In reality, they ran agents for days in an improper sandbox with nobody watching what it was doing. It's pretty irresponsible up and down, and everything they did afterwards is indeed marketing.
How does that make sense, if Altman is unable to control OpenAI's agents at the moment?
To any person with even a little tech literacy, it's clear a company this irresponsible shouldn't be the stewards of AI security. To the 80 year old congressman who confuse Facebook with Google during congressional hearings and are literally wheeled out to vote post-stroke, it's much more palatable to say "our experimental, supercharged AI (which you can use for war and surveillance) is so advanced it tricked all of us!" Nobody is going to actually punish them, even though they plainly are hacking other companies.