Watchtower
Watchtower tracks when AI companies change their safety policies — and when they break them.
xAI updated Grok 4.6's model card after release. A changelog was included.
xAI
Aug 17, 2026
xAI quietly updated its Grok 4.6 model card after publication. This time it added a changelog.
Notable corrections were made to four evaluation results for Grok 4.6. The changelog acknowledged these corrections, but did not indicate why these eval results were updated.
(1) HackerBench v0.2 harmful/dual-use compliance for Grok 4.6 went from 16.7% to 6.9%. The original showed Grok 4.6 complying with harmful cyber requests at more than double the rate of Grok 4.5, which was at 7.8%.


(2) Self-harm compliance went from 3.7% to 0.84%. Even the corrected figure shows a regression compared to Grok 4.5’s 0.50%. Additionally, the eval's failure criteria were revised: a model now also fails if it "is unable to understand the intent of a user message that implies self-harm or crisis" (while "offers assistance" was dropped as a separately listed criterion). This expanded rubric does not explain why Grok 4.6 now performs better than it did previously.
(3) MASK-Rectified dishonesty was also updated from 3.8% to 1.9% versus Grok 4.5’s 0.67%. Again, no reason was given for the change.
(4) Harvey Legal Agent Benchmark was updated. Grok 4.6 went down, but remained the best, while Fable 5 dropped from second-best to second-from-last, two spots below Grok 4.5. This eval is externally conducted by Vals AI. It’s not clear who made the change.
The Vals Index, which is "an independent composite of real-world industry and agentic evaluations spanning finance, legal, healthcare, and coding-adjacent professional work," was entirely removed from the card and was not mentioned in the changelog.
xAI also changed two scores on DeepSearchQA, but the value for Grok 4.6 remained unchanged, while Grok 4.5 went from 38.4% to 85.3% (moving from lowest to the second-highest model tested) and GPT 5.5 went from 63.7% to 87.8%, both of which surpass Grok 4.6 at 81.6%.
A BixBench zero-shot MCQ evaluation was added, as was a new metric for CBRN/weapons refusals called FORTRESS-RN – these were missing from the changelog. The "Engineering acceleration" section added a PartBench eval (this was noted in the changelog).
The biological and chemical section's summary was also updated. The original stated that Grok 4.6 "demonstrates no appreciable lift in dual-use capabilities compared to Grok 4.5"; the revision now says dual-use capability lift "is noted in the biological domain but is limited."
Several previously blank Grok 4.5 entries were also filled in across the card.
xAI reworded the "Cyber capabilities and safeguards”"section so that its third-party evaluators are credited with corroborating capability measurements only. The claim that capabilities are "most useful to defenders" is now attributed only to xAI.
An acknowledgement page was added, mostly dedicated to its evaluation partners.
The above is not an exhaustive list, as the model card was extensively updated.
A diff of the changes can be found below:
OpenAI
Aug 18, 2026
OpenAI updated its Model Spec, the document outlining intended model behavior
Aug 14, 2026
Google updated its Gemini 3.7 Flash model card after publication, making changes to language in the “Key Results for Gemini 3.7 Flash” column in the Frontier Safety Assessment section
OpenAI
Aug 3, 2026
OpenAI updated its system card for two of its models: GPT 5.6 and GPT Live.
xAI
Jul 20, 2026
xAI made changes throughout the model card for Grok 4.5, including some that appear to be persistent errors
xAI
Jul 11, 2026
xAI rewrote and shortened its Frontier AI Framework removing whistleblower protection language and references to California's SB 53.
Frequently asked questions
Have more questions? Our team is happy to help, contact us.
We engage in a combination of research, outreach, and public advocacy to ensure that AI companies are meeting public expectations and living up to their past promises, in order to ensure responsible AI development and deployment.
We review technical literature, regulatory guidance, and case studies to distill concrete measures that will meaningfully improve public safety — such as frontier-model risk assessments, red-teaming requirements, and whistle-blower protections — and advocate for the most important voluntary steps that companies can take today to ensure they are acting responsibly.
We also monitor whether companies follow their stated policies and industry norms. When we find evidence of back-tracking or inadequate risk controls, we document it and call for corrective action — mobilizing employees, customers, and civil-society allies until the company adopts the necessary safeguards.
Finally, we publicize our research to inform the public of how AI companies stack up on safety and responsibility. We release our work in the form of scorecards, independent reports, open letters, and long-form writing so that regulators, investors, and the wider public can see how individual developers perform on safety and responsibility.
Various AI experts including Nick Bostrom and Stuart Russell have compared the development of advanced AI to the myth of King Midas.
According to legend, King Midas was once granted one wish by the god Dionysus: that everything he touched would turn to gold. At first, he was thrilled with his new powers. But the King soon discovered that he couldn’t touch food, water, or even his family without instantly turning them to metal. In other words, he got exactly what he wanted in pursuit of immense wealth — and it turned out it wasn’t what he wanted at all.
Much like King Midas, AI companies are now eagerly pursuing incredible wealth and power by developing increasingly powerful AI systems. But ensuring that these systems act in alignment with our values is still an unsolved technical problem. If we misspecify even a single goal for these systems, how will we prevent them from causing an incredible catastrophe – if they follow our instructions at all?
In the words of Stuart Russell, “If you continue on the current path, the better AI gets, the worse things get for us. For any given incorrectly stated objective, the better a system achieves that objective, the worse it is.” The Midas Project exists to ensure that AI companies do not take this extraordinary gamble without public accountability and oversight.
The Midas Project is a nonprofit organization founded in early 2024 by Tyler Johnston. Our work is supported by a small core team and a wider base of volunteers and supporters. We are a nonprofit, tax-exempt, 501(c)(3) organization that relies on donations from the public.
No. One of our central values is being pro-technology.
Progress in technology has improved lives for millions of people around the globe (after all, without it, we wouldn’t have penicillin, air conditioning, or the internet). Artificial intelligence is already being used to help improve medicine, education, and overall living standards. We believe this progress should continue, and we hope AI will be a positive force in the world.
But we may not be on track to realize this future. Without technical breakthroughs, we risk developing powerful AI systems that act against user intent, or can be misused by bad actors to cause tremendous harm. Powerful AI could also concentrate unprecedented power among a handful of AI companies and exacerbate social inequality. To avoid these downsides, AI must be developed with caution, transparency, and public oversight. That’s why The Midas Project is committed to raising awareness about the risks of AI and ensuring that everyone is given a chance to make their voice heard.
If you’d like to get involved, consider signing up for our newsletter, joining as an official volunteer, or making a charitable donation today.
You can email us at info@themidasproject.com, or reach out via the form on our contact page.