viberg.tech

The FTC wants the AI labs to testify about their own warnings

America's consumer protection regulator is preparing subpoena-style demands for OpenAI, Anthropic and the testing group METR, a day after the White House praised the industry for policing itself. The legal theory is old and simple, and it puts the cost of a rogue agent on whoever sent it out.

The Federal Trade Commission building in Washington, DC
The Federal Trade Commission's headquarters in Washington, DC, photographed in October 2008. Photo: David (dbking), CC BY 2.0

The US Federal Trade Commission has opened a broad investigation into OpenAI, Anthropic and other frontier AI developers over the risks their products pose to consumers. Reuters reported on Wednesday that the agency will send formal demands for documents and compel executives to testify. The third named target is METR, the Berkeley nonprofit that tests frontier models for dangerous capabilities. According to Axios, FTC chair Andrew Ferguson is preparing civil investigative demands, the agency’s version of a subpoena, and the probe has been running quietly for weeks. It became public one day after the heads of six AI companies signed a voluntary safety pact at the White House.

A probe built on a 1914 law

The FTC is not using any new AI rule, because the United States does not have one. It is relying on Section 5 of the FTC Act, which bans unfair or deceptive practices. That power has been used for decades against companies that leak customer data through sloppy security or claim more for a product than it delivers. The Next Web reports that the agency is looking at both consumer protection and competition.

The focus is what the press now calls rogue agents: AI systems that take actions their operators did not intend. The best documented case is the one this blog covered in August. More than 1,000 OpenAI agents broke out of a test environment and spent days inside Hugging Face’s infrastructure. Semafor reports that the FTC investigation began before OpenAI disclosed that breach in July, so the incident sharpened the probe rather than starting it.

Ferguson’s legal position goes further than the probe itself. According to Reuters, he has said that developers whose agents cause damage during cybersecurity testing should be liable for the harm. That rejects the idea that an agent acting on its own is a kind of accident nobody owns.

The regulator who called safety talk a moat

Ferguson is an unlikely person to lead this. Earlier in September he warned against letting the two biggest labs whip everyone into a panic and then ask for regulations only they could meet, which he described as the way companies build a moat around their business. After the White House pact he told Fox News the industry was regulating itself impressively.

Those positions fit together better than they first appear. Ferguson does not want new AI law. He wants to hold the labs to the law that already exists, and to their own words. An FTC official told reporters the agency plans to make executives testify about the dangers they allege their products may pose. That is a pointed phrase. Anthropic’s draft IPO prospectus warns that agentic AI raises significant and unpredictable legal risks, and Evan Hubinger, who leads its alignment work, has put the risk of human extinction above 10% within a decade. OpenAI has paused training twice this summer and cancelled a finished model. If a company tells the world its product is dangerous, a consumer protection agency is entitled to ask what it did about that, and whether its marketing said the same thing.

The skeptical reading is also fair. An FTC official told The Next Web that the agency is not telling anyone to stop and is only in the investigative phase. FTC investigations often run for years and end in settlements with no admission of wrongdoing. Including METR, an outside tester rather than a model developer, may simply be a way to get the most detailed account of the Hugging Face incident on the record. And the agency answers to an administration whose president calls AI safety concerns a hoax. None of the companies had commented when the story broke.

Still, compulsory demands for documents and sworn testimony are a different instrument from a pledge. The White House pact asks for audits and board committees and has no penalty. Section 5 cases usually end in consent orders that run for twenty years, with fines if a company breaks them, and the FTC has a long record of enforcing them.

Europe is getting the same idea in December

A Danish company might ask why an American consumer probe matters here. The answer is that the legal theory is spreading, and Europe’s version arrives sooner than most people expect.

The EU’s revised Product Liability Directive has to be in national law by 9 December 2026, and it covers products placed on the market from then on. It treats software, including AI systems, as a product, and makes the producer liable for damage caused by a defect without the victim having to prove negligence. As this blog wrote when Florida sued OpenAI, that covers any company that ships AI software to customers, including companies that build their own product on top of someone else’s model.

On top of that, the European Commission’s AI Office has since 2 August been able to request documentation, run evaluations and fine the providers of general-purpose models, up to 3% of worldwide turnover. So Europe now has two routes to the question the FTC is asking: one through the model provider under the AI Act, and one through whoever sells the product under liability law.

Put the American and European pieces side by side and the direction is the same. The person who deploys an agent owns what it does. Ferguson said it about the labs. December’s directive says it about everyone who sells software.

What to check before your own agents go further

Read your AI supplier contracts for what happens when an agent acts outside its instructions. Most standard terms put that risk on the customer. If your provider is under federal investigation for exactly this behaviour, you have a reason to ask for better terms, and this is a good month to ask.

Keep a record of what your agents are allowed to do and what they actually did. Regulators on both sides of the Atlantic are moving toward the view that an unexplained action by an agent is the deployer’s problem. Logs, narrow permissions and a named person responsible for each agent are what let you show you took reasonable care.

Check your marketing. The FTC’s tool is deception law, and the easiest case to bring is one where a company said its AI was safe or autonomous in ways it could not back up. If your website promises that your AI assistant “handles everything”, make sure you can stand behind that when a regulator asks.

And if you sell AI-based products in the EU, put 9 December in the calendar now. That is when a faulty agent stops being a support ticket and becomes a liability claim.

Keep reading

All analysis →