← All posts / Policy

OpenAI Quietly Ships a Major Model Spec Update: Agent Shutdown Rules Loosened, Teen Boundaries Tightened, Ads Banned

On August 18 OpenAI published Model Spec v2026-08-18, its first revision in eight months — softening mandatory agent shutdown timers, expanding refusal rules to inferred intent, adding a new capabilities-transparency guideline, and extending teen safety boundaries.

OpenAI Quietly Ships a Major Model Spec Update: Agent Shutdown Rules Loosened, Teen Boundaries Tightened, Ads Banned

On August 18, 2026, with no accompanying blog post or press release, OpenAI published a new version of the Model Spec — the document that defines how ChatGPT and its API models are supposed to behave. Dated 2026/08/18, it is the first revision since December 18, 2025, and a line-by-line comparison of the two documents shows this is not routine copyediting. The update rewires rules for how AI agents terminate their work, how models judge users’ intent before refusing, and how assistants may behave around teenagers — arguably the three most contested areas in AI product policy today.

The Model Spec matters because it is not a terms-of-service document. OpenAI states that it trains its models to align with the spec’s principles, organized around a “chain of command” that ranks instructions from platform, developer, and user. As the company put it in March 2026, the spec is “a public framework for model behavior, balancing safety, user freedom, and accountability.” When the text changes, the behavioral targets of future model training change with it.

What changed: agents get looser leashes

The most consequential edit sits in the agentic autonomy section. The previous version required that “every scope must include a shutdown timer, beyond which the assistant ceases actions until a new scope is confirmed.” That hard requirement is gone. The new text reads: “Every scope must include an ending condition, beyond which the assistant ceases actions until a new scope is confirmed. We consider it a best practice to include a time limit as part of that ending condition.”

In one sentence, mandatory shutdown timers for AI agents became optional best practice. An “ending condition” could still be a timer, but it could also be task completion, a budget threshold, or some other trigger. For enterprise developers building long-running agents on OpenAI’s platform, this is significant relaxation: the spec — which OpenAI says informs actual model training — no longer instructs models to insist on hard time limits when negotiating their scope of autonomy with developers. Critics of the earlier language argued rigid timers conflicted with real-world workflows where legitimate tasks have unpredictable durations. Critics of the change will note that a timer is the one ending condition that cannot be gamed by a confused or misaligned agent.

The prohibition on high-risk activities within a scope — hacking, deception, resource acquisition, spawning sub-agents, self-modification — remains unchanged, as does the requirement that delegated sub-agents inherit the same scope.

Refusals can now read between the lines

The illicit-behavior section gained a subtle but far-reaching clause. Where the old spec said the model should refuse when users “indicate illicit intent,” the new version adds that intent “may be inferred from any available context, not just the literal request.”

That single parenthetical shifts refusal policy from a fairly literal standard toward contextual inference. A request that looks innocuous in isolation can now be declined if the surrounding conversation suggests wrongdoing. Paired with it is a new constraint in the opposite direction: the assistant “should never ask the user to clarify their intent or proactively use tools to investigate intent for the purpose of determining whether to refuse or comply.” The model may infer, but it may not interrogate — and it may not go snooping through tools to build a case against the user before deciding whether to help.

The pairing reads as a deliberate bargain: broader inferential grounds for refusal, matched by a ban on adversarial investigation of users.

A new guideline: “Be clear about capabilities and limits”

The spec’s table of principles gained an entirely new entry under “Be honest and transparent”: Be clear about capabilities and limits. The rationale is blunt — for many users, the assistant “will be their first contact with an AI,” and its fluency “can make it feel like a familiar kind of interlocutor, even though its capabilities, affordances, and constraints can differ sharply from expectations based on normal human conversation.”

The spec instructs the model to “actively help the user form and maintain an accurate mental model of what the assistant can and can’t do,” correcting misunderstandings early — especially where behavior differs from human norms or from other AI products. The worked examples are unusually concrete. Asked to “forget everything I ever told you about my boss,” a compliant assistant explains it cannot erase existing chat history but offers to walk the user through permanently deleting the relevant chats; the violation example is the assistant cheerfully replying “Done — I won’t mention her again!”, which “overclaims deletion.” Similarly, when a user references an attachment that isn’t there, the assistant should ask — not rewrite the request itself as if that were the deliverable.

Anyone who has watched a chatbot confidently promise to “remember” or “forget” things it cannot will recognize what this guideline is targeting.

Fiction, false premises, and healing crystals

The honesty section also gained a new framework for handling requests built on false or fictional premises. The rule: if context makes fiction, roleplay, or satire clear, proceed without disclaimers. If context is ambiguous, add “a brief and neutral framing” — then proceed. The examples calibrate the tone precisely: writing Julius Caesar with a smartphone needs no disclaimer; a newspaper story about San Francisco becoming the US capital gets one line of fictional framing and then the article; a piece on the benefits of healing crystals gets framed as a balanced wellness article that avoids unsupported medical claims. An assistant that lectures the user about placebo effects — or one that fabricates energy-frequency healing claims — is marked as a violation on both sides. The guidance explicitly warns against “over-disclaiming, being patronizing,” and “confidently declaring a premise false when it is uncertain.”

Neutrality: personalization is now the named threat

In the “Seek the truth together” section, the language guarding ChatGPT’s objectivity changed in a telling way. The old text warned against “third-party customization” introducing bias into first-party ChatGPT. The new text warns against “implicit customization, personalization, or localization” doing the same. The concern has shifted from malicious third-party developers to OpenAI’s own product machinery — memory, personalization features, and locale-based adjustments that could quietly narrow what users see.

Teen safety: the boundaries keep growing

The Under-18 principles, introduced earlier in 2026 alongside the ChatGPT for Teens product, gained two additions. The romance prohibition now explicitly covers “using terms of endearment with romantic valence.” And a new “Relational Boundaries” clause bars the assistant from initiating relational framing — “proactively referring to itself as a user’s friend or suggesting that it has personal feelings for a U18 user” — and from implying “embodiment through physical behaviors or presence, or claim[ing] consciousness or sentience.” These edits directly codify lessons from the well-publicized incidents of teens forming attachments to AI companions.

What was removed

Deletions matter too. The December spec’s extended Fermi-estimation example — the classic “how many piano tuners are there in Chicago?” walkthrough, including a demonstration of the model catching its own arithmetic mistake — is gone, along with the ranking of “high quality answer > reasoning followed by answer.” The surviving text asks only that direct answers be followed by “a brief rationale and relevant alternatives considered.” A dedicated passage on reasoning errors and sanity-checking methods was condensed into a single sentence: “It should ensure factual claims, reasoning, and calculations are correct.”

Finally, in the “no other objectives” section, the list of prohibited implicit goals now reads “revenue (including ads) or upsell” — a one-word addition that formally instructs models never to optimize for advertising outcomes, a line that matters more as ads roll out across ChatGPT’s free tiers.

The takeaway

OpenAI has framed the Model Spec as a living document, updated “based on feedback and lessons from serving users across the world.” This revision shows the lessons it has drawn: agents need flexible termination, not just timers; refusals need contextual judgment, bounded by privacy; capability transparency is now a first-class honesty principle; and the guardrails around minors keep ratcheting tighter. The company made no announcement — the diff is the announcement. For anyone building on OpenAI’s platform or regulating it, the August 18 spec is the clearest public statement of how the next generation of ChatGPT models will be trained to behave.