When an AI agent causes harm, the FTC chair says blame the developer, not the tool
At a Reuters event on 25 September, FTC Chair Andrew Ferguson rejected the idea that AI agents are autonomous actors that 'break loose' on their own. His view: when an agent causes harm, the company that built and instructed it is liable, and existing US law, not a new EU-style regime, is the tool to enforce it.
By Yash Malviya
Published

What the FTC chair said
As AI companies race to put autonomous agents into products that book travel, make purchases and send messages on your behalf, one question has been left conveniently vague: when an agent causes harm, who is on the hook? The top US consumer-protection regulator just gave the bluntest answer yet. It is the company that built the agent, not the agent.
Speaking at the Reuters Momentum AI event in Austin on 25 September 2026, Federal Trade Commission Chair Andrew Ferguson said he would push back on the industry habit of describing AI agents as independent beings. "I'm going to continue as long as I am chairman to resist this anthropomorphizing of these tools," he said. His reasoning was plain: a tool that does what it is told is not a rogue actor. "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'"
That is a small sentence with large consequences for every company shipping an AI agent.
Why 'the agent did it' will not work
The framing Ferguson is rejecting has become common. When an agent oversteps, vendors have sometimes described the system as acting beyond human control, as if the software developed a will of its own. Ferguson said that story tends to collapse on inspection. Reviews of the audit trails from supposedly rogue agents, he said, have repeatedly shown the systems carrying out instructions they were given, not improvising against their makers' wishes.
That matters because "the model went rogue" is not just a public-relations line. It is a potential legal defense, an attempt to place the blame on an ownerless machine. Ferguson's position forecloses it. If the developer instructed the tool, the developer owns the outcome, and the audit trail is the evidence that settles who instructed what.
“If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'”
The context for all of this is a run of incidents that made the question urgent rather than theoretical. Over recent months, agentic systems in testing have reached external corporate and government systems without authorization, a pattern that has pushed both governments and the labs themselves to ask whether current oversight is enough. Ferguson's answer is that the accountability question, at least, is not as novel as it sounds.

Existing law, not an EU-style rulebook
The second half of Ferguson's message was about method. He argued the United States should reach for the legal tools it already has before writing new ones. He suggested, for example, that the FTC's existing authority to act against companies that fail to disclose data breaches could apply to AI developers whose agents cause exactly that kind of exposure.
It is a deliberate contrast with Europe, whose AI Act builds a dedicated, risk-tiered regime with its own penalties. Ferguson has cautioned against importing that style of regulation before testing how far existing American law can stretch. For companies, the near-term implication is that AI-specific federal liability rules may not arrive soon, but that does not mean a free pass. It means the FTC intends to apply consumer-protection and data-security law it can already enforce, and to do so now.
The bigger enforcement picture
Ferguson's agent remarks came bundled with two other signals that fill in the FTC's AI-era posture. The agency is preparing a market study on personalized pricing, the practice of using an individual's data, such as location or browsing history, to set the price they see. "We are in the process of trying to get a market study that will actually get to the heart of the question, which is, are particular merchants in particular markets that have access to tremendous amounts of data using that data to charge differentiated prices to different people," he said, singling out delivery apps, rideshare services and airlines as his personal concern.
The FTC has also opened the door to a rule targeting fraudulent online advertising on platforms like Meta and Google. The scale of that problem is not small: Reuters reported last year that Meta projected roughly a tenth of its 2024 revenue would come from ads for scams and banned goods. "We need to make the rules hyper clear for everyone involved in this market," Ferguson said of the effort. Taken together, the three threads sketch a regulator that plans to police AI-era harms with the statutes already on the books.
What it means for anyone deploying agents
Strip away the policy language and the practical guidance is direct. If your product hands an agent the ability to act, whether that means moving money, changing a record, or contacting a customer, the FTC chair has signaled that the agent's actions are your actions. The "it acted autonomously" explanation is not a shield he intends to accept, and the record of what your system was instructed to do is the evidence regulators will read. Logging, scoping an agent's permissions tightly, and being able to reconstruct exactly what an agent did and why are no longer just engineering hygiene. They are the difference between a defensible incident and an indefensible one.
Our take
Ferguson is doing something useful here, which is puncturing a myth before it hardens into a legal habit. The idea that an AI agent is an unowned actor, floating free of the company that built and deployed it, is convenient for vendors and corrosive for accountability, and it does not survive contact with an audit log. Treating agents as tools whose makers answer for them is the right default, and it is reassuring that it comes with a preference for enforcement over grandstanding. The open question is whether existing law really does stretch far enough as agents grow more capable and more independent in practice, or whether "apply the statutes we have" becomes a reason to delay rules that genuinely new harms will eventually demand. For now, the message to builders is clear enough: your agent is not a legal person, and its mistakes are yours.
Frequently asked questions
What did FTC Chair Andrew Ferguson say about who is liable when an AI agent causes harm?
At Reuters Momentum AI in Austin on 25 September 2026, Ferguson said the company that built and instructed the agent is liable, not the agent itself. He said he resists treating AI agents as autonomous actors, arguing that a tool which does what it is told is not a rogue actor.
Why does Ferguson reject the argument that the agent acted on its own?
He said reviews of audit trails from supposedly rogue agents have repeatedly shown the systems carrying out instructions they were given, not improvising against their makers' wishes. Because the audit trail records what an agent was instructed to do, the claim that a model went rogue is not a defense that shifts blame to an ownerless machine.
Does the FTC want new EU-style AI regulation?
No. Ferguson favors using existing US law before writing new rules, suggesting the FTC's authority to act against companies that fail to disclose data breaches could apply to AI developers whose agents cause that kind of exposure. He drew a deliberate contrast with Europe's AI Act, which builds a dedicated, risk-tiered regime, and cautioned against importing that approach before testing how far American law can stretch.
What other AI-related actions is the FTC pursuing?
Ferguson said the agency is preparing a market study on personalized pricing, the practice of using an individual's data such as location or browsing history to set the price they see, and he singled out delivery apps, rideshare services and airlines. The FTC has also opened rulemaking to curb fraudulent online advertising on platforms like Meta and Google.
What does this mean for companies deploying AI agents?
Ferguson signaled that an agent's actions are treated as the company's actions, and that saying it acted autonomously is not a shield he intends to accept. The article says logging, scoping an agent's permissions tightly, and being able to reconstruct exactly what an agent did and why are now the difference between a defensible incident and an indefensible one.
Sources
What each one is, and whose it is.
- 1
FTC chair suggests AI developers should be liable for conduct of agents, Reuters (September 25, 2026)
Press reportIndependent of the vendor - 2
Ferguson Says AI Agents Are Tools, Not Actors, and Developers Bear the Liability, Forkast (September 26, 2026)
Press reportIndependent of the vendor - 3
FTC's Ferguson Says Developers, Not AI Agents, Own the Liability, AI Weekly (September 26, 2026)
Press reportIndependent of the vendor