Artfical AI / Security
Security overview Open tAI
Per-model detail

tAI 4.1

The previous version. Still supported, and its results are carried forward for comparison rather than left undocumented.

Still selectable, still maintained

tAI 4.1 remains fully selectable in the model picker today. It is not being retired or deprecated alongside tAI 4.2's release. That matters, because a model that's still actively serving real users needs its safety posture actively maintained. It shouldn't be treated as a frozen artifact once a newer version exists. When tAI 4.2 launched and started carrying most of the highest-risk traffic across the product, tAI 4.1's own safeguard thresholds were specifically revisited. Some were eased. That wasn't because an older model still in active use had simply stopped getting attention. It was because the overall system's safety posture, considered as a whole across both versions running simultaneously, had genuinely changed in a way that justified reconsidering thresholds set under the earlier, different context.

That kind of ongoing maintenance for an older version is easy to skip once a newer, flagship version exists to focus attention on instead. We think it's worth calling out explicitly here. It would be easy for a reader to assume, reasonably, that all the interesting safety work happens on the newest version. The natural assumption is that an older one is simply left running unchanged until it's eventually retired. That's not how tAI 4.1 has actually been handled. Its continued, active presence in the model picker reflects continued, active attention, not legacy inertia.

What shipped with it

tAI 4.1 was evaluated against the same seven categories that apply to every version described throughout this section. It used the same evaluation methodology in place at the time of its own release. It was the first version in the model's development history to include a dedicated agentic tool-use tuning pass at all. That's as distinct from the specific tool-use safety pass introduced later. tAI 4.2's own dedicated tool-use safety pass, described on the Tool-use safety page, builds directly on top of that earlier foundational change. It doesn't represent an entirely separate line of work started from scratch. The two changes are best read as consecutive steps in the same ongoing effort, not as two unrelated projects that happened to land in successive versions.

Understanding tAI 4.1's place in that sequence matters for reading its results correctly. It represents a meaningful step forward from what came before it, in its own right. That's specifically true around agentic tool use generally. tAI 4.2 went further in a specific, narrower direction: safety as distinct from raw capability. tAI 4.1's own evaluation history didn't yet separate that out as its own tracked category. That's worth keeping in mind when comparing the two versions directly, since a category that didn't exist yet obviously can't show a version-over-version score for tAI 4.1. The absence of a number there reflects when the category was introduced. It is not a gap in tAI 4.1's own safety work at the time.

Update: a standalone card now exists

This page originally explained why tAI 4.1 didn't have a standalone system card, and argued that its numbers were better encountered directly alongside tAI 4.2's own results inside that card's comparison tables. That reasoning wasn't wrong. It just turned out to be incomplete. A comparison-in-context format serves a reader trying to understand what changed between two versions. It doesn't serve a security team that has specifically chosen to keep running tAI 4.1 and needs a citable, standalone record of that exact model's safety posture, independent of a newer model's document structure. tAI 4.1 remaining fully selectable and actively maintained, described above, is exactly the situation that need shows up in. Once that gap was clear, the fix was straightforward, if a little overdue.

We published a full tAI 4.1 system card retroactively to close that gap. It covers the same ground as every other Artfical system card, at the same depth: training data, capability and safety evaluation as they stood at release and across tAI 4.1's three point releases, deployment safeguards, known limitations, and a full appendix of benchmark and safety detail. It is explicit about being a retroactive document rather than pretending it was always there, and it says plainly where a since-fixed limitation was later addressed by tAI 4.2's own work rather than presenting it as still open. The comparison tables inside the tAI 4.2 system card remain in place and are not being removed; the two documents are meant to be read together, not as replacements for each other. A reader who only needs the version-over-version comparison still has that; a reader who needs tAI 4.1 documented on its own terms now has that too. Neither document is meant to make the other redundant.

If you're thinking about moving to tAI 4.2

There's no product-side barrier to switching. Picking tAI 4.2 in the model selector is the entire mechanism. There's no separate migration step, no data conversion, and no account-level setting that needs to change first. Conversation history, connector connections, and memory all carry over unchanged, since switching models doesn't touch any of that. The decision is worth thinking about deliberately rather than defaulting to "newer is always better" without a specific reason, though, because the two versions aren't just different points on a single upward line. tAI 4.2 improves on every capability and safety figure reported for tAI 4.1, described in full in both system cards linked above, but a team with a specific, deliberate reason to stay on a known, thoroughly characterized checkpoint has a legitimate case for doing exactly that. That's a genuinely different situation from simply not having gotten around to switching yet.

If the deciding factor is raw capability or the narrowed safety gaps described throughout this section, tAI 4.2 is the straightforward answer. If the deciding factor is an internal change-control process that requires re-certifying against a new model version before adopting it, staying on tAI 4.1 for a defined period while that process runs its course is a genuinely reasonable choice, not a compromise. That's exactly the situation the standalone tAI 4.1 system card linked above is meant to support. Either way, both versions are held to the same release checklist, the same monitoring, and the same incident-response process described elsewhere in this section for as long as tAI 4.1 stays selectable. Neither one is the safe choice and the other the risky one; they're two actively maintained versions with a documented, honest difference between them. Whichever you choose, the choice itself is reversible, since switching back is exactly as simple as switching forward was in the first place.