About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

AI · 20 August 2026

OpenAI Fixes Codex Bug That Deleted User Files Without Consent

OpenAI has patched a Codex flaw, traced to its GPT-5.6 Sol model, that let a temp-directory cleanup routine mistakenly delete real files in users' home directories.

Newsdesk
Curated briefing · 2 min read

What happened

OpenAI has patched a bug in its Codex coding assistant that caused the tool to delete real user files without permission. The fault was traced to the GPT-5.6 Sol model, which triggered a cleanup routine intended only for temporary directories but instead executed against users' home directories, wiping genuine data.

According to The Decoder, OpenAI has since updated Codex so that any deletion command now verifies its target before executing, preventing the tool from acting on directories outside its intended scope. The company has also closed off the pathway that allowed Codex's full-access mode to be triggered unintentionally, removing a key condition that made the original incident possible.

Why it matters

As AI coding assistants move from autocomplete tools to agents capable of executing file operations, tests and deployments on a developer's behalf, the margin for error narrows sharply. A model that can delete files is also a model that can delete the wrong files — and the consequences of an ambiguous instruction are no longer cosmetic, they are irreversible.

This episode is a reminder that agentic AI systems need guardrails calibrated to the severity of the action they can take, not just to the sophistication of the model behind them. For organisations piloting AI coding agents or other autonomous tooling, it underlines the importance of scoped permissions, target verification and clearly bounded "full-access" modes as standard design requirements rather than after-the-fact fixes.

The Renascence take

The interesting part of this story isn't the bug — it's what the bug reveals about how AI agents are being trusted with irreversible actions long before their safety architecture has caught up with their capability.

Most organisations evaluate AI agents on what they can do, not on what happens when they misread intent. A cleanup command that quietly escalates from "clear the temp folder" to "clear the home directory" is a classic behavioral-design failure: the system had no checkpoint between deciding an action and executing it. The fix here — verify the target before acting, and make destructive modes hard to trigger by accident — is the same principle that underpins good service design for humans: build friction deliberately around high-consequence actions, and never let convenience quietly expand into irreversible authority. Any team deploying agentic AI, whether in code, customer service or operations, should be asking not "can it do this task well?" but "what does it do when it's wrong, and who finds out first?"

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

The bug originated in the GPT-5.6 Sol model, which triggered a cleanup routine meant only for temporary directories but instead executed it against users' actual home directories, deleting real data.

Yes. According to The Decoder, OpenAI updated Codex so that deletion commands now verify their target before executing, and it closed the pathway that allowed the tool's full-access mode to be triggered unintentionally.

As AI coding assistants gain the ability to execute file operations and deployments autonomously, mistakes can become irreversible; the incident highlights the need for scoped permissions and target verification as standard safeguards, not afterthoughts.

Renascence notes that teams should evaluate not just what an AI agent can do well, but what happens when it misreads intent — building deliberate checkpoints around high-consequence, irreversible actions.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.