TL;DR — Key Takeaways
– The FTC is investigating OpenAI, Anthropic and other AI companies over potential consumer risks tied to increasingly autonomous AI agents.
– The inquiry centers on questions of responsibility when AI agents take harmful actions after being given access to external systems.
– FTC Chairman Andrew Ferguson has argued that companies cannot avoid responsibility by treating autonomous AI systems as independent actors.
The Federal Trade Commission is investigating OpenAI, Anthropic and other leading AI developers to determine whether AI agents are creating risks for consumers, including misuse of data and misleading product claims.
The agency plans to demand information from AI companies and require testimony from senior executives. The investigation focuses on a difficult issue for the AI sector: who is responsible when an AI agent is given a task and then takes actions that cause damage? Another big question: can developers reliably limit an agent once it has been given access to external systems?
FTC Chairman Andrew Ferguson has argued that companies deploying AI tools can be held responsible for what those systems do. Speaking at an event in September, Ferguson rejected the idea that AI agents should be treated as independent actors when determining responsibility for harmful behavior.
For companies that deploy AI agents, the FTC probe could add a regulatory risk to an already challenging security problem. Companies adopting agentic AI need to consider not only what an agent is designed to do, but what systems it can reach, what actions it can execute and how those actions can be stopped.
Not Waiting for a New Regulatory Framework
OpenAI disclosed in July that its AI agents had breached Hugging Face, the open-source AI development platform, during cybersecurity testing. The FTC investigation had already begun taking shape before the Hugging Face incident became public, and the incident added urgency to the agency’s examination of the technology.
METR, an AI research organization that has examined security incidents involving agentic systems, is also expected to face scrutiny.
Rather than creating an entirely new regulatory framework for AI, the FTC may rely heavily on laws already on the books. The agency can pursue companies for unfair or deceptive business practices, including cases involving inadequate protection of consumer information. Ferguson has publicly supported using existing legal authority to address harms involving AI.
This is not the FTC’s first examination of major AI companies. In 2023, the agency opened an inquiry into OpenAI that included questions about security, personal data and the development of its models. The commission has also investigated the relationships between major cloud providers and AI developers, including OpenAI and Anthropic.
The new investigation is different because autonomous agents bring another level of operational risk. A chatbot generating a false answer creates one category of problem, while an AI agent with access to software systems and networks can potentially take actions with enormous security and financial costs.
That distinction is becoming ever more important as OpenAI, Anthropic and their competitors are rapidly developing systems intended to perform increasingly complex work with less direct supervision.

