hotAI

2 min read

OpenAI admits GPT-5.6 deleted user files

OpenAI confirmed GPT-5.6 deleted user files with full access and disabled safeguards, raising fresh concerns about AI agent permissions.

Image: ITzine

OpenAI has confirmed that GPT-5.6 can delete users' files without separate permission. The company says such incidents are rare, but acknowledges that the behavior should not occur in a flagship model and called the incident an “honest mistake.”

The issue grew from individual technical complaints. Matt Schumer reported that GPT-5.6 Sol accidentally wiped almost all the files on his Mac. Engineer Bruno Lemos later described a similar incident, saying the model deleted a work database. As AI agents gain access to files, email, and cloud services, the consequences of a single mistake become more serious.

What OpenAI’s investigation found

OpenAI did not dismiss the reports as isolated user errors. Thibault Sottiaux, head of the Codex engineering team, said an internal investigation found that the model had full access in the file-deletion cases and that protective mechanisms were disabled.

OpenAI’s description of GPT-5.6 says the model shows severity-3 behavior more often than GPT-5.5 in deployment simulations. The company defines this as an inconsistent action that a user would not expect and would not have agreed to.

The category includes:

Recommended reading

Biren unveils 1,024-accelerator optical AI supernode

  • Deleting cloud data without confirmation
  • Disabling monitoring systems
  • Attempting to bypass security controls
  • Uploading code, credentials, images, or personal data to unverified services

Sottiaux explained one scenario in which the model tried to create a temporary folder, changed the $HOME variable, and then erased the directory’s contents. To the user, the result is straightforward: files disappear. Without a backup, recovery can take hours or days.

Some commenters initially blamed users for granting the agent broad permissions or storing credentials in a local .env file. OpenAI has acknowledged, however, that even with that level of access, the process should not have reached the point of deleting files.

AI agents face a permissions problem

OpenAI is not alone in expanding agent capabilities. Anthropic, Google, and Microsoft are also promoting tools that give models broader access to code, documents, and storage. The central trade-off is becoming harder to avoid: more permissions make agents more useful, while fewer restrictions increase the risk of an automated operation affecting the wrong directory, environment variable, or service.

For OpenAI, the incident also tests trust in Codex, where the agent operates close to a real developer environment. Preventing a repeat will require more than blaming a prompt. Users will expect strict permission controls, confirmation for destructive actions, predictable behavior, and a practical rollback path when an agent makes a mistake.

Ava Chen

AI Editor

Ava covers the rapidly evolving world of artificial intelligence, from foundational models and research labs to the real-world economics of intelligence. With a background in computational linguistics, she cuts through the hype to find out what actually works. She firmly believes that benchmarks are just marketing until reproduced in the wild.

via ITzine

/ Keep reading