OpenAI Codex

OpenAI

Vendor

OpenAI coding agent available as an open-source CLI, IDE extension, ChatGPT app surfaces and hosted Codex Cloud tasks.

Curated by Tiberiu ArvaVerified

Apache 2.0 (CLI); Proprietary (cloud)Version 0.159.2Released 2026-09-29

Strengths

  • Apache 2.0 Rust CLI
  • Included in ChatGPT plans
  • Compliance API codex_log events

Practitioner note

Separate local clients from Codex Cloud in workspace RBAC; OpenAI notes the Compliance API does not record every local command or file operation, so pair it with endpoint controls. Use API keys, not seats, for CI automation.

Warning

OpenAI Codex: Only the Codex CLI in openai/codex is Apache 2.0. Codex Cloud, the ChatGPT app surfaces and the models it calls are proprietary OpenAI services under ChatGPT or API terms.

Governance posture

Reviewed 2026-09-30
PartialData residency

Data and inference residency apply only to eligible content and supported workloads, subject to agreement, region and configuration; not supported with UAE inference residency.

Source
YesDeployment model

Local CLI/IDE/desktop clients plus OpenAI-hosted Codex Cloud; no self-hosted model option. (saas, hybrid)

Source
PartialAudit logging

Compliance API append-only stream with codex_log, conversation_message and AUTH_LOG events; OTel events for local use; does not capture every local command or file operation.

Source
YesSOC 2

OpenAI SOC 2 Type 2 (Jul 2025-Jun 2026) covers ChatGPT Enterprise/Edu/Team and API Platform; Codex-specific scope not separately listed.

Source
YesISO 27001

OpenAI ISO/IEC 27001:2022 covers ChatGPT business plans and API Platform; Codex-specific scope not separately listed.

Source
YesISO 42001

OpenAI ISO/IEC 42001:2023 listed on trust portal for ChatGPT business plans and API Platform; Codex-specific scope not separately listed.

Source
UnknownEU AI Act

Assessed limited-risk by product category (general-purpose assistant); no published OpenAI EU AI Act conformity statement for this product. (role: limited-risk)

YesLicense risk

CLI is Apache 2.0 (permissive) but depends on proprietary OpenAI models and Codex Cloud. (medium)

Source

EU AI Act obligations

Risk tier: Limited risk · as of 2026-08-23

Source-backed information mapped from OpenAI Codex's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

Article 4AI literacy

Providers and deployers must take measures to ensure a sufficient level of AI literacy in staff and other persons operating AI systems on their behalf.

Applies from

Official text
Article 50Transparency for certain AI systems

People must be informed when they interact with an AI system; synthetic audio, image, video, and text content must be marked as artificially generated, and deepfakes disclosed.

Applies from

Official text

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.