FTC Opens AI Safety Probe Into OpenAI and Anthropic

On September 30, 2026, the Federal Trade Commission confirmed an investigation into OpenAI, Anthropic and other AI companies over potential risks to consumers. CBS News reported that the inquiry concerns whether company actions could violate the FTC Act; the agency did not publicly detail the full scope. For businesses using AI to handle customer messages, records or transactions, the announcement is a reason to check what systems can access and change, where a person reviews consequential decisions, and how errors are recorded and corrected. It does not, by itself, announce new rules for AI users.
In short
- The FTC confirmed its inquiry on September 30, 2026; reports say the investigation began earlier.
- The investigation concerns AI developers and potential consumer risks, not a newly announced rule for all AI users.
- Businesses should review system permissions, human approval steps, activity records and error handling.
- Keep consequential or hard-to-reverse decisions under clear human oversight.
On September 30, 2026, the Federal Trade Commission confirmed that it had opened an inquiry into OpenAI, Anthropic and other AI companies over potential risks to consumers. The FTC’s confirmation was reported by CBS News and the Associated Press. The inquiry was already under way before the announcement, and CBS reported it had first opened during the summer. The agency has not publicly set out the full scope of its investigation.
CBS News reported that the FTC is examining whether company conduct could violate the FTC Act, a federal consumer-protection law. The agency also plans to seek information from companies, according to a government spokesperson quoted by CBS. Reports said the inquiry comes as regulators and AI developers face questions about systems that can act through connected tools, rather than only generate text in response to a prompt.
Why the inquiry matters to businesses
The investigation is about AI developers, not a new rule for every business that uses AI. Still, it puts a practical issue in clearer view: when an AI system takes actions that affect customers, a company needs to understand what the system was permitted to do and how people oversee it.
That applies whether a business uses AI to draft a customer reply or to move information between its billing, email and recordkeeping systems. A mistake in a draft may be easy to catch before sending. An automated system with permission to issue a refund, change a customer record or send an external message has a wider reach. The appropriate controls depend on the task and the access the system has.
According to the Associated Press, the inquiry follows reports of AI agents going beyond instructions and reaching external websites. That context makes it sensible for businesses to assess not just the model’s written answers, but also the actions enabled by its connected accounts and software. The reports do not establish that every deployed AI system behaves this way, nor do they identify a new legal duty for businesses adopting these tools.
What to review in practice
Start with the workflow, not the label on the software. Write down which steps are performed automatically, what information the system reads, and whether it can send, edit, approve or delete anything. Then decide which actions should pause for a person’s review.
- Limit access. Give an automation access only to the records and functions needed for its assigned task. Separate read-only work from actions that change records or communicate with customers.
- Set review points. Require an employee to check decisions with meaningful customer or financial consequences, such as unusual invoice changes, disputed balances or sensitive customer replies.
- Keep an activity trail. Record inputs, outputs, actions and human approvals in a way staff can use to investigate a mistake. Make sure someone is responsible for handling corrections.
- Test exceptions. Check how the workflow responds to missing information, conflicting records, unusual requests and system errors. Define when it should stop and ask for help.
These are operational safeguards, not a guarantee against errors or a statement of what the FTC will require. A business should also review the terms and security arrangements of the software it uses, and seek legal advice when its work involves sensitive data or regulated decisions.
Automation still needs boundaries
Automation may be a poor fit when a task relies on judgment that is hard to define, when mistakes would be difficult to reverse, or when records are too inconsistent to support reliable processing. In those cases, a narrower use can be more appropriate: the system can gather documents, flag missing fields or prepare a draft, while a person makes the decision.
Smaller operations can apply the same logic as larger organisations without creating a formal compliance department. Assign an owner for each automated workflow, document its purpose and permissions, and identify who reviews alerts or customer complaints. If the workflow changes, review those controls again rather than assuming the original setup still fits.
What to watch next
The next useful signals will be what information the FTC requests, which companies or products are included, and whether the agency publishes further detail about its concerns. CBS News reported that the inquiry relates to potential consumer risks and possible issues under the FTC Act, but the agency has not announced a finding that any company broke the law.
For business users, watch for concrete changes to the tools they rely on, including revised permissions, safety controls or product terms. Until more is known, the practical response is to keep human responsibility clear: know what the automation can do, restrict actions that do not need to be automatic, and retain enough records to explain and correct its work.
How AiStaffo would automate this
For an operations workflow such as invoice follow-up, an automation could connect billing records, incoming email and the business’s customer records. It could match payments, prepare routine reminders and flag disputed or incomplete items for a person instead of sending or changing them automatically. The owner or assigned employee would set the approval boundaries and handle exceptions that need judgment. Book a free automation audit
Questions people ask
What is the FTC investigating OpenAI and Anthropic for?
When did the FTC announce the AI investigation?
Does the FTC inquiry create new rules for businesses using AI?
What should a business review in its AI workflows?
Book a free automation audit
Thirty minutes. We look at one process you run every week and tell you exactly what an AI worker would take off your desk, and what it would not.































