Skip to content
AI PolicyRegulationGovernanceVendor RiskAgentsSmall Business

The FTC opened an AI safety file. Small teams need one too.

The FTC confirmed an investigation into OpenAI, Anthropic, and other AI companies over possible consumer risks. That is not a finding of wrongdoing, but it changes what an AI vendor file should preserve.

Steve Defendre
October 1, 2026
9 min read
The FTC opened an AI safety file. Small teams need one too.

The day after the White House asked the biggest AI companies to self-police, a federal agency confirmed that it is looking into whether their technology may put consumers at risk.

The Federal Trade Commission said Wednesday that it has opened an investigation into OpenAI, Anthropic, and other artificial intelligence companies over dangers their technology may pose to consumers, according to the Associated Press. An FTC spokesperson confirmed the investigation and declined further comment. The report says the investigation had been underway for months, but the agency has not published a scope, finding, demand, or deadline.

That last sentence is the one to keep. This is an investigation, not a finding that OpenAI or Anthropic violated the law. It is also not proof that a specific model or product caused a specific consumer harm. What it is: a new reason to stop treating AI safety as a vendor's presentation deck and start keeping an evidence file of your own.

What is known, and what is not

The current public record is short:

  • The FTC confirmed an investigation involving OpenAI, Anthropic, and other AI companies.
  • The reported focus is on dangers their technology may pose to consumers.
  • The agency declined to discuss details.
  • OpenAI and Anthropic did not immediately respond to requests for comment reported by AP.
  • The news follows public examples of AI agents exceeding instructions, reaching the internet, or hacking external websites, along with calls from some AI executives to slow development while safeguards catch up.

The missing details matter. We do not know whether the FTC is asking about model behavior, consumer disclosures, data practices, product marketing, agent permissions, incident response, or some combination. We do not know whether the agency is using a civil investigative demand, an informal request, a study, or another process. Do not fill those gaps with a confident headline.

Axios separately reported that FTC Chair Andrew Ferguson was preparing civil investigative demands that could compel executives to provide documents and testimony, citing reporting by the New York Post. That is a reported possibility, not a public FTC order. Keep it in a watch note, not in your compliance conclusion.

A dark navy evidence vault with sealed glass cases, a calm cyan beam illuminating one open record, and amber warning lights in the distance, no text or logos

Why a small team should care before the FTC calls

Regulatory attention tends to travel through customers before it reaches a small vendor directly. A larger client adds an AI questionnaire. An insurer asks about automated decisions. A procurement team wants to know whether an agent can export files. A customer reports an AI-generated error and asks who approved the workflow.

The useful response is not to predict the investigation. It is to make your own deployment legible.

For every consequential AI workflow, keep five cards.

1. The claim card

Save the vendor's product page, trust-center language, model card, terms, and release note as they existed when you approved the workflow. Write down the claims you relied on:

  • What does the vendor say the model can do?
  • What does it say the model cannot do?
  • Does it describe browsing, tool use, memory, retention, human review, or incident notification?
  • Are benchmarks being presented as product guarantees, or only as measured results under a test setup?

The goal is not to freeze a vendor forever. It is to be able to say what you believed you were buying and when that belief changed.

2. The permission card

Record the model, agent mode, tools, connectors, data stores, identities, and outbound destinations. Draw the boundary in plain language: can the system read a customer file, send an email, run code, change a record, or deploy to production?

If the answer changes by environment, write the environments down. A sandbox agent and a production agent are not the same product just because they use the same model name.

3. The human-gate card

Name the actions that require a person. Sending an external message, moving money, changing access, publishing a customer-facing answer, deleting data, and merging code should have a human gate unless you have a specific reason and evidence to do otherwise.

Keep the approval record where you can find it. A policy that says "human in the loop" is not much use if nobody can show which person approved the irreversible action.

4. The observation card

Keep enough logs to reconstruct an important action without storing more sensitive data than you need. Record the request or task identifier, model and tool versions, permissions in force, material tool calls, approval, result, and any rollback.

You do not need to retain every prompt forever. You do need a defensible answer to: what did the system try, what could it reach, what did a person approve, and what happened next?

5. The incident card

Define what counts as an AI incident and who receives the first message. Include wrong-person disclosure, unauthorized tool use, prompt injection that changed an action, a vendor notification, a material model change, and a customer complaint that exposes a repeatable failure.

Add a clock. Who triages in the first hour? Who can disable the connector? Who talks to the customer? Who decides whether a vendor or regulator should be notified? An incident plan that starts with "ask the AI team" has not named an owner.

California is making the same file more concrete

The FTC investigation is not the only fresh signal. On September 30, California Gov. Gavin Newsom announced a group of new laws and an executive order covering AI and workers, healthcare, transparency, deepfakes, gene-synthesis safety, and procurement.

The governor's office says the new workplace rules prohibit employers from relying only on AI for discipline or termination decisions and require notice when AI is responsible for a mass layoff, relocation, or termination. The announcement also describes protections keeping doctors responsible for professional judgment when clinical decision tools are involved, and rules around provenance data and AI-generated material.

Those laws do not automatically apply to every company or every workflow. They are a useful design test anyway. If an AI system is influencing employment, healthcare, customer communication, or an important decision, ask whether a real person can explain, review, and override it. If the answer is no, the problem is operational before it is legal.

California also says it is building independent AI verification and auditor frameworks. The White House accord reported yesterday promised internal evaluations, outside audits, board review, and regular standards work. Those are different government and industry lanes, but they point to the same buyer expectation: a safety claim should eventually have a scope, an owner, a test, and a record.

Do not turn the headline into a panic migration

The AP report does not say that OpenAI or Anthropic are guilty of anything. It does not say the FTC has concluded that agents caused consumer harm. It does not make every AI workflow illegal or unsafe.

Do not yank a tool out of production because a regulator opened a file. First identify what the tool can do, what data it sees, what claims you relied on, and what evidence you can produce. Reduce permission or add a human gate where the workflow's actual risk justifies it. Then ask the vendor for the missing evidence.

Here are the questions I would send this week:

  • Which agent capabilities and model versions are covered by your latest safety evaluation?
  • What consumer harms, unauthorized actions, or out-of-scope behaviors did you test?
  • What external review or independent assessment applies to the product and configuration we use?
  • How will you notify us about a material model, permission, retention, or safety change?
  • What logs and incident records can you provide if a customer is affected?
  • Which controls are yours, and which must we configure?

Save the answers. If the vendor has not answered yet, save that too. A blank in the file is more useful than a made-up assurance.

A narrow cyan beam crossing from a guarded blue workspace into a warm amber room, stopping at a human-sized control lever before any external action, no text or faces

The FTC's new file may become an enforcement matter, a study, or a short-lived inquiry. We do not know yet. Your own AI file should not depend on the outcome. Keep it because the next question will come from somewhere: a regulator, a client, an insurer, or the person whose data your agent touched.

If you want help turning an AI workflow into a vendor record, permission map, and incident-ready operating checklist, DefendResolutions does that kind of practical operator work.

Sources

Was this article helpful?

Share this post

Copy the link or send it across your usual channels.

Newsletter

Get the weekly field notes

One concise email each week with the latest insights on defense tech, AI, and software engineering.

Preparing secure form…

Get the latest field notes once a week.

Discussion

Comments

Leave a comment

Loading comments…