TechScriptsNepal
Blog

OpenAI DevDay 2026: agents that operate software the way people do

TechScripts Nepal · Kathmandu · October 7, 2026 · 3 min read

At DevDay 2026, OpenAI announced a batch of developer updates headlined by a new model, GPT-6.1 Sol, but the more consequential changes are in how agents get built and run. Three of them are worth understanding even if you never touch OpenAI's platform, because they point at where agent tooling in general is heading.

Computer use arrives in the Agents API

The Agents API now supports computer use, meaning an agent can operate software through its graphical interface instead of only through a structured API. On OpenAI's managed service, agents can work websites and apps through a browser that OpenAI hosts. The same API also folds in multi-agent capabilities from Codex, tool search, tool calling, and context compaction, with OpenAI running the underlying execution infrastructure.

The practical point is reach. A huge amount of business software has no good API, or an API that covers a fraction of what the interface does. An agent that can click through a web app reaches all of it, which is exactly why it also deserves more caution than an agent calling a narrow, well-defined endpoint.

Codex moves into the cloud

Codex now has cloud environments that a team shares, preloaded with your repositories and dependencies. A task keeps running while your laptop sleeps. OpenAI also announced Codex Security Cloud, which points the coding agent at defense: scanning whole GitHub repositories on demand or on a schedule, checking each new commit, investigating findings, removing duplicates, and preparing fixes without a developer's machine being involved.

That's a notable shift in where the work happens. When an agent runs on your laptop, you are implicitly the supervisor. When it runs in a shared cloud environment on a schedule, supervision has to be designed in: who reviews the fixes, what the agent can merge, and what it can reach.

The Decisions API and new distribution channels

OpenAI also introduced the Decisions API in limited preview, aimed at millisecond-scale classification, plus three new distribution channels: Sign in with ChatGPT, plugin extensions, and the OpenAI Marketplace. Those matter most to companies selling products on top of the platform, less to teams building internal tools.

What this means for teams building with agents

The pattern across these announcements, and across Google's enterprise agent platform, is the same: agents are being given more reach (a whole browser, a whole repository) and more autonomy (running unattended in the cloud). A few questions are worth settling before you give an agent either:

  1. What can it touch? A browser session is broad by default. Decide which sites, accounts, and actions are in scope, and keep credentials separate and minimal.
  2. What happens when nobody is watching? Scheduled and background agents need logging and review built in, not added after the first surprise.
  3. Where does a human sign off? Fixes prepared by an agent are only safe if someone reviews them before they ship. Decide that step up front.

We covered what happens when that last layer of discipline is missing in our post on a Gemini security test that escaped its sandbox. The tools are getting more capable quickly. The guardrails still have to be designed by whoever deploys them.