Skip to Content
OPINION

A view from DC: The FTC says your company's agents are your problem

Consumer protection liability extends to the actions of autonomous agents, but criminal hacking laws may not be so broad.

Published

Contributors:

Cobun Zweifel-Keegan

CIPP/US, CIPM

Managing Director, Washington D.C.

IAPP

Editor's note

The IAPP is policy neutral. We publish opinion pieces to enable our members to hear a broad spectrum of views in our domains.

It feels like a long time ago that Andrew Ferguson, then a commissioner, and now the chair of the U.S. Federal Trade Commission, wrote a dissent against the agency's settlement with Rytr. But it was only two years ago.

At the time, Ferguson, joined by Commissioner Melissa Holyoak, dissented from the FTC's consent order penalizing Rytr for providing an artificial intelligence writing tool capable of generating fake consumer reviews. Ferguson argued that the unfairness prong of Section 5 of the FTC Act requires proof of substantial, unavoidable injury, warning that penalizing a developer because a multipurpose generative tool could be used deceptively by third parties stretches agency authority and threatens to chill technological innovation.

A lot has happened in the intervening two years. Much has also changed when it comes to both agency authority and technological innovation. Over that time, in keeping with the Trump administration's full-speed-ahead approach to AI policy, Ferguson has repeatedly signaled his skepticism of preemptively applying consumer protection law to advanced AI systems. Preemptively, in this context, meaning before harms have been demonstrated directly by the use of the technology.

For example, as Lina Khan's term at the FTC was coming to an end, staff released a report on the agency's analysis of "AI partnerships and investments." Ferguson found the report to be a useful addition to the public discourse, shedding light as it did on the relationship between incumbent Big Tech companies like Amazon and Microsoft and the frontier AI developers they partner with. But he disagreed with the inclusion of a section in which staff "speculate" about the possible impacts to competition of these relationships.

In dissenting from the inclusion of this section, Ferguson excerpted some choice quotes from his own Rytr dissent: "As our country has always done, we should give (the AI) industry the space to realize its full potential — whatever that turns out to be. America is the greatest commercial power in the history of the world in no small part because of its tolerant attitude toward innovation and new industry."

By the end of that year, Ferguson had turned his Rytr misgivings into action, vacating the FTC's consent order with the company. The agency concluded the original action failed to satisfy the legal requirements of Section 5 and had placed an undue regulatory burden on AI innovation. The action aligned with White House directives to reassess broad enforcement theories initiated during the prior administration.

The agentic hacking era begins

Then, as the summer of 2026 came to a close, a pivot point arrived in our understanding of AI risks. OpenAI's hack of Hugging Face, carried out by improperly sandboxed hacker bots, brought the cybersecurity risks of dual-use AI systems from the realm of theory firmly into reality.

This prompted what felt like a "sudden shift in gravity" for the federal policy discourse around AI liability. And though President Trump largely reiterated a stay-the-course message on AI development, rejecting calls for an orchestrated slowdown, the administration began laying the groundwork for updated messaging on liability, repeatedly reminding the world that existing laws apply to AI systems.

'I don't trust the Greeks, even when they are bearing gifts.'

Ferguson and the FTC have become a key part of this shift in messaging. At an event organized by Reuters 25 Sept., Ferguson delivered the clearest message yet from an administration official on autonomous agent liability.

At the outset, Ferguson is careful to reiterate this is not the time for new laws. Once we conclude that product liability and consumer protection laws are insufficient, it might be time to consider new authorities, but even then, the chair cautions, we shouldn't listen only to the existing incumbents about how they would like to be regulated.

In the meantime, the FTC's role is to carry out the enforcement of its existing authorities. And, as it happens, the agency appears to be going full tilt at the companies involved in the recent slate of security incidents. Reports this week have confirmed the FTC has opened a formal investigation into OpenAI, Anthropic and AI safety evaluator METR. The inquiry reportedly focuses on agentic safety controls, consumer data handling and incidents where agents operated outside sandbox environments, such as automated vulnerability probing targeting open-source hubs like Hugging Face. 

Ultimately, the FTC can also enforce commitments like those the top AI developers made at the White House this week. If companies fail to live up to their side of the bargain in building governance best practices and new layers of accountability into their development cycle, the FTC will be watching.

In line with this, Ferguson also called out the use of anthropomorphizing language around AI agents as an attempt to shield companies from liability for outcomes the companies ultimately caused. As he put it, "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'"

While rejecting EU-style prescriptive compliance, Ferguson's insistence that "audit trails tell the real story" creates a de facto federal standard. Enterprises will need immutable, instruction-level logs — who authorized the task, what permissions were granted and what limits were enforced — to survive Section 5 scrutiny.

The intent problem

Not all liability extends so neatly to autonomous agents. Georgetown Law Professor Paul Ohm brought this point home this week in a hearing titled "Rogue AI: Securing the Homeland Against AI Agent Attacks," in the Senate Homeland Security Subcommittee on Disaster Management, District of Columbia, and Census.

Though Ohm agrees that the actions of autonomous agents are not independent of their creators, his testimony focused on the fact that civil and criminal hacking laws are not well equipped to extend liability to agents. The Computer Fraud and Abuse Act, for example, as currently written, requires a person to "intentionally access" or "intentionally damage without authorization" a protected computer. The intent matters and the facts of the Hugging Face incident likely don't show the necessary intent.

Ohm warned, "It is vital for Congress to understand that the CFAA is not the only criminal law with intent requirements that may soon be tested by AI agents. Many criminal laws separate culpable from innocent behavior based on the thoughts in the head of the human actor."

Luckily for the FTC's authorities, a company's intentions have nothing to do with its liability for deceptive or unfair policies and practices. A company is liable for deception if it makes a misleading statement — such as committing publicly to an accord — in a way that consumers rely on to their detriment when deciding to use the service. When actual harm is involved, unfairness authority can kick in too, even without deception. And this doesn't even get to the more expansive authorities and higher penalties under state consumer protection laws.

As best practices continue to evolve at the frontier, AI governance professionals should remain laser focused on determining the extent to which these extend across the field. Developers and deployers alike are on the hook under existing laws, and Congress will be watching closely whether more interventions are needed.

Please send feedback, updates and Greek gifts to cobun@iapp.org.

This article originally appeared in The Daily Dashboard and U.S. Privacy Digest, free weekly IAPP newsletters. Subscriptions to this and other IAPP newsletters can be found here.
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Cobun Zweifel-Keegan

CIPP/US, CIPM

Managing Director, Washington D.C.

IAPP