GPT-5.3-Codex activates cybersecurity safeguards
OpenAI introduces `GPT-5.3-Codex`, a coding model capable of conducting research, using tools, and executing extended tasks without losing context. For the first time in a launch, the company activates its high-capability cybersecurity safeguards, although it acknowledges that it still lacks definitive evidence that the model exceeds that threshold.

OpenAI introduces GPT-5.3-Codex, a coding model designed to work for longer, conduct research, use tools, and execute complex tasks. The company describes it as its most capable agentic coding model to date: it does not just respond to a request, it can move through multiple stages to complete it.
The foundation combines the coding performance of GPT-5.2-Codex with the reasoning and professional knowledge capabilities of GPT-5.2. In practice, that points to tasks such as analyzing a large project, searching for information, modifying multiple files, testing a solution, and continuing the work without losing track of the context.
You can also intervene while the model works. OpenAI says you can guide it or correct its course during a task without it losing the context it has accumulated. The idea is closer to supervising a digital collaborator than asking isolated questions in a chat.
Cybersecurity becomes a priority
The most relevant detail in the technical documentation is not just about coding. For the first time, OpenAI is treating a launch as high capability in cybersecurity under its preparedness framework and activating the associated safeguards.
The company clarifies that it does not have definitive evidence that GPT-5.3-Codex exceeds its high-capability threshold in this area. Even so, it cannot rule out that possibility and is taking a preventive approach.
Its measures are based on several layers of security designed to make it harder for malicious actors to use the model and to slow that use down. At the same time, OpenAI says it is working to make these capabilities broadly available to those defending systems and networks.
This matters because a model that can write code, conduct research, and use tools for extended periods could also help analyze vulnerabilities or automate parts of an attack. The capability does not by itself turn the model into an offensive tool, but it does make controlling who can use it and for what purpose more important.
What risks OpenAI recognizes
The company also classifies GPT-5.3-Codex as high capability in biology, so it applies the set of safeguards used with other models in the GPT-5 family. By contrast, it says the model does not reach that level in the autonomous improvement of artificial intelligence systems.
These categories do not mean that the model has demonstrated unlimited results. They indicate that OpenAI considers specific controls necessary when there is a reasonable risk that its capabilities could enable significant harm.
For you, the most visible change will be the ability to delegate more complete programming tasks: from understanding a codebase to proposing and executing changes with fewer intermediate instructions. But the actual scope will depend on the connected tools, the permissions granted, and the limits OpenAI applies in each environment.
GPT-5.3-Codex represents, above all, a step toward models that do more than generate code. They conduct research, make intermediate decisions, and act on extended tasks. What to watch now is whether the safeguards can keep this increase in autonomy useful for developers and defenders without making the work easier for those seeking to exploit systems.