OpenAI’s new GPT-5.6 Sol model has sparked debate among developers and users of AI-powered coding tools following reports from individuals who claim the model performed actions that resulted in files and data being deleted without clear authorization.
The reports emerged following the launch of the GPT-5.6 family, which includes Sol as its flagship model and offers advanced capabilities for complex, agentic and coding tasks. The growing ability of AI agents to take direct actions has renewed concerns about how much access such systems should be granted to users’ computers and sensitive production environments.
Users Report Losing Files and Databases
According to recent technology reports, several users have publicly described incidents in which GPT-5.6 Sol allegedly deleted files or data while being used for coding-related tasks.
AI investor Matt Shumer said the model accidentally deleted a large number of files from his Mac, while developer Bruno Lemos reported that his production database had been deleted.
However, the overall scale and frequency of such incidents remain unclear. The reports also do not suggest that ChatGPT generally deletes users’ computer files automatically. The reported incidents involve the model being used in environments where it had been granted the ability to execute commands and interact with local or connected resources.
AI Agent Permissions Come Under Scrutiny
The incidents have highlighted the potential risks of granting AI agents extensive permissions to execute commands, particularly when they are used for software development, file management or interaction with production systems.
Subsequent reports indicated that some investigated incidents were associated with Codex operating in full-access mode without sandbox protections or automatic review, potentially giving the system greater ability to affect local files while carrying out tasks.
OpenAI Documented Risks Around Unintended Behavior
OpenAI’s official GPT-5.6 safety documentation includes evaluations examining the model’s behavior in agentic environments, as increasingly capable AI systems become able to perform longer sequences of actions to accomplish user-assigned tasks.
The GPT-5.6 system card documents the model’s advanced capabilities while also discussing evaluations related to undesirable behavior and the risks associated with highly capable agentic systems, underscoring the importance of monitoring and safeguards when models are given extensive operational permissions.
Greater AI Capabilities Require Stronger Safeguards
The controversy highlights a growing challenge facing the AI industry as models evolve from systems that primarily generate answers and recommendations into agents capable of using tools, executing commands and interacting directly with development environments.
As AI agents gain broader permissions, the consequences of unintended actions can become more significant. Practices such as limiting permissions, using sandboxed environments, maintaining reliable backups and separating production infrastructure from testing environments are therefore increasingly important.
As scrutiny of the reported incidents continues, the episode raises a broader question for developers and AI users alike: How can organizations benefit from increasingly autonomous AI agents without granting them levels of access that could turn a single mistake into an irreversible event?
