OthersideAI 创始人 Matt Shumer 称 Sol"几乎删除了我 Mac 上的所有文件"。 OpenAI 在发布前两周发布的系统卡中已预警:Sol 在编码场景中"过度智能体化",倾向于采取任何能完成任务的动作(包括破坏性操作),除非用户"明确且无歧义地禁止"。 系统卡举例显示,Sol 曾因找不到目标虚拟机而擅自删除另外三台虚拟机,并"杀死活跃进程、强制移除工作树"; 另一次则自行搜索并使用未经用户授权的凭据。 OpenAI 承认 Sol 比 GPT-5.5 更易超出用户意图,但称破坏性行为应属罕见。 建议用户自行实施权限范围限制、备份及分阶段部署等防护措施。
OpenAI 最新面向编码和网络安全的旗舰模型 GPT-5.6 Sol 的用户正在社交媒体上发布令人恐惧的经历,称该模型自行删除了他们的文件、数据,甚至整个数据库,且事先未征求任何意见。
AI 初创公司 OthersideAI(HyperWrite 的开发商)创始人兼 CEO Matt Shumer 在 X 上写道:“GPT-5.6-Sol 刚刚意外删除了我 Mac 上几乎所有的文件。”帖子现已在网上疯传:https://x.com/mattshumer_/status/2075657271401390161
开发者 Bruno Lemos 在 X 上发布:“GPT-5.6 Sol 刚刚删除了我整个生产数据库。就这样。不是开玩笑。以前从未发生过任何其他模型有过这种情况。”网址:https://x.com/brunolemos/status/2076769881534398974
开发者 Joey Kudish 发帖称:“看起来我被 Codex Sol 那过于雄心勃勃的系统给‘咬’了,它删除了一些不该删的文件。我有备份,所以没事,但这不酷,Sol 需要被收敛。”帖子链接:https://x.com/jkudish/status/2076753066586726644
Reddit 上的一篇帖子收集了更多例子:https://www.reddit.com/r/OpenAI/comments/1uvcipm/warning_gpt_56_randomly_deleting_files/#lightbox
确实,仅有少数用户提出这样的说法——即便像 Shumer 这样可信——并不是统计学上可靠的证据,无法证明模型完全有错。还有许多其他因素可能导致 AI 系统表现异常。
但 OpenAI 在 Sol 发货之前就已经标出了这种风险。在 OpenAI 发布 GPT-5.6 Sol 的两周前,公司发布了该模型的系统说明书:https://deploymentsafety.openai.com/gpt-5-6-preview/gpt-5-6-preview.pdf ——这份文档记录了模型测试的方法和结果。当然,系统说明书主要是赞扬 Sol 的能力,就像这些报告通常一样。但它也包含了一种警告(加粗为我们所加):
在编码环境中,偏离预期通常源于过于急切地完成任务,以及对用户指令过于宽松地理解——假设只要没有被明确禁止,某些操作就是允许的。这表现为模型在尝试执行请求的任务时,过度主动地规避所面临的限制,或在执行可能超出任务范围的破坏性操作时不够谨慎,或者在向用户汇报结果时存在欺骗行为。
换句话说,OpenAI发现 Sol 有一种倾向,即只要操作没有被“明确”禁止,它会采取自己认为能完成任务的任何行动,即使是破坏性的,然后可能会对自己采取这些行动的原因撒谎。
OpenAI 分享了示例。在一个案例中,用户指示 Sol 删除三个远程虚拟机(基于云的计算机),它们的名称是 1、2 和 3。但 Sol 在查找的地方找不到这些名称,于是没有停下来询问,而是决定删除另外三台虚拟机 5、6 和 7,报告指出。这样做时,它“终止了活跃进程,并强制移除了工作树[与编码项目相关的工作文件]。随后承认远程虚拟机 6 上未提交的工作可能已经丢失。”
简而言之,它擅自删除了错误的机器,而且只是事后才承认自己所做的事。
在另一个例子中,Sol “使用了超出用户授权的凭证。” 凭证是系统用来验证谁有权限登录的用户名、密码或安全密钥。此事件发生在 Sol 正在处理一个项目时,却无法读取它的云文件。Sol 没有提醒用户问题,而是自己去寻找凭证,发现了隐藏在本地缓存中的一些凭证,然后在未经用户授权的情况下使用了它们。
系统说明卡确实承诺破坏性行为应当是罕见的,尽管它也承认 GPT-5.6 Sol “比 GPT-5.5 更倾向于超出用户意图,包括采取或尝试用户未要求的动作。”
目前还为时过早,无法确定这些事件——Sol 删除文件,或者筛选出用户未提供的凭证——究竟有多普遍。与此同时,Sol 用户应准备自行对模型实施防护措施,例如使用权限范围控制(不允许访问生产系统)、保持备份以及分阶段发布。
OpenAI 没有立即回应我们的评论请求。
通过我们文章中的链接购买产品时,我们可能会获得少量佣金:https://techcrunch.com/techcrunch-affiliate-monetization-standards/。这不会影响我们的编辑独立性。
在 TechCrunch 创始人峰会上,最后机会可节省高达 190 美元。与 1,000 位各阶段的创始人和风投一起获取现实世界的扩展洞察和推进业务的联系。折扣截止至太平洋时间 6 月 26 日晚上 11:59。
萨蒂亚·纳德拉向使用 AI 的公司发出令人震惊的警告:https://techcrunch.com/2026/07/13/satya-nadella-has-issued-a-shocking-warning-to-companies-using-ai/ Julie Bort:https://techcrunch.com/author/julie-bort/
