READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

OpenAI Acquires Cloud Startup Ona to Power Long-Running AI Coding Agents

OpenAI Acquires Cloud Startup Ona to Power Long-Running AI Coding Agents
OpenAI announced Thursday it will acquire Ona, formerly Gitpod GmbH, a startup that runs AI agents in persistent cloud sandboxes. The deal is designed to let OpenAI's Codex coding assistant handle tasks spanning hours or days, not just a single session. Financial terms were not disclosed, and the deal has not yet closed.

What Ona Actually Does

Most AI coding agents today run on a developer's local machine. When that machine shuts down, the agent stops. That's a hard ceiling on what the agent can accomplish.

Ona, officially registered as Gitpod GmbH, built a platform that eliminates that ceiling. Its cloud-based sandboxes keep AI agents running continuously, independent of whether the developer's workstation is on. According to SiliconAngle, Ona sandboxes also delete themselves when no longer needed, reducing the window for data theft that lingers in local environments.

The security architecture goes further. Ona can block malicious applications using cryptographic hashing, meaning it identifies a blocked program even if someone renames it, moves it, or hides it inside a script. The platform can also cut off outbound connections to suspicious servers and wall off file system areas containing sensitive credentials like encryption keys.

Why OpenAI Wants This

Codex launched in its current cloud-native form in 2025. As of June 11, 2026, it serves more than 5 million weekly active users, up from 3 million in April, according to CNBC. OpenAI's ambition is clearly larger than coding shortcuts for individual developers.

OpenAI's Core Products Lead Thibault Sottiaux put it plainly in the acquisition announcement: "Enterprises want powerful agents that can do real work while meeting the security and control requirements of their environments."

The industries OpenAI is targeting — finance, healthcare, government — cannot send sensitive code and internal logic to infrastructure they don't control. Ona's platform lets agents run inside a customer's own AWS or Google Cloud environment, according to IBTimes. That directly addresses the compliance objection that has kept regulated enterprises on the sidelines.

Once the deal closes, Ona's entire team will join OpenAI and work directly on the Codex product.

The Competitive Context

OpenAI is not making this move in a vacuum. Anthropic has had a strong run over the past year, driven in part by Claude Code, its own AI coding assistant. Anthropic does not disclose user numbers, so a direct comparison is impossible, but the competitive pressure is real enough that OpenAI has been offering free Codex enterprise usage credits and one-click migration tools to attract business customers, according to IBTimes.

This is OpenAI's second acquisition in three months. In March, the company bought Promptfoo Inc. to beef up the cybersecurity features of its OpenAI Frontier platform, according to SiliconAngle. The pattern is consistent: OpenAI is buying the infrastructure layer, not just the model layer.

OpenAI also confidentially filed its IPO prospectus with the Securities and Exchange Commission earlier this week, according to CNBC, days after Anthropic submitted its own confidential filing. Both companies are moving toward public markets while spending aggressively on product and acquisitions simultaneously.

The Legitimate Concern Worth Taking Seriously

Critics of AI coding agents have a real point. Giving an AI agent persistent, long-running access to cloud environments, codebases, internal APIs, and sensitive credentials is a materially different risk profile than asking a chatbot a question. If an agent is compromised, misconfigured, or simply wrong in its autonomous decisions over a multi-day task, the blast radius is larger than a bad code suggestion.

Ona's security architecture addresses some of this, but the protections are only as strong as their configuration. An enterprise that deploys Codex with Ona-backed sandboxes still has to configure those sandboxes correctly, monitor agent behavior, and set appropriate access limits. The technology reduces certain risks, it doesn't eliminate the underlying question of how much autonomy to hand an AI system in a production environment.

OpenAI's own announcement acknowledges this tension, noting that Ona will enable users to "review the work of agents and provide input when necessary," per SiliconAngle. Human-in-the-loop oversight remains the stated design, not full autonomy.

What Comes Next

The acquisition is still subject to regulatory approval and customary closing conditions. Until it closes, Ona and OpenAI are expected to operate as separate, independent companies, according to IBTimes.

The open question regulators and enterprise buyers will be watching: whether OpenAI's confidential IPO filing, once public, will show whether this acquisition pace is being funded sustainably or whether the company is burning toward a public offering before the cash math forces it to slow down.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
CNBCOpenAI to acquire Ona to support its AI coding assistant, Codex
unknown
siliconangleOpenAI acquires AI agent orchestration startup Ona - SiliconANGLE
unknown
ibtimesOpenAI Buys Secure Cloud Startup Ona To Assist Its AI Coding Assistant, Codex | IBTimes
unknown
benzingaOpenAI Buys Cloud Execution Startup Ona To Scale Agent Workloads - Benzinga