Connect with us

AI

Hitachi Lets Codex Read Japan’s Mission-Critical Source

Hitachi will use OpenAI’s Codex to analyze source across approximately 15,000 Japanese systems, then fold that method into HMAX, starting with banks.

Published

on

Hitachi will point OpenAI’s Codex at mission-critical source code, starting with banks, the company said on June 17, 2026. Joint forward deployed engineers will use the agent to analyze that code and make system design visible enough to migrate safely.

President and CEO Toshiaki Tokunaga said Hitachi already operates approximately 15,000 of those systems in Japan alone. What the teams learn is slated for HMAX, Hitachi’s next AI suite for social infrastructure.

Codex Will Read the Source Before Anyone Rewrites It

Hitachi, Ltd. (TSE:6501) said it would expand its work with OpenAI on two jobs that Japanese enterprises have failed to finish with people alone: aging core systems, and defense against faster attacks. The modernization half is the part that changes who holds the spec.

Both firms’ forward deployed engineer teams will run Codex against the source of mission-critical legacy systems. The stated aim is a method that runs from visualizing high-level specifications from existing code through to migration testing on the new stack. Hitachi then wants to sell that method, first to financial institutions, then across other industries.

Hitachi has long been engaged in developing systems that support mission-critical social infrastructure, with approximately 15,000 systems currently in operation in Japan alone. Modernizing legacy systems and enhancing security are critical management priorities for all enterprises seeking sustainable growth in the age of AI.

Toshiaki Tokunaga, President and CEO, Hitachi, June 17, 2026 release

The company’s own account posted the same morning.

Tadao Nagasaki, president of OpenAI Japan, called the work “an important step toward enabling the safer and more practical use of AI in Japan’s critical industries and social infrastructure.” He did not name a bank, a mainframe, or a language. The release does not say where the source will be processed, and it does not claim the code leaves Japan.

Handing social-infrastructure source to a US coding agent is still the trade this deal makes. The release never answers who owns the specs once Codex has written them down. That is the part Hitachi plans to productize.

15,000 Systems and the Cliff Japan Did Not Close

Those approximately 15,000 systems are not a side fleet. Hitachi reported revenues of 10,586.7 billion yen for FY2025, which ended March 31, 2026, with 606 consolidated subsidiaries and approximately 290,000 employees worldwide. The Japan install base is the social-infrastructure load that statement is built on.

Japan’s Ministry of Economy, Trade and Industry warned in 2018 that old, poorly documented systems would stall digital work and bring large annual losses. METI called that risk the 2025 Digital Cliff and put the upper bound at 12 trillion yen a year after 2025. The year arrived. On May 28, 2025, METI published a new report from its Legacy Systems Modernization Committee, set up because the same core systems were still in the way.

Hitachi’s June release describes the same failure in plainer words: retirement of experienced engineers has cut visibility into legacy systems, and companies cannot move while the code is a black box. Codex is being hired to read that box.

FROM THE CLIFF TO CODEX

  1. 2018: METI’s DX report names the 2025 Digital Cliff and warns of up to 12 trillion yen a year in losses if legacy systems stay put.
  2. May 28, 2025: METI issues the Legacy Systems Modernization Committee’s comprehensive report after a year of hearings.
  3. October 2, 2025: Hitachi and OpenAI sign a memorandum, announced October 21, centered on global AI data centers and on putting OpenAI models into Lumada, including HMAX.
  4. June 17, 2026: Hitachi says Codex will analyze mission-critical source, starting with financial institutions, and that insights will flow back into HMAX.

The October 2025 data center partnership was the first public pact, signed October 2 and announced October 21. It covered power, cooling, long-lead equipment, and prefabricated data-center design, with Lumada and HMAX listed as a third workstream. Eight months after that announcement, the workstream that matters for Japanese banks is no longer cooling gear. It is source code.

Hitachi Tests the Models on Its Own Stack First

Three Hitachi units split the job, and mixing them up hides the product plan. The Modernization Center of Excellence will turn the Codex method into solutions and put them inside Modernization powered by Lumada, Hitachi’s existing core-system refresh offer. Financial institutions are the first named buyers.

The Cyber CoE is the other door. Hitachi plans to take OpenAI’s cyber models through Trusted Access for Cyber, the trust layer OpenAI introduced on February 5, 2026, and which Hitachi ties to OpenAI’s Japan Cyber Action Plan. Under a Daybreak defense setup, those models are meant for vulnerability identification, ranking, fixes, and checks, with safeguards, governance, and a person in the loop.

Hitachi’s phrase for the cyber work is “Customer Zero.” The Cyber CoE will run the models on Hitachi-provided systems first, then use what it learns to harden what it sells. That is an internal proving ground, not a bank rollout.

The third unit, the Frontier AI Deployment Center, is the hub that is supposed to take insights from both tracks and apply them, in sequence, to HMAX. HMAX is not a chatbot seat. It is the suite Hitachi wants sitting on social infrastructure after the specs have been pulled out of the old code and the defenses have been tested on Hitachi’s own kit.

OpenAI now sells that cyber path as a Daybreak cyber defense stack: frontier models, the Codex harness, Codex Security, and partner workflows, with 1 billion dollars in subsidized access over six months for a defined set of defenders. The models Hitachi wants under Trusted Access for Cyber sit on the same track as OpenAI’s first critical cyber model, which the lab has been folding into Codex since the June release.

In May 2026, finance minister Satsuki Katayama said some Japanese financial institutions had already been granted GPT-5.5-Cyber under the same verified-defender program. Hitachi is arriving after that door opened, not before it.

