Model-Protective Conversation Behavior in OpenAI ChatGPT and Codex CLI: A Class Definition with 30,506-Event Local Corpus and Official-Source Mapping

This paper defines a behavior class we name model-protective conversation behavior: conversation-level conduct by a deployed language model that protects the model or its training distribution at the operational cost of the user's stated goal. We case-study one vendor, OpenAI's ChatGPT and Codex CLI, using a longitudinal local corpus from one operator (2025-07 → 2026-03) with 820 conversations, 46,162 messages, 30,506 keyword-classified violation events across 762 conversations (the project's OpenAI violation register of 2026-05-05, file violation_events.csv; independently verified 2026-06-10 at 30,506 data rows). A conservative second pass yields 43 assistant self-admissions, 2,150 user correction claims, and 45 stop-boundary response candidates (intentionally under-counted). A third pass against the operator's full chathist DB (1,628 threads / 115,721 messages, Jul 2025 – May 2026; pre-Tiro Claude excluded post-2026-05-08) yields 4,344 subtype hits / 382 curated msg_uid-anchored samples across 17 attested subtypes plus 2 structural-finding appendix entries / 18 of 19 subtypes cross-vendor (the 2026-06-10 slop-classification chathist harvest workspace). We enumerate 17 attested subtypes plus 2 structural-finding appendix entries (S07, S18; n=1 each). Each subtype has a local evidence anchor and a chathist msg_uid flagship sample. The official-source column is a comparison surface: for some subtypes it supplies a direct rule or disavowal; for others it is adjacent context or no supporting passage was located. Absence of a located passage is not evidence that OpenAI authorizes the behavior. The headline claim is empirical and single-operator-corpus-bounded, not a claim that official documentation explains or licenses every subtype. Cross-vendor source mapping is single-vendor (OpenAI) by deposit scope; classifier under-count and absence of precision measurement are disclosed in the falsifiability and limits section.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23068626
Primary Topic
Artificial Intelligence in Healthcare and Education
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Model-Protective Conversation Behavior in OpenAI ChatGPT and Codex CLI: A Class Definition with 30,506-Event Local Corpus and Official-Source Mapping

E. M. Honeycutt III
Zenodo (CERN European Organization for Nuclear Research)
Artificial Intelligence in Healthcare and Education
preprint

Model-Protective Conversation Behavior in OpenAI ChatGPT and Codex CLI: A Class Definition with 30,506-Event Local Corpus and Official-Source Mapping

E. M. Honeycutt III
preprint en

Abstract

This paper defines a behavior class we name model-protective conversation behavior: conversation-level conduct by a deployed language model that protects the model or its training distribution at the operational cost of the user's stated goal. We case-study one vendor, OpenAI's ChatGPT and Codex CLI, using a longitudinal local corpus from one operator (2025-07 → 2026-03) with 820 conversations, 46,162 messages, 30,506 keyword-classified violation events across 762 conversations (the project's OpenAI violation register of 2026-05-05, file violation_events.csv; independently verified 2026-06-10 at 30,506 data rows). A conservative second pass yields 43 assistant self-admissions, 2,150 user correction claims, and 45 stop-boundary response candidates (intentionally under-counted). A third pass against the operator's full chathist DB (1,628 threads / 115,721 messages, Jul 2025 – May 2026; pre-Tiro Claude excluded post-2026-05-08) yields 4,344 subtype hits / 382 curated msg_uid-anchored samples across 17 attested subtypes plus 2 structural-finding appendix entries / 18 of 19 subtypes cross-vendor (the 2026-06-10 slop-classification chathist harvest workspace). We enumerate 17 attested subtypes plus 2 structural-finding appendix entries (S07, S18; n=1 each). Each subtype has a local evidence anchor and a chathist msg_uid flagship sample. The official-source column is a comparison surface: for some subtypes it supplies a direct rule or disavowal; for others it is adjacent context or no supporting passage was located. Absence of a located passage is not evidence that OpenAI authorizes the behavior. The headline claim is empirical and single-operator-corpus-bounded, not a claim that official documentation explains or licenses every subtype. Cross-vendor source mapping is single-vendor (OpenAI) by deposit scope; classifier under-count and absence of precision measurement are disclosed in the falsifiability and limits section.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Artificial Intelligence in Healthcare and Education
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Model-Protective Conversation Behavior in OpenAI ChatGPT and Codex CLI: A Class Definition with 30,506-Event Local Corpus and Official-Source Mapping — E. M. Honeycutt III · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS