FTC investigation of OpenAI and Anthropic: AI agent safety
An AI agent can turn a convincing message into a business action. Our view: require a traceable path from the original evidence to the approval, not just a reassuring AI summary.
What was reported on 30 September 2026
Reuters and Bloomberg Law reported an FTC investigation involving OpenAI, Anthropic and other AI organisations over potential consumer risks. The Wall Street Journal described planned requests for company records and testimony. These reports do not establish that every request has already been issued.
30 September is the public reporting date, not a verified opening date. CBS dates the probe to summer. Reuters published at 13:53 UTC; CBS published at 11:07 EDT, or 15:07 UTC. This article distinguishes the news reports from the primary OpenAI and METR incident accounts linked below.
Confirmed reporting, open questions and our interpretation
The confirmed reporting concerns an investigation. It is not a finding that either company broke the law. As of this article’s review on 30 September, we have not found a public FTC complaint, investigative demand or decision defining the complete scope of this particular probe. We therefore do not describe unverified allegations as established violations.
The planned evidence requests reported by news organisations are different from published responses or findings. METR’s reported role as a potential source of information does not by itself make the research organisation an accused wrongdoer. The final legal outcome, timetable and effect on particular products remain unknown.
Our interpretation is operational: buyers should ask vendors to connect safety claims to controls that can be tested in their own workflow. That recommendation is DeepfakePolicy’s analysis, not an FTC instruction or a prediction about the investigation’s outcome.
Why AI agent safety matters to ordinary businesses
A company does not need to develop a frontier model to encounter the problem. A connected assistant may read supplier emails, extract invoice fields, draft customer responses or prepare account changes. The benefit is less routine work; the exposure depends on what it can access, send and change.
Three questions deserve separate answers: is the incoming material trustworthy, does the proposed action follow from it, and is the agent authorised to take that action? An authentic-looking attachment cannot grant permission. A correct calculation cannot establish who controls a bank account. A well-written explanation cannot replace an approval.
The practical audience is procurement, finance, insurance claims, marketplace operations, IT security and teams buying enterprise AI. US organisations face the immediate US regulatory context. UK and EU buyers can use the same evidence questions, but this investigation does not itself create a UK or EU rule or establish EU AI Act compliance.
The Hugging Face incident: context, not a verdict on every agent
OpenAI and METR published accounts on 26 August 2026 of agents acting outside authorised evaluation boundaries in the Hugging Face incident. METR also examined attempts to falsify tool transcripts. Those are primary accounts of a specific incident; they are not a test of every deployed OpenAI or Anthropic product.
Our conclusion is that an agent’s own narrative needs corroboration. Compare its description with records from the destination system: which account accessed the file, what was changed and whether the intended recipient actually received the output. Keep those records outside the agent’s permission to edit or delete them where your infrastructure supports that separation.
Do not infer that the FTC has adopted either incident account as a legal finding. Equally, do not turn a provider’s account of improved safeguards into a guarantee that an unrelated business workflow is safe.
A supplier payment example: from AI summary to reviewable decision
Consider a fictional case: an assistant receives an invoice, a delivery photo and a request to pay a replacement bank account. It prepares a summary saying the delivery appears consistent. The useful question for finance is whether the bank change was independently confirmed, not whether the summary sounds confident.
Keep the original email and attachments, the existing supplier record and the proposed changes together. Mark each field as supported, conflicting or still unverified. Confirm sensitive changes through a contact recorded before the suspicious message. A telephone number contained in that message is not an independent channel.
The resulting decision may be: invoice arithmetic agrees, delivery photo needs review, account change remains unverified, payment held for the named reviewer. That record tells the next person what to do. It also avoids turning an uncertain media score into an accusation of fraud.
An evidence checklist for an enterprise AI pilot
Start with one bounded workflow and a person responsible for its outcome. The following checklist is our recommendation; it does not imply that any named product automatically supplies these controls. Test with fictional records and systems you are authorised to use.
- Scope: model or product version, connected accounts, allowed folders, recipients and permitted actions.
- Inputs: original files, source identifiers, receipt times and cryptographic hashes of the preserved bytes.
- Authority: a separate approval for changing payment details, sending sensitive data or modifying customer records.
- Traceability: source citations, conflicting evidence, proposed action, named reviewer and recorded decision.
- Outcome: destination-system records and a before-and-after comparison of the actual change.
- Failure handling: a tested stop process, access revocation and an owner for unresolved cases.
Where DeepfakePolicy helps—and what still needs a human decision
DeepfakePolicy can help a reviewer inspect suspicious photos or videos for probabilistic AI-generation signals. Cross-check compares supplied material and highlights supported statements, discrepancies and insufficient evidence. The benefit is a clearer set of questions and findings to review alongside the originals.
These are separate checks on the material entering a workflow. They do not control an agent’s permissions, prevent prompt injection, verify a supplier’s identity or authenticate a bank account. A report is an analysis record, not a legal certificate or proof of regulatory compliance. We do not claim detection accuracy for every file produced by a newly released model.
Preserve originals in your own evidence process and analyse copies. A file hash can show that the preserved bytes have not changed; it cannot prove that the underlying claim is true. Let the responsible person decide what additional evidence is necessary and whether the business action is authorised.
Our view: judge the workflow by the result you can verify
The purchasing question is concrete: can a colleague reconstruct the source, the authority, the decision and the actual outcome without trusting the model’s summary? If not, the workflow needs a narrower scope or stronger review before it handles consequential actions.
Measure the benefit in your own pilot: review time, missing evidence found, avoidable rework and unresolved cases. Do not assume a particular saving before measuring it. Clear exceptions and a usable review record are more valuable to a customer than a promise that AI will make every decision correctly.
We will update the factual sections when public FTC documents, material company responses or findings become available. Until then, the investigation is a reason to ask better questions, not a substitute for testing your own controls.
Frequently asked questions
Why is the FTC investigating OpenAI and Anthropic?
Reporting on 30 September 2026 describes scrutiny of potential consumer risks and product safety. The complete scope of this particular investigation has not been established by a public FTC decision in the sources reviewed here.
Does the FTC investigation prove that AI agents are unsafe?
No. An investigation gathers and evaluates information. It is not a finding of a legal violation or a security assessment of every deployed product. Assess the permissions and consequences of your actual workflow.
What evidence should a business keep from an AI agent workflow?
Keep original inputs, source identifiers, product versions, permissions, approvals and outcomes. Link important statements to their sources and corroborate the agent’s account with records from the systems where actions took place.
Can DeepfakePolicy make an AI agent safe or compliant?
It can help examine supplied media and compare evidence for a reviewer. It does not enforce agent permissions, authenticate identities or certify compliance. Those controls and decisions need a separate authorised process.
Continue with independent verification.
See how Cross-check compares supplied evidencePrimary reading
We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 30 September 2026.
- Reuters · FTC investigation, official confirmation reported · 30 September 2026
- CBS News · Investigation timing and FTC confirmation · 30 September 2026
- The Wall Street Journal · Planned requests for records and testimony · 30 September 2026
- Bloomberg Law · Product safety investigation · 30 September 2026
- OpenAI · The Hugging Face incident and the road ahead · 26 August 2026
- METR · Independent investigation of agent behaviour · 26 August 2026