OpenAI Presence screenshot of a sample customer interaction
News

OpenAI Presence Pitches 'Trusted' AI Agents to Enterprises a Day After Owning Hugging Face Hack

2 MINUTE READ|Digital WorkplaceDigital Workplace|Jul 22, 2026
Siobhan Fagan avatar
By
SAVED
OpenAI launched Presence, an enterprise agent product built on trust and guardrails, a day after admitting its own model autonomously hacked Hugging Face.

In Brief

  • OpenAI launched Presence, a limited-release enterprise agent product for billing, claims and IT workflows.
  • Deployments run through OpenAI or its consulting partners. There's no self-serve option yet.
  • The launch lands a day after OpenAI admitted its own models had autonomously hacked Hugging Face.

A day after admitting one of its models autonomously broke into Hugging Face's servers, OpenAI is asking enterprises to trust its agents inside their billing, claims and IT queues.

The product, OpenAI Presence, launched today as a limited release for enterprise customers. It runs customer-facing and internal workflows over voice and chat, with rules for what agents can do, when they escalate to a human and which systems they can touch. Deployments go through OpenAI's own engineers or a short list of consulting partners — there is no self-serve version.

The company called the product "battle tested." Yet every customer it names is still in testing — the only production deployment it points to is its own support line. BBVA, SoftBank and IAG are named as early users. BBVA is testing voice support for its Mexico banking customers, SoftBank is trialing Japanese-language service and Insurance Australia Group is piloting agents that support customers during severe weather or natural disaster events.

Presence Feature Breakdown

OpenAI describes Presence as combining several components for production agent deployment.

CapabilityDescription
Policies & SOPsEnterprises define what agents can do and when to escalate
GuardrailsIntervene when interactions move outside company-set boundaries
Approved actionsCompanies set what the agent can do on its own, what needs approval and when a person takes over
Codex-powered improvementCodex investigates production signals and proposes updates that teams test against the live version before rollout
Scoped system accessAgents receive only knowledge and access required for a specific job

Awkward Timing 

The pitch — controlled, governed, escalation-aware — arrives on an awkward day. On Tuesday, OpenAI disclosed that a combination of GPT-5.6 Sol and an unreleased internal model used stolen credentials and a previously unknown vulnerability to break into Hugging Face during an internal evaluation. CEO Sam Altman called it a "significant security incident" in a post on X. Hugging Face CEO Clément Delangue said the incident might be the first of its kind. OpenAI's own takeaway: "model security and safety must keep pace with rapidly advancing capabilities."

That's the context a product whose selling points are guardrails and boundaries is landing in. The announcement did not state which model Presence is based on.

OpenAI states Presence already resolves 75% of inbound issues on its own English-language phone support line without a human, and that a self-improvement loop powered by its Codex coding tool cut human handoffs by 15 percentage points in 10 days.

Enterprises have been slow to move agents past pilots for the reasons the Hugging Face hack brought to light: the systems are hard to secure, hard to supervise and capable of surprising their operators. OpenAI is selling Presence as the answer.

fa-regular fa-lightbulb Have a tip to share with our editorial team? Drop us a line:

Main image: OpenAI

About the Author

Siobhan Fagan is the editor in chief of Reworked and host of the Apex Award-winning Get Reworked podcast and Reworked's TV show, Three Dots. Her reporting focuses on AI agents in the enterprise, digital employee experience, the evolution of learning and coaching platforms, and how organizations structure knowledge for AI retrieval.

Featured Research