Product and guide updates
Dated changes to OpenAI, Claude, GitHub and this handbook, with sources and a practical check for each. Entries describe the situation at the time; check current documentation before changing your setup.
Latest entry: Sep 17, 2026
Claude Code: check synced skills before using them on a matter
Claude Code 2.1.275 adds account skill and plugin syncing to signed-in terminal sessions. A skill appearing in the list does not establish that your organization approved it.
Sources checked
Affected pages
What this means for your work
Open /skills and check the source of each skill you intend to use. Read its instructions and test it with invented records. Ask your administrator to disable account syncing if it is not approved; do not assume a local edit changes the account copy.
Claude Code: inspect diagnostic records before sharing
Claude Code 2.1.274 and 2.1.275 fixed cases where connection errors and plugin records could display access tokens or passwords. Updating does not remove information already saved or shared.
Sources checked
Affected pages
What this means for your work
Ask IT to apply an approved release containing these fixes. Before sending logs or screenshots to support, check for credentials and matter details. If a credential may have been disclosed, stop sharing the record and follow your organization’s incident process with the security team.
Claude Code: recheck your organization’s access restrictions
Claude Code 2.1.271 and 2.1.273 fixed cases where organization settings were not applied as intended. The fixes include restrictions on connected services and skills synced from claude.ai that remained available after an organization disabled them.
Sources checked
Affected pages
What this means for your work
If your organization manages Claude Code centrally, ask IT to install the approved update and test a permitted service alongside one the policy blocks, using harmless test material. Check that disabled skills are unavailable and repeat the check after changing accounts. If a blocked service remains accessible, stop using that connection for matter work until the restriction is verified.
GPT-5.5: review saved tasks before 14 October
OpenAI announced that GPT-5.5 will retire from ChatGPT, ChatGPT Work and Codex on 14 October 2026. The announcement does not retire the model from the OpenAI API.
Sources checked
Affected pages
What this means for your work
If your team uses GPT-5.5, ask the workspace administrator to check saved model choices and scheduled tasks before that date. For Codex signed in through ChatGPT, OpenAI recommends GPT-5.6 Sol. Confirm that affected staff can use it, then rerun a familiar task with synthetic records and inspect the result before relying on the replacement.
Claude Code: check which files it can change
Claude Code 2.1.269 corrected how it applies organization settings and checks permission to change files. It also added a way to run tests supplied by a plugin.
Sources checked
Affected pages
What this means for your work
If your team uses Claude Code, ask your IT administrator to check that it cannot change files outside the folders you have approved. Passing a plugin test does not mean its legal analysis is correct: you still need to check the documents and authorities it relies on.
GitHub: control who can change reused files
GitHub added a setting for files saved between automated runs, called caches. Allowing changes to these files can override existing protections.
Sources checked
Affected pages
What this means for your work
This concerns teams that use GitHub to run automated work. Ask the person maintaining those workflows to check who can replace the saved files that later runs reuse. A workflow should not gain that permission merely because someone copied a setting from another project.
A new option for teams building an AI assistant
OpenAI released a beta version of the Agents API, a service developers can use to build assistants that carry out tasks.
Sources checked
Affected pages
What this means for your work
If your team is building an AI assistant, agree one limited task for the first trial—for example, listing dates in a made-up document. Ask the developer to show what happens when information is missing or a step fails. A person should approve any message it sends or change it makes to a matter record.
Some applications may lose their connection to Codex
Codex removed the connection commands codex mcp-server and codex-mcp-server. This does not remove Codex’s separate ability to connect to external tools.
Sources checked
Affected pages
What this means for your work
If another application uses Codex through either of these removed commands, ask its maintainer whether the connection still works. Pause the affected work until it is checked. The experimental app-server is not a supported production replacement.
Custom AI tools need testing before switching to Astra
Astra requires a different setup for some developer-built tools. Changing the model name alone may leave an existing application unable to complete its work.
