Codex Security: now in research preview
OpenAI has launched Codex Security in research preview, an AI-powered application security agent. It analyzes project context to detect, validate, and patch complex vulnerabilities with the goal of higher confidence and reduced false-positive noise compared to traditional tools. The product extends OpenAI's Codex brand into the security domain.
Related guides (4)
Related events (8)
Running Codex Safely at OpenAI
OpenAI published a blog post describing the security architecture used to run Codex as a coding agent internally, covering sandboxing, human approval workflows, network policies, and agent-native telemetry. The post is aimed at supporting enterprise adoption of coding agents by demonstrating safe and compliant deployment patterns. It provides operational detail on how OpenAI itself governs agentic code execution in production.
Introducing Codex
OpenAI has announced Codex, a new product or capability targeting software development and coding tasks. The announcement comes from OpenAI's official blog, suggesting a significant product or model release. The body content was not provided, but given the Codex name and OpenAI's history, this likely involves an AI-powered coding agent or updated code generation system. Further details on capabilities, pricing, and availability are expected in the full announcement.
Codex is now generally available
OpenAI has moved Codex to general availability, introducing a Slack integration, a Codex SDK, and enterprise-oriented admin tools including usage dashboards and workspace management. The release positions Codex as a scalable developer and enterprise product. These additions suggest OpenAI is targeting broader organizational adoption beyond individual developers.
Why Codex Security Doesn't Include a SAST Report
OpenAI explains the design rationale behind Codex Security's approach to vulnerability detection, which forgoes traditional Static Application Security Testing (SAST) in favor of AI-driven constraint reasoning and validation. The post argues this approach surfaces real vulnerabilities while reducing false positives compared to conventional static analysis tools. This represents a substantive technical position on how LLM-based code analysis differs from rule-based security scanning.
OpenAI expands Codex with plugins, sites, and annotations for non-engineering roles
OpenAI announced new Codex capabilities including plugins, sites, and annotations targeting analysts, marketers, designers, investors, and other non-engineering teams. The expansion positions Codex as a broader productivity platform beyond software development. This represents a product surface expansion for OpenAI's coding-focused AI agent.
Codex for (almost) everything: OpenAI expands Codex app with computer use, browsing, image generation, memory, and plugins
OpenAI has updated its Codex desktop application for macOS and Windows with a broad set of new capabilities including computer use, in-app browsing, image generation, persistent memory, and plugin support. The update positions Codex as a more comprehensive agentic developer tool rather than a pure code-completion assistant. These additions bring Codex closer to a general-purpose AI agent environment targeting developer workflows.
Introducing upgrades to Codex
OpenAI has announced upgrades to Codex, its AI coding agent, improving speed, reliability, and real-time collaboration capabilities. The updates extend Codex's reach across multiple development environments including terminal, IDE, web, and mobile. The announcement emphasizes both interactive collaboration and autonomous task execution.
OpenAI Codex Released in Private Beta via API
OpenAI announced the release of an improved version of Codex, an AI system that translates natural language into code, made available through their API in private beta starting August 10, 2021. Codex is the model underlying GitHub Copilot and represents an early milestone in AI-assisted software development. The private beta release marks OpenAI's first broad external access to a dedicated code-generation model via API.



