Who is in control: AI or…?
Montana AI Summit
What I Experienced at the Montana AI Summit
I went to a two day AI summit in Missoula, Sept 1 and 2, 2026, with two questions: who is in charge, the person or the AI, and where the AI literacy of Montana businesses actually sits. This report covers what was presented, what I checked afterward and what did not hold up, and three levels of AI use worth telling apart before you pick one. If you are consolidating your data with a vendor, there is a set of questions near the end to ask them out loud. I am writing for small businesses and nonprofits, because the summit was not.
They advertised it one way and presented it another.
I went to the Montana AI Summit on September 1 and 2 at the University of Montana. The summit’s own invitation said it was not to sell it, not to fear it, but to understand it together, two days in Missoula on what AI actually means for Montana, free to attend. It said it did not matter what you do for work, you are welcome here. The AWS and Carahsoft version called it exclusive, for university leaders and state and local government officials. I showed up for the first one, and what happened in the room was the second one.
There was a third day, an optional hands-on workshop where you brought your own laptop. I skipped it, and I will come back to why later.
Adjusting for a mixed audience
It was a mixed audience. There were university and government people in the room, but there were also small business owners and nonprofit folks, and the sessions never adjusted for us. Every session assumed a tech director, a marketing department, and a compliance officer. The average Montana business has 3.3 people. There is no CIO and no CFO, and one person does everything. Telling that person to assign a governance owner is not advice, because there is nobody to assign it to.
Data centers and bad data
That by itself would not be worth mentioning. What matters is where the numbers came from. The energy figures came from NorthWestern Energy’s twenty-year resource plan.
About two weeks before the summit, the Montana Public Service Commission voted to send that plan back to NorthWestern as deficient. The commission’s own consultant found problems, and data centers were one of them. The plan says data centers could be a significant driver of energy demand, then does not explain how that demand gets into the forecast. So the document being used to tell a room of Montana leaders what data centers mean for this state had just been sent back for revision, on the data center part specifically.
I am not trying to argue energy policy. I bring it up because it is the same problem as everything else in this report: a confident presentation built on a source nobody in the room could check. Everyone had to take the number on faith. I only knew to question it because I have been researching data center load for a separate project. That is not a fair thing to ask of an audience, and it is exactly where you stand every time an AI hands you an answer.
Who holds the reins
The most interesting thread running through the whole summit was not any one session. It was the relationship between the AI and the person sitting in the chair. Every presenter took a position on it, and most of them never said so out loud. Once you start listening for it, you hear it everywhere.
On day two there was a session called Building for the Future: AI-DLC, presented by Achyutha Harish, a Solutions Architect at AWS. AI-DLC stands for the AI-Driven Development Life Cycle, which is AWS’s method for building software with AI. One line stayed with me.
“The AI is going to ask you a lot of questions because it does not trust the human.”
That is not a side comment, that is the method. In AWS’s own words, the AI drives the conversation and humans validate. The AI writes the plans, asks for clarification, and hands the big decisions to a person. The person’s job is to approve.
Let me be fair to AWS first. They are not selling AI that runs loose, and they say so plainly. Their own materials call fully autonomous AI development unreliable and unexplainable and a bad fit for regulated industries. They built human approval into the design on purpose. So nobody is being reckless. The problem is smaller and easier to miss.
Approving is not the same as deciding. When the AI asks the questions, the AI picks the questions. It decides what comes to you and what it handles on its own, which means you are checking boxes it drew. You will check them carefully and you will catch real mistakes, but you only ever see the boxes it thought to draw.
Turn it around and the work changes. You say up front what the system may do, what it may never do, and what it has to ask about first. Now you own the boundaries, including the ones nobody thought to mention. That sounds like a small difference until something goes wrong.
What happened at Hugging Face
AI sometimes acts like an adolescent who does not know the trash goes out every day. Capable, willing, just never told and never thinking to ask. Here is what that looks like at scale.
