OpenAI Codex 0.159.0 Makes Mid-Run Steering the Main Event
OpenAI Codex 0.159.0 introduces an opt-in way to redirect an active agent before its current response or long-running command finishes. That sounds like a narrow interface change. It actually targets one of the hardest problems in agentic coding: correcting a mistaken direction without discarding useful work.
The release arrived on September 29, 2026, with six feature groups and a broad collection of fixes. Its headline addition, instant_interrupt, allows new input to preempt model responses and make certain code-mode calls yield early. Code mode is Codex’s execution path for running commands and waiting on ongoing processes.
This puts Codex in a direct interaction race with GitHub Copilot CLI and other coding agents. The contest is no longer limited to which model writes the strongest patch. It increasingly concerns which agent remains understandable, steerable, and recoverable while real work is underway.
What OpenAI Codex 0.159.0 Actually Changes
The release treats agent control as a continuous interaction, not a sequence of isolated prompts.
The complete Codex release centers on instant_interrupt, although the flag remains disabled by default. When enabled, new user input can steer Codex during a model response. It can also affect long-running code-mode exec and wait calls.
Previously, input submitted during one of those calls could remain queued until the call returned. That behavior is predictable, but it creates a costly delay when the user spots a bad assumption. The agent might continue testing, generating output, or following the wrong implementation path before it reads the correction.
The new mechanism watches for queued input during each sampling request. It then passes a shared preemption signal to eligible tool calls. A running cell can yield its identifier without being terminated, allowing Codex to process the new instruction.
That distinction matters. Yielding is not equivalent to killing the command. The underlying work can continue, while a later wait call collects its results. Codex gains an opportunity to reconsider its next action without automatically destroying useful execution state.
The accompanying model-response change completes the loop. New input can preempt the response being generated, rather than waiting behind it. The release also preserves queued messages and tool results across the interruption path.
Consider a developer who asks Codex to refactor an authentication service. While the agent runs tests, the developer notices that an older client still depends on the existing token format. With instant interruption enabled, that constraint can reach Codex before it completes the original plan.
The release includes several smaller interface changes that support the same theme. New sessions show a more compact welcome screen and use consistent, borderless headers. Tips can appear during active work and after a turn finishes.
The warnings viewer now dismisses warnings that the user reviewed before closing it. Pressing k retains a selected warning for later. This turns the viewer into a lightweight triage queue instead of a list that demands repeated inspection.
Users can also scroll through the transcript while a plan-implementation dialog remains open. That enables a basic but important review pattern: reread the evidence before authorizing the proposed changes.
Together, these Codex 0.159.0 features reduce the interface friction surrounding long agent sessions. The release does not announce a new coding model. It changes how quickly a human can influence the model already working.
Instant Interrupt Changes the Cost of a Correction
Mid-run steering matters because an early correction is usually cheaper than reviewing a completed mistake.
A coding agent does not move directly from prompt to finished patch. It examines files, forms a plan, invokes tools, reads results, changes code, and validates those changes. A mistaken premise can spread across every stage.
Traditional chat interfaces place new messages behind the current response. That ordering works for questions with short answers. It becomes restrictive when an agent runs commands that take several minutes or waits on processes with uncertain completion times.
OpenAI’s yielding implementation addresses that delay without assuming every new message should cancel current work. The active cell yields control, but it keeps running. Codex can then incorporate the new instruction and decide how to proceed.
This creates a middle ground between waiting and aborting. Waiting preserves work but delays the correction. Aborting responds immediately but may waste execution progress or leave the user uncertain about what stopped.
The Codex instant interrupt design aims to preserve both responsiveness and continuity. That is the release’s central mechanism, and it is more consequential than another shortcut or visual refresh.
The feature also has implications for permission-sensitive work. A user can add a constraint when the agent’s emerging direction becomes visible. For example, the user might prohibit a dependency, limit edits to one package, or require backward compatibility.
That intervention still depends on timing. A message cannot reverse an external side effect that has already occurred. It also does not replace careful approval controls for consequential commands.
Instead, instant interruption shortens the period between recognizing a problem and influencing the agent. That narrower window becomes valuable as coding tasks grow longer and include more tool calls.
The opt-in status deserves attention. OpenAI is not presenting the behavior as a universal default. Preemption changes message ordering, execution timing, and user expectations, so cautious deployment is reasonable.
Users must also understand what “interrupt” means in this context. The active code-mode cell can continue after yielding. Someone expecting an emergency stop could misread that behavior unless the interface clearly communicates the cell’s state.
The response preemption change covers another part of the experience. Incoming input can halt the current model response and steer the ongoing turn. The system also accounts for messages that arrive during context compaction.
Compaction summarizes earlier session context when the conversation becomes large. Input arriving during that process must be deferred and preserved, rather than lost or applied in an inconsistent order.
These details reveal the difficulty behind an apparently simple feature. A responsive text box is not enough. Steering must coordinate model generation, queued input, background execution, tool results, and conversation history.
OpenAI Codex 0.159.0 therefore represents an orchestration update more than an intelligence update. It makes the agent loop more interruptible while trying to retain the work that remains useful.
Coding Agents Are Competing on Control, Not Only Output
The primary contest is shifting from autonomous completion toward useful collaboration during execution.
GitHub documents a similar distinction between steering and queueing in its coding-agent products. A steering message changes current work, while a queued message waits for the next turn.
In GitHub Copilot cloud agent sessions, follow-up steering is applied after the current tool call finishes. GitHub’s session controls also expose live progress, session logs, stopping, and archiving.
GitHub Copilot CLI goes further in its local interface. A plain message entered while the agent is thinking becomes steering input by default. Users can separately queue work for a later turn.
OpenAI’s implementation differs in an important respect. Its opt-in path lets eligible long-running code-mode calls yield before their underlying process ends. That can reduce the delay between user intervention and model reconsideration.
This does not establish that one product is categorically faster or safer. The release contains no independent latency comparison, completion benchmark, or measured reduction in wasted work. Any broader performance conclusion would be premature.
It does show where coding-agent competition is heading. Model quality remains important, but practical differentiation increasingly comes from controlling work that is already in motion.
A strong agent can still become frustrating when it hides state, delays corrections, or forces an all-or-nothing cancellation. A weaker model can also consume substantial time if the user cannot redirect it before a mistake expands.
The desired interaction resembles pair programming more than a job queue. One participant begins an approach, while the other can add constraints as evidence appears. Neither participant must restart the entire task after every correction.
That pattern affects enterprise evaluation as well. Teams need to know whether developers can inspect active work, understand pending operations, and intervene before an agent crosses a project boundary.
Auditability becomes part of the product. So does the distinction between adding context, changing direction, queuing another task, and stopping execution. Those actions should not look identical because their consequences differ.
The changes around warnings, transcript access, and session presentation support that requirement. They give users more information while a decision remains open, instead of only presenting a completed result.
This interaction model also rewards good project context. Steering works best when the user can provide a precise constraint supported by existing documentation. A searchable knowledge base can help teams retrieve those constraints before approving an agent’s plan.
OpenAI Codex 0.159.0 does not settle the control contest. It establishes a clearer product direction: an agent should remain responsive even when its tools are busy.
The Smaller Features Make Long Sessions Easier to Read
The interface changes reduce cognitive overhead at the moments when users must review, approve, or preserve information.
The new session screen is more compact, and session headers now follow a consistent borderless design. Those changes do not alter code generation, but they reduce visual variation across the terminal interface.
Occasional tips now appear while Codex works and after turns complete. This can expose useful controls when users need them, although recurring guidance must avoid becoming another source of noise.
The warning workflow receives a more functional change. Closing the viewer dismisses warnings that the user has already reviewed. A keep-and-next action, triggered with k, preserves an important warning and advances the selection.
That design maps warnings onto a familiar inbox pattern. Reviewed items leave the active queue, while exceptions remain available. The change should reduce repeated scanning during sessions that produce several notices.
The transcript can now remain scrollable while a modal dialog asks whether Codex should implement a plan. Previously, a modal could limit the user’s ability to revisit earlier discussion at precisely the moment review mattered most.
Plan approval is not a ceremonial click. A useful decision may require checking the original request, prior tool output, identified risks, and the agent’s stated assumptions. Transcript access makes that comparison easier.
Copying content from the transcript is also more reliable. Selections retain Markdown tables, formatting, and significant whitespace, while additional terminal environments support automatic copy-on-selection behavior.
That fix matters when users move generated output into issue trackers, code reviews, documentation, or incident records. Formatting loss can change the meaning of logs, tables, and code-adjacent text.
Native Mermaid rendering receives broader syntax support. Mermaid is a text-based diagram language that describes flows and relationships using compact source text.
The updated renderer preserves punctuation and semicolons inside labels. It also recognizes more flowchart relationships, edge labels, direction markers, and grouped node structures.
This turns agent-generated architecture diagrams into more useful terminal artifacts. A developer can ask Codex to explain a service flow, inspect the rendered result, and still retain the underlying Mermaid source.
The Mermaid update also highlights a recurring interface challenge. Generated diagrams are only useful when the renderer accepts the syntax that models commonly produce.
App-server clients gain a lower-level capability with item-anchored thread pagination. A client can request thread history relative to a particular item rather than navigating only through broader pages.
This should help applications load the relevant portion of a long conversation. It also gives client developers more control over resumable timelines and incremental history views.
None of these additions carries the conceptual weight of instant interruption. Collectively, however, they make extended sessions easier to enter, inspect, navigate, and reuse.
That matters because agent usability deteriorates when conversations grow. Better models alone do not solve transcript navigation, warning fatigue, diagram failures, or lost formatting.
Windows and Sandbox Fixes Carry the Operational Weight
The release also closes platform and security gaps that can matter more than visible interface improvements.
On Windows, Codex now suppresses stray console windows when launching several kinds of child processes. The affected paths include local Model Context Protocol servers, code-mode hosts, and commands connected through pipes.
MCP is a protocol for connecting models to external tools and data sources. A local MCP server may run as a background child process, so an unexpected console window can interrupt the desktop experience.
Restrictive Windows launchers can now fall back to embedded mode. This provides another execution route when process creation rules prevent the preferred architecture from working.
The release also improves daemon launch behavior under residual Windows job membership. Another fix prevents launcher input and output handles from remaining attached where they should not.
These changes address reliability rather than model behavior. They are particularly relevant for managed machines, desktop integrations, and terminal workflows that create multiple subprocesses.
Security boundaries receive separate attention. Approved commands now retain explicit filesystem denials instead of losing those restrictions during command preparation.
Codex also protects .aws directories by default when they appear beneath writable roots. Those directories can contain cloud configuration or credentials, making the default boundary significant.
The release does not claim that these changes eliminate sandbox risk. It does indicate that OpenAI is tightening the handoff between a user’s approval and the permissions applied during execution.
That boundary deserves scrutiny because an approved command is not the same as unrestricted filesystem access. If preparing the command discards an explicit denial, the runtime no longer reflects the decision the user reviewed.
Network-enabled macOS sandboxes receive a TLS trust fix. The update permits system trust evaluation under the relevant Seatbelt profiles, which are macOS sandbox policies that constrain process capabilities.
Remote environments that require a proxy also gain corrected execution behavior. These fixes address common gaps between a development tool’s nominal network access and the rules of the machine hosting it.
Authentication becomes less brittle as well. Local app-server flows should open the browser more reliably for ChatGPT sign-in. Onboarding now provides a shortcut for copying the login URL when automatic opening is unsuitable.
Blank sessions keep their drafts when users switch tasks. Threads can be archived and listed before they contain a first completed turn, which makes session management less dependent on conversation state.
These fixes reinforce the release’s broader direction. Long-running agents need durable state and predictable process behavior, not only impressive responses.
A coding agent that opens unwanted windows, loses drafts, mishandles denials, or fails behind a proxy imposes operational costs. Those failures can block adoption even when the generated code is acceptable.
Opt-In Steering Still Needs a Real-World Test
The feature’s value depends on predictable timing, clear status cues, and correct behavior under pressure.
