AI Coding Tools Roundup: Codex CLI Ships Voice Mode, Copilot Adds Local Sandboxing

It's a quieter day than yesterday's simultaneous Claude Opus 5.5 launch, but three of the biggest names in AI-assisted coding still shipped meaningful updates on September 22–23, 2026: OpenAI's Codex CLI picked up voice mode and a full terminal UI, GitHub Copilot's desktop app got a new local sandboxing feature, and Claude Code landed a stability release. Here's what's new since yesterday's roundup.
OpenAI Codex CLI 0.156 Adds Voice Mode, a Fullscreen TUI, and a Usage Dashboard
OpenAI's Codex CLI rust-v0.156.0, released September 22, is one of the bigger feature drops the tool has had in months. Voice conversations are now enabled by default, with an F8 toggle, a /voice settings picker, and bundled audio runtimes for Linux and Windows. An optional fullscreen terminal UI, launched with /tui, adds transcript search, mouse text selection, and right-click copying — plus six new terminal themes and support for Mermaid diagrams and math notation in responses.
The release also adds a /usage analytics dashboard for exploring account usage, token totals, and plugin or skill activity; task filtering by status; and worktree session creation from the agent command center, with worktree support now enabled by default. On the security side, 0.156.0 closed sandbox isolation gaps involving Windows inbound connections and macOS file-handle writes. A same-day hotfix, rust-v0.156.1, added GPT-6 Sol and GPT-6 Luna to Codex's own model picker — separate from their earlier rollout inside GitHub Copilot — with the rate-limit switch prompt now recommending Luna as the cheaper fallback.
GitHub Copilot App Ships Local Sandboxing
GitHub shipped local sandboxing in the GitHub Copilot app on September 23, now in public preview. It lets developers set per-project sandbox policies for local agent sessions across three categories: filesystem access (read/write, read-only, or blocked folders), network access (outbound internet and local network), and credentials (Git and GitHub CLI authentication). Sandboxing is off by default — enable it per project in app settings under "Sandbox new sessions," or turn it on mid-session with /sandbox on. Enterprise admins can enforce stricter policies than individual projects set, and if the host OS can't enforce a requested policy, the session fails closed rather than running unprotected. It currently covers local sessions only — not cloud or remote Copilot sessions.
Claude Code v2.1.281 Focuses on Stability
Anthropic's Claude Code v2.1.281, released September 23, is a fixes-focused follow-up to Opus 5.5's debut a day earlier. Sessions that got stuck retrying "unexpected tool_use_id" errors now self-heal via transcript repair; MCP servers configured as http no longer time out after roughly five minutes; and auto mode no longer retries an action endlessly when a safety check declines to review it. The update also fixes Write calls failing validation when a model sends slightly incorrect parameter names, along with several dialog keyboard and MCP connection-handling fixes.
What It Means for Developers
None of today's changes are as flashy as a new flagship model, but they matter for day-to-day use: Codex's voice mode and /tui push it further toward being a full terminal environment rather than just a chat loop, and its worktree-by-default change is worth checking if you rely on specific branch layouts in CI. Copilot's local sandboxing is a meaningful risk-reduction step for anyone running agentic coding sessions with broad filesystem or network access — worth turning on for any project where an agent might run unreviewed shell commands. And Claude Code's v2.1.281 fixes are the kind of quiet reliability work that matters most in long-running agent sessions and MCP-heavy setups, even if none of it makes a headline on its own.
Resources & References
Comments
Share your thoughts and join the conversation