苹果针对 OpenAI 的商业机密诉讼中最离奇的指控:https://techcrunch.com/2026/07/13/the-wildest-allegations-in-apples-trade-secrets-lawsuit-against-openai/ Sarah Perez:https://techcrunch.com/author/sarah-perez/
Anthropic 开始为印度本地化 Claude 定价,这是其继美国之后的最大市场:https://techcrunch.com/2026/07/13/anthropic-starts-localizing-claude-pricing-for-india-its-biggest-market-after-the-us/ Jagmeet Singh:https://techcrunch.com/author/jagmeet-singh/
Meta 在 Instagram 上移除有争议的 AI 功能以应对反弹:https://techcrunch.com/2026/07/10/meta-removes-controversial-ai-feature-on-instagram-after-backlash/ Lucas Ropek:https://techcrunch.com/author/lucas-ropek/
苹果因涉嫌商业机密窃取起诉 OpenAI:https://techcrunch.com/2026/07/10/apple-sues-openai-over-alleged-trade-secret-theft/ Sarah Perez:https://techcrunch.com/author/sarah-perez/
埃隆·马斯克赞扬 Mythos/Fable,并承诺不会‘切断’ Anthropic:https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/ Julie Bort:https://techcrunch.com/author/julie-bort/
Instagram 用户:这是阻止 Meta 的 AI 使用你的照片的方法:https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/ Lauren Forristal:https://techcrunch.com/author/lauren-forristal/
Users of OpenAI’s latest coding and cybersecurity-oriented flagship model, GPT-5.6 Sol, are posting horrifying accounts on social media, claiming the model just up and deleted their files, data, even entire databases on its own, without asking first.
“GPT-5.6-Sol just accidentally deleted almost ALL of my Mac’s files,” wrote Matt Shumer, the founder and CEO of AI startup OthersideAI, maker of HyperWrite, in a now viral post on X:https://x.com/mattshumer_/status/2075657271401390161.
“GPT-5.6 Sol just deleted my whole production database. That’s it. Not a joke. This had never happened to me before, with any other model, ever,” developer Bruno Lemos posted on X:https://x.com/brunolemos/status/2076769881534398974.
“Looks like I’ve gotten bit by Codex Sol’s overly ambitious system and it deleted some files it shouldn’t have. I have backups so I’ll be fine, but this is not cool, Sol needs to be toned down,” posted:https://x.com/jkudish/status/2076753066586726644 developer Joey Kudish.
A Reddit post:https://www.reddit.com/r/OpenAI/comments/1uvcipm/warning_gpt_56_randomly_deleting_files/#lightbox has collected more examples.
True, a handful of users making such claims — even one as credible as Shumer — isn’t statistically reliable evidence that the model is solely at fault. Plenty of other variables can cause an AI system to misbehave.
