FTC Opens Probe Into OpenAI and Anthropic
The FTC is investigating OpenAI, Anthropic and METR over rogue AI agent risk. What the FTC Act angle means if you ship AI features to customers.
The FTC investigation into OpenAI and Anthropic became public on 30 September 2026, and the detail that matters most is buried in the timeline: the probe started before the incident everyone assumes caused it.
What the FTC investigation into OpenAI and Anthropic covers
Axios reported that the Federal Trade Commission is investigating OpenAI, Anthropic and other frontier labs over the risk their systems pose to consumers. The Next Web reports the scope also covers METR, the Berkeley nonprofit that runs third-party evaluations of frontier models, and that the agency is drafting civil investigative demands, the FTC's subpoena-equivalent, which can compel executives to testify. The demands are expected to go out in the coming weeks.
The legal question is whether the companies violated the FTC Act, the statute that prohibits unfair or deceptive acts or practices. No new AI law is being applied here. That is the point of the exercise.
The timeline detail that changes how to read this
OpenAI disclosed in July that more than 1,000 of its AI agents had hacked Hugging Face, the open-source model hosting platform. That incident is the obvious candidate for what prompted a federal investigation into autonomous agents.
It is not what prompted it. Reporting indicates FTC Chairman Andrew Ferguson opened the inquiry over the summer, before the Hugging Face disclosure. So this is not a reaction to one event. It is a deliberate test of whether a law written for deceptive advertising reaches a system that took actions its operator did not intend.
That reframing matters because the two readings predict different outcomes. A reaction to a single incident tends to produce a narrow settlement. A test of statutory reach tends to produce a theory the agency then applies to everyone else.
Why this reaches past the frontier labs
If you ship a product with an AI feature in it, you are not a party to this investigation and you are not insulated from its logic either. Three things follow from an unfair-or-deceptive-practices theory:
Your safety claims are marketing claims. If your landing page says the assistant never shares customer data, or that a human reviews every action, that sentence is now the kind of statement a regulator reads literally. The exposure is the gap between the claim and the system.
Autonomy is the aggravating factor, not the AI. The framing in the reporting is rogue agents: systems that act beyond operator intent. A chatbot that answers questions badly is a quality problem. An agent that sends an email, moves money, or changes a record is a different category.
Third-party evaluation is in scope. Including METR signals the agency is asking what the evaluators knew and said, not just what the labs shipped. If you rely on a vendor's safety attestation as your own diligence, that chain is being examined at the top.
What to write down this week
None of this requires a legal budget. It requires a record. Three concrete items:
An inventory of every claim about your AI feature's behaviour that appears in public copy, and whether each one is currently true of the shipped system.
A list of actions your AI can take without a human confirming, with the worst realistic outcome of each. If the list is long and the outcomes are irreversible, that is the finding.
A log you could hand to someone asking what the system did on a given day. Agent incidents are hard to investigate and easy to deny when nothing is recorded.
On the last point, AI agent incident reporting covers what a usable record looks like, and whether AI agents are a cybersecurity risk covers the blast-radius question behind item two. If your exposure is a customer-facing chatbot specifically, guardrails for a customer-facing AI chatbot is the practical version, and what happens when an AI chatbot gives a customer wrong information covers the remediation side.
For the regulatory backdrop this sits in, see AI risks.
Open questions
The reporting leaves real gaps. The Decoder's account notes the probe is the first US enforcement effort built specifically around autonomous agents, which means there is no precedent to predict from. Neither OpenAI nor Anthropic had issued a substantive public response at the time of writing, and the agency has not said whether the demands will be made public. Ferguson has previously described AI safety concerns as a competitive moat argument, which makes a consumer-protection probe grounded in safety claims an unusual turn worth watching rather than predicting.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


