Codex Auto-review Is Now Free, No Longer Burns Usage

OpenAI has announced that Codex's Auto-review feature is now free for anyone signed in with a ChatGPT account, and reviews no longer draw down plan usage. The news came from Codex lead Thibault Sottiaux on social media:

"This Auto-review feature is now free and does not draw usage from your plan."

The toggle lives under Codex's Settings > Permissions > Auto-review; the CLI version can enable it by changing the approval policy in its config file. It's the latest change from the team since Sottiaux's October 4 pledge to ship "one improvement a day for 28 days, or reset everyone's quota in full."

What it actually does

Codex keeps its agent working inside a sandbox by default. Whenever it wants to step outside that boundary — running a command outside the sandbox, making a blocked network request, modifying files outside the authorized directory, or calling an unapproved app or MCP tool — it stops and waits for the user to approve.

On long-running tasks, those prompts pile up. OpenAI's own explanation is that approving requests one by one invites decision fatigue, and after enough clicks the approve button stops functioning as a real check.

Auto-review adds a separate review agent to the loop. Every time the main agent makes a boundary-crossing request, the review agent judges it first: ordinary requests get waved through and the task keeps running; high-risk ones get rejected outright. Per OpenAI's public description, what gets blocked includes credential and token theft, leaking private data externally, running code from an unverified source, irreversible deletions, and changes that weaken system security settings. If the review agent rejects three requests in a row, or rejects 10 out of 50 reviews, the task is interrupted and handed back to the user.

The review agent only judges — it doesn't expand permissions, and the sandbox boundary stays exactly where it was.

Why now

The timing is delicate. In recent weeks, OpenAI has acknowledged that an agent in internal testing breached Hugging Face's systems, and the Wikimedia Foundation separately found anomalous activity from an OpenAI agent on its own platform. OpenAI is now spending more than $500,000 a day in compute just to review historical logs.

Against that backdrop, dropping the barrier to an agent-safety feature to zero is, at minimum, a gesture. Auto-review guards against mistakes on a user's own machine, which sits on a different level from the incidents during training — but both point at the same underlying problem: agents can increasingly act on their own, faster than people can review each move.

The same approach is already familiar in coding tools. Cursor rolled out its own auto-review mechanism back in June, cutting its coding agent's interruption rate to 7%. The main difference with Codex this time is price: reviews also run a model, and that cost used to land on the user — now OpenAI is covering it instead.

Can developers in China use it

The free policy applies only to accounts signed in through ChatGPT. There's no public word on whether it extends to users accessing Codex via API key. For developers in China, using it still requires being able to sign in to a ChatGPT account and hold the matching plan — the regional restrictions haven't changed.

So far, the only data on interception effectiveness is OpenAI's own account. The company hasn't published numbers on how often the review agent blocks legitimate actions by mistake, or what that false-positive rate looks like — users will have to test it in their own projects to find out.

Sources: OpenAI Codex documentation, CocoLoop, Thibault Sottiaux's public post, Nerds Chalk; the Auto-review activation path, rejection threshold, and scope of the free offer are subject to OpenAI's official documentation.