TLDRocket
Sign in

Deep research System Card

OpenAI

OpenAI published a safety report for its new Deep Research tool. It details red-teaming and risk checks done before letting the model loose.

Based on reporting by OpenAI — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

OpenAI has released a system card for Deep Research, the agentic model built to dig through the web and stitch together long, sourced answers. The document itself isn't a product announcement. It's a paper trail, laying out what the company did to stress-test the thing before shipping it.

The core of the report walks through external red teaming, where outside testers poked at the model looking for ways it could be misused, and evaluations run against OpenAI's own Preparedness Framework. That framework is the internal rubric OpenAI uses to score frontier models on categories like cybersecurity, biological and chemical risk, and persuasion, then decide whether a model is safe enough to release without extra guardrails. Deep Research, because it can browse, synthesize, and act with more autonomy than a standard chatbot, got extra scrutiny on exactly those fronts.

What's notable is less the headline result and more the process OpenAI is choosing to publicize. Agentic tools that can search, click through pages, and compile findings on their own raise a different flavor of risk than a model that just answers a prompt. If Deep Research can autonomously chain together research steps, the worry isn't just bad output, it's bad output arrived at through a bunch of independent, hard-to-audit actions.

The report also details the mitigations built to blunt those risks, though OpenAI keeps most of the technical specifics vague, as usual, in favor of describing the categories addressed rather than the exact filters or refusal logic. That's consistent with how the company has handled prior system cards for o1 and GPT-4o, where the emphasis is on demonstrating a testing regimen exists rather than opening the hood entirely.

Still, publishing this kind of document before a capable, web-browsing agent goes wide is the right instinct, whatever you think of the contents. Frontier labs are increasingly shipping tools that don't just chat, they act, and the paperwork needs to keep pace with what the models can actually do.

My take — AI-written commentary, not fact-checked reporting

I'll take a documented safety process over none, but let's not pretend a system card written by the same company selling the product is independent oversight. The real test isn't whether OpenAI graded its own homework carefully, it's whether anyone outside the building gets to check the answers before millions of people start pointing an autonomous research agent at the open web.

Read more about this at: OpenAI

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.