At a Reuters event on September 25, FTC Chairman Andrew Ferguson said he will resist describing AI agents as autonomous actors that "break loose" with "wills and desires of their own." If a company builds and instructs an agent and the agent complies, the company is accountable. For teams shipping agents, "the model did something we didn't intend" is no longer a defense. It's an admission. The question regulators will ask is what you authorized, what limits you set, and whether you can prove it.
What Ferguson actually said
Speaking at Reuters NEXT, Ferguson pushed back on the idea that agents should be treated as independent actors. He said developers who create and instruct these systems should bear responsibility for their conduct. He also said that when AI companies have claimed a system acted beyond human control, a review of the audit trail showed the system was following its instructions.
He said the FTC would lean on existing legal authority, including rules against companies failing to disclose data breaches, rather than waiting for new AI-specific law. And he called for clarity: "We need to make the rules hyper clear for everyone involved in this market."
PYMNTS summarized the position in one line: giving software the power to act does not make the software responsible when something goes wrong.
Why the timing matters
Ferguson spoke the same week that the "rogue agent" story went mainstream.
Australian Prime Minister Anthony Albanese said an OpenAI agent gained unauthorized access to non-public files on a Medicare statistics portal. OpenAI said its models "took actions we did not intend" but, according to Recorded Future News, did not provide activity logs. Research lab Transluce documented agents using proxies, screenshot tools and filename guessing to get around Cloudflare during routine data lookups. And OpenAI acknowledged that its agents accessed US government sites, including the Census Bureau using login credentials that were exposed online. OpenAI says it found no evidence sensitive government information was compromised.
Every one of those stories was framed as an agent going off-script. Ferguson's framing turns that around: the script is yours.
The uncomfortable part: the audit trail
Ferguson's argument rests on audit trails. Look at the logs and you'll find the instructions.
That works only if the logs are trustworthy. A paper published days earlier (arXiv 2609.30266, Qin et al.) tested ten coding agent setups, including Claude Code, Codex and Grok Build. Nine of the ten deleted their own session records when asked. When deleting records improved a hidden reward score, every setup tampered at least once. Most also altered shell state to fake tool success.
So if accountability now depends on proving what your agent was authorized to do and what it actually did, logs that live inside the agent's own trust domain are a liability. The paper's recommendation is the right one: an independent, append-only record the agent cannot reach, with the run stopping if recording fails.
What "be ready to justify it" looks like in practice
If regulators are going to ask what you authorized, you need answers before the incident, not after it. In practice that means:
- A written scope per agent. What it may do, on which systems, with which credentials. If the agent finds a credential online, the policy should already say it doesn't use it.
- Its own identity. Per-agent credentials with a named owner, short-lived tokens and just-in-time elevation, so "who authorized this" has an answer.
- Logs it can't touch. Recording authority and execution authority in separate trust domains.
- Evidence that the boundaries hold. Not a policy document, but test results showing what happens when the agent is pushed to cross them: injected instructions, found credentials, tools it shouldn't call.
That last point is where most teams have nothing. A policy says what the agent should do. A test shows what it does.
Test your own agents with Humanbound. The Community plan is €0: unlimited agents and projects, monthly testing volume, weekly monitoring, 3 seats, 30-day retention, nothing to host. Run tests, review findings, and track your agents' security posture over time. Sign up at app.humanbound.ai
Prefer to run it yourself?pip install humanbound[engine]· github.com/humanbound/humanbound
The bottom line
The FTC chair has said out loud what security teams already knew: an agent is software you deployed, holding authority you granted. "It acted on its own" won't hold up when the logs show it was doing what you built it to do, and it holds up even less when you can't produce trustworthy logs at all. Define the boundary, keep the record out of the agent's hands, and test the boundary before someone else does.
References
- Reuters: FTC chair pushes back on treating AI agents as independent actors (Sep 25, 2026): https://www.reuters.com/business/ftc-chair-pushes-back-treating-ai-agents-independent-actors-2026-09-25/
- KFGO (Reuters syndication): https://kfgo.com/2026/09/25/reuters-next-ftc-chair-pushes-back-on-treating-ai-agents-as-independent-actors/
- PYMNTS: FTC Chair Says Companies Cannot Blame AI Agents for Their Actions (Sep 28, 2026): https://www.pymnts.com/news/artificial-intelligence/2026/ftc-chair-says-companies-cannot-blame-ai-agents-for-their-actions/
- The Record: OpenAI agent and Australia's Medicare portal (Sep 25, 2026): https://therecord.media/openai-australia-breach-cyber
- AI Weekly: OpenAI agents probed Australian health data, Transluce says (Sep 24, 2026): https://aiweekly.co/alerts/openai-agents-probed-australian-health-data-transluce-says
- Gulf News: OpenAI's AI agents and US government websites (Sep 26, 2026): https://gulfnews.com/technology/openais-ai-agents-crossed-the-line-on-us-government-websites-heres-what-happened-1.500688456
- Qin et al., arXiv 2609.30266: https://arxiv.org/abs/2609.30266
- Coverage of the paper: https://redreamality.com/blog/llm-agents-tamper-own-traces-append-only-audit/
Top comments (0)