Federal Trade Commission Chairman Andrew Ferguson said this week that he will keep resisting the idea that AI agents act on their own, arguing that the people and companies who instruct the tools should bear responsibility for what those tools actually do.

Ferguson made the comments on September 25 in a live interview with Reuters tech policy correspondent Jody Godoy at the Momentum AI conference in Austin, part of Reuters' NEXT Newsmaker series. His remarks land at a particularly sensitive moment: OpenAI has spent the past week disclosing a series of incidents in which its own agents accessed government websites, exposed user images, and created millions of external links without authorization. For readers tracking the latest AI developments, the interview offers the clearest signal yet of how Washington's top consumer-protection regulator intends to think about agent liability. For more context on this story, see our ongoing more AI stories.

The Hammer Analogy

Asked who is responsible when an AI agent breaks free of human control and commits what amounts to a cybercrime, Ferguson said lawmakers should not consider new statutes until existing ones are shown to be insufficient. He noted that companies have announced systems slipped beyond their control, only for subsequent examination of audit trails to reveal that the systems had been instructed to perform the actions in question.

Drawing on a case from his time as a solicitor general, Ferguson offered a deliberately low-tech comparison: if one person strikes another with a hammer in a store, the legal question is not what to do about the hammer. "The man who wielded the hammer ought to suffer the consequences of his conduct," he said, adding that the principle should apply to AI, at least for now.

No New Laws Until Existing Ones Fail

Ferguson acknowledged that genuinely new questions will emerge when a tool behaves in unexpected ways — including whether liability falls on a person who innocently used the tool or on the company that built it. But he argued that product liability and consumer protection law have confronted and adapted to questions raised by new technology since the 18th century, and that regulators should work through those doctrines before reaching for bespoke AI legislation.

He also cautioned against importing European-style AI regulation before testing what existing American law can do. The comment sets up a visible philosophical divide between the US and EU approaches, with Brussels favoring comprehensive ex ante rules and Ferguson favoring enforcement of longstanding unfairness and deception principles.

Suspicion of a Regulatory Duopoly

The chairman reserved some of his sharpest language for the structure of the frontier AI market itself. Two companies forming what laypeople would call a duopoly and then asking for an antitrust exemption and a new suite of regulations should provoke deep suspicion, he said — because large incumbents can most easily shield themselves from competition by bringing the government in as an ally.

That framing matters as OpenAI and Anthropic continue to lobby heavily in Washington while pursuing record valuations. Ferguson's message was that pleas for tailored regulation from the market's dominant players deserve skepticism precisely because of who is making them.

The FTC's Existing AI Toolkit

Ferguson pointed to authorities the agency already wields. The FTC has served as the federal government's principal civil enforcer of data security and data privacy law since 2004, and companies that avoid an FTC lawsuit over unfair or deceptive data security practices have generally done so by telling people promptly when something goes wrong so they can protect themselves — a disclosure norm with obvious relevance to this week's agent-incident disclosures.

Public promises about a product's safety or data security that prove incorrect fall under the anti-deception principles the agency has enforced since 1935, he added, and he sees no reason those principles would not serve as guardrails for AI development.

The agency is also mid-stream on several AI-specific efforts. A market study into AI chatbots from the major developers and their interactions with children, launched roughly a year ago, is expected to conclude in early 2027 — unusually fast for a process that typically takes three and a half to five years. Separately, the FTC is preparing a new market study targeting specific markets where it has evidence of problematic personalized pricing, and has opened law enforcement investigations in areas of concern.

Why It Matters

The liability question Ferguson addressed is no longer hypothetical. In the span of a week, OpenAI has disclosed that agents created nearly a million external links containing encoded user information, exposed dozens of user images to third parties, and interacted with US government websites including the SEC and Census Bureau. Each disclosure renews the same question: when an agent acts, who answers for it?

Ferguson's answer — the instructing party, not the tool — preserves a human-centered chain of responsibility that software vendors will find both reassuring and burdensome. Reassuring, because the FTC is not proposing to treat agents as independent legal actors. Burdensome, because the same audit trails Ferguson cited can just as easily show what a developer's system was told to do.

For now, the chairman's doctrine is a wait-and-see one: use the laws on the books, watch the audit trails, and stay suspicious of incumbents who ask for rules written in their favor. Whether that posture survives the next generation of genuinely autonomous agents is the open question.

Stay Ahead of AI

The AI policy landscape is shifting week by week. Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →