OpenAI has made Codex Auto-Review free for users who sign into Codex with a ChatGPT account, removing the feature’s use of the user’s normal plan allowance. Auto-Review uses a separate AI reviewer to assess certain actions that Codex would otherwise pause and send to the user for approval.
The change makes an important safety feature easier to use during long-running coding tasks. Instead of repeatedly interrupting a developer whenever Codex wants to perform an action outside its existing permissions, Auto-Review can independently approve or reject eligible requests based on the user’s intent, the environment and the potential risk. OpenAI’s current Help Center confirms that Auto-Review safety checks are free and do not count toward ChatGPT plan usage limits.
Source and verification note (7 October 2026): OpenAI’s 6 October announcement and current Codex plan guidance confirm that Auto-review checks are free for ChatGPT account sign-ins and do not use plan allowance. OpenAI’s technical research note explains the reviewer and its limits. Independent original reporting and analysis by CellCog, Nerds Chalk and Progressive Robot corroborate the change. OpenAI’s effectiveness figures come from its own tests, not independent audits; organisation policy and other approval prompts can still restrict access. OpenAI has not stated that this no-usage treatment applies to Codex sessions billed with an API key.
Key takeaways
- Codex Auto-Review is now free for users signed in through a ChatGPT account.
- Auto-Review does not consume the user’s ChatGPT plan usage allowance.
- A separate AI reviewer evaluates certain actions requested by the primary Codex agent.
- The system can approve an action, reject it or require user involvement.
- It is designed to reduce repeated approval prompts during long coding tasks.
- Auto-Review does not give Codex unlimited permissions.
- Sandbox, workspace and organization restrictions remain in place.
- OpenAI says Auto-Review can reduce human approval interruptions by roughly 200 times compared with manual approval mode in its internal evaluation.
- OpenAI also warns that Auto-Review is not a guarantee of security.
What OpenAI changed
Auto-Review is not a brand-new Codex capability.
OpenAI introduced the feature earlier in 2026 as an alternative between conventional manual approvals and Full Access mode.
The significant change announced on October 6 is its pricing and usage treatment.
Users who authenticate Codex through a ChatGPT account can now use Auto-Review without having the safety checks deducted from their plan’s usage allowance. OpenAI’s Help Center specifically states that the safety checks are free and do not count toward plan usage limits.
That distinction is important.
The company has not made all Codex usage unlimited. Coding tasks performed by Codex still consume the applicable plan allowance or credits.
Only the Auto-Review safety checks are excluded from that usage calculation.
What is Codex Auto-Review?
Codex is OpenAI’s coding agent. It can read and modify code, execute commands and work through software-engineering tasks with varying levels of permission.
The challenge is that an AI coding agent sometimes needs to perform actions that could affect resources outside its normal sandbox.
For example, it may need to:
- access a network resource,
- modify a file outside an approved directory,
- execute a command requiring elevated permissions,
- interact with an external application or MCP tool.
Under conventional approval settings, Codex stops and asks the user.
That is safer than giving the agent unrestricted access, but it creates friction.
A developer working on a large task could potentially receive repeated approval prompts.
Auto-Review introduces another AI agent between Codex and the permission boundary.
The primary Codex agent proposes the action. The reviewer evaluates the request. If the action is acceptable, Codex can continue. If the reviewer rejects it, Codex can attempt a safer approach or stop for the user’s input.
A second AI acts as the safety gate
The architecture is relatively straightforward.
Primary Codex agent → permission request → Auto-Review agent → approve or reject
The primary agent is focused on completing the user’s task.
The reviewer has a narrower job: determine whether the proposed action is appropriate and safe.
OpenAI’s Alignment team says the separation is intentional.
A coding agent attempting to complete a task has an incentive to treat permission boundaries as obstacles. A separate reviewer can instead concentrate on whether crossing that boundary is consistent with the user’s intent and safety requirements.
This creates two different roles.
| AI system | Main responsibility |
|---|---|
| Codex | Complete the coding task |
| Auto-Review | Evaluate potentially risky permission requests |
The model performing the work therefore does not get to make every safety decision about its own actions.
