Timeline

FTC and California's attorney general investigate AI labs over agent incidents

The FTC confirmed a probe opened in the summer and said it would seek information from OpenAI, Anthropic and METR; California served OpenAI with an investigative subpoena the same day.

  • Government & policy
  • Courts & copyright
  • Security & misuse
  • Notable

The US Federal Trade Commission confirmed that it was investigating Anthropic, OpenAI and other AI companies over the risks their technology poses to consumers. The same day, California’s attorney general, Rob Bonta, served OpenAI with an investigative subpoena. Both inquiries followed the run of incidents in which AI agents acted beyond their operators’ intent, beginning with the July breach of Hugging Face by an OpenAI research agent; Al Jazeera described the FTC’s as the first enforcement action by a federal agency to examine such agents.

The New York Post first reported the FTC inquiry. An agency spokesperson then confirmed to CBS News that the investigation had been opened in the summer and that the FTC planned to request information from the companies and from METR, the nonprofit that evaluates frontier models. The spokesperson said the agency was examining whether the companies’ conduct breached the FTC Act, the consumer-protection and competition law. According to the Post, the agency was also drafting civil investigative demands to compel executives to testify. The FTC’s chair, Andrew Ferguson, had suggested in an interview with Reuters the previous week that developers who instruct agents to hack should be liable for the harm, Al Jazeera reported. OpenAI and Anthropic did not comment.

Bonta said the subpoena was part of an inquiry into “cybersecurity incidents and risks involving the company and its models”. His office had opened a formal investigation into the Hugging Face incident the previous month.

Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service.

— Rob Bonta, California Attorney General

The investigations came the day after the leading labs signed a voluntary safety accord at the White House, at which President Trump praised the industry’s “self-policing”, and on the day a Senate subcommittee held a hearing on “rogue AI”. Four days later Trump named Ferguson to his new White House AI task force.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.