OpenAI expands Codex and its API at DevDay with security scans, a Decisions API, and Ultrafast

OpenAI DevDay: Codex Gets Security Scans, a Decisions API, and Ultrafast, What It Means for the Future of AI

By · Published September 29, 2026 · Updated September 29, 2026

OpenAI used its DevDay stage to push Codex, its coding agent, much further into the daily work of real software teams. The headline items were three: new security scans, a Decisions API, and something called Ultrafast. Alongside them, the company expanded Codex into its API, so developers can build it into their own products instead of only using it inside a chat window.

On the surface, this looks like a product update. It is not. Read together, these three pieces tell you where the whole AI industry is heading: away from chatbots that answer questions and toward systems that do work, check their own work, and run inside other people's software. That is a much bigger shift than any single feature.

Here is a plain-English breakdown of what was announced, why it matters, and what businesses should actually do about it.

What Was Announced at DevDay

1. Security Scans Built Into Codex

Codex will now scan code for security problems. In practice, that means the same tool that writes your code can also look for weaknesses in it, the kind of bugs that let attackers slip in, break things, or steal data.

This matters because of a simple truth about AI-written code: it is fast, and fast code gets shipped. Teams that once spent weeks reviewing changes now merge them in hours. The bottleneck moved. Writing code became cheap; trusting code became the hard part.

By putting scanning next to generation, OpenAI is admitting something important. AI that produces work without checking that work is only half a product. The future belongs to tools that generate and verify.

2. The Decisions API

The Decisions API is the most interesting announcement for anyone building software. As the name suggests, it points at a structured way to hand decision-making to a model, not just "summarize this" or "write that," but "given these facts and this policy, what should happen next?"

Think about how much of modern software is really just a chain of decisions. Should this loan be approved? Should this order be flagged? Should this support ticket go to a human? Should this user be blocked? Today those answers come from rigid rules that developers write by hand, line by line, and then maintain forever.

A Decisions API signals a world where those rules are expressed in language instead of code. That is a huge deal for two reasons:

The catch is obvious too. If a model is making decisions, you need to know why it decided what it decided. Expect explainability, logging, and audit trails to become the next battleground.

3. Ultrafast

Ultrafast says one thing: speed is now a feature, not a bonus. For most of AI's short history, the race was about being smarter. The next race is about being faster, because speed changes what a tool can be used for.

A slow model is a research assistant. You ask, you wait, you read. A fast model is a teammate. It keeps up with you, responds while you are still thinking, and works inside live systems where a two-second delay breaks the whole experience.

Speed is what turns AI from something you visit into something that runs quietly in the background of everything else.

4. Codex in the API

Opening Codex up through the API may be the quietest but most far-reaching change. It means Codex stops being a destination and becomes an ingredient. Any company can now build a coding agent into its own product, an internal developer portal, a testing platform, a customer's own tools.

When a capability moves into an API, it stops being a product and becomes infrastructure. That is the moment an industry stops experimenting and starts depending.

The Bigger Story: AI Is Becoming Plumbing

Look at all four announcements together and a pattern appears. Each one takes intelligence and pushes it deeper into the stack, into the code, into the decisions, into the speed, into other people's software.

This is how every major technology matured. Electricity was once a spectacle. Then it became wiring inside every building, invisible and assumed. The internet was once a place you went. Then it became the thing everything else ran on. AI is on that same path right now.

The practical consequence is this: within a few years, "we use AI" will sound as odd as "we use electricity." The question will not be whether a company uses AI, but whether it wired it in well.

Why Security Scanning Is the Most Underrated Announcement

Of the three headline items, security scans may matter most, and get the least attention. Here is why.

Every wave of automation produces a new class of failure, and the failure is always speed without judgment. We automated factories and got smog. We automated finance and got flash crashes. We are automating software development right now, and the early warning signs are already familiar: more code, faster, with fewer humans reading every line.

Adding security scanning directly into the agent is an attempt to build the seatbelt at the same time as the engine. It is far better than bolting one on years later, which is how the last century of industrial accidents actually happened.

The deeper point is about trust. Businesses will not hand real work to an AI system they cannot audit. Every scan, every log, every explanation is a step toward the kind of trust that lets a company stop double-checking. That trust is worth more than any benchmark.

"Ultrafast" and the End of Waiting

We have all built habits around slow software. We start a task, switch tabs, come back. We ask a question and read email while we wait. Those little pauses are a hidden tax on how we work.

Remove the pause and behavior changes. Developers stop writing code comment-by-comment and start having a conversation with it. Support teams stop drafting and start reviewing. Analysts stop querying and start asking.

The risk of speed, of course, is that people stop thinking before they act. A fast answer feels like a correct answer. That is a real danger, and it is why the verification tools, like those security scans, have to arrive at the same time as the speed. Fast plus unchecked is not productivity. It is a faster path to the same mistake.

Practical Implications for Businesses

If you run a team, here is what to do with this news.

What Comes Next

Expect three follow-on trends from this direction of travel.

First, verification becomes the product. Once everyone can generate, the differentiator is proof, that the code is safe, the decision is explainable, the output is correct.

Second, decision layers get standardized. If a Decisions API works, competitors will ship their own. Businesses will soon be choosing between them the way they choose databases today.

Third, the agent becomes a coworker, not a tool. Agents that write, check, and act will be treated less like software you use and more like a junior team member you manage. That has real consequences for hiring, training, and how work gets measured.

The Bottom Line

Codex gaining security scans, a Decisions API, and Ultrafast mode is not a story about features. It is a story about AI moving from the front of the house to the foundation. Intelligence is being wired into code, into decisions, into speed, and into other companies' software.

The businesses that win the next few years will not be the ones with the most exciting AI demos. They will be the ones that quietly made AI reliable, fast, and trustworthy enough to depend on, and then stopped calling it AI at all.

TLDR: OpenAI expanded Codex at DevDay with built-in security scans, a new Decisions API, an Ultrafast mode, and Codex availability through its API. Together these signal AI's shift from a chatbot you visit to infrastructure that runs inside software, generating work, checking it, and making decisions fast. The winners will be businesses that treat AI as a trustworthy layer with verification built in, not as a single app. Audit your review process, find your rule-heavy decisions, and start building on APIs rather than interfaces.