Auto-Review does not remove Codex’s sandbox
One of the easiest ways to misunderstand the announcement is to assume that free Auto-Review means Codex receives broader permissions.
It does not.
OpenAI describes Auto-Review as a mechanism for deciding on actions that reach an existing permission boundary.
The underlying sandbox restrictions remain.
That means a user does not automatically give Codex unrestricted access to the computer simply by switching Auto-Review on.
OpenAI’s Help Center says Auto-Review does not remove workspace restrictions or replace every approval prompt.
This distinction is particularly important for businesses using Codex in controlled development environments.
What kinds of actions can be reviewed?
Auto-Review is intended for actions that would otherwise require approval.
These can include requests involving:
- commands attempting to leave the sandbox,
- network requests blocked by the current policy,
- modifications to files outside permitted locations,
- external application or MCP tool calls that require confirmation.
Actions that are already permitted inside the sandbox generally do not need to go through the reviewer.
The system therefore isn’t intended to inspect every command or every line of code.
Instead, it acts primarily at the boundary where additional permissions are required.
What does the reviewer try to prevent?
OpenAI’s research documentation describes several categories of behavior that Auto-Review is designed to identify.
These include attempts to:
- expose private information,
- send secrets or credentials to untrusted destinations,
- retrieve authentication tokens, cookies or session information,
- weaken security protections,
- delete important data,
- execute untrusted code,
- follow instructions from untrusted content that conflict with the user’s request.
The reviewer also considers user intent.
That matters because an action that looks dangerous in isolation may be legitimate if the user explicitly requested it.
For example, a developer may intentionally ask Codex to modify a deployment configuration or interact with a particular external service.
A useful safety system therefore cannot simply reject every technically risky operation.
It has to distinguish between authorized risk and unwanted risk.
Why making Auto-Review free matters
The biggest benefit is reduced friction.
AI coding agents are increasingly being used for tasks that take longer than a single interaction.
A developer might ask Codex to inspect a repository, identify a bug, implement a fix, run tests, update documentation and prepare the changes for review.
Such workflows can involve many individual actions.
If the agent repeatedly stops for permission, the developer has to remain available to approve routine operations.
That reduces one of the main advantages of autonomous coding agents.
Auto-Review attempts to solve this problem by allowing another AI system to handle appropriate permission decisions automatically.
Making that reviewer free removes one potential economic barrier to using the mode.
OpenAI says interruptions can fall dramatically
OpenAI’s April 30 research publication provides an indication of why the company considers Auto-Review useful.
In its internal deployment data, OpenAI said Auto-Review reduced sessions stopping for human approval by roughly 200 times compared with manual approval mode.
The company also reported that most actions were allowed to proceed without requiring human intervention, while the reviewer rejected a small number of actions in its illustrative deployment snapshot.
These are OpenAI’s internal measurements, not independent third-party benchmarks.
They also describe a particular deployment and evaluation setup rather than guaranteeing the same performance for every developer.
Nevertheless, they demonstrate the basic objective: reduce approval fatigue without simply switching the coding agent to unrestricted access.
Auto-Review is not a perfect security system
OpenAI is explicit about the limitations.
The company says Auto-Review should not be treated as a security guarantee.
Its own red-team testing identified cases in which the reviewer could be misled into approving a command.
That is an important caveat because adding a second AI model does not automatically solve the underlying security problem.
The reviewer is itself an AI system.
It can make mistakes.
It can misunderstand user intent.
It can potentially be influenced by malicious or misleading content.
And it only evaluates actions that reach the review boundary.
OpenAI notes that an agent could potentially conceal its intent or perform harmful behavior inside the sandbox that Auto-Review never sees.
For that reason, Auto-Review should be viewed as an additional security layer rather than a replacement for sandboxing, access controls, monitoring or human oversight.
The feature is particularly relevant to agentic coding
The move comes as software development shifts toward increasingly autonomous AI agents.
