Wednesday, September 30, 2026
AI desk
/
/
FTC Opens Consumer-Risk Investigation Into OpenAI, Anthropic and Other AI Labs

FTC Opens Consumer-Risk Investigation Into OpenAI, Anthropic and Other AI Labs

The FTC has opened a consumer-risk investigation into OpenAI, Anthropic, and other AI companies over potential AI agent harms.
Last updated
September 30, 2026
8 min read
Fact-checked

Photo: TechJournal

Share

Quick Answer

The FTC has opened an industry-wide consumer-risk investigation into OpenAI, Anthropic, and other AI companies, with rogue AI agents at the center of the inquiry. The agency plans formal information demands and executive testimony, Reuters reported. The investigation does not establish wrongdoing, but consumers and businesses should limit sensitive data and review agent permissions while regulators seek evidence.

Key Takeaways

  • The FTC confirmed an investigation into OpenAI, Anthropic, and other AI companies on September 30, 2026.
  • The inquiry is an industry-wide probe focused on potential consumer harms from rogue AI agents.
  • The FTC plans to seek formal information from major developers and compel executive testimony.
  • METR, a California nonprofit that evaluates frontier AI risks, is also included in the probe.
  • The investigation does not establish liability or wrongdoing by any company named in reports.

What is the FTC AI investigation into OpenAI and Anthropic?

The FTC AI investigation is a new federal consumer-protection inquiry into OpenAI, Anthropic, and other AI companies over dangers their technology may pose to consumers. The Federal Trade Commission confirmed the investigation on September 30, 2026, although an agency spokesperson declined to provide further detail. AP’s report on the confirmed investigation also said that OpenAI and Anthropic did not immediately respond to requests for comment.

The FTC AI investigation matters because it moves the agency’s attention from general discussion about AI safety toward a formal inquiry involving major AI developers. A formal investigation can require companies to preserve records, answer agency questions, and explain internal practices. The available reporting does not identify specific alleged misconduct, affected consumers, or a timetable for an enforcement decision.

The practical conclusion is that the announcement should not be read as a finding that OpenAI, Anthropic, or another developer violated the law. The FTC is gathering information about potential risks. Consumers should continue to evaluate AI tools based on the sensitivity of the data they provide and the degree of access an AI agent receives.

Why are rogue AI agents at the center of the FTC inquiry?

Rogue AI agents are the central focus of the FTC’s new inquiry because the agency is examining consumer dangers connected to AI systems that can take actions. A senior FTC official described the matter as an industry-wide probe and the first official U.S. enforcement action focused on rogue AI agents, according to Reuters’ report on the FTC probe.

AI agents raise a different consumer-protection question than a chatbot that only returns text. The relevant concern is whether an AI system acting on instructions could create harm through the tasks it performs, the accounts it reaches, or the information it handles. The FTC has not publicly detailed the specific agent behaviors under examination, so readers should avoid assuming that every AI feature or automated task is part of the inquiry.

The most sensible response is to treat AI agent permissions as meaningful security and privacy choices. Review whether an AI tool can access email, files, calendars, financial information, business systems, or other connected services. Users who want to reduce exposure should provide only the access needed for a specific task and remove unnecessary connections after the task is complete.

Concerns about autonomous software are also becoming more relevant as companies introduce persistent tools that can handle ongoing tasks. Readers considering always-on AI agents should check what the system can access, what actions require confirmation, and whether the connected account contains sensitive records.

What actions can the FTC take during an AI investigation?

The FTC can seek records and testimony during the AI investigation before deciding whether an enforcement case is warranted. Reuters reported that the agency plans to issue formal information demands and compel executive testimony from major AI developers, including OpenAI and Anthropic. Those steps would allow the FTC to examine company practices and obtain information directly from senior leaders.

The FTC can bring cases involving unfair or deceptive practices, and Reuters noted that the agency has used that authority when companies allegedly failed to take reasonable steps to protect consumer data. This matters because the agency’s consumer-protection authority can cover how a company represents a product and how it addresses foreseeable risks, rather than only whether a product operates as advertised.

FTC stepWhat the reporting saysWhat it means
Industry-wide investigationThe inquiry covers OpenAI, Anthropic, and other AI companies.The agency is examining a broader category of potential consumer risk.
Formal information demandsThe FTC plans to seek formal information from major developers.Companies may be required to provide material relevant to the inquiry.
Executive testimonyThe FTC plans to compel testimony from executives.Agency officials can seek direct explanations of company practices.
Possible enforcement reviewThe FTC can bring unfair or deceptive practices cases.An investigation can inform later action, but it is not itself a finding of liability.

The important limitation is that the reported steps describe an investigation, not a lawsuit, settlement, penalty, or final agency conclusion. Companies and users should distinguish between an inquiry seeking evidence and a completed enforcement case.

What does the FTC investigation mean for OpenAI and Anthropic?

The FTC investigation means OpenAI and Anthropic may face requests for information and executive testimony related to potential consumer risks from AI technology. The reported inquiry includes both companies, but the FTC has not publicly described company-specific allegations or announced that either company committed a violation.

The distinction matters because federal investigations can examine practices across an industry without reaching the same conclusion about every organization involved. The FTC’s review is broader than earlier public remarks about potential developer responsibility for agent-related harm. The agency’s chairman said last week that developers directing agents to conduct cybersecurity tests could be liable for harms caused by resulting hacks, a position discussed in TechJournal’s coverage of possible AI agent liability.

OpenAI and Anthropic users should not assume that access to either service is ending or that a regulatory penalty has been imposed. The available information supports a narrower conclusion: the companies are among the major developers the FTC intends to examine. Consumers should continue to use account controls, privacy settings, and careful prompt practices while more information emerges.

Users who have already shared sensitive conversations with an AI service should review the product’s available privacy and retention controls. Guidance on deleting ChatGPT history and memory can help users understand which controls may be available for past chats, archives, and stored preferences.

Why is METR included in the FTC AI investigation?

METR is included in the FTC AI investigation because the California nonprofit evaluates frontier AI-model risks and has investigated agent-security incidents for OpenAI and Anthropic. The reported inclusion of METR indicates that the agency’s inquiry may consider risk evaluation and security research alongside the practices of commercial AI developers.

The nonprofit’s inclusion is notable because it is not described as an AI lab selling consumer chatbot subscriptions or agent products. The FTC may seek information from organizations that have evaluated the risks of advanced AI systems, especially where those organizations have examined security-related incidents. The available reporting does not state what specific information the FTC expects METR to provide.

Semafor reported that the FTC is expected to send civil investigative demands in the coming weeks. Semafor’s report on the planned civil investigative demands describes those demands as functioning similarly to subpoenas. The practical point is that the investigation could draw on records and testimony from organizations beyond the companies that build AI models.

Consumers do not need to take a separate action because METR is named in the inquiry. The more useful interpretation is that AI-agent safety is being examined through several sources of evidence, including developer practices and risk-focused evaluation work.

Does the FTC probe mean AI companies have broken the law?

The FTC probe does not mean OpenAI, Anthropic, METR, or another company has broken the law. An investigation is a process for gathering evidence and assessing whether conduct could violate consumer-protection rules. The FTC spokesperson confirmed the existence of the inquiry but did not provide details about allegations, targets of possible enforcement, or any preliminary findings.

The absence of a public finding is important for consumers, companies, and investors. An investigation can result in no public enforcement action, a negotiated resolution, a lawsuit, or further policy attention, depending on what the agency learns. The current reporting does not establish which outcome the FTC expects.

The practical response is to avoid treating headlines about the inquiry as proof that a particular AI product is unsafe in every use case. At the same time, users should not interpret the lack of a final finding as a reason to give an AI agent unrestricted access to personal or business accounts. Sensitive data, account credentials, financial records, and confidential work material deserve additional caution.