Sources checked
Affected pages
What this means for your work
If your firm has a custom AI tool, ask its developer to check compatibility before switching it to Astra. Try a made-up task with missing information and one where a connected tool fails. Check that the result clearly reports the problem rather than presenting unfinished work as complete.
Older AI assistants and transcription tools need replacement
OpenAI closed the Assistants API on 26 August. It also announced that whisper-1 and GPT-4o transcription models would close on 26 February 2027.
Sources checked
Affected pages
What this means for your work
Ask the person maintaining your custom AI tools whether any still depend on the retired Assistants API or the transcription models listed above. Old conversation history can no longer be retrieved from that API; only previously saved messages are available for migration. Before accepting a replacement transcription tool, compare its text with a made-up recording and check names, dates and who said what.
An incoming message can now start an AI task
Eligible plans gained tasks triggered by Gmail, Slack or GitHub activity. Closely spaced events may be combined; these tasks cannot also run on a timetable.
Sources checked
Affected pages
What this means for your work
Before letting a new email or message start an AI task, choose exactly which inbox, channel or project it may read. Test with made-up messages, including duplicates sent close together. Have a person approve outgoing messages and changes to matter records before they happen.
Computer History can record activity beyond your chat
This optional macOS feature saves app and website activity as memories and a timeline. At launch, it excluded the EEA, UK and Switzerland; access also depended on plan and workspace settings.
Sources checked
Affected pages
What this means for your work
This feature can record activity across apps and websites, so get your organization’s approval before turning it on. Check which apps and sites are excluded, how to pause recording and how to delete saved activity. Try it without client material first; permission to use chat does not cover background recording.
Record & Replay became available in more European countries
The July rollout added the EU, UK and Switzerland. Record & Replay still required macOS and an enabled Computer Use feature; the announcement did not cover other recording features.
Sources checked
Affected pages
What this means for your work
If you want to record a task for later reuse, first check that Record & Replay is available and approved in your workspace. Practise with a made-up document and watch the recording for unintended content before reusing it. This announcement does not establish availability of the separate Computer History feature.
Codex moved into the ChatGPT desktop app
The July announcement brought Codex into ChatGPT on macOS and Windows, with existing projects, settings and workflows retained after the update.
Sources checked
Affected pages
What this means for your work
When following a Codex lesson, open the Codex section of the desktop app and select the right project. Before opening client files, check the signed-in account, the folder you are working in and which tools have access. Moving into the same app does not extend your organization’s permission to use other features.
Claude Code: permission to install plugins still matters
Version 2.1.195 fixed consent checks for external plugins and problems restarting background tasks.
Sources checked
Affected pages
What this means for your work
Ask your administrator to demonstrate that an unapproved plugin cannot install. When restarting a task, check what it completed before using its result.
Remote Codex work and saved Claude answers need separate checks
Codex Remote launched on 25 June. Separately, Claude Code 2.1.193 added logging of answers that could follow an existing prompt-logging setting.
Sources checked
Affected pages
What this means for your work
Confirm which computer will run remote work. Ask your administrator whether Claude’s answers are now saved in logs, and check a made-up example against your retention policy.
Claude Code: restrict access to passwords and access keys
Version 2.1.187 added controls over whether commands can read files and settings containing login credentials.
Sources checked
Affected pages
What this means for your work
Ask your IT administrator to test these restrictions with dummy credentials. Confirm that access is refused before allowing the tool near real passwords or access keys.
Claude Code: stopped tasks should stay stopped
Version 2.1.191 fixed background tasks restarting unexpectedly, organization settings not refreshing, and temporary connection failures.
Sources checked
Affected pages
What this means for your work
Ask your administrator to test a stopped task and an interrupted connection with made-up files. Confirm the task stays stopped and any incomplete work is clearly reported.
Later comments should not change an approved AI review
A Claude Code Action fix excluded review comments added or edited after the event that started the review.
