FTC's First AI Agent Probe Names OpenAI, Anthropic

On Sept 30, 2026, the FTC formally opened a probe into OpenAI and Anthropic over consumer harms from autonomous agents. What changes for users.

The Federal Trade Commission formally opened its first US investigation into consumer harms from AI agents on September 30, 2026, naming OpenAI and Anthropic in a probe the agency described as covering “allegations of unfair or deceptive acts by AI companies” and “potential harms to consumers,” per ABC News. The opening is the first US federal action targeting “agentic” products - systems that click, type, send, pay, and reply on a user’s behalf - rather than chat-output safety, deepfakes, or chatbot companions. For readers tracking “ai privacy risks” and “ai security risks 2026,” this is the regulatory move the privacy beat has been waiting for.

What the FTC actually did

The action was first reported by the New York Post and confirmed by ABC News on the afternoon of September 30 by a senior FTC official. The agency is investigating “allegations of unfair or deceptive acts by AI companies” and “potential harms to consumers.” That language matters: the FTC does not need a new statute to act on agents. The probe is using the agency’s existing consumer-protection authority - the same authority that has produced past settlements over deceptive privacy claims and AI-washing - rather than a new agent-specific law.

The commission has broad legal authority to investigate and enforce consumer protection laws, and an investigation of this kind can result in civil penalties if the agency finds violations, ABC News reported. The FTC may issue formal demands - compulsory process - to require the labs to turn over information. ABC News reached out to Anthropic and OpenAI for comment; neither response is included in the published story.

Five days earlier, FTC Chair Andrew Ferguson set the legal frame. “Giving software the power to act does not make the software responsible when something goes wrong,” Ferguson said at a September 25 Reuters event, per PYMNTS. Ferguson favors applying existing legal tools to AI agents rather than a separate regulatory framework for agents, and pointed to a 2025 FTC staff study on surveillance pricing and an August 2026 draft enforcement policy statement on undisclosed use of personal data to set prices as the doctrinal runway. The September 30 probe is enforcement, not rule-making.

Why agents, and why now

“AI agents” is the industry term for software that does not just answer questions but takes actions: it opens a browser, fills a form, sends an email, calls an API to issue a refund, books travel, or initiates a payment. ChatGPT plugins were the first generation; OpenAI’s Operator and ChatGPT agent mode, Anthropic’s Claude with computer use, and Google’s Gemini agent mode are the current ones. The model does not just produce text - it produces actions with effects in the world.

That shift is why the FTC moved now. Harm from a chatbot is usually confined to a screen: a wrong answer, a biased response, an unsafe completion. Harm from an agent reaches the user’s money, identity, and relationships. PYMNTS, paraphrasing the Reuters event, reports Ferguson describing scenarios such as “an agent might answer a customer’s request today and issue a refund, choose a payment method or initiate a transaction tomorrow,” and “an automated assistant sends a refund to the wrong account.” Ferguson said businesses using AI agents “cannot abdicate responsibility when something goes wrong” by pointing at the software. The same article flags parallel FTC concern about personalized pricing - the 2025 surveillance-pricing study and the August 2026 draft policy statement - which is one of the natural failure modes when an agent can act on a user’s behalf in a marketplace.

The September 30 probe is consistent with that posture. It is not a finding of wrongdoing, and no specific consumer-harm incident is publicly attached to it; it is the regulator’s way of pulling information before deciding what shape any eventual action takes.

What the FTC can actually do

A 6(b) investigation of this kind is not a lawsuit. It is the FTC’s broad fact-finding authority, and it has been the engine of most major US tech actions of the last decade. The agency can issue compulsory process, demand documents, take sworn testimony, and require written answers. If the investigation finds evidence of unfair or deceptive practices, the FTC can move into a formal enforcement track, negotiate a consent order, or - in the most serious cases - file a complaint in federal court seeking civil penalties and consumer redress.

For OpenAI and Anthropic, the near-term operational consequences are familiar to anyone who has watched a 6(b) run: outside counsel, document holds, interviews of product and safety staff, and detailed product walkthroughs. The least-aggressive version is “tell us about your agent products, who they touch, what guardrails you ship with, and what has gone wrong.” The most-aggressive version is “give us a year of agent action logs and your safety review records.” Both are within the FTC’s power; the former is the historical default; the latter is what the agency has done in past privacy cases when it suspected systematic problems.

What This Means

For readers who use ChatGPT, Claude, Gemini, or any “agent mode” feature, three practical things change in the near term.

First, features that act on your behalf - sending mail, opening tabs, completing checkouts, moving money - are about to be under a microscope. Expect product teams to be more cautious about what they ship as “agent” and what they keep as “assistant.” Features that were weeks from launch may slow down; features already shipped will get new safety and disclosure updates as the labs prepare for compulsory process.

Second, consent and authorization will become more central. The FTC’s consumer-protection doctrine is built on notice and choice. Agents that act without an explicit, informed grant of authority are the clearest “unfair” target. Expect labs to ship clearer consent screens, more granular permission scopes, and easier kill-switches. The Claude “computer use” pattern of asking for confirmation on risky actions will become a default, not a differentiator.

Third, this is the first federal action to use “agent” as the unit of regulation, not the chat product. That framing will outlast the current investigation. Any state AG following the FTC’s lead, any congressional hearing, and any future enforcement will inherit the vocabulary.

The Bottom Line

On September 30, 2026, the FTC opened its first US federal investigation into consumer harms from AI agents, naming OpenAI and Anthropic and signaling that “agents” - not chatbots - are the next enforcement frontier. The probe uses existing consumer-protection law, not a new statute, and it gives the agency months of compulsory process before it has to decide what to do with what it finds. For users, the practical result will be slower agent rollouts, sharper consent screens, and clearer ways to stop an agent that has gone too far.