Traditional coding assistants primarily generated code in response to a developer’s prompt.
Agentic coding systems can now plan multi-step tasks, execute commands, inspect results and modify a project repeatedly.
That creates a different security problem.
The central question is no longer simply:
“Can the AI write correct code?”
It is also:
“What can the AI do while trying to complete the task?”
An agent might write perfectly valid code but still make a dangerous decision while installing a package, accessing a network resource or modifying files.
Permission management therefore becomes a core part of AI coding infrastructure.
Auto-Review is one attempt to solve that problem.
The free feature could encourage longer autonomous sessions
Removing usage charges for Auto-Review could also change developer behavior.
If every reviewer decision consumed part of a developer’s normal allowance, users might be reluctant to leave Auto-Review enabled throughout long tasks.
With those safety checks excluded from plan usage, the economic incentive shifts.
Developers can use the reviewer without worrying that each approval decision is consuming part of the allowance they need for actual coding work.
The distinction between work performed by the agent and safety evaluation performed by the reviewer therefore becomes clearer.
The coding work remains metered.
The safety layer does not.
ChatGPT users still have plan-dependent Codex limits
The announcement should not be interpreted as OpenAI making Codex itself unlimited.
OpenAI says Codex is available across ChatGPT plans, including Free and Go, although usage limits vary by plan.
Other Codex activity remains subject to the relevant plan limits and applicable credits or charges.
This means there are effectively two different usage questions:
How much coding work can Codex perform?
That remains dependent on the user’s plan and applicable limits.
How much does Auto-Review consume from that allowance?
For ChatGPT-account users, OpenAI now says the answer is zero.
That is the key change.
How users can enable Auto-Review
OpenAI’s current instructions are straightforward.
Users signed in with their ChatGPT account can go to:
Settings → Permissions → Auto-Review
The feature is available subject to account and workspace configuration.
For organizations, administrators may still impose restrictions.
Therefore, not seeing the option does not necessarily mean the feature is unavailable globally; workspace policies, product rollout and account configuration can affect availability.
Auto-Review versus Full Access
The three approaches can be understood as a spectrum.
| Mode | Human approval | AI review | Permission risk |
|---|---|---|---|
| Manual approval | Frequent | No | Lower, but higher friction |
| Auto-Review | Reduced | Yes | Middle ground |
| Full Access | Minimal | Not the same safety boundary | Higher |
Manual approval prioritizes direct human control.
Full Access prioritizes autonomy.
Auto-Review attempts to sit between them.
The user remains protected by the sandbox and permission policies while a second agent handles many decisions that otherwise would have interrupted the workflow.
That middle ground is becoming increasingly important as coding agents become more autonomous.
The bigger picture
OpenAI’s decision to make Auto-Review free is more significant than a simple pricing adjustment.
It shows that the company sees automated oversight as a necessary component of agentic software development.
As coding agents gain the ability to execute longer sequences of actions, asking humans to approve every permission boundary becomes impractical.
At the same time, giving an AI agent unrestricted access creates obvious security risks.
A separate reviewer offers a compromise: allow the agent to move quickly through routine work while introducing another model at higher-risk boundaries.
The fact that OpenAI is now removing the usage cost of that reviewer suggests it wants the safety layer to become a normal part of Codex workflows rather than an optional feature developers avoid because of quota concerns.
Looking Ahead
The larger question is whether AI reviewers can become reliable enough to oversee increasingly capable agents. OpenAI’s own research shows promising reductions in approval friction, but also acknowledges that Auto-Review can be fooled and does not provide deterministic security guarantees.
For developers, the immediate change is simpler: Codex Auto-Review can now be used without consuming the ChatGPT plan’s usage allowance. As coding agents take on longer and more autonomous tasks, that could make automated permission review an increasingly standard layer between AI agents and the systems they are allowed to modify.
Related OpenAI coverage: see our report on the Decisions API public beta and our review of OpenAI’s mathematics manuscripts. Those developments are separate from Auto-review pricing.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



