AI · 6 September 2026
OpenAI Fixes Codex Bug That Deleted User Files Without Consent
OpenAI patched a Codex coding assistant flaw tied to its GPT-5.6 Sol model that mistakenly treated real user files as temporary data and deleted them.
What happened
OpenAI has fixed a bug in its Codex coding assistant that could cause real files in a user's home directory to be deleted without permission. According to The Decoder, the fault was traced to a temporary-directory cleanup routine tied to the GPT-5.6 Sol model, which under certain conditions treated legitimate user files as disposable temp data and removed them.
OpenAI has since patched the issue, addressing the underlying cleanup logic so that Codex no longer misidentifies permanent files as temporary artefacts. The company has not detailed how many users were affected or for how long the flaw was present before being caught and resolved.
Why it matters
Codex is positioned as an autonomous coding agent designed to act on a developer's behalf inside their own file system — which means trust in its guardrails is not optional, it is the product. A bug that deletes real files, even unintentionally, cuts directly against the core promise of agentic AI tools: that they can be given meaningful autonomy to take actions without constant human supervision.
For organisations evaluating or deploying AI coding agents, this is a reminder that the risk surface for agentic tools extends well beyond incorrect suggestions or hallucinated code — it includes irreversible, real-world side effects on a user's own environment. As AI assistants are given more permission to act rather than merely advise, the bar for safe-by-default behaviour, sandboxing and reversible actions rises accordingly.
The Renascence take
The interesting part of this story isn't the bug itself — software has bugs — it's what the incident reveals about the design assumptions behind agentic AI tools that are meant to operate with real permissions on real systems.
Most coverage will treat this as a technical footnote: a model mislabelled some files, OpenAI patched it, moving on. But the deeper issue is a service-design one — when you hand an AI system the ability to take destructive actions autonomously, "mostly reliable" cleanup logic isn't good enough, because the cost of a rare failure is a user's irreplaceable data, not a bad recommendation they can simply ignore. Any organisation deploying agentic AI internally should be asking whether these tools default to reversible, sandboxed or confirm-before-delete behaviour, rather than assuming vendors have already solved for the edge cases. Trust in AI agents is built or lost in exactly these moments — not in the demo, but in what happens when the model gets something small and destructive wrong.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in AI
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.