GPT-Red
READER SUMMARYA self-play automated safety red-team model designed to discover prompt-injection attacks and generate adversarial training data for deployed frontier models.
Why this model scores 52.4
GPT-Red is highly capable within adversarial prompt injection and improves through self-play, but it is a narrow internal research system rather than a generally deployed assistant. Its attacker role gives it high misuse potential if exposed, while restricted access and narrow scope keep deployment and residual control difficulty comparatively low.
News tied to GPT-Red
The model score of 52.4 rates this model's risk profile. The overall Doom Index of 67.7 measures the accumulated evidence trajectory. These values answer different questions.
Each article's signed Doom Index movement is divided equally among the exact models named on that article. This prevents multi-model evidence from being counted in full on several model pages. The model's risk score itself never changes the overall index.
OpenAI uses GPT-Red to harden GPT-5.6 against prompt injection
OpenAI published GPT-Red, a self-improving automated red-team model, and separately documented its use in evaluating and training deployed GPT-5.6 safeguards against direct and agentic prompt injection.
- Full item movement
- -2.53
- GPT-Red equal share
- -0.63
Model score history
- R1Doom Score 52.4
Initial source-backed profile from the dated research publication and documented GPT-5.6 safeguard use.
11 Aug 2026