How OpenAI Already Scripts a COBOL Pilot

Codex did not become a modernization tool on June 17. OpenAI’s own cookbook, dated November 19, 2025, walks engineers through modernizing a COBOL-based investment portfolio system, with JCL jobs, copybooks, and parity tests against the live legacy run. Engineers keep architecture and business rules. The agent inventories programs, drafts the spec, and proposes the new code.

Hitachi is wrapping that pattern in domain knowledge from years of mission-critical builds and selling it as a CoE method. The cookbook is the specimen of what “visualizing high-level specifications based on existing source code” looks like in practice.

WHAT THE CODEX PILOT ACTUALLY WRITES DOWN

  • The inventory: Codex lists COBOL programs and copybooks, the JCL jobs that call them, and the files or tables they read and write, then draws the flow in plain language.
  • The spec: It drafts a modernization technical report that restates each program’s behavior, the data model, and known traps such as date handling and packed decimals.
  • The target design: Engineers pick the new service shape, tables, and APIs; Codex scaffolds an OpenAPI file and a first-draft implementation with comments back to the original paragraphs.
  • The parity test: The old COBOL flow and the new service run on the same inputs, and outputs are compared before anyone cuts over.

That last step is the only brake the method has. If the agent misreads uncommented business logic, the error is supposed to show up as a failed parity check, not as a silent change in a payments run. Hitachi’s release promises “safe migration through enhanced visibility.” It does not publish a hit rate.

SoftBank’s Patch Desk Reached 3,000 Companies First

The day before Hitachi’s release, SoftBank Group, SoftBank Corp., and SB OAI Japan, the 50-50 Japan joint venture with OpenAI, announced Patching as a Service. On July 14, 2026, SoftBank Corp. and SB OAI Japan said the service was in full launch and expanding to 3,000 eligible Japan-based companies that support critical infrastructure.

SoftBank ran the tool on a first set of firms and published the yield. Assessments found an average of approximately 280 potential vulnerabilities per 10 million lines of source code, and 25% of those were classed as high-risk and possibly in need of an immediate fix. A dedicated Enterprise AI Cyber Defense Office was due to open on July 16, 2026, with a team of approximately 1,000 people to deliver the service and consult.

SOFTBANK’S FIRST PATCH NUMBERS

  • The install base: Full launch on July 14, 2026, aimed at 3,000 eligible companies in Japan.
  • The find rate: Approximately 280 potential vulnerabilities per 10 million lines of source, with 25% classed as high-risk.
  • The desk: Approximately 1,000 staff, after SoftBank first ran the same process on its own systems.
  • The next offer: A separate modernization service for refactoring, language moves, and cloud migration, to be sold alongside the patches.

A trading company quoted in SoftBank’s launch note said yearly assessments used to take about two months, and that the source-code report arrived two days after work began. That is the cyber half of OpenAI’s Japan pitch, already billed as a service, while Hitachi’s Codex modernization method is still being built.

SoftBank’s planned modernization add-on is the same job Hitachi assigned to its Modernization CoE: reorganize source, move languages, lift old on-prem stacks. Two Japanese distributors are now pointing the same US agent at the same cliff. Hitachi’s edge is the approximately 15,000 systems it already runs. SoftBank’s edge is that it shipped.

Nine Thousand NTT Data Desks Already Run Codex

NTT Data Group got there first as a seller. On April 24, 2025, it said it would become OpenAI’s first sales agent in Japan for ChatGPT Enterprise, aiming at 100 billion yen in OpenAI-related sales by the end of fiscal 2027, and that it would run an acceleration program for 100 large companies. On July 22, 2026, OpenAI said NTT Data Group had expanded Codex to approximately 9,000 employees and had cut incident analysis to 30 minutes with the agent.

In October 2025, OpenAI and Japan’s Digital Agency said Gennai, a tool on OpenAI technology, would go to government staff. The Hitachi deal does not replace those seats. It tries to take the same models into the source of core systems that NTT Data, SoftBank, and Hitachi have all been paid for decades to keep alive.

OPENAI’S JAPAN INSTALL BASE

Partner Date What they took Where it stood
NTT Data Group April 24, 2025 First Japan reseller of ChatGPT Enterprise Codex with approximately 9,000 staff as of July 22, 2026
Japan Digital Agency October 2025 Gennai for government employees Public-sector use cases on OpenAI technology
Hitachi and OpenAI MoU October 2, 2025 (announced October 21) AI data centers plus Lumada and HMAX Follow-on work that became the June Codex plan
SB OAI Japan and SoftBank June 16 and July 14, 2026 Patching as a Service Full launch to 3,000 eligible companies
Hitachi June 17, 2026 Codex on legacy source, TAC cyber access Method still being built, banks first

Japan is funding Japan’s national AI model push on a separate track. Hitachi’s June choice still sends the hard part of the cliff, reading the source, through OpenAI’s agent. The two policies can coexist on paper. They do not point at the same stack.

Banks Go First and the Specs Travel With Them

Financial institutions are the first industry Hitachi named because that is where the unread COBOL still clears money. Katayama’s May 2026 confirmation that some banks already had GPT-5.5-Cyber means the same sector is also the first customer for OpenAI’s defensive models. Hitachi is offering those banks a second pass: not only patches, but a reconstructed spec of the systems the patches sit on.

No bank is named in the June 17 release. No go-live date is named. The Modernization CoE still has to turn a joint FDE method into a Lumada product, and the Cyber CoE still has to finish Customer Zero on Hitachi’s own kit. Until those two things exist, the 15,000-system claim is an inventory, not a migration.

HMAX is where Hitachi says the extracted specs and the cyber lessons are supposed to land. The first bank that lets Codex read its core will also be feeding that suite. That is the deal past the footprint story, and it still has no public client name.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending