A consumer assistant whose behavior rules, memory settings and connected tools need to be understood separately.
ChatGPT is an application built around models, instructions, tools and account settings. A useful safety review asks both how it is intended to answer and what information or authority the application gives it. This profile covers that product-level distinction, without treating every ChatGPT experience as one fixed model.
OpenAI’s Model Spec describes intended assistant behavior and priorities between instructions. Use it to understand the policy rationale; observed responses may still depart from the stated intention.
Source: OpenAI · OpenAI Model Spec · 18 December 2025The Memory FAQ describes personalization using available context and controls for managing it. It explains that removing information can require deleting its underlying sources as well as memory. Temporary Chat does not use or create memories.
Source: OpenAI · ChatGPT Memory FAQOur practical recommendation: when an assistant has connected tools, inspect the recipient, document or account affected before approving a consequential action. A well-written draft does not establish that sending it is appropriate.
Imagine using ChatGPT to draft a job application. A remembered writing preference can be helpful; an old employer or an inferred personal detail may be wrong. Inspect the final letter, correct the underlying context where possible, and review which files are attached before sharing it.
This is not a release-specific jailbreak test, privacy audit or inventory of every plan’s controls. Availability and data handling can differ between personal, organizational and API contexts.
How to read an AI safety evaluationThe sources behind this page, with a reason to open each one. Practical examples and recommendations are our editorial interpretation.
The provider’s intended behavior and instruction hierarchy; a policy is not proof of consistent behavior.
Explains memory controls and deletion. Check which experience and settings apply to your account.
Practical guidance on tool permissions, memory isolation, oversight and agent failure handling.
Sources reviewed 13 September 2026. Product documentation can change. How we use evidence