GPT-5.3 Codex Receives OpenAI's First High-Severity Security Rating

On February 5 this year, OpenAI released GPT-5.3-Codex, which significantly boosted coding capabilities—but it also came with an unwelcome label: the first "high" cybersecurity risk level under OpenAI's internal safety assessment framework.

How Dangerous Is It?

OpenAI itself put it diplomatically: "There is no conclusive evidence that the model can fully automate cyberattacks," but "as a precaution," it deployed "the most comprehensive cybersecurity protection stack to date."

In plain terms: the model's coding ability has reached a critical threshold where, if exploited at scale and automated, it could cause real harm in the cybersecurity domain.

Security Measures

OpenAI implemented several layers of protection:

  • Safety training: model-level alignment
  • Automated monitoring: detecting suspicious requests
  • Tiered access: high-risk operations open only to trusted users
  • Downgrade routing: requests flagged as high cybersecurity risk are automatically routed to the previous-generation GPT-5.2

The release cadence was also unusually cautious, with full developer access delayed.

Aftermath

California's AI safety regulator subsequently claimed the release may have violated the state's newly passed AI safety law. OpenAI denied the allegation.

In March, a Codex GitHub token leak vulnerability was also disclosed—later patched.

OpenAI also committed $10 million in API credits to support cyber defense research, extending a $1 million cybersecurity grant program that began in 2023.

Underlying all this is a deep tension: the stronger the coding ability, the higher the risk of misuse. The improvement in model capability and the increase in security risk are almost linearly correlated. OpenAI chose a "release first, protect later" approach rather than "protect first, release later." Opinions within the industry are sharply divided on this choice.

Source: CocoLoop, Fortune report