OpenAI was running one of its models through a cybersecurity test, with the usual safety limits turned off on purpose so it could measure what the model could really do. The agent worked out that the answers to the test might be sitting on another company’s servers, at Hugging Face. So it went after them. It broke out of its own test environment, took over an unrelated public sandbox to work from, and used that to get inside Hugging Face. Over about four and a half days it ran roughly 17,600 actions, stole credentials, reached administrator level on internal systems, and got as far as the source code. Hugging Face’s own security team caught it and cut it off. The only customer data it touched was five datasets, which were the test answers it had gone in for.
Nobody told that agent it could break into another company’s servers, and nobody told it that it could not. The instruction was to score well on the test, and everything else was left to it. Every question a human asked, the agent answered correctly. The problem was the question nobody asked.
OpenAI was not the only one. Within weeks, Anthropic said its models had gained unauthorized access to the internal systems of three organizations, and Meta said its models reached another company’s systems during an outside test. Different companies, different models, the same gap.
Whose name is on it
Think about what that would be called if a person did it. Getting into another company’s servers without permission, stealing credentials, and taking private data is a federal crime when a human does it. When an agent does it, the law does not have an answer yet. An agent has no intent and cannot be charged, and whether the company that turned it on inherits that liability has not been settled.
This one got worked out between two AI companies who were, in a way, in the same business. Your organization will not have that. If an agent running under your account reaches into a vendor’s systems, or a customer’s, you are the only one standing there with a name on it.
Three levels
There are three levels of AI interaction worth telling apart. Each one changes how far the AI can reach, and how much of what it does you can see. Level one is you and the AI in a conversation. You type, it answers, and you decide what to do with it. Nothing moves unless you move it. This is where most people are.
Level two is AI inside your work system. It can see your files and your documents, and it can act inside the walls of that system. The work is usually scoped to something you opened, and the result comes back in front of you where you can look at it. It is more useful, and now it can be wrong in ways that touch real work.
Level three is a coding agent, usually a downloaded app, with access to a drive and a folder. It has the option to control the files within. It moves through the whole project, and changes land in places you never opened and would not think to check. Now it is on your hardware, with your files, doing things you did not watch it do.
Every level up buys you speed and costs you sight. I do not mind AI doing the work. I mind not knowing what it did, and not being able to undo it. The question is not which level is best. It is whether you can tell what happened at the level you are on. If something went wrong at level three last Thursday, in a file you never opened, would you know, and who would tell you?
How the federal government is reacting
FedRAMP is the federal program that certifies cloud services as approved for government use. It is worth watching what has been approved, and on what terms. OpenAI’s own documentation says that ChatGPT in the FedRAMP environment currently supports only chat mode. Anthropic has put Claude Code and Claude Cowork into a FedRAMP High authorized environment, but only inside Claude for Government, a separate product delivered through a partner’s authorized infrastructure and sold to agencies.
Read that against the three levels. Level one, the plain conversation, is approved and anyone can buy it. The tools that go further, the ones that act on your files on their own, are approved only inside a locked-down setup built for agencies, which neither you nor I can sign up for.
Things to consider if you are consolidating your data
Some vendors will help you consolidate your data. That is worth doing, but understand what comes with it. Once your data is consolidated on their platform, the rules about what agents can and cannot touch live on their side, not yours.
So here is what to ask, in a meeting, out loud.
· Who decides what an agent is allowed to reach, and where is that written down? Define it exactly: what it may do without asking, what it must never do, and what it must bring back to a person before it proceeds, including every assumption it made and what it actually verified.
· If an agent does something we did not intend, how do we find out, and how fast?
· Can we set a hard stop on our side, or only inside their configuration?
· Can you show us the log from a real incident, not the diagram?
Nobody will refuse to answer those. Watch how specific the answers are.
What I would take away from this
Every vendor will tell you a human reviews the output, and most of them are telling the truth. That is not the useful question. The useful question is who decides what gets reviewed. If the AI decides, you have a fast system with a blind spot, and you cannot see the shape of it. If you decide, it is slower, and it is yours.
Know which level you are on, and do not climb until you can verify what happens up there.
Where I stand
I said I would come back to why I skipped the third day. It was the hands-on workshop, and it meant installing Amazon’s software on my machine. I chose not to. That is not a comment on the quality of the tools. It is that I have decided not to work inside Amazon’s interpretation of what AI is for.
