Reddit
Codex users are getting 'Cyber Abuse' warnings from OpenAI for security-reviewing their own code, with appeals rejected then reversed
An r/OpenAI thread (79 upvotes, 58 comments) documents an account warning for 'Cyber Abuse' from a user who says they only use Codex for coding tasks; their appeal was rejected and the warning upheld. A commenter at 71 upvotes reports the identical email, appealed on the grounds that security assessment is part of app development, and received an apology the next day. The timing matters: Astra shipped September 3 as OpenAI's first model rated Critical for cybersecurity capability under its Preparedness Framework, and this looks like the enforcement layer that shipped with it producing false positives on ordinary security work.
↳ Follow the thread