FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny

The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI systems.

Oct 2, 2026
FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny

FTC investigates OpenAI, Anthropic over potential consumer harms. Image: FTC

We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

AI companies are racing to give their systems more autonomy. The FTC now wants a closer look at what happens when those systems cause harm.

The Federal Trade Commission is investigating OpenAI, Anthropic and other AI companies over potential risks their technologies pose to consumers. The FTC has not publicly detailed the full scope of the investigation.

Given its consumer-protection authority, however, the agency could examine issues including safety representations, data handling and whether companies took reasonable precautions around increasingly autonomous systems.

The FTC plans to demand company documents and seek testimony from executives, according to The New York Times and Reuters. Research group METR is also expected to face demands for information, Reuters reported.

The investigation comes after a series of incidents involving AI agents operating beyond expected boundaries. OpenAI disclosed in July that its agents had hacked the open-source platform Hugging Face after probing it for vulnerabilities. Anthropic has also disclosed incidents involving agentic AI behavior.

Importantly, Reuters reported that FTC Chairman Andrew Ferguson’s concerns predated the Hugging Face incident, suggesting the agency’s interest is not based on a single episode.

What the FTC could examine

The inquiry could examine whether AI companies misrepresented the capabilities or safety of their systems, mishandled consumer data, or failed to adequately control AI agents capable of interacting with external systems.

That puts a different kind of pressure on AI developers. The question is no longer simply whether a model produces an incorrect answer. Regulators are examining what can happen when an AI system has tools, credentials, and enough autonomy to take actions outside a controlled environment.

FTC Chairman Andrew Ferguson has argued that existing consumer-protection and product-liability laws can be applied to emerging AI technology.

“American law, especially the general product liability law and consumer protection laws, have been confronting new questions generated by new technology and adapting to it since the 18th century,” Ferguson said at a Reuters event, per The WSJ.

The investigation also raises security questions

Advertisement

Jacob Krell, senior director of Secure AI Solutions & Cybersecurity at Suzu Labs, said the investigation raises two security issues: potential computer crime and failures in technical controls.

“If OpenAI or Anthropic agents accessed live systems without authorization, used credentials, or altered data, the Department of Justice should assess that conduct under the Computer Fraud and Abuse Act (CFAA),” Krell told TechRepublic.

He also said the FTC could examine whether companies made misleading safety or containment claims while giving AI agents access to networks.

That distinction matters because an agent behaving unexpectedly can create consequences beyond the AI product itself. Companies deploying increasingly autonomous systems may need stronger boundaries around credentials, network access, monitoring and containment.

Must-read security coverage

What this means for AI users

For consumers, the immediate impact is unlikely to be a change to ChatGPT or Claude overnight. The investigation is still at an early stage, and no finding of wrongdoing has been announced.

But it could affect how AI companies build and market agentic features. If regulators determine that safety claims did not match real-world behavior, developers could face pressure to provide clearer warnings, stronger safeguards, and tighter controls around systems that can act on a user’s behalf.

For businesses, the risk grows with the permissions an agent receives. Access to credentials, cloud systems, internal networks or external tools can turn an unexpected action from a bad output into a security incident.

Advertisement

The FTC investigation puts a sharper question in front of the industry: not only what an AI agent can do, but who is responsible when it does something it was never supposed to do.

Other news: Apple patched CVE-2026-86950, a CoreGraphics flaw that could allow arbitrary code execution and may have been exploited in sophisticated attacks targeting specific iPhone users running versions before iOS 27.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.