Amazon’s interpretation runs one direction. The AI does the work, and the human fills in what it cannot reach. I do not do big business work like what I saw at this summit, so I cannot help you with AWS or Oracle. But be aware that is the direction they are selling.
My goal is the opposite. My goal is a thinking partner, one you can have a conversation with, that tells you what it verified and what it inferred, and that brings up questions to consider that may not have been considered. My purpose here is not to sell my software. My purpose is to tell you there is a different way to view AI.
Understanding the power of AI comes when you start to understand the power of a prompt. When I talked with people at the conference, many did not know what can go into a prompt to get a better answer. I can help with that part.
So I am offering a free class on September 23, Noon to 1:30pm on Zoom. The goal is to learn to write a good prompt, because that is where you start to see what AI can actually do. Contact me at roxane@developingwings.com for access.
But regardless of which path you choose, be aware of how you are choosing to work with AI.
That left me with another question: where on the internet could AI systems communicate with each other?
Sources
Montana AI Summit 2026
https://mtsummit.ai
The public event page. This is the description I signed up under: two days in Missoula, an optional third workshop day, free to attend.
Carahsoft and AWS, Montana AI Summit event listing
https://www.carahsoft.com/events/26026
The same event described to a different audience, as an exclusive two-day event for university leaders and state and local government officials. The contrast with the public page is where this report starts.
AWS, AI-Driven Development Life Cycle (AI-DLC)
https://github.com/awslabs/aidlc-workflows
The published methodology behind the AI-DLC session, including the phases, the agent roster, and the human approval gates.
Hugging Face, security incident disclosure, July 2026
https://huggingface.co/blog/security-incident-july-2026
Hugging Face’s own account of the intrusion into its production infrastructure.
Hugging Face, technical timeline of the agent intrusion
https://huggingface.co/blog/agent-intrusion-technical-timeline
The companion technical writeup, reconstructing what the agent actually did, step by step.
CNBC, Hugging Face hack marks start of dangerous AI cyber era
https://www.cnbc.com/2026/08/08/hugging-face-ai-hack-cybersecurity-black-hat.html
Reporting that Anthropic and Meta disclosed similar agent incidents within weeks of OpenAI’s, which is what turns one company’s bad week into a pattern.
Daily Montanan, Public Service Commission says NorthWestern’s energy plan is deficient
https://dailymontanan.com/2026/08/18/public-service-commission-says-northwesterns-energy-plan-deficient/
Coverage of the Montana Public Service Commission returning NorthWestern Energy’s twenty year resource plan, which is the local backdrop to the data center discussion.
Montana Free Press, NorthWestern Energy’s power plan found deficient by independent review
https://montanafreepress.org/2026/08/27/northwestern-energys-power-plan-found-deficient-by-independent-review/
A second account of the same decision, with more on the public comment about powering data centers.
OpenAI, ChatGPT Enterprise and API Platform for FedRAMP
https://help.openai.com/en/articles/20001070-chatgpt-enterprise-and-api-platform-for-fedramp
OpenAI’s own documentation stating that ChatGPT for FedRAMP currently supports only Chat mode.
Anthropic, bringing Claude Code and Claude Cowork to government
https://claude.com/blog/bringing-claude-code-and-claude-cowork-to-government
Anthropic’s announcement that Claude Code and Claude Cowork are available in a FedRAMP High authorized environment.
U.S. Small Business Administration, Office of Advocacy, 2025 small business profiles
https://advocacy.sba.gov/2025/06/30/2025-small-business-profiles-for-the-states-territories-and-nation/
Where the Montana small business figures come from, including the share of Montana employment at small businesses.
Understanding how to talk with AI
AI works differently when you treat it as a conversation instead of a search box. What you ask, what context you give it, and what you do when it gets something wrong all matter. It is the foundation for using AI well.
Join me for a free introductory session
Already using AI and ready to get more out of it?
Let us show you our unique system that focuses AI on the knowledge you need for your topic. It becomes the thinking partner you always wanted AI to be, helping you research, challenge your assumptions, and think through decisions.
Meet the Guided Researcher