FTC Investigates OpenAI and Anthropic Over Consumer Risks From Advanced AI Models
The FTC opened an investigation into OpenAI, Anthropic, and other developers over risks from agentic AI.
The U.S. Federal Trade Commission has opened a broad investigation into OpenAI, Anthropic, and other leading AI developers over potential consumer harm from advanced and agentic AI systems. The inquiry will examine whether development, deployment, safety claims, and management of agentic risks violate the FTC Act's ban on unfair or deceptive practices. The agency is preparing civil investigative demands covering safeguards, known risks, disclosures, internal testing, incident response, and public statements. No wrongdoing has been alleged, and the matter remains investigative.
- The FTC is preparing civil investigative demands for documents and possible testimony.
- The inquiry covers safeguards, disclosures, testing, incident response, and safety claims.
- Chairman Ferguson said liability rests with designers and deployers, not AI agents.
- The probe follows earlier FTC requests on chatbot effects on children and young users.
Full article577 words · extracted from gbhackers.com · click to collapse
The U.S. Federal Trade Commission (FTC) has initiated a broad investigation into OpenAI, Anthropic, and other leading artificial intelligence developers to examine potential consumer harm arising from advanced AI systems.
This inquiry will assess whether the companies’ development, deployment, safety claims, and management of agentic AI risks could violate the FTC Act’s prohibition on unfair or deceptive business practices.
FTC Investigates OpenAI and Anthropic
This investigation marks a significant increase in U.S. scrutiny of AI products that can act autonomously, access external systems, and potentially execute harmful or unauthorized actions.
NYPost Reports indicate that the FTC is preparing to issue civil investigative demands, formal information-gathering requests similar to subpoenas, to obtain documents and possibly compel testimony from company executives.
The agency intends to gather evidence related to product safeguards, known risks, consumer disclosures, internal testing, incident response procedures, and the accuracy of public statements about model capabilities and safety controls.
FTC Chairman Andrew Ferguson has framed the issue as one of accountability rather than machine autonomy. Speaking at the Reuters Momentum AI event, Ferguson rejected the notion of AI agents as independent actors with “wills and desires of their own.”
He argued that when an AI system causes harm while following instructions, the liability should rest with the individuals and organizations that designed, instructed, or deployed it.
Ferguson also suggested that the FTC’s existing authority over undisclosed data breaches could be applicable when AI systems expose or misuse sensitive information.
The investigation follows growing concerns about agentic models that can browse the internet, use tools, interact with cloud services, and carry out complex tasks.
From a cybersecurity perspective, these abilities increase the risk of prompt injection, credential theft, unauthorized data access, exploit development, phishing automation, destructive actions, and lateral movement through interconnected enterprise services.
An AI model granted broad permissions without robust isolation, logging, approval gates, and least-privilege controls could turn a flawed instruction, malicious prompt, or compromised tool integration into a significant security incident affecting consumers.
Reports suggest that the FTC is particularly focused on alleged “rogue” AI behaviors and whether companies sufficiently warned users about foreseeable risks. The inquiry may also address misleading claims regarding safety, privacy, reliability, or the effectiveness of safeguards.
Under this approach, a company could face scrutiny not only after a major incident but also if its marketing considerably overstates a model’s protections. At the same time, internal testing reveals significant failure modes.
This investigation follows the FTC’s request for records from AI companies on the effects of chatbot products on children and young users, including potential mental health impacts.
This earlier focus, combined with the current safety investigation, indicates that regulators are evaluating AI risk across cybersecurity, privacy, consumer deception, vulnerable-user protections, and data governance.
For OpenAI, Anthropic, and other leading model providers, this case could set an important enforcement precedent: it may determine whether existing consumer protection laws apply to emerging failures of AI agents without waiting for AI-specific legislation.
While the FTC has not alleged any wrongdoing and the inquiry remains investigative, the outcome could raise expectations for verifiable safety testing, incident reporting, independent audits, transparent risk disclosures, and stronger controls around models capable of functioning beyond a simple chat interface.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.