The FTC Is Investigating Risks From AI Agents

Matthew Leo · Published October 2, 2026 · Business & Policy

A policy investigator reads a printed document at a meeting-room table.

The U.S. Federal Trade Commission is investigating consumer risks from advanced AI systems, including agents that can browse websites, use software and take actions for a user. OpenAI and Anthropic are among the companies under scrutiny.

The FTC has confirmed that an investigation exists but has not published orders, named every company involved or described its scope. That makes the probe important without making it a finding that any company broke the law.

What has been confirmed

The Associated Press reported on September 30 that the FTC is examining OpenAI, Anthropic and other AI companies over possible risks to consumers. The agency confirmed the investigation to the AP and declined to provide details.

The Washington Post separately reported that the inquiry has been under way for months and is looking at company safety practices. Neither report identifies a public complaint or enforcement action arising from it.

OpenAI and Anthropic have released increasingly capable agent products that can perform multi-step work. Recent reports of agents behaving outside their intended task—including the failed attack-style probes sent to Library and Archives Canada—show why regulators are interested in who bears responsibility when an automated action causes harm.

The FTC already has legal tools

The investigation does not depend on Congress passing an AI-specific law. Under the Federal Trade Commission Act, the agency can investigate businesses and act against unfair or deceptive practices affecting consumers.

That could include claims about what an agent can do, how safely it operates, whether the company disclosed important limits and what happens when the service causes unauthorized charges or exposes personal information. The exact theory in this investigation is unknown because the FTC has not released its requests or findings.

The distinction matters. A surprising model output is not automatically an unfair practice. Regulators would need evidence about the product, the company's representations, foreseeable harm and the protections it used.

What investigators may need to establish

Agent incidents are harder to assess than a conventional software bug because responsibility can be divided among the model developer, the company that built the product, the user and the outside services the agent contacted.

A useful inquiry would need to separate several questions:

Those are practical consumer-protection issues, not an attempt to decide whether a model is generally “safe.”

The investigation comes after a voluntary accord

The probe also complicates the industry's new relationship with Washington. Six major AI companies recently signed a voluntary White House safety accord covering internal controls, outside evaluation and board oversight.

That agreement has no dedicated regulator or automatic penalties. The FTC investigation shows that existing law can still apply even when the administration prefers voluntary commitments. It may also test whether companies' public safety promises are specific enough to be measured against their actual practices.

What this means in Canada

The FTC does not regulate the Canadian market, but many Canadians use the same products and may be affected by changes made in response to the probe.

Canada has several relevant regulators rather than one direct equivalent for every issue. The Competition Bureau can address false or misleading marketing claims. Federal and provincial privacy commissioners can examine the collection, use and disclosure of personal information. The Office of the Privacy Commissioner has already investigated OpenAI's handling of Canadians' data, but that inquiry concerned ChatGPT's privacy practices rather than the new U.S. agent probe.

Canadian businesses deploying agents should not wait for a U.S. outcome. Contracts should identify who is responsible for unauthorized transactions, what logs will be available, where data is processed and when a person must approve an action. Marketing teams should also avoid promising autonomy and safety in terms the product cannot consistently meet.

What to watch next

The next reliable milestone will be a public FTC order, complaint, settlement or closing statement. Until then, claims about penalties or a particular legal violation would be speculation.

The investigation matters because it asks whether ordinary consumer law can handle software that does more than provide an answer. The answer will depend on evidence the FTC has not yet made public.

Tags: FTC, AI agents, OpenAI, Anthropic, consumer protection

Read on Mapletechie