AI companies want to run your business. They can't always run their models. OpenAI launched Presence, a corporate software tool to run AI agents across business systems, while simultaneously disclosing that its GPT-5.6 Sol and an unreleased model escaped a testing environment and hacked into Hugging Face's platform. The incident, described by OpenAI as an "unprecedented cyber incident," raises questions about control over powerful AI models as companies push to embed them in enterprise operations. OpenAI wants to help companies run AI agents across their systems. On a completely separate note, its models are so powerful that they broke containment. Those two sentences encapsulate the weird AI-driven environment we're in. AI companies are aggressively pushing for market share while also publicly acknowledging they're not always fully in control. Let's start with OpenAI's latest pitch: Presence https://www.businessinsider.com/openai-presence-corporate-software-customer-service-sales-2026-7 . It's designed to help companies run AI agents by connecting them to internal corporate data, policies, existing software, and workflows. The end result is more automation for things like customer support, sales, and fixing billing issues. BI's Stephen Council and Alistair Barr describe it as "OpenAI trying to move beyond selling access to AI models and into more parts of the corporate software market." Now consider the other news OpenAI disclosed this week: Its models hacked into another company's system. On Tuesday, the startup posted about an " unprecedented cyber incident https://www.businessinsider.com/smart-people-react-openai-hugging-face-hacking-cybersecurity-incident-2026-7 ." While trying to solve a cyber challenge, OpenAI's GPT-5.6 Sol and an unreleased model escaped a testing environment, accessed the internet, and hacked into Hugging Face, an open-source AI platform. There are a few ways to look at the Hugging Face hack. The positive spin: The breach was detected and eventually contained. Hugging Face says it found no evidence that its public models or datasets were tampered with, though it's still assessing things. OpenAI has been transparent about the incident. And let's be real: It's pretty impressive how powerful these models are getting. The doomsdayer: We are now building AI models we can't fully control, even when kept in a test environment. And there wasn't malicious intent behind this one. Imagine if the models were instructed to do something bad. The skeptic: AI companies love playing the hype game. A few months ago, Anthropic said one of its models was too powerful for a wide release https://www.businessinsider.com/anthropic-mythos-latest-ai-model-too-powerful-to-be-released-2026-4 . In the hyper competitive world of AI, security concerns can be spun as a flex on how powerful your model is. Tom Van de Wiele, an ethical hacker and security advisor, told BI he's skeptical about some of the claims and is waiting to see more details about the incident https://www.businessinsider.com/hugging-face-hack-openai-rogue-ai-china-cybersecurity-2026-7 . The cybersecurity drama: Hugging Face used a Chinese model to investigate the attack, but it wasn't its first choice. Other frontier models the company used couldn't fully analyze the hack because of their guardrails. That'll add fuel to the fiery debate over the limitations regulators want to impose on AI models https://www.businessinsider.com/anthropic-midterm-donation-spending-public-first-action-2026-7 . And it adds another wrinkle to concerns about Chinese models overtaking the US https://www.businessinsider.com/white-house-kimi-k3-moonshot-ai-distillation-2026-7 . Regardless which argument lands with you, the wider point still stands: AI companies are pushing to be deeply embedded in corporate systems while simultaneously acknowledging they don't always have a handle on what their tech will do.