Legal Grew 108x. Engineering Grew 5x. Only One of Them Has Code Review.

TV
Thiago Victorino
7 min read
Legal Grew 108x. Engineering Grew 5x. Only One of Them Has Code Review.

Since February, weekly active enterprise Codex users grew 108x in legal, 41x in sales, 41x in recruiting and 26x in marketing, compared with 5x in engineering. Those are multipliers, not percentages, and they come from OpenAI’s own enterprise telemetry across more than 10 million messages.

The growth story is the boring half. The interesting half is which functions are growing, and what those functions do not have.

Engineering’s 5x is the slowest number on the list, and engineering is also the only function on that list where an agent’s output passes through a pull request, a diff a second person reads, a test suite, a deployment gate and a revert button. Legal grew more than twenty times faster into a workflow where the equivalent of all five of those controls is a partner glancing at a document before it goes out.

Whose Numbers These Are

Before anything is built on top of these figures, the provenance matters. This is OpenAI’s own customer telemetry, published as an unbylined company announcement in August 2026. There is no external control group. The customers are self-selected, and usage is the metric OpenAI monetizes. Treat every number here as vendor-reported, useful for direction and shape, not as an independent measurement of enterprise AI adoption.

The direction is still worth taking seriously, because the shape is unusual. A vendor with an incentive to make coding agents look dominant published a dataset where the coding function grew the least. That is the sort of number that survives its own bias.

Software engineering spent thirty years building an apparatus for handling work produced by someone whose judgment you cannot fully verify. Version control gives you a before state. Pull requests force a second reader. Continuous integration runs a mechanical check nobody has to remember to run. Staged deploys limit the blast radius of a bad change. Rollback makes the worst case recoverable in minutes.

None of that scaffolding was built for agents. It was built for junior developers, for tired seniors, for people at 4pm on a Friday. Agents inherited it by accident, and that accidental inheritance is why the function with the highest-stakes automated output is also the function with the most mature containment.

Now look at the functions growing fastest.

Legal produces contracts, memos and filings. The artifact goes from an author to a reviewer whose review is a read-through, and then it goes external, where it becomes binding. There is no diff between draft eleven and draft twelve that a machine checks. Recruiting produces screening decisions and outreach, where the failure mode is a pattern of exclusion nobody sees until a regulator or a plaintiff sees it, which is the algorithmic monoculture problem applied to a hiring funnel running at 41x volume. Sales produces commitments to customers. Marketing produces public claims.

Each of those functions is now absorbing agent output at five to twenty-one times the rate of the function that has the review machinery. Agents are oldest in engineering and newest everywhere else. The unguarded surface is everywhere else.

The Frontier Cohort Is a Usage Metric

OpenAI splits its customers into cohorts, and the definition deserves reading literally: “Each month, we rank enterprise customers by output tokens per active user. Frontier firms are those in the top 10% that month, while typical firms fall between the 45th and 55th percentiles.”

So “frontier” means high token consumption per user. It does not mean good outcomes, measured quality, or governed deployment. With that in mind, the reported spread is still striking: as of June, frontier firms generated 8.3x as many output tokens per active user as typical firms, up from a 2.6x spread in January. The distance roughly tripled in five months.

Two more figures fill in what the frontier cohort actually does differently. Among weekly active users, 21% at frontier firms use Plugins and 19% use skills, against 9% and 3% at typical firms. Skills adoption is more than six times higher. That is the difference between individuals prompting well and an organization encoding a workflow once so that everyone runs the same one. The frontier firms are not just consuming more tokens. They are consuming them through shared, reusable structures.

And the adoption is bottom-up: six months after adoption, early-career employees sent 13 more messages per week than executives. The people accumulating the most agent hours are the ones with the least institutional authority to define how agent output gets checked.

Codex at 64% Is Where the Governance Conversation Already Happened

As of June, Codex generated 64% of combined Codex and ChatGPT output tokens among enterprise customers. Most of the token volume is flowing through the coding surface, which is also the surface where the review apparatus exists.

That is a comfortable statistic for anyone who assumes governance follows volume. It does not. The 5x function carries the volume and the controls together. The 108x function carries neither, and its growth curve is the steepest one in the dataset.

OpenAI’s own stated agenda names the missing piece directly. The enterprise playbook it describes is to “connect agents to the context and tools needed to complete valuable work; establish clear permissions, review, and governance; and help employees turn effective individual workflows into shared ways of working.” Permissions, review and governance are listed second, ahead of scaling workflows. The vendor is telling its customers the control layer comes before the shared-workflow layer.

For legal specifically, the volume is real and it is arriving through more than one vendor. We wrote about Harvey’s numbers on legal agents at scale earlier. What this dataset adds is the comparison: legal is not simply adopting fast in absolute terms, it is adopting at more than twenty times engineering’s rate from a standing start, inside a function whose entire quality system is one human reading a document.

Do This Now

Take one non-engineering function where agent use is already real, and give it the two controls that cost the least and catch the most.

Control one: a durable record of what the agent produced and who accepted it. Not the chat transcript. A stored artifact with the prompt, the output, the human who approved it and the timestamp, in a system your legal team can query two years from now. When an agent-drafted clause becomes a dispute, that record is the only thing standing between your company and reconstructing a conversation from memory. The reason to do this before you need it is the same reason audit logs became legal evidence: the retention decision is made long before the subpoena.

Control two: a named second reader for a defined class of output. Pick the class by consequence, not by volume. External commitments, anything that touches a candidate or a customer, anything with a signature line. One person, named, whose review is recorded. This is the pull request, rebuilt in the cheapest possible form, for a function that never had one.

Both take a week. Neither requires a platform purchase. The alternative is discovering, at 108x, which artifacts nobody was reading.

The verification work does not disappear when agents get faster. It moves and concentrates, and right now it is concentrating in four functions that have no idea it landed on them.


This analysis synthesizes From assistance to execution: How enterprises put AI to work (OpenAI, August 2026), an unbylined company announcement reporting OpenAI’s own enterprise customer telemetry.

Victorino Group helps companies extend engineering-grade review controls to the legal, sales and recruiting functions now running agents without them. Let’s talk.

All articles on The Thinking Wire are written with the assistance of Anthropic's Opus LLM. Each piece goes through multi-agent research to verify facts and surface contradictions, followed by human review and approval before publication. If you find any inaccurate information or wish to contact our editorial team, please reach out at editorial@victorinollc.com . About The Thinking Wire →

If this resonates, let's talk

We help companies implement AI without losing control.

Schedule a Conversation