AI · July 22, 2026
OpenAI Codex Encrypts Inter-Agent Instructions: CX Accountability Gap
OpenAI has made agent-to-agent instructions in Codex opaque by default since June 2025, leaving organisations unable to audit AI delegation chains — a direct threat to CX accountability.
What happened
Since early June 2025, OpenAI has introduced encryption on the instructions that a primary agent passes to its subagents inside Codex, the company's AI-powered coding tool. The change means developers can no longer observe how tasks are broken down and delegated internally within a multi-agent workflow — the reasoning and directives exchanged between agents are now opaque by design.
For the larger GPT-5.6 model variants, named Sol and Terra, this encrypted inter-agent communication is not optional: it is enforced as a mandatory default. Developers working with these models have no mechanism to inspect or audit the delegation chain, regardless of their configuration choices.
Why it matters
Transparency is a foundational principle of trustworthy service design. When a customer-facing product is powered by a chain of AI agents — each handing off subtasks to the next — the organisation deploying that product is implicitly responsible for every decision made along that chain. Encrypting inter-agent instructions does not remove that accountability; it simply makes it harder to exercise. For CX leaders and service designers, this creates a meaningful gap between the experience they intend to deliver and the experience they can actually verify is being delivered.
From a behavioural-economics perspective, this move also affects the trust architecture of AI-assisted services. Customers and internal operators alike rely on the perception of legibility — the sense that a system's behaviour can, in principle, be explained. When the delegation logic of an AI system becomes structurally invisible, that legibility collapses, and with it a key driver of user confidence. Organisations building on Codex or similar agentic frameworks will need to think carefully about how they surface accountability signals to end users when the underlying mechanics are sealed off.
By the numbers
- Early June 2025: the date from which inter-agent instruction encryption became active in Codex.
- 2 model variants — Sol and Terra (both GPT-5.6 scale) — now have mandatory, non-configurable encryption of agent-to-agent instructions.
The Renascence take
Most commentary on this development will focus on the security rationale — encrypting agent instructions could, in theory, prevent prompt-injection attacks that target the delegation layer. That framing misses the more consequential tension: between operational security and the organisational accountability that good service design demands.
The instinct to seal off internal AI reasoning in the name of security is understandable, but it transfers risk rather than eliminating it — from adversarial interference to internal blindness. A customer-obsessed operator should be asking not just "is this system secure?" but "can I stand behind every decision this system makes on my customer's behalf?" Where the answer is structurally unknowable, the responsible move is to narrow the scope of what the agent is permitted to decide autonomously, not to accept opacity as a given. Legibility is not a luxury feature; it is a service-design prerequisite for any AI system that touches a real customer outcome.
Sources
This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in AI
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.