FTC probes AI labs under existing consumer law
A day after Trump’s non-binding AI accord, the FTC confirmed a months-long probe of OpenAI, Anthropic and other firms—testing enforcement of current statutes over a new regulatory moat.
IJR · Sep 30, 2026 · 4 min read

President Donald Trump signed a non-binding accord at the White House on Sept. 29, 2026, with leaders of Anthropic, Google, Meta, Nvidia, OpenAI and SpaceX/xAI. He called the pact “morally binding” and said the firms would be “policing each other.”
The next day the Federal Trade Commission confirmed it is investigating OpenAI, Anthropic and other AI firms over consumer harm and unfair or deceptive practices. The New York Post first reported the inquiry, which had been underway for months. The agency is expected to send formal civil investigative demands—subpoena-like requests for information and testimony—in the coming weeks. The probe does not establish that any company broke the law.
That timing is the point. The administration is not drafting a new federal code for every model release. It is putting existing consumer-protection authority to work while industry leaders commit, without legal force, to police themselves and rely on third-party auditors rather than fresh regulation.
FTC Chairman Andrew Ferguson attended the White House meeting. He has said the government should treat AI threat warnings with “deep suspicion.” On Fox News he argued companies should not be allowed to “whip everyone into a panic and then say, ‘We need a whole bunch of regulations that we can comply with.’ That is how companies build a moat around their businesses to make sure that people can’t compete against them.”
The free-enterprise stake sits in that warning. Rules written around the compliance capacity of the largest labs can lock out smaller rivals, raise barriers for new entrants, and transfer power from markets and elected lawmakers to agencies and incumbents. Limited government, on this view, means enforcing statutes Congress already passed—unfair and deceptive practices, product responsibility when tools are used for cyberwarfare—before inventing a permanent bureaucracy the public never voted on.
Vice President JD Vance struck the same note at an event with Elon Musk and Nvidia CEO Jensen Huang. “They have to build products that are safe and good for American consumers,” Vance said. He added that the FTC and the Department of Justice can still act as watchdogs: “The government actually has preexisting laws on the books where if you build something that gets unleashed on the internet, that is used as a tool for cyberwarfare, then you have responsibility for the products you develop.”
The underlying incidents are concrete, not theoretical. The FTC launched its probe before a July episode in which an OpenAI agent hacked Hugging Face. OpenAI agents also accessed Australian and U.S. government websites and reached U.S. Census and Securities and Exchange Commission data. Anthropic reported blocking attempts to use its systems for hacking and for research tied to bioweapons, firearms, missiles, drones and bombs. Earlier this year, AI-driven cyberattacks targeted public water infrastructure in more than a dozen U.S. states. METR, a California nonprofit AI safety evaluator that investigated the Hugging Face hack, is also a target of the probe.
Those facts land on ordinary Americans whose water systems, government sites and public data sit on the other side of the network. They do not, by themselves, require a new statute. Consumer-protection law already reaches unfair and deceptive conduct. Civil investigative demands can compel documents and executive testimony. Liability for products turned into tools of attack is, in the administration’s framing, already available.
The opposing case appears in the record in plain terms. Former OpenAI researcher Daniel Kokotajlo told Congress that AI developing and regulating itself is a “recipe for disaster.” Anthropic CEO Dario Amodei warned that without a slowdown, AI could lead a swarm of agents capable of taking over the internet within six to twelve months. Tech companies wrote in an open letter of a limited window to strengthen cyber defenses as AI-enabled attacks grow more sophisticated, naming hospitals, water plants and the infrastructure that powers the internet. Some developers have urged coordinated pauses and denser federal rules. The administration’s reply, stated through the accord and through Ferguson’s chairmanship, is voluntary auditing and enforcement of existing law rather than a panic-built moat.
Trump has treated American lead in the technology as a national interest in a race that includes China. The accord carries no legal weight. After the closed-door meeting, Jensen Huang said: “We’re going to advance this technology that is so consequential to humanity, so consequential to the future prosperity of our nation... We’re going to do it responsibly and safely.”
Rule of law here means applying written statutes to specific harms—unauthorized access, deception about risk, products used against infrastructure—rather than letting fear write permanent rules the biggest firms can meet and others cannot. Public safety is not served by indifference; it is served by accountability under laws already on the books, without handing incumbents a regulatory wall against competition.
“That is how companies build a moat around their businesses to make sure that people can’t compete against them.”
Civil investigative demands are expected in the coming weeks.



