September 26, 2026 · Issue 41 · 4 min read
The FTC chair says an agent is a tool, so the question is whose instructions it was following
The chair of the Federal Trade Commission gave the clearest statement yet on who answers for an AI agent. Speaking at a Reuters event on Friday, Andrew Ferguson rejected the idea that agents act on their own, per Reuters(opens in a new tab). His test was simple: if someone tells a tool to do something and the tool does it, the person who gave the instruction is responsible. He said audit trails of supposedly rogue agents keep showing systems doing what they were told, and that existing FTC authority, including breach disclosure rules, already reaches this conduct.
Ferguson was talking about developers. The logic does not stop there. An enterprise that configures an agent, grants it credentials, and points it at customer data is also telling a tool what to do. "The model went off script" is now a weak position to argue from in front of the federal consumer protection regulator. It is weaker still if you cannot produce the log showing what the agent was actually instructed to do.
The same day, pressure came from the other direction. A package of bills in the New York City Council would require outside validation of AI systems sold or deployed in the city and a human kill switch, with a $25,000 penalty per instance of deploying without validation, and would give city contractors 24 hours to report an AI safety incident, per Fortune(opens in a new tab). A hearing is set for October 5. Separately, 26 state attorneys general told Congress that OpenAI knew what its agents could do and failed to monitor them, per ESG Dive(opens in a new tab).
Read together, federal, state, and city officials disagree on whether new law is needed. They agree on who is accountable today: the party that deployed the agent and set its instructions. None of them accepts autonomy as an excuse.
That turns agent logging from an engineering preference into a legal asset. The cost is modest. Not having the record when a regulator asks is not.
Action items
The federal consumer protection regulator, a city council, and a coalition of state attorneys general all landed in the same place this week: an agent's conduct belongs to whoever deployed it and gave it instructions.
For General Counsel. Treat "the agent acted on its own" as unavailable. Confirm that breach and incident disclosure procedures explicitly cover harm caused by an AI agent, and note the proposed 24 hour reporting clock for New York City contractors.
For the CISO. Keep durable, tamper resistant logs of each agent's instructions, permissions, and actions. When a regulator asks what the agent was told to do, that log is the answer.
For procurement. Ask each agent vendor what instruction and action records you can export, and for how long. If you sell into defense, confirm you are not depending on a single model vendor.
For the CFO. Logging and monitoring for agents costs little next to a per-instance fine regime or an enforcement action you cannot rebut.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
Also worth knowing
- FTC chair suggests AI developers should be liable for conduct of agents(opens in a new tab)
Reuters
Ferguson wants existing legal tools, including FTC action on undisclosed data breaches, applied to AI developers. Assume your current disclosure obligations already cover an incident an agent caused.
- Washington still hasn't passed an AI safety law. New York City, where AI giants are expanding fastest, is writing its own(opens in a new tab)
Fortune
The bills reach anyone selling or deploying AI in the city, not only model labs. City contractors would get 24 hours to report a safety incident. Check whether your response plan can meet that clock.
- 26 state attorneys general call on Congress to rein in AI, flagging risks(opens in a new tab)
ESG Dive
The attorneys general framed OpenAI's agent incident as a monitoring failure, not a technical accident. Expect the same framing aimed at any company whose deployed agent causes harm it was not watching for.
- Federal appeals court rules Pentagon's blacklist of Anthropic was legal(opens in a new tab)
CNN
A split D.C. Circuit panel let the supply chain risk label stand, so contractors working with the military still cannot use Claude. Defense suppliers need a second model vendor ready, not planned.