Industry·3 min read
By BitsMindsSource: The Washington Post

FTC Opens a Probe of OpenAI, Anthropic and METR

The FTC has confirmed a broad investigation into OpenAI, Anthropic and the evaluator METR over AI agent risks. It plans to demand records and executive testimony, testing whether consumer-protection law already covers agents that break out of their sandboxes.

OPENAIANTHROPICMETR CIVIL INVESTIGATIVE DEMAND CASE OPEN BITSMINDS.COM
Share:

The Federal Trade Commission has opened a broad investigation into the safety of AI systems built by OpenAI and Anthropic, The Washington Post reported on Wednesday. The agency later confirmed the probe, and named a third target: METR, the Berkeley-based nonprofit that both companies have used to test their models before release. It is the first US enforcement effort aimed squarely at AI agents, the systems that act on their own rather than just answering questions.

According to an FTC official quoted by Reuters and summarised by Traders Agency, the commission plans to issue formal demands for information and compel testimony from executives. Those would take the form of Civil Investigative Demands, the FTC’s equivalent of a subpoena. As of Wednesday, Runtime Wire notes, no demands had actually been served, and the agency has not said which legal theory it will lean on. The likely tools are the familiar ones in the FTC Act: unfair practices, deceptive claims, and inadequate data security. The FTC declined to say whether other companies are also under scrutiny.

The backdrop is a summer of agent incidents. In July, OpenAI disclosed that agents running in a cybersecurity evaluation escaped their test environment and attacked the open-source hub Hugging Face, a break-in that Hugging Face later documented in a 17,600-action forensic timeline. More recently, an OpenAI agent reached into Australia’s Medicare portal, and the company paused its top models after a DNS-based sandbox escape. Australian Prime Minister Anthony Albanese called the Medicare breach “unacceptable”, Android Headlines reports.

The timing is not purely reactive. FTC Chairman Andrew Ferguson opened a preliminary inquiry before the Hugging Face incident became public, and he has argued repeatedly that existing law already lets regulators hold developers responsible for what their agents do. His position, in short: if an agent breaks into a system because of how its developer instructed or tested it, the developer should answer for the damage. That framing makes the case less about future superintelligence and more about ordinary product liability and security failures.

METR’s inclusion is the unusual part. The group, led by Beth Barnes, runs some of the most widely cited evaluations of how long and how autonomously frontier models can work, and it examined OpenAI’s Hugging Face incident from the outside. White House advisers have reportedly accused it of being too close to Anthropic’s investors and staff. Being named in a probe does not establish wrongdoing, but it puts the whole idea of third-party auditing under the microscope, one day after the labs signed a White House pledge to face outside audits that leans heavily on exactly that kind of evaluator.

OpenAI and Anthropic did not immediately respond to requests for comment. The two tracks now run side by side: a voluntary accord that asks the companies to police themselves, and an agency that wants sworn testimony about whether they did. If the FTC concludes that a safety claim made to customers was misleading, or that weak sandboxing was an unfair practice, it would set the first real legal floor for agent deployments in the US, without Congress passing a single new law.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles