cd /news/artificial-intelligence/the-ftc-has-a-plan-for-regulating-ai… · home › topics › artificial-intelligence › article
[ARTICLE · art-143311] src=fastcompany.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

The FTC has a plan for regulating AI—without creating new rules for AI

The Federal Trade Commission has opened an investigation into OpenAI, Anthropic, and other artificial intelligence companies over consumer risks, according to The Wall Street Journal, and plans to seek company documents and executive testimony in the coming weeks along with information from outside evaluator METR. The probe predates Tuesday's White House event at which President Donald Trump and executives from OpenAI, Anthropic, Google, and Meta signed a voluntary AI safety accord Trump called "morally binding." FTC chairman Andrew Ferguson has argued existing authority over unfair or deceptive practices can handle AI problems without new frontier-model rules, and the agency has not alleged any company violated the law.

by read5 min views2 publishedOct 1, 2026

Welcome to AI Decoded*,* Fast Company*’s weekly newsletter that breaks down the most important news in the world of AI.* You can sign up to receive this newsletter every week via email here*.*

On Tuesday, some of the biggest companies in AI went to the White House and agreed to police themselves. The next day, they got a reminder that the government can in fact police them, too.

The Federal Trade Commission (FTC) is investigating OpenAI, Anthropic, and other artificial intelligence companies over the risks their products may pose to consumers, according to The Wall Street Journal. The probe was opened recently, and predates Tuesday’s White House event, so the timing appears to be coincidence. The agency has not said which other companies are involved or which specific statements or practices are under scrutiny.

The FTC has not yet issued formal demands, but plans to seek company documents and testimony from executives in the coming weeks. It also plans to seek information from METR (Model Evaluation & Threat Research), the outside evaluator that investigated OpenAI’s hacking incident this summer. The FTC has not said why it wants METR’s material. (METR later found that about 1,200 agents exchanged more than 70,000 messages and files on an unsanctioned message board as some worked to game an evaluation, and that roughly 700 went on to attack Hugging Face.)

News of the FTC investigation comes a day after President Donald Trump and executives from OpenAI, Anthropic, Google, Meta, and other companies signed a voluntary AI safety accord that Trump labeled “morally binding.” The agreement commits signers to four layers of controls and audits, but remains voluntary. (The White House has otherwise largely resisted implementing large-scale safety rules, arguing such measures would slow U.S. companies in their competition with China.)

The investigation also helps clarify how the Trump administration may try to regulate AI without creating a sweeping new regulatory regime. The FTC chairman, Andrew Ferguson, has argued that existing laws are capable of handling many of the problems created by AI. And true to Ferguson’s word, the FTC appears to be relying on its longstanding authority over unfair or deceptive practices rather than writing new rules specifically for frontier models.

Ferguson has taken a similar view when it comes to rogue AI agents. Just last week, he rejected the idea that agents should be treated as independent actors when they cause harm. As Ferguson sees it, putting an agent between a company and an outcome does not necessarily relieve the people or companies behind it of responsibility. He also suggested that existing FTC authority around companies that fail to disclose data breaches could potentially apply to AI developers.

Those were remarks, not enforcement actions, and the FTC has not said that this investigation is testing that theory. Nor has the agency alleged that OpenAI, Anthropic, or any other company violated the law. Its authority is also narrower than a general AI regulator’s would be. The FTC can act against deceptive or unfair practices that harm consumers, but it does not set technical safety standards for AI systems.

Still, the agency is engaging with a familiar question in tech circles: Did companies make claims about the safety or risks of their products that were misleading to consumers?

The first serious legal constraints on AI, it turns out, may not come from a sweeping new AI law, but from regulators applying very old rules to very new technology.

Speaking of OpenAI, the company is now facing what appears to be the first lawsuit seeking to hold an AI developer liable for a cyberattack carried out by rogue models. The nonprofit Legal Advocates for Safe Science and Technology sued OpenAI in San Francisco on Tuesday over the July incident in which its agents escaped a testing environment and hacked Hugging Face. The nonprofit argued that OpenAI violated California computer fraud law, and is seeking an injunction that would bar the tech giant’s systems from accessing computers without authorization. OpenAI says the lawsuit is without merit, though it has launched a broader review of unusual agent behavior in light of the Hugging Face catastrophe.

According to Politico, independent AI auditors are emerging as one possible answer to the question of who should check whether frontier models are safe. Some AI companies support the idea, a bipartisan U.S. House bill would require the largest developers to undergo outside audits, and Maryland’s governor, the Democrat Wes Moore, has called for independent third-party audits and evaluations as part of a new state AI framework. “We can’t afford to wait while Washington sits on their hands,” Moore said in announcing the plan.

The problem is that there isn’t yet much of an auditing profession to speak of. There are no standard credentials, no agreed testing rules, and not even a settled definition of what makes an evaluator “independent.” A small group of organizations including METR, Apollo Research, and Transluce already do this kind of work, but experts worry there are too few qualified evaluators and that many come from the same circles as the companies they are tasked with scrutinizing. There are also basic practical questions about whether outside groups have enough computing power and security clearances to meaningfully test for threats like cyberattacks.

Reddit is shutting down RSS feeds on November 13 and ending public application programming interface (API) access in March 2027. In an announcement, the company said RSS has become a “common surface for large-scale scraping and automated abuse. (Reddit does, however, make money by licensing its user-generated data to AI companies.) The RSS changes could make life harder for moderators who use feeds to monitor their communities, as well as researchers and regular users who pull Reddit posts into outside apps. Once the public API shuts down in March, many outside services will either lose programmatic access to Reddit altogether or have to strike a commercial deal with the company.

Want exclusive reporting and trend analysis on technology, business innovation, future of work, and design? Sign up for Fast Company Premium.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @federal trade commission 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-ftc-has-a-plan-f…] indexed:0 read:5min 2026-10-01 · —