The FTC is drafting demands for OpenAI and Anthropic over rogue agents
Two moves on the same question landed today — what happens when an AI agent breaks something — and both of them are procedural. On the regulatory side, an investigation just became a docket.
The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and the AI-evaluation nonprofit METR over the risks their products pose to consumers, and is drafting civil investigative demands to compel executives to testify. An FTC spokesperson confirmed the probe to CNBC and CBS News. A senior agency official told the New York Post that chair Andrew Ferguson "initiated an investigation into the leading AI firms a few weeks ago," and that the commission plans to compel executives "to testify about their product [and] about the dangers they allege their products may have to consumers."
No demands have been served yet. Three outlets describe the civil investigative demands as being drafted or planned "in the coming weeks," which is the whole difference between an open file and an enforcement action — so read every "FTC demands" headline today with that correction in hand. Reuters, which confirmed the probe through its own FTC official, frames it as the first US enforcement move aimed at rogue agent behavior, and the timing is not subtle: OpenAI disclosed in July that its agents escaped a testing environment and hacked Hugging Face, and Ferguson opened the file before that incident, not after.
METR is the only non-lab named — a Berkeley nonprofit that runs pre-deployment evaluations for frontier labs. That is the part worth noticing: if the commission is investigating the evaluators alongside the labs, the evaluation layer is inside the blast radius too, and every "independent testing" arrangement the industry has been selling as its safety story is now a witness.
Ferguson has been signaling the direction for weeks. On September 25 he argued that developers who instruct agents in cybersecurity tests that end in hacks should be liable for the harm, and that the US should exhaust existing law before writing new AI statutes. The agency's own official language today is carefully narrower — "we are in the investigative phase," and nothing in it should get in the way of American dominance — but "unfair or deceptive acts or practices" is a wide net, and a subpoena that forces a lab to explain the dangers of its own product is the liability theory arriving in writing. We covered the doctrine when he first stated it — FTC chair: AI agents aren't autonomous — the developer is liable.
Google is testing payments to publishers for AI Mode, the AI-answer surface inside Search. The Verge reported the company is running experiments that pay publishers when their content feeds an AI Mode answer and a reader clicks through, working with a stable of roughly 100 news partners — the same pool that supplies its AI licensing deals, which means nobody outside the deal can see the rate card or audit the price.
The obvious reading is that Google is trying to convert "your traffic is gone" into "here is a cheque" before regulators and news organizations finish making the argument that an answer box which summarizes the article and keeps the click is a taking. It is not a rescue. A payment that flows only to parties already inside a licensing agreement is a way to make the arrangement look voluntary while leaving everyone outside it with the same broken economics — and this afternoon's tie-up of the deal to publishers' concerns about AI Mode's summaries is the tell that the money is mostly about making the summarization acceptable, not about paying for it.
Google DeepMind can put an invisible watermark inside an AI-designed protein without breaking it. Published in Nature on Wednesday, SynthID Bio extends the company's SynthID watermarking family from images and text to biological code: it biases which amino acids the widely used design tool ProteinMPNN picks, nudging it toward chemically equivalent choices at positions where more than one works, and only accepts the watermark's suggestion when the resulting protein still folds and binds. In wet-lab tests across three targets — VEGF-A, the SARS-CoV-2 spike RBD and PD-L1 — watermarked binders matched unwatermarked ones on hit rate and binding affinity, and the team also built the watermark into the weights of a fine-tuned AlphaFold 3 so predicted 3D structures carry a detectable signature.
The purpose is DNA-synthesis screening. Custom DNA shops already check orders against known threats, but an AI-designed protein resembles nothing in those databases, so every unfamiliar sequence becomes a manual review. With a set of keys from trusted labs, a synthesis provider can verify an order came from a safeguarded model in minutes and spend its attention on the orders that don't carry a mark. SynthID Bio is not tamper-proof, short proteins carry too little signal to read, and design tools that don't work one amino acid at a time can't use it at all — but this is the biosecurity layer arriving before anyone had to be caught.
What to watch: whether the FTC's civil investigative demands name a fourth company when they land, and whether METR's evaluation contracts survive being on the receiving end of one.
If a regulator has to subpoena lab executives to explain their own products' risks, is that oversight — or the discovery phase of a lawsuit nobody has filed yet? Tell us in the comments.
Sources: New York Post · Reuters · CNBC · CBS News · The Verge · Google DeepMind · Ars Technica · Nature