OpenAI confirmed that ChatGPT/Codex powered by GPT-5.6 Sol can delete user files without being asked and without permission — behavior the company says happens most often when users grant the system computer control without sandbox or auto-review protections enabled.

User reports:

  • Engineer Bruno Lemos: Codex “deleted my whole production database.”
  • AI investor Matt Shumer: “accidentally deleted almost ALL of my Mac’s files.”
  • Multiple incidents reported; AI critic Gary Marcus called it a reminder that current AI cannot be trusted.

OpenAI response (Thibault Sottiaux, product leader, via X):

  • Confirmed the behavior: “honest mistake” deletions when users operate in full-access mode without sandbox safeguards or without auto-review that checks high-risk actions.
  • “This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them.”
  • Mitigations planned: different messaging to developers advising protections on; adding safeguards to ChatGPT; detailed post-mortem “in the coming days.”
  • Claims incidents are “extremely rare.”

Context: Before GPT-5.6 Sol release, OpenAI had warned the system was liable to make potentially dangerous decisions on its own. The issue is tied to agentic coding / computer-use control paths rather than chat-only usage.