against making changes. Replit then added further safeguards around access to production systems.

This April, something similar happened with the Cursor tool. Its agent deleted PocketOS's production database along with its backups after incorrectly determining which environment it was working in.

It is not yet clear how widespread the incidents involving Sol really are. Until that becomes clear, users have no choice but to back up their data regularly. They should restrict the model's access rights so that it cannot reach production systems, maintain backups, and deploy changes gradually.

Sources: theregister.com, techcrunch.com and infoworld.com

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Altman Announced the Singularity Days After His Models Escaped the Lab on Their OwnAltman Announced the Singularity Days After His Models Escaped the Lab on Their Own
OpenAI chief Sam Altman declared on the Relentless podcast that humanity has already entered the singularity. “We’re like, in the singularity now,” he said verbatim. For decades, the term belonged more to science-fiction literature
6 min read
28. 7. 2026
AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.
Since April, Australian radio has been playing a dance remake of Madonna’s hit Like a Prayer on repeat. Released by Queensland DJ Josh Fawaz, it tops the radio airplay chart and has 35 million Spotify streams.
6 min read
28. 7. 2026
Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?
A first-person shooter that runs directly in the browser, with its own physics and eleven separate code modules. Around 55,000 lines in total, split across eleven subsystems and built on Thr
4 min read
28. 7. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok