False positive cyber-risk rerouting (routed to GPT-5.2)
mention your thread ID 019c6e09-3124-78f3-8f47-adf4fdc362a5 in an existing issue.
Date: 2026-02-17
Surface: [Codex CLI / Codex app / IDE extension / Codex web / other]
Warning shown:
"Warning: Your account was flagged for potentially high-risk cyber activity and this request was routed to gpt-5.2 as a fallback..."
What I asked (sanitized):
[Paste the prompt/request that triggered the warning]
Context / intent:
This was legitimate, non-malicious work: [e.g., normal software engineering / defensive security on my own systems with authorization].
No credential theft, malware creation/deployment, or unauthorized testing.
Request:
Please review this as a false positive, and adjust the classifier / remove account-level routing if possible.
14 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
@AidenNovak, did you successfully complete the Trusted Access verification?
@etraut-openai even though I've already completed it back in the o3 days for the API, now I can't complete using either drivers license or passport. I've been a Pro customer for 14 months surely I can get this resolved quickly?
<img width="645" height="251" alt="Image" src="https://github.com/user-attachments/assets/9420d91c-7027-4b4b-9677-ebe959e8953c" />
not able yet , but please help with this fix if your great teams can do , i am working with one project outside without my private mobile phone , and having this issue really made me extreme terrible , i am the pro subscriber , thanks for your reply , and i feel the hope to get back then
Also received the identity cannot verify message and not sure how to dispute/identify issues.
Same here. Verification success, but routing to gpt5.2 and asking for verification again.
019c6fbc-ce2e-7a93-911b-de88bb4548c4
Same issue. Very frustrating in the middle of my work day.
<img width="396" height="167" alt="Image" src="https://github.com/user-attachments/assets/be0a31d4-fc30-40b1-89e6-77097cde79a8" />
<img width="1268" height="716" alt="Image" src="https://github.com/user-attachments/assets/22e68075-5300-495a-b4e3-7634fb26cf97" />
finally https://chatgpt.com/cyber shows me as verified, but the long wait was not an ideal customer experience at all and needs fixing.
I have the same issue right now and I completed my verification with my driver's licence.
Same problem.
On 2026-02-18 around 14:00 (JST) in Codex CLI on macOS, a normal feature-development request (not security/cyber-
related) was rerouted from gpt-5.3-codex to gpt-5.2 with this warning.
I don’t remember the exact prompt text, but it was general implementation/feature suggestions.
Also, I can’t complete Persona verification: I don’t have a physical driver’s license card (I use a digital license) and
I don’t have a passport. I tried selecting “Driver’s license” and uploading my My Number card photo, but it was rejected.
Please review and remove the flag / restore access to gpt-5.3-codex if possible.
Codex CLI version: codex-cli 0.103.0
thread ID: 019c6fcf-6040-7be0-8696-c4b2e43e5ce3
For what it's worth: I too was verified, after waiting a couple of hours, even after the webpage seemed to indicate it didn't work. I think all around, this feature needs work both on the false positive side (inevitable but seems the drag net was huge) and on the website linked, it could indicate further process.
As I reported above, I updated to codex-cli 0.104.0 again today and was successfully able to use gpt-5.3-codex without individual authentication.
Other than that, I only reported the situation via /feedback within CodexCLI and posted in this issue; I wonder if they did something to address it?
Are this issues been fixed yet? It's been 3 days ffs and there's not a single statement from them
Thanks for the bug report. We're continuing to tune our cyber safety classifiers to make them more accurate. You can read more about this here. If you see this again in the future and believe it's a false positive (i.e. you aren't doing anything related to cybersecurity), please use the
/feedbackslash command and choose "Safety Check" to report it. That will help us further tune our checks.