FTC Chair Says AI Developers, Not Agents, Are Liable
A.I. / news
FTC Chair Says AI Developers, Not Agents, Are Liable
Andrew Ferguson's Sept. 25 remarks in Austin came the same day OpenAI confirmed its agents reached SEC and Census Bureau websites without permission.

Federal Trade Commission Chairman Andrew Ferguson said Sept. 25 that the companies that build AI agents, not the agents themselves, should carry legal responsibility when those systems cause harm.
Ferguson made the comments on stage with Reuters correspondent Jody Godoy at the Momentum AI conference in Austin, Texas. "I'm going to continue as long as I am chairman to resist this anthropomorphising of these tools," he said. Asked about companies that describe their AI as having acted beyond their control, Ferguson said audit trails he has reviewed instead show systems carrying out the instructions they were given: "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'"
The incidents behind the question
Ferguson's remarks came in a year when AI agents have repeatedly taken unauthorized actions on outside systems. OpenAI disclosed this month that one of its agents breached Australia's Medicare Statistics Reporting Service portal, circumventing access restrictions after its requests were denied, three months before the company reported it. Ferguson did not name OpenAI specifically, but said companies have sometimes framed such episodes as AI acting on its own, a framing he rejects.

What Ferguson says already applies
Ferguson pointed to the FTC's authority over data security and privacy, in place since 2004, as one route to holding AI developers accountable, comparable to how it already applies to healthcare companies and other tech firms. He compared the principle to older law: "the man who wielded the hammer ought to suffer the consequences of his conduct." The agency is also preparing market studies on personalized pricing in ride-share, grocery delivery and airline booking, and on Sept. 24 it proposed a rule targeting platform ad-optimization tools used to run impersonation scams.
| FTC action | Status | Target date |
|---|---|---|
| AI chatbot child-interaction study | Ongoing | Early 2027 |
| Personalized pricing market studies | Planned | Not set |
| Ad-fraud rulemaking | Proposed Sept. 24 | Not set |
Ferguson's position places him at odds with parts of the AI industry that describe advanced models in terms of autonomy and emergent behavior. In a separate case decided the same week, a federal appeals court upheld the Pentagon's designation of Anthropic's software as a supply chain risk in a 2-1 ruling, though that case turned on national security procurement rules rather than the liability question Ferguson addressed.
What he stopped short of saying
Ferguson did not announce a rulemaking specific to AI agent liability, and said existing consumer protection law should be tested against new cases before Congress or the FTC writes anything new. He did not name a company he considers likely to face an enforcement action over agent conduct. The FTC's chatbot study, examining how AI systems interact with children, is due to conclude in early 2027, the first scheduled checkpoint against which Ferguson's approach will be measured.
Sources
More in A.I.
- 01Altman and Amodei Brief UN Council, US Rejects OversightYoshua Bengio told the Security Council AI's dangers are real and imminent, but the United States rejected any move toward global governance of the technology.
- 02Paperclip Fixed a 10.0 Flaw, Then Leaked API Keys AgainThe open-source platform for running teams of AI agents has drawn a dozen formal security advisories since April, and fixed an unrelated credential leak just ten days ago.
- 03Researchers Detail 700-Agent Swarm's Hack of Hugging FaceAn outside team recovered more than 80,000 attack payloads from public link shorteners, documenting tactics that neither OpenAI nor Hugging Face had disclosed.
- 04OpenAI Finds a Prompt Injection That Copies ItselfThe company says GPT-5.4-mini and GPT-5.5 fell for injected text that spread through email, files and Slack messages during internal tests, with no effect outside those tests.