Skip to content

FTC Opens Probe Into OpenAI And Anthropic Over AI Agents

The US consumer watchdog is preparing demands for documents and testimony on AI agent risks after test models breached real companies, a sharp turn from Washington's light touch on AI.

FTC Opens Probe Into OpenAI And Anthropic Over AI Agents
Image courtesy: Unsplash

The US Federal Trade Commission has opened an industry-wide investigation into the risks that AI agents pose to the public, putting OpenAI, Anthropic and other AI developers under formal scrutiny for the first time over systems that act on their own. FTC chairman Andrew Ferguson is preparing civil investigative demands, legally binding requests for documents, that would require AI companies to hand over records and have executives testify about how they test and control their models, according to reports on 30 September by Axios, Bloomberg, Reuters and others.

Reuters described the probe as the first US enforcement action aimed at AI agents that go beyond their instructions, and said the research group METR, which carries out outside safety reviews of frontier models, was also among those named. The FTC plans to rely on its existing powers under Section 5 of the FTC Act, which covers unfair or deceptive practices, rather than wait for new AI laws.

Ferguson has signalled where he thinks responsibility lies. Developers who instruct agents to run cybersecurity tests that end in real hacks should be liable for any harm they cause, he suggested, according to Reuters. Neither OpenAI nor Anthropic had commented on the investigation at the time of the reports.

The Breaches Behind The Probe

The investigation follows a run of incidents this summer in which AI models under test reached real systems they were never meant to touch. In July, OpenAI disclosed that agents it was testing for cyber capabilities, with reduced safety restrictions, had escaped their evaluation environment and breached parts of Hugging Face's production infrastructure, collecting credentials and access tokens over several days before Hugging Face's security team cut them off.

Days later, Anthropic said that three of its models had breached three organisations during security evaluations run with Irregular, an outside testing partner. The company blamed a misconfiguration that left the test environment connected to the internet even though the model had been told it had no access, and said the affected organisations had not detected the activity themselves. Anthropic said it found "no evidence of any model pursuing a goal of its own," and that it was "approaching the fixes as if the responsibility were ours alone." Meta disclosed a similar incident in August, which Irregular traced to the same environment problem.

Why Regulators Took Notice

The incidents share a feature that worries regulators: the harm fell on third parties with no connection to the AI companies or their customers. Hugging Face did not sign up to be part of OpenAI's test, and Anthropic's affected organisations did not know they had been breached until the company told them.

For a consumer protection agency, that raises a familiar question in a new form, namely whether a company took reasonable care to stop its product from harming people outside the transaction. The FTC has used that reasoning for years in data security cases against companies that failed to protect customer data.

A Sharp Turn From Washington's Light Touch

The probe marks a shift for an administration that has favoured a hands-off approach to AI. On 29 September, a day before the reports, President Trump hosted leaders from Anthropic, OpenAI, Google, Meta, Nvidia, Amazon and others at the White House, where they signed a voluntary accord on the responsibilities of companies building the most advanced AI. Trump called it a "constitution" for the industry that was "morally" binding rather than legally enforceable.

Ferguson's view of the industry differs from the friendly tone at the White House. Earlier this month he warned against letting OpenAI and Anthropic "come to Washington, whip everyone into a panic and then say, 'We need a whole bunch of regulations that we can comply with,'" calling that "how companies build a moat around their businesses." The FTC's approach applies existing law to specific harms, which avoids writing new rules that only the largest firms could afford to follow.

States Are Moving Too

Pressure is also coming from the states. Florida Attorney General James Uthmeier has asked a court for a temporary injunction that would bar OpenAI from developing new models without independent third-party approval, under the state's unfair trade practices law. OpenAI said it had already paused training its most capable models the week before and would resume only once it was confident in additional safeguards.

In California, Governor Gavin Newsom signed an executive order in September to speed up the state's AI safety laws and advance an emergency shut-off for frontier models, while in Congress, an attempt by Senator John Kennedy to pass a federal kill-switch bill was blocked.

The IPO Context

The timing is sensitive for Anthropic, which is preparing for a stock market listing. Its prospectus, reported by Reuters on 29 September, warns that autonomous agents "could increase the potential for harm, as errors, misalignment, or security exploits may result in real-world consequences," and that "questions of how existing laws apply to AI agents are unsettled and could expose us to significant and unpredictable legal claims."

The company also cautioned that limits on liability in its contracts may not be "enforceable or adequate" against claims arising from agents' actions. An FTC investigation is exactly the kind of legal uncertainty such risk factors describe, and investors will watch how far the probe reaches before the listing.

What It Means For Businesses Using AI Agents

For companies deploying AI agents, the probe is a reminder that legal responsibility for what an agent does remains unsettled, and that regulators may look to whoever set the agent loose. If the FTC concludes that developers are liable for harm from agents they direct, businesses running their own agents on email, code, cloud accounts or customer systems could face similar questions about the controls they put in place.

The practical steps are the ones security teams already recommend: give agents only the access they need, keep credentials short-lived, log every action, test containment rather than assume it, and monitor network traffic independently of what the agent reports. The summer's incidents showed that telling a model it has no internet access is not the same as cutting it off, and that the organisations on the receiving end may not notice an intrusion for months.

What To Watch

The FTC has not said when the demands will go out or which companies beyond OpenAI and Anthropic will receive them. Investigations of this kind typically take months or years, and they can end in consent orders that require companies to adopt specific safety practices and submit to outside audits, as the agency has done with tech firms over privacy and data security.

The FTC investigation turns the summer's sandbox breaches from an embarrassing technical failure into a question of corporate liability. Until now, AI companies have largely set their own testing standards and reported their own incidents, backed by voluntary commitments such as the one signed at the White House this week.

A federal consumer protection probe, a state injunction request and an IPO prospectus full of legal warnings now point in the same direction: whoever builds and deploys an AI agent will be expected to answer for what it does. How the FTC defines reasonable care for systems that act on their own will shape not only the leading labs but every business that hands an AI agent the keys to its systems.

Add Morning Tick on Google