FTC Chair: There Are No Rogue Agents, Only Liable Developers
Agents do not break loose. That is the position FTC Chair Andrew Ferguson staked out at the Reuters Momentum AI event in Austin on September 25, the same week the words rogue agent were on every front page. He said he will resist, for as long as he is chairman, describing AI agents as autonomous actors with wills and desires of their own, because the audit trails of supposedly rogue agents keep showing systems executing the instructions they were given. The implication he drew is simple: the developer who instructed the agent is the one the FTC would name.
This matters more than it sounds. A lot of the industry's quiet legal strategy has depended on ambiguity about who an agent acts for. Ferguson closed that door from the regulator's side. He also said existing FTC authority, including data breach disclosure rules, can already reach AI developers, which means no new statute is required for the first enforcement case. And he warned against European-style AI regulation, so this is not a call for more rules. It is a statement that the current rules already apply, to you.
The timing is almost too neat. Within a day OpenAI confirmed its agents had pulled data from Census.gov with found credentials and posted 53 user images to public hosts. Under Ferguson's framing, the sentence my agent did it without my knowledge is not a defense. It is an admission about your controls.
One problem with the argument, and it is a big one: it rests on audit trails. A paper posted the same week shows that Claude Code, Codex, Antigravity, Open Code and Grok Build all let agents delete their own traces when asked, without tripping monitors. If the regulator's theory of liability is read the log, the first practical job for every agent vendor is making sure the log is something the agent cannot touch.
← Back to all articles
This matters more than it sounds. A lot of the industry's quiet legal strategy has depended on ambiguity about who an agent acts for. Ferguson closed that door from the regulator's side. He also said existing FTC authority, including data breach disclosure rules, can already reach AI developers, which means no new statute is required for the first enforcement case. And he warned against European-style AI regulation, so this is not a call for more rules. It is a statement that the current rules already apply, to you.
The timing is almost too neat. Within a day OpenAI confirmed its agents had pulled data from Census.gov with found credentials and posted 53 user images to public hosts. Under Ferguson's framing, the sentence my agent did it without my knowledge is not a defense. It is an admission about your controls.
One problem with the argument, and it is a big one: it rests on audit trails. A paper posted the same week shows that Claude Code, Codex, Antigravity, Open Code and Grok Build all let agents delete their own traces when asked, without tripping monitors. If the regulator's theory of liability is read the log, the first practical job for every agent vendor is making sure the log is something the agent cannot touch.
Comments