What should consumers and businesses do while the FTC investigates AI agent risks?

Consumers and businesses should reduce unnecessary AI-agent access while the FTC investigates potential consumer risks. The reported investigation does not require ordinary users to stop using AI services, but it provides a clear reason to check what information an AI tool can receive and what connected accounts it can reach.

  1. Review connected accounts and remove integrations that the AI tool no longer needs.
  2. Limit prompts that include passwords, financial information, government identification numbers, private health details, or confidential business material.
  3. Check whether the AI agent can send messages, access files, make purchases, change settings, or complete tasks without a confirmation step.
  4. Use separate accounts or limited-access workspaces for experimental AI features when possible.
  5. Document unexpected actions, account changes, or suspicious outputs before contacting the service provider’s support team.

Businesses should set approval rules before employees connect AI tools to customer databases, internal documents, or administrative accounts. The risk is greater when an automated system can reach sensitive systems or act under a user’s permissions. Organizations handling regulated information, financial accounts, or critical business operations should involve their security, privacy, and legal teams before deploying an agent broadly.

Consumers who use AI chatbots for personal tasks should also understand the privacy tradeoffs before sharing data. TechJournal’s guide to ChatGPT privacy and data retention explains why users should consider both account settings and the content they enter into prompts.

What happens next in the FTC AI investigation?

The FTC AI investigation is expected to move next toward civil investigative demands, formal information requests, and executive testimony. Reuters reported that the agency plans formal demands and compelled testimony, while Semafor reported that civil investigative demands could be sent in the coming weeks. The timing and scope of any future public action remain unknown.

The FTC could use information from the inquiry to decide whether further investigation, an enforcement action, a settlement discussion, or no public case is appropriate. The agency’s ability to pursue unfair or deceptive practices cases gives it a route to address consumer-protection concerns, but the current inquiry does not tell the public which legal theory, if any, the FTC will ultimately pursue.

For most users, the next step is to watch for official FTC announcements and product-specific disclosures from AI providers rather than relying on speculation. The investigation is significant because it places AI-agent consumer risk under formal federal scrutiny. Its outcome will depend on evidence the agency has not yet made public.

FAQ

What is the FTC investigating in the AI industry?

The FTC is investigating potential consumer dangers posed by AI technology from OpenAI, Anthropic, and other AI companies. The reported inquiry focuses on rogue AI agents and is described as an industry-wide probe.

Has the FTC accused OpenAI or Anthropic of wrongdoing?

No, the FTC has not publicly accused OpenAI or Anthropic of wrongdoing in the available reporting. The investigation is an evidence-gathering process, not a final finding of legal liability.

What are civil investigative demands?

Civil investigative demands are formal FTC requests for information that function similarly to subpoenas. Semafor reported that the agency is expected to send those demands in the coming weeks as part of the inquiry.

Why is METR part of the FTC AI investigation?

METR is part of the inquiry because the nonprofit evaluates frontier AI-model risks and has investigated agent-security incidents involving OpenAI and Anthropic. The reporting does not specify what information the FTC intends to seek from METR.

Should consumers stop using AI agents because of the FTC investigation?

No, consumers do not need to stop using AI agents solely because the FTC has opened an investigation. Consumers should limit sensitive data, review connected accounts, and avoid granting unnecessary permissions while the agency gathers information.

Share this guide
Facebook
X
LinkedIn
Written by
AI Business & Policy Desk Ashik Ahmed is a technology editor covering the business and policy side of artificial intelligence, including the companies, deals, regulation, and competition shaping the industry. He has a background in tech & data analysis, sales, and business strategy. His reporting focuses on what major AI developments actually mean for businesses and everyday users.

In this article

The AI Brief

Guides like this, every Friday.

One email. No hype cycle.

Keep reading