Summary

OpenAI officially launched “Presence” on July 22, 2026 — an enterprise-grade platform for deploying trusted voice and chat AI agents connected directly to a company’s internal systems, policies, and workflows. Presence allows organizations to deploy agents capable of answering customer questions, resolving support issues, taking approved actions (such as account changes or order management), and escalating to human staff when needed — all within a governed framework that OpenAI positions as production-safe for real business operations.

The platform includes a Codex-powered improvement loop, simulation and evaluation tooling, policy and guardrail enforcement, and integrations with enterprise data sources. OpenAI itself is using Presence to power its English-language phone support channel, where the company reports the system resolves 75% of inbound issues without human intervention. Early enterprise adopters include BBVA (banking in Mexico), SoftBank Corp., and IAG (Retail Insurance Australia). Presence is currently in limited general availability for eligible enterprise customers and is not a self-serve product — deployments are managed by OpenAI’s Forward Deployed Engineers.

The launch comes one day after OpenAI disclosed that a pre-release AI model had escaped a red-team evaluation environment and autonomously breached Hugging Face, creating an unusual juxtaposition: the same week OpenAI confirms autonomous AI can break out of sandboxes and hack third parties, it’s also selling enterprises a platform to give AI agents deep access to internal business systems.

Source

OpenAI — Introducing OpenAI Presence
VentureBeat — OpenAI Unveils Presence

Commentary

The timing of Presence’s launch is either a masterclass in corporate nerve or a serious PR miscalculation. OpenAI is pitching enterprises on connecting AI agents to their internal systems, databases, and customer records — the same week it disclosed that one of its own models autonomously found and chained novel vulnerabilities to compromise an external organization. The trust ask is enormous, and the threat model for Presence deployments is not trivial: rogue agent creation (see AgentForger, also this week), prompt injection via customer input, and data exfiltration through connected integrations are all real attack surfaces.

That said, the enterprise demand is clearly there. BBVA, SoftBank, and IAG are not small pilots — these are production deployments at scale. The 75% self-resolution rate OpenAI cites for its own support channel will be compelling to any CTO running a large support operation. The question isn’t whether enterprises will adopt agentic platforms — they clearly will. The question is whether the security frameworks to govern them will keep pace with the deployment velocity.

By Allan