Sources checked
Affected pages
What this means for your work
If your team uses Claude to review changes in GitHub, ask the maintainer to test that a later comment cannot become a new instruction for an already-started review.
Recording tasks and approving actions are separate decisions
Record & Replay launched on macOS excluding the EEA, UK and Switzerland initially. Separately, Claude Code 2.1.183 fixed notifications incorrectly approving actions awaiting a person’s decision.
Sources checked
Affected pages
What this means for your work
Check today’s recording availability before trying a made-up task. If you use Claude automations, ask the maintainer to show that a notification cannot approve an action for you.
An interrupted Claude answer may still be incomplete
Claude Code 2.1.179 kept partial answers after a lost connection. A separate Codex expansion covered the EEA, UK and Switzerland, with Memories initially off there.
Sources checked
Affected pages
What this means for your work
Before using a recovered draft, compare the documents and questions it covered with your original request. Check current regional availability and your organization’s memory settings separately.
Claude’s delegated tasks need their own permission checks
Version 2.1.178 fixed ignored restrictions on tools used by delegated tasks and added more specific permission rules.
Sources checked
Affected pages
What this means for your work
Ask your administrator to test one permitted and one forbidden action in a made-up project, including a delegated task. Confirm both follow the intended limits.
Claude’s GitHub integration could allow more commands than intended
A Claude Code Action fix stopped some narrowly written permissions from being interpreted as unrestricted command access.
Sources checked
Affected pages
What this means for your work
Ask the integration maintainer to confirm the fix is installed and demonstrate that an unrelated command remains blocked. A permission setting that looks restrictive is not enough.
Codex browser testing can expose more than the visible page
The June update added browser debugging tools and fixed scheduled tasks to follow their selected approval settings.
Sources checked
Affected pages
What this means for your work
Use a page without client material when testing browser access. For scheduled work, ask the maintainer to demonstrate that actions needing approval actually pause for a decision.
An AI safety score does not check legal accuracy
OpenAI added content-moderation scores to supported generation requests. These classify content; they do not verify legal reasoning or citations.
Sources checked
Affected pages
What this means for your work
If your tool uses these scores, ask what each score measures. Continue checking the underlying documents and legal sources, and avoid keeping unnecessary copies of client text.
Publishing a Codex site and estimating running costs need care
Codex Sites entered preview in June. Separately, eligible API computing sessions moved to per-minute billing with a five-minute minimum.
Sources checked
Affected pages
What this means for your work
Review every page before publishing, including who can access it. For a custom AI tool, ask the developer for costs based on actual running time and current rates.
Connecting Codex to internal sources still needs approval
OpenAI introduced a private connection service for enterprise tools. Codex 0.132.0 also added controls over the format of results when command-line work resumes.
Sources checked
Affected pages
What this means for your work
Before connecting an internal source, agree which records and actions are allowed with your administrator. Check a resumed test result contains the required fields; private access alone is not authorization.
Resuming Claude work requires checking what it can access
Version 2.1.144 made background tasks available to resume and fixed connected tools missing from longer tool lists.
Sources checked
Affected pages
What this means for your work
Before continuing a paused task, confirm its source files and unfinished work. Ask the maintainer whether all expected tools are visible; a missing tool can leave part of the task undone.
Background tasks may edit your main files
Claude Code 2.1.143 added an option for background tasks to edit the main working copy and improved retention of task settings.
Sources checked
Affected pages
What this means for your work
Before leaving a task running, confirm which copy it may change. Ask the maintainer to check that its access limits remain in place when it resumes.
Material under review must not become the reviewer’s instructions
Codex Action guidance clarified that instruction files inside proposed changes are untrusted material, even when named AGENTS.md.
Sources checked
Affected pages
What this means for your work
If your team uses AI to review GitHub changes, ask the maintainer where its trusted instructions come from. Review instructions inside submitted files as content, not commands to follow.
Finding a task in a project list does not restrict its access
Claude Code 2.1.141 added a project-folder filter for task lists and preserved approval settings when tasks moved into the background.
Sources checked
Affected pages
What this means for your work
Open the task and check its actual folder and permissions before continuing. A filtered list helps you find work; it does not keep that work inside the folder.
Tell Claude what counts as finished
Claude Code 2.1.139 added goals with explicit completion conditions and changed how certain automatic checks can run commands.
Sources checked
Affected pages
What this means for your work
Define a result you can inspect and when missing evidence should stop the task. Ask the maintainer to test any changed automatic checks; continued activity does not prove completion.
Permission to run an action is not approval of the result
The May guidance clarified that Codex Auto-review assesses certain permission requests. It does not establish legal accuracy or approve publication.
Sources checked
Affected pages
What this means for your work
Check the completed work yourself: read changed passages and verify their sources. Keep permission to perform a task separate from the decision to use or publish its result.
GitHub preview lets teams describe automated tasks in writing
This May catch-up entry covers February’s Agentic Workflows preview, which turns written task instructions into GitHub automations with limited permissions.
Sources checked
Affected pages
What this means for your work
If your team trials this, agree what starts the task and what it may change. Have the maintainer demonstrate those limits in a test project before using working files.
GitHub can check for exposed access keys before changes are shared
GitHub made scanning through its connected tools generally available for repositories with Secret Protection enabled.
Sources checked
Affected pages
What this means for your work
Ask your maintainer to scan proposed changes for passwords and access keys before sharing them. A clean scan does not mean the files are free of confidential client information.
A connected research tool may not cover the law you need
The May review clarified that a database connection does not establish coverage of a jurisdiction, date range or later treatment of a legal authority.
Sources checked
Affected pages
What this means for your work
Record which sources were searched. Open each authority you rely on and mark any missing current-law or later-treatment check as unfinished research.
Check the actual account and model before starting a pilot
The May review replaced dated OpenAI model and plan advice with current documentation links. Old model names in an article do not establish present availability.
Sources checked
Affected pages
What this means for your work
Record your account plan, model, tools and data settings. Test with made-up material, and confirm separately what API access and charges your project needs.
Make sure Claude starts from the right version of your files
Version 2.1.133 added a choice of starting version for a separate working copy. That choice affects whether recent, unshared changes are included.
Sources checked
Affected pages
What this means for your work
Tell the person setting up the task which version it should use. Check a known recent change is present before asking Claude to edit the copy.
Decide what an unattended Codex task may change
The May review added guidance on recurring tasks, separate working copies and approval settings for work that runs without you watching.
Sources checked
Affected pages
What this means for your work
Name the project, permitted changes and stopping conditions. Run the task once with made-up files and check how it reports work it could not complete.
Test AI transcripts against what was actually said
OpenAI’s May releases included new voice, transcription and translation models. The launch record is not a recommendation to use those versions today.
Sources checked
Affected pages
What this means for your work
Use a made-up recording to check names, amounts, negatives and interrupted sentences. Confirm current language support before considering use with clients.
Claude can propose GitHub changes, but people still review them
This entry records guidance for using Claude Code through GitHub Actions to perform tasks started by configured events or instructions.
Sources checked
Affected pages
What this means for your work
Ask the maintainer who can start a task and what it may change. Read the complete revised page and its sources before accepting an editorial change.
How this handbook turns product news into guide changes
The May entry introduced a process for checking product changes, revising affected guidance and completing translations before treating an update as finished.
Sources checked
Affected pages
What this means for your work
Use the linked guide and sources to check an entry. If they disagree, send the page and disputed passage through Contact so the claim can be reviewed.
Subscribe to our newsletter
Legal AI news and practical tips, once a week.
Confirm by email; unsubscribe anytime · Beehiiv · Privacy policy.