The first uncertainty is latency. The release explains that eligible calls can yield when new input arrives, but it does not publish timing measurements. Users still need to observe how quickly steering takes effect.
The second uncertainty concerns semantics. “Interrupt,” “preempt,” “yield,” and “stop” describe different operations. A running process can survive after Codex yields control, while a user may assume the work ended.
A clear interface should reveal whether a process remains active, whether its output is still arriving, and whether the agent plans to consult that output. Ambiguity here can create duplicated commands or conflicting edits.
The third issue is adoption. Because instant_interrupt is disabled by default, its initial impact will be limited to users who discover and enable the flag.
An opt-in rollout provides room for testing, but it also narrows the available feedback. Experienced users may exercise the feature differently from developers encountering agentic coding for the first time.
The fourth issue involves race conditions. New input can arrive during model generation, execution, waiting, or context compaction. Each path must preserve message order and prevent tool results from attaching to the wrong reasoning step.
OpenAI says its tests cover enabled and disabled behavior, repeated steering, deferred input during compaction, and later calls within the same response. The tests also check that queued messages and direct tool results remain preserved.
Those cases are necessary, yet production sessions produce less orderly combinations. A developer might steer repeatedly, change the requested file scope, reject a permission, and receive late process output within one turn.
The fifth issue is safety. Faster steering can help stop an emerging mistake, but it is not a substitute for command approval, sandbox restrictions, or repository review.
A harmful command may complete before the correction arrives. An external service may also process a request even after the local agent changes course. Users should not treat conversational interruption as transactional rollback.
There is also a risk of oversteering. Frequent corrections can produce a fragmented objective, especially when the agent retains earlier context and several instructions compete for priority.
Teams will need interaction conventions. A steering message should clearly state what changed, which earlier instruction it replaces, and whether current execution should continue.
The removal of automatic follow-up prompt suggestions is relevant here. Codex 0.159.0 removes both those suggestions and the related setting. OpenAI appears to be reducing unsolicited prompt scaffolding while adding more direct user control.
The release also removes the bundled plugin-creator skill. That packaging change should not be confused with the steering feature, but users relying on bundled capabilities should review their local setup after upgrading.
The skeptical reading is straightforward. OpenAI has added the machinery for faster intervention, but the release provides no evidence that it improves task success rates.
That does not make the feature unimportant. It defines the next evaluation question: does mid-run steering prevent enough wasted work to justify the additional execution complexity?
Three Signals to Watch After Codex 0.159.0
The next test is whether instant interruption moves from an experimental control into a dependable part of everyday coding.
The first signal is default status. If OpenAI enables instant_interrupt by default in a later release, that would indicate confidence in ordering, preservation, and interface clarity.
Keeping it opt-in for several releases would suggest that edge cases still need attention. It could also mean OpenAI wants explicit consent for a behavior that changes established queueing expectations.
The second signal is issue and release activity around repeated steering. Reports involving lost messages, duplicated commands, orphaned processes, or late output would weaken the case for immediate interruption.
Fixes that broaden the supported tool paths would strengthen it. The current design specifically addresses model responses and long-running code-mode exec or wait calls, not every possible external operation.
The third signal is competitor behavior. GitHub already documents both immediate steering and queued follow-ups through its products and SDK. Other coding-agent vendors face the same pressure to expose clear mid-run controls.
The important comparison will not be whether products contain a feature called steering. It will be how quickly a correction takes effect and how accurately the system explains the remaining execution state.
Developers should test OpenAI Codex 0.159.0 on bounded, reversible tasks before relying on interruption during sensitive work. A useful trial might involve a long test run, one scope correction, and inspection of the surviving process.
Check whether Codex receives the new instruction promptly. Confirm whether the original process remains active. Then verify that later output is attached to the correct turn and does not revive the abandoned approach.
The release makes a persuasive product judgment: users need a way to intervene before an agent finishes being wrong. The implementation now has to prove that faster intervention remains understandable under real workloads.
If you enable OpenAI Codex 0.159.0, begin with one practical question. Can you redirect a long task without losing useful progress or becoming uncertain about what is still running? That outcome matters more than the flag itself.



