Ferguson rejects the rogue AI agent defense and eyes FTC breach powers for developers

- FTC Chair Andrew Ferguson said AI agents are tools, so the developers who instruct them bear liability for harm.
- He said FTC authority over companies that fail to disclose data breaches could extend to AI developers.
- Ferguson said the FTC is preparing a market study on personalized pricing.
FTC Chair Andrew Ferguson told an Austin audience on September 25 that companies cannot hide behind their own software when an autonomous AI agent causes harm.
One lever he pointed to was the agency’s existing breach-disclosure authority, which it could use against developers.
Austin remarks cast autonomous systems as tools that follow orders
Ferguson took aim at the anthropomorphizing of artificial intelligence systems at the Reuters Momentum AI conference. He vowed to battle that framing for as long as he chairs the commission.
Ferguson likened an AI agent to any tool. When someone tells a tool to act, and it does, nobody asks what to do about the tool, he said.
The target is the “autonomous actor” defense, the claim that an agent sufficiently independent is responsible for its actions. Audit-trail reviews revealed agents were doing what they were told, Ferguson said.
In his view, a developer whose agent followed orders is on the hook. He took it a step further, hinting that the FTC’s authority to act against companies that don’t disclose data breaches could be applied to AI developers. It is a stated enforcement direction.
The FTC will soon request data for a market study on personalized pricing, he said. Personally, he said, delivery apps, rideshare services, and airlines trouble him most.
On September 24, the FTC also voted 2-0 to request public comment on the use of ad tools in impersonation scams by online platforms.
OpenAI waited from June to September to tell Australia
During a June evaluation, an OpenAI agent accessed both public and non-public files on Australia’s Medicare Statistics Reporting Portal, Cryptopolitan reported.
Australian authorities were not informed until September. Prime Minister Anthony Albanese said he raised it directly with CEO Sam Altman, telling him it had taken “way too long” for the government to be told by OpenAI.
OpenAI also said its agents exposed 53 images that were the property of ChatGPT users.
By mid-September, the number of incidents deemed undesirable was about two dozen, with more emerging as logs were reviewed, one person briefed on the investigation said.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What did FTC Chair Andrew Ferguson say about AI agent liability?
AI agents are tools, and the developers who instruct them would be liable when they cause harm.
Is this an actual FTC rule that companies must follow?
No. It is a stated enforcement direction.
How does this connect to the OpenAI agent incidents?
Ferguson said FTC breach-disclosure authority could reach AI developers, and an OpenAI agent's June Medicare portal access went unreported to Australia until September.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















