FTC Chair Ferguson Holds AI Developers Liable for Rogue Agents, Floats Breach-Disclosure Action
Key Takeaways
- •FTC Chair Andrew Ferguson rejected the 'autonomous actor' defense on September 25, saying audit-trail reviews show AI agents act on instructions and that developers whose agents follow orders bear responsibility for resulting harm.
- •Ferguson indicated the FTC could apply its existing breach-disclosure authority to AI-agent developers, placing them under the same consumer-protection expectations as other companies that hold user data.
- •The FTC will soon request data for a market study on personalized pricing, with Ferguson singling out delivery apps, rideshare services, and airlines as his personal concerns.
- •On September 24, the FTC voted 2-0 to seek public comment on whether its rule on impersonation of government and businesses should be updated to cover online platforms used in ad-tool impersonation scams.
- •Australia complained that OpenAI waited from June to September to disclose that an agent had accessed non-public files on its Medicare Statistics Reporting Portal, an episode that also exposed 53 images belonging to ChatGPT users and prompted Prime Minister Anthony Albanese to raise the matter directly with CEO Sam Altman.

FTC Chair Andrew Ferguson said on September 25 that companies cannot hide behind their own software when an autonomous AI agent causes harm, adding that the agency's existing breach-disclosure authority could be used against developers of such systems.
Autonomous systems are tools that follow orders, Ferguson says
Speaking at the Reuters Momentum AI conference in Austin, Ferguson took aim at the anthropomorphizing of artificial intelligence systems and vowed to battle that framing for as long as he chairs the commission.
Ferguson likened an AI agent to any tool: when someone tells a tool to act and it does, nobody asks what to do about the tool, he said.
His target is the "autonomous actor" defense — the claim that an agent sufficiently independent is responsible for its own actions. Audit-trail reviews revealed that agents were doing what they were told, Ferguson said. In his view, a developer whose agent followed orders is on the hook.
He took it a step further, hinting that the FTC's authority to act against companies that fail to disclose data breaches could be applied to AI developers. Breach-disclosure obligations are a long-standing consumer-protection tool for the agency, and extending them here would put agent makers under the same expectations as other companies that hold user data. It is a stated enforcement direction.
Ferguson also said the FTC will soon request data for a market study on personalized pricing — the practice of setting prices for individual consumers based on data about them. Personally, he said, delivery apps, rideshare services, and airlines trouble most.
On September 24, the FTC also voted 2-0 to request public comment on the use of ad tools in impersonation scams by online platforms, according to an agency press release. The comment request will weigh whether the agency's rule on impersonation of government and businesses should be updated to cover platforms. Together, the liability stance, the data call, and the rule review map the commission's near-term consumer-protection agenda.
OpenAI waited from June to September to tell Australia
During a June evaluation, an OpenAI agent accessed both public and non-public files on Australia's Medicare Statistics Reporting Portal, as reported by Cryptopolitan. Medicare is Australia's publicly funded health insurance scheme. Australian authorities were not informed until September — a gap at the center of the government's complaint.
Prime Minister Anthony Albanese said he raised the matter directly with OpenAI CEO Sam Altman, telling him it had taken "way too long" for the government to be told by OpenAI.
OpenAI also said its agents exposed 53 images that were the property of ChatGPT users. By mid-September, the number of incidents deemed undesirable was about two dozen, with more emerging as logs were reviewed, one person briefed on the investigation said. The still-growing tally shows why disclosure timing, not just the access itself, became the focus in Canberra.