On October 6, 2026, OpenAI executive Tibo Sottiaux said Codex Auto-review would not draw usage from the plan for people signed in through a ChatGPT account. The announcement concerns Auto-review’s usage accounting; it does not make Codex or a ChatGPT subscription free.
What Auto-review checks—and what stays with you
Auto-review sends certain requests to cross the sandbox boundary to a separate reviewer agent. Examples include escalated shell or exec calls, blocked network requests, edits outside writable roots, and some approval-gated MCP or app-tool calls, according to OpenAI’s feature documentation.
The main Codex agent keeps its configured sandbox and permission limits. Auto-review changes who reviews eligible approval requests; it does not give the agent broader file or network access. Actions already allowed inside the sandbox do not go to the reviewer, and Computer Use app approvals still appear to the user.
How to enable Auto-review
Sottiaux gave the settings path as Settings > Permissions > Auto-review and also called the mode “Approve for me.” In Codex configuration, approvals_reviewer = "auto_review" selects the reviewer. It needs an interactive approval policy—such as approval_policy = "on-request" or a granular policy that surfaces the relevant request—so there is a prompt for Auto-review to assess. With approval_policy = "never", no approval request is created for it to review. OpenAI’s documentation describes these settings and the boundary they apply to.
What OpenAI reported in its April 2026 evaluation
In an evaluation published April 30, 2026, OpenAI reported a 99.1% approval rate on escalated actions and a 99.93% effective approval rate across all actions, including actions that stayed inside the sandbox. These are approval-rate measures, not rates of detecting unsafe actions.
OpenAI says Auto-review can make mistakes and may be misled in unusual or adversarial situations. It is not a deterministic security guarantee, and OpenAI describes it as a complement to sandbox design and monitoring. The two reported approval rates therefore do not guarantee that the system will catch unsafe actions.