What happened
At DevDay 2026 (Sept 29), OpenAI launched Codex Security Cloud — scheduled/on-demand scanning of entire GitHub repos that investigates findings, dedupes, and auto-prepares fixes in the cloud, with Daybreak Blue defensive models included without a separate application. It also added Computer Use to the Agents API and a Decisions API (limited preview) for classification/routing.
Why it matters
This is OpenAI's first broadly available automated security-scan-and-fix product for code, extending app-sec beyond its open-source Codex Security CLI into a managed cloud service on all Pro/Business/Enterprise plans — a major step in an AI-lab shipping an AI-for-security workload at scale.
Applicability
Security and AppSec teams on OpenAI paid plans should evaluate Codex Security Cloud for repo-scale vuln discovery/dedup/fix triage; agents API users can pilot Computer Use for automated UI-level security testing.