2025-05-23 · OpenAI

Addendum to OpenAI o3 and o4-mini system card: OpenAI o3 Operator

agentsmodelsenterprise

read at source ↗ openai.com

Addendum to OpenAI o3 and o4-mini system card: OpenAI o3 Operator

Source: OpenAI Date: 2025-05-23 URL: https://openai.com/index/o3-o4-mini-system-card-addendum-operator-o3

Summary

Summary

OpenAI published an addendum to the o3/o4-mini system card specifically covering o3’s deployment as the model powering the Operator web agent. The addendum documented safety evaluations specific to the agentic deployment context — where the model is not just generating text but taking actions in web environments — and the additional mitigations applied for the Operator use case.

Implications

Safety/agentic thread. Agent-specific system card addenda represent an evolving safety documentation practice: the same model has meaningfully different risk profiles depending on whether it is generating text or controlling a browser. The Operator addendum acknowledges that the standard o3 evaluations were insufficient for the agentic deployment context, requiring additional safety work. Key agent-specific concerns include: the model acting on malicious instructions embedded in web content (prompt injection), the irreversibility of agent actions (form submissions, purchases), and authorization scope (what the model is permitted to do on the user’s behalf without re-confirmation). This documentation practice — model-plus-deployment-context system cards — is a template that the agentic AI industry needs but has not yet standardized.

← all signals