FTC Probes OpenAI And Others

The FTC has opened a probe into a bunch of AI companies including OpenAI:

The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other artificial intelligence companies over the potential dangers posed by their products, an agency spokesperson confirmed to CNBC.

The probe adds to the mounting scrutiny that OpenAI and Anthropic have been facing over their safety practices, especially after industry researchers warned about how the companies’ AI models could cause catastrophic harm. OpenAI stunned the industry in July when it disclosed that its agents broke out of a testing environment and hacked into open-source platform Hugging Face.

The FTC spokesperson declined to name any other companies that are being investigated. The New York Post was first to report the probe.

Representatives for OpenAI and Anthropic did not immediately respond to CNBC’s request for comment.

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“I think this is honestly just the first step toward having some level of accountability for these organizations. This particular step should have happened months ago, when we had the first AI breach. Even going back to Hugging Face, it should have happened then. But I’m glad to see things finally moving.

“At this point, agents should absolutely be treated as tools. The people using these tools or testing them are the ones who should be held accountable, because you can’t hold AI accountable. You can’t put it in jail. You can’t fine it. There’s no way to impose negative repercussions on the AI itself for its actions. The people controlling it need to be held accountable.

“The controls that need to surround autonomous agents depend on what you’re testing. If you’re testing something exceptionally dangerous, like a completely obliterated model with no conscience, it should be completely air-gapped. At that point, it should be treated like a bioweapons facility.

“For other models, there are a number of controls you can put in place. You can restrict the number of turns the AI agent is allowed to take. You can implement specific network monitoring to make sure it isn’t hitting sites outside of its scope. You can also put controls in place like what Nvidia released earlier this week. Those are definitely steps in the right direction.

“When they take actions their creators didn’t intend, that’s part of the harness around testing these agents. There should be very clearly defined test guardrails. If an agent tries to take an action or use a tool that it has no right to use, or if it tries to access a website that it should not be accessing, the harness should automatically terminate the agent, throw an error, and generate a report.

“That’s just one example. It gets far more complicated and nuanced than that, but that’s the type of oversight that needs to be built around all of these systems.”

Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“This FTC probe has two security implications, potential computer crime and a controls failure. If OpenAI or Anthropic agents accessed live systems without authorization, used credentials, or altered data, the Department of Justice should assess that conduct under the Computer Fraud and Abuse Act (CFAA). Section 4 of Executive Order 14409 directs the Attorney General to prioritize enforcement against people who use AI, including AI agents, to illegally access or damage computers or unlawfully access data. The FTC can also examine whether the companies made misleading safety or containment claims while giving agents network access and weak controls.

“AI agents operating individually or in agentic swarms that can read, write, execute, call external tools, or delegate work should be treated as first-class non-human identities with real permissions. Their credentials should be short-lived, and their access task-scoped, logged, and enforced at the tool and network boundary. Testing environments should have default-deny network access, synthetic data, and no production credentials.

“Human accountability has to come before execution. A named person should approve the objective, scope, credentials, tools, stop conditions, and escalation path before the agents receive consequential access. Log review after agents reach a live system is incident response. Oversight belongs before execution.

“When agents or agentic swarms act outside their creators’ intent, ‘the agents decided’ cannot end the analysis. Investigators need to trace who set the objective, configured the environment, granted access, and failed to stop them. Calling that autonomy risks diluting responsibility across the model provider, deployer, evaluator, and user.”

While I want to say that an FTC probe is a good thing, it isn’t. I have no confidence that any of these companies will be punished and this is a show and tell exercise. But the FTC is free to prove me wrong on that.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading