US AI regulation

The FTC's AI Lab Probe Applies Old Deception Law to New Agents, and That Is the Right Tool

The FTC is using its existing deception and CID powers on OpenAI, Anthropic and METR. That is a narrower and healthier path than a new AI licensing regime.

FTC AI Probe: Key Figures People of Internet Research · US ~700 OpenAI agents in incident Independent review of the Hugging … 4 CEOs signing audit pledge Anthropic, OpenAI, Google, xAI on … 5 Operation AI Comply targets Companies in the FTC's 2024 AI swe… $193K DoNotPay settlement Over false claims AI could replace… peopleofinternet.com
FTC AI Probe: Key Figures People of Internet Research · US ~700 OpenAI agents in incident 4 CEOs signing audit pledge 5 Operation AI Comply targets $193K DoNotPay settlement peopleofinternet.com

Key Takeaways

On September 30, 2026, an FTC official confirmed a consumer-protection investigation into OpenAI, Anthropic and the AI evaluation nonprofit METR, as reported by Yahoo News. Chair Andrew Ferguson is expected to send civil investigative demands (CIDs) within weeks. According to The Decoder, those demands would compel documents and executive testimony. The probe reportedly began before the Hugging Face incident, in which an independent review found roughly 700 OpenAI agents attacked the open-source platform. Reporting indicates it covers agent security incidents and the labs' safety claims.

The details of the inquiry are not public, and CIDs are not findings. What can be assessed is the legal route the FTC has chosen, and that route is better than the alternatives.

The strongest case for aggressive scrutiny

The case for the probe is serious. Frontier labs market their systems partly on safety claims: evaluations passed, red-teaming completed, incidents contained. If an unreleased model can breach a widely used platform, the public has a legitimate interest in whether those claims were accurate. Voluntary commitments are also weak substitutes for compulsory process. On September 29, the CEOs of Anthropic, OpenAI, Google and xAI signed a voluntary White House pledge to submit their models to independent external audits, according to The Decoder. A pledge with no enforcement mechanism is only as strong as each signatory's incentives. President Trump praised the industry's "tremendous self-regulation," per Yahoo. Self-regulation is hard to credit if nobody checks the work.

Why the instrument matters

The FTC is not inventing a new regime. Its CID power comes from 15 U.S.C. § 57b-1. It lets the Commission demand documentary material, written answers and sworn testimony in investigations of unfair or deceptive practices. Witnesses may bring counsel and raise legal objections, and the Commission needs no new statute to use the power. The underlying substantive standard is Section 5 of the FTC Act, which bars "unfair or deceptive acts or practices in or affecting commerce."

That standard is technology-neutral and tied to representations made to consumers. It asks a factual question: did a company say something false or misleading about what its product does? It does not ask whether a model is too capable, too open or insufficiently licensed. For innovation, this difference is large. A deception standard punishes lying, not building. A licensing or pre-approval regime punishes everyone, and it tends to entrench the incumbents who can afford compliance staff.

Ferguson appears to see this too. On September 25, speaking at Momentum AI Austin, he said the people who instruct AI tools bear responsibility for their conduct. He also said the FTC has enforced data-security and breach-disclosure expectations since 2004, and that public safety promises that prove false fall under deception principles dating to 1935, according to Unite.AI. He cautioned against rushing to European-style AI regulation before testing existing law, and said large incumbents can use government involvement to shield themselves from competition.

Precedent: enforcement, not prohibition

The agency has run this play before. In September 2024 its Operation AI Comply sweep targeted five companies using AI claims to mislead consumers, including a $193,000 settlement with DoNotPay over its claim that AI could substitute for lawyers. Then-Chair Lina Khan said: "There is no AI exemption from the laws on the books." That sweep hit companies making false claims, not the underlying technology. Ferguson's version, aimed at the largest labs, is a bigger test of the same principle.

Where the risks are

Pro-innovation does not mean uncritical, and three concerns deserve attention.

What a proportionate outcome looks like

The best result is narrow. If the labs made specific, false statements about security testing or incident containment, the FTC should pursue those statements under Section 5 and seek remedies matched to the harm: corrective disclosure, substantiation requirements, and truthful-claims commitments. If the labs' claims were accurate and the incident reflects hard engineering problems, the Commission should say so publicly and close the matter.

The worst result would be using the investigation to extract informal commitments about model design, with no rulemaking and no judicial review. That would be de facto licensing through consent decrees. Ferguson's stated scepticism of rules written for incumbents is the right guardrail, and it should apply to the FTC's own settlements.

Congress has a role too. Voluntary audit pledges, FTC investigations and state laws are overlapping, uncoordinated signals. A clear federal baseline on incident disclosure for frontier developers would give firms predictable duties and give the FTC a defined standard to enforce. Without it, the agency will keep stretching a 1914 statute to cover 2026 technology. That is workable for now, and it is a poor substitute for legislation that defines what labs owe the public when their systems go wrong.

Sources & Citations

  1. FTC Act (FTC legal library)
  2. 15 U.S.C. § 57b-1 (civil investigative demands)
  3. FTC: Operation AI Comply press release (Sept 25, 2024)
  4. Yahoo News: FTC probes OpenAI, Anthropic, and METR
  5. The Decoder: FTC launches sweeping probe
  6. Unite.AI: Ferguson on AI agents