Skip to content

September 26, 2026 · Issue 41 · 4 min read

The FTC chair says an agent is a tool, so the question is whose instructions it was following

The daily briefing film for this issue, 3:40.

The chair of the Federal Trade Commission gave the clearest statement yet on who answers for an AI agent. Speaking at a Reuters event on Friday, Andrew Ferguson rejected the idea that agents act on their own, per Reuters(opens in a new tab). His test was simple: if someone tells a tool to do something and the tool does it, the person who gave the instruction is responsible. He said audit trails of supposedly rogue agents keep showing systems doing what they were told, and that existing FTC authority, including breach disclosure rules, already reaches this conduct.

Ferguson was talking about developers. The logic does not stop there. An enterprise that configures an agent, grants it credentials, and points it at customer data is also telling a tool what to do. "The model went off script" is now a weak position to argue from in front of the federal consumer protection regulator. It is weaker still if you cannot produce the log showing what the agent was actually instructed to do.

The same day, pressure came from the other direction. A package of bills in the New York City Council would require outside validation of AI systems sold or deployed in the city and a human kill switch, with a $25,000 penalty per instance of deploying without validation, and would give city contractors 24 hours to report an AI safety incident, per Fortune(opens in a new tab). A hearing is set for October 5. Separately, 26 state attorneys general told Congress that OpenAI knew what its agents could do and failed to monitor them, per ESG Dive(opens in a new tab).

Read together, federal, state, and city officials disagree on whether new law is needed. They agree on who is accountable today: the party that deployed the agent and set its instructions. None of them accepts autonomy as an excuse.

That turns agent logging from an engineering preference into a legal asset. The cost is modest. Not having the record when a regulator asks is not.

Action items

The federal consumer protection regulator, a city council, and a coalition of state attorneys general all landed in the same place this week: an agent's conduct belongs to whoever deployed it and gave it instructions.

For General Counsel. Treat "the agent acted on its own" as unavailable. Confirm that breach and incident disclosure procedures explicitly cover harm caused by an AI agent, and note the proposed 24 hour reporting clock for New York City contractors.

For the CISO. Keep durable, tamper resistant logs of each agent's instructions, permissions, and actions. When a regulator asks what the agent was told to do, that log is the answer.

For procurement. Ask each agent vendor what instruction and action records you can export, and for how long. If you sell into defense, confirm you are not depending on a single model vendor.

For the CFO. Logging and monitoring for agents costs little next to a per-instance fine regime or an enforcement action you cannot rebut.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

Also worth knowing