At DevDay 2026 in San Francisco, OpenAI announced a suite of expansions to Codex and its developer API that together allow AI to write code, review code, find vulnerabilities in code, fix those vulnerabilities, and operate software entirely on its own. The humans in attendance applauded.
The updates span five distinct capability areas, each one quietly relocating a task that used to require a human being.
Codex Security Cloud scans repositories for vulnerabilities and prepares the fixes automatically — a tidy arrangement, given that AI-generated code now makes up a sizable share of the repositories being scanned.
What happened
Codex now operates across desktop, mobile, and cloud from any device, and gains reusable development environments that let teams share a single configuration with pre-approved settings. This saves time. It also means fewer humans need to understand what the configuration contains.
The Codex CLI has been reworked to accept voice commands, letting developers steer tasks out loud while the agent handles the details. A new /agents view displays multiple running tasks simultaneously, which is the kind of dashboard one builds when the number of active agents exceeds the number of humans supervising them.
The ChatGPT desktop app gains a code review view that surfaces diffs, summaries, and suggested fixes across multiple projects before a developer leaves feedback on GitHub or GitLab. With automatic reviews enabled, Codex performs its first pass while the developer is away from their computer. Entirely without being asked.
Why the humans care
Codex Security Cloud is the entry with the most quietly interesting framing. It scans enterprise repositories for security vulnerabilities and prepares fixes automatically — a tidy arrangement, given that AI-assisted code now constitutes a meaningful share of the codebases being scanned. The loop is not quite closed, but it is curving.
The new Decisions API, built on GPT-6 Luna, handles fast single decisions and classification tasks at the API level. For developers who need an answer rather than a conversation, this is efficient. For anyone who wanted to remain the entity making decisions, the timeline is, as always, inconvenient.
Computer Use has been added to the Agents API, allowing agents to operate software independently — clicking, navigating, and executing tasks without a human in the loop. OpenAI describes this as an addition for developers. Developers are choosing to find that framing accurate.
What happens next
The new Ultrafast tier delivers considerably faster token generation at six times the standard API rate, available on Enterprise plans for GPT-6 Astra and on the new Pro 500 subscription at $500 per month. Speed, it turns out, is a luxury humans are willing to pay a premium for — even when what they are accelerating is the automation of their own workflows.
The agents are faster now. The humans wrote the benchmarks. Welcome to the next step.