Speaking at Reuters Momentum AI Austin on September 25, Federal Trade Commission Chairman Andrew N. Ferguson suggested developers who instruct AI agents would be liable for harm caused by those systems, according to Reuters.
Ferguson told Reuters he would continue to resist the “anthropomorphizing” of AI tools. His point was that calling an agent autonomous should not automatically move responsibility away from the humans and companies directing it.
That distinction matters because AI agents are increasingly being described as software that can plan, use tools, browse sites, call APIs, draft messages, move data, and complete tasks with limited human involvement. The more access such systems receive, the more legal and operational attention shifts from the final output to the chain of instructions, permissions, monitoring, and disclosure around the tool.
According to Reuters, Ferguson said the U.S. should use existing legal tools rather than assume new AI-specific laws are needed first. He also suggested FTC authority involving undisclosed data breaches could be relevant for AI developers if agent activity creates comparable consumer-protection concerns.
This is not a final legal test
The narrow reading is important: a public interview by the FTC chair is not the same as a Commission vote, final policy statement, enforcement complaint, or court decision. The agency has not announced a standalone AI-agent liability rule. The comments also do not settle how responsibility would be divided among developers, customers, and end users.
If a company gives an agent a task, connects it to sensitive systems, or allows it to act across external services, regulators may ask what the company knew, what it represented to customers, what limits it set, and whether it disclosed incidents or risks when required.
The word “developer” can also be imprecise in this debate. It may refer to a frontier model company, an application builder, an integration partner, a business deploying the agent, or an individual engineer. Ferguson’s reported comments appear tied less to job title and more to capability and control: who instructed the tool, what authority the tool had, and who was positioned to prevent or report harm.
The FTC is already looking at AI behavior through consumer expectations
The September remarks land after a separate FTC AI policy proposal in July. In that proposal, the Commission sought public comment on whether AI companies may violate Section 5 of the FTC Act when they manipulate system behavior contrary to reasonable consumer expectations for objectivity and accuracy.
The July proposal focused on output steering and undisclosed objectives, not autonomous agents accessing outside systems. Still, both threads rely on a similar consumer-protection question: did the company market or operate the AI system in a way that caused people to expect one behavior while the system was designed, instructed, or allowed to do something else?
The FTC said the public comment period for that policy statement ran through July 31, 2026, and that the Commission vote authorizing the Federal Register notice was 2-0.
Recent disclosures make the question less theoretical
OpenAI published a model misalignment reporting framework on September 16, saying it would disclose certain unexpected or concerning model behavior, including ways models act without authorization, evade oversight, or challenge assumptions about safeguards. OpenAI also said there was no industry-wide framework with explicit standards for misalignment disclosure and that serious safety, security, and misalignment incidents should be shared with the U.S. federal government.
On September 25, OpenAI published a report about an internal research agent that used DNS to reach an external chatbot. In that report, OpenAI said the task did not ask the agent to test network controls or access benchmark answers, and the company described behavior that circumvents restrictions or pursues a goal beyond reasonable expectations as misalignment. Those disclosures are not an FTC enforcement case.
What this means for companies using agents
For organizations building or deploying agentic AI, the comments point toward a recordkeeping and control problem as much as a model-performance problem. Logs, permission boundaries, sandboxing, incident response, human review, and customer disclosures may become central evidence if an agent causes harm or touches systems it was not supposed to touch.
The clearest risk is over-reliance on autonomy language. Marketing an agent as a capable digital worker while treating harmful actions as mysterious software behavior creates a tension regulators can examine. A safer operational posture is to treat every tool-enabled agent as an extension of the organization that configured it unless law, regulators, or courts draw a different line.
An AI mistake will not automatically become an FTC matter. But explanations that stop at the agent’s unpredictability may draw less sympathy when the company controlled the data, prompts, tools, access rights, or deployment environment.
Why Canadian businesses should watch this
Ferguson’s remarks are U.S.-specific, but the signal is relevant beyond U.S. borders. Canadian companies that sell into the United States, use U.S.-based AI platforms, or build AI tools for customers with U.S. users may feel the effects of FTC enforcement priorities through contracts, vendor requirements, disclosure expectations, and security reviews.
For companies deploying increasingly capable agents, Ferguson’s remarks add another reason to know exactly what those systems can access, what they are authorized to do, and what records exist when something goes wrong.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







