OpenAI added computer use to the Agents API on September 29, 2026, extending a managed agent platform first announced in public beta on September 10. Developers can now connect an agent workflow to browser interactions, while the application remains responsible for important access and approval decisions.
Separate the harness from the environment
The original announcement offers OpenAI’s managed Codex harness with a choice of execution environments. The computer-use guide describes the browser capability added later. These are two milestones in one platform, not a new API created at DevDay.
A harness coordinates reasoning, context, and tools. An environment is where code or browser actions run. Treating them separately makes a deployment review clearer: identify where files reside, which network destinations are reachable, how credentials enter the session, and who can inspect artifacts after the task ends.
The application still owns authorization
A browser can interact with a site that has no convenient API, but it also exposes a larger interface to an agent. A page can contain untrusted instructions, and an authenticated session can expose actions that go beyond the user’s task. Define which sites and operations are permitted before starting work.
Use test accounts and synthetic records for the first evaluation. Include sign-in failure, an expired session, and a page that tries to redirect the agent’s goal. Require human review for commitments such as sending messages, changing access, or spending money. A screenshot showing a completed form is not evidence that the action was authorized.
Parallel work needs bounded ownership
Managed multi-agent execution can be useful for independent investigations, but several agents writing the same resource can create conflicts or duplicate actions. Give each worker a clear assignment and one coordinator responsibility for consequential writes. Set limits on concurrent work, elapsed time, and tool spend.
Record a result’s evidence and failure state as well as its final text. If a subtask fails, the coordinator should report what remains unresolved rather than turn an incomplete workflow into success.
AWS hosting is a distinct deployment option
Amazon Bedrock Managed Agents provides an AWS deployment path for related capabilities. Evaluate it against the account, data, and operational boundaries your organization needs rather than assuming all managed environments have identical controls.
The practical starting point is one workflow with an observable completion condition and a recoverable failure path. Managed infrastructure can reduce engineering work; it does not remove the need to specify what the agent may do.