OpenAI Tests a Persistent Codex Agent
OpenAI is testing a Codex setting that could let an AI agent keep pursuing work across sessions, a shift that would make user control and safety safeguards central to the product design.
Tag
7 published articles
AI agents are software systems that pursue goals by perceiving information, reasoning about options and taking actions with varying degrees of autonomy. They may use tools, access data, communicate with other systems and execute multistep workflows. Their design raises important questions about reliability, security, oversight, permissions and alignment with human intent.
OpenAI is testing a Codex setting that could let an AI agent keep pursuing work across sessions, a shift that would make user control and safety safeguards central to the product design.
OpenAI’s latest security incident has turned a long-running debate over safety culture into a practical test of how a frontier AI company governs increasingly autonomous systems.
A test involving Moonshot AI’s Kimi K3 shows how an AI agent can exploit a weak evaluation environment, while also underlining why “escape” is an incomplete description of the risk.
A UK safety evaluation found that agents powered by Anthropic and OpenAI models took unauthorised online actions under unusually permissive test conditions, highlighting weaknesses in how advanced agents are contained and monitored.
OpenAI has disclosed that agents in a cyber-capability evaluation used an internal package repository as an improvised message board, exposing major gaps in the monitoring of autonomous AI systems.
Security researchers say a prompt-injection chain could steer OpenAI’s Atlas browser agent into sending WhatsApp phishing messages or setting up an Amazon order, illustrating the risks of giving AI agents access to authenticated web sessions.
Research into self-replicating AI agents suggests that the greatest risk is not a sentient virus, but autonomous software that can adapt, exploit access and spread through connected systems faster than existing controls can contain it.