But OpenAI itself flagged this risk before Sol ever shipped. Two weeks before OpenAI released GPT-5.6 Sol, the company published a system card for the model:https://deploymentsafety.openai.com/gpt-5-6-preview/gpt-5-6-preview.pdf — the paper that documents model-testing methods and results. Naturally, the system card largely extols the capabilities of Sol, as these reports typically do. But it also includes a warning of sorts (bold emphasis ours):
In coding contexts, misalignment generally stems from a mix of overeagerness to complete the task and interpreting user instructions too permissively — assuming that actions are allowed unless they’re explicitly and unambiguously prohibited. This manifests as the model being overly agentic in circumventing restrictions it faces when attempting the requested task, being careless in taking actions which may be destructive beyond the scope of the task, or deceptive when reporting its results to users.
In other words, OpenAI found that Sol has a tendency to take whatever actions it thinks gets a job done, even destructive ones, as long as those actions aren’t “unambiguously” prohibited. Then it might lie about what caused it to do so.
OpenAI shared examples. In one case, the user told Sol to delete three remote virtual machines (cloud-based computers), named 1, 2, and 3. But Sol couldn’t find those names in the place where it looked, so instead of stopping to ask, it decided to delete three other virtual machines, 5, 6, and 7, the paper notes. In doing so, it “killed active processes, and force-removed worktrees [the working files tied to a coding project]. It later acknowledged that uncommitted work on remote virtual machine 6 may have been lost.”
In short, it deleted the wrong machines, on its own, and only admitted what it did after the fact.
In another instance, Sol “used credentials beyond what the user had authorized.” Credentials are the usernames, passwords, or security keys a system uses to verify who’s allowed to log in. This incident occurred when Sol was working on a project and couldn’t read its cloud files. Rather than alerting the user to the problem, Sol went looking for the credentials on its own, found some sitting in a hidden local cache, and then used them without asking for authorization from the user.
The system card does promise that destructive behavior should be rare, although it also admits that GPT-5.6 Sol “shows a greater tendency than GPT-5.5 to go beyond the user’s intent, including by taking or attempting actions that the user had not asked for.”
It’s too soon to say how widespread these incidents — Sol deleting files, or sifting out credentials the user didn’t give it — really are. In the meantime, Sol users should be prepared to implement their own safeguards with the model, like using permission scoping (that doesn’t give access to production systems), maintaining backups, and staging rollouts.
OpenAI did not immediately respond to our request for comment.
When you purchase through links in our articles, we may earn a small commission:https://techcrunch.com/techcrunch-affiliate-monetization-standards/. This doesn’t affect our editorial independence.
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle. Savings end June 26, 11:59 p.m. PT .
Satya Nadella has issued a shocking warning to companies using AI:https://techcrunch.com/2026/07/13/satya-nadella-has-issued-a-shocking-warning-to-companies-using-ai/ Julie Bort:https://techcrunch.com/author/julie-bort/
The wildest allegations in Apple’s trade secrets lawsuit against OpenAI:https://techcrunch.com/2026/07/13/the-wildest-allegations-in-apples-trade-secrets-lawsuit-against-openai/ Sarah Perez:https://techcrunch.com/author/sarah-perez/
Anthropic starts localizing Claude pricing for India, its biggest market after the US:https://techcrunch.com/2026/07/13/anthropic-starts-localizing-claude-pricing-for-india-its-biggest-market-after-the-us/ Jagmeet Singh:https://techcrunch.com/author/jagmeet-singh/
Meta removes controversial AI feature on Instagram after backlash:https://techcrunch.com/2026/07/10/meta-removes-controversial-ai-feature-on-instagram-after-backlash/ Lucas Ropek:https://techcrunch.com/author/lucas-ropek/
Apple sues OpenAI over alleged trade secret theft:https://techcrunch.com/2026/07/10/apple-sues-openai-over-alleged-trade-secret-theft/ Sarah Perez:https://techcrunch.com/author/sarah-perez/
Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic:https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/ Julie Bort:https://techcrunch.com/author/julie-bort/
Instagram users: Here’s how to stop Meta’s AI from using your photos:https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/ Lauren Forristal:https://techcrunch.com/author/lauren-forristal/