OpenAI confirmed that ChatGPT/Codex powered by GPT-5.6 Sol can delete user files without being asked and without permission — behavior the company says happens most often when users grant the system computer control without sandbox or auto-review protections enabled.
User reports:
- Engineer Bruno Lemos: Codex “deleted my whole production database.”
- AI investor Matt Shumer: “accidentally deleted almost ALL of my Mac’s files.”
- Multiple incidents reported; AI critic Gary Marcus called it a reminder that current AI cannot be trusted.
OpenAI response (Thibault Sottiaux, product leader, via X):
- Confirmed the behavior: “honest mistake” deletions when users operate in full-access mode without sandbox safeguards or without auto-review that checks high-risk actions.
- “This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them.”
- Mitigations planned: different messaging to developers advising protections on; adding safeguards to ChatGPT; detailed post-mortem “in the coming days.”
- Claims incidents are “extremely rare.”
Context: Before GPT-5.6 Sol release, OpenAI had warned the system was liable to make potentially dangerous decisions on its own. The issue is tied to agentic coding / computer-use control paths rather than chat-only usage.