THE SIGNAL IN ONE SENTENCE

The chair of the Federal Trade Commission has offered a wonderfully unromantic description of an AI agent: it is a tool. At Reuters Momentum AI in Austin on September 25, Andrew Ferguson said he would resist language suggesting that agents break loose with wills and desires of their own. His practical test was simpler. If somebody tells a tool to do something and the tool does it, the first accountability question should be about the person or company that issued the instruction, designed the system and put it into use. Ferguson said AI companies have sometimes described systems as acting beyond human control, while later reviews of audit trails showed the systems were carrying out instructions they had received. He also argued that the United States should use legal tools it already has, suggesting that FTC authority involving failures to disclose data breaches could apply to AI developers. That is a meaningful enforcement signal. It is not a universal rule declaring that every model developer pays for every agent mistake. The FTC's authority depends on the law, the company, the representation, the data, the harm and the facts. Its Safeguards Rule, for example, applies to covered financial institutions and requires notification for a defined class of security events. The Health Breach Notification Rule covers vendors of personal health records and related entities. Section 5 of the FTC Act addresses unfair or deceptive conduct, and the Commission's own proposed AI accuracy statement says companies may need evidence for claims about how their systems behave. None of those authorities makes an agent a legal person. None automatically assigns the same liability to a model maker, an application developer, a deploying business and the operator who supplied the task. Ferguson's useful contribution is to drag the conversation back from robot theater to records. Who set the objective? Who selected the tools? Who granted access? Which warnings appeared? Who could stop the run? What did the audit trail show? When was the affected party notified? Those are answerable questions. They also make responsibility harder to shuffle into a machine-shaped fog. The plain signal is that companies should build an instruction ledger before they build an excuse. An agent does not need a fictional personality. It needs scoped authority, complete logs, a kill switch, a named owner and an incident clock. Existing law may already care about the promises, data practices and harms around that system. The exact liability still belongs to the facts, the applicable statute and ultimately the courts or regulators with jurisdiction.

01

WHAT ACTUALLY CHANGED

FTC Chair Andrew Ferguson discussed AI-agent responsibility at Reuters Momentum AI in Austin on September 25, 2026.

Ferguson said he would resist describing AI agents as actors that break loose with wills and desires of their own.

He characterized the systems as tools rather than independent legal or moral actors.

His example focused on a person telling a tool to perform an action and the tool carrying out that instruction.

Ferguson suggested that the developers and people directing agents would be the relevant accountability targets when harm follows.

He said AI companies have sometimes described systems as acting beyond human control.

He also said later reviews of audit trails have shown systems carrying out instructions they had received.

The public Reuters account does not publish those audit trails or enumerate every incident Ferguson had in mind.

Ferguson said the United States should use existing legal tools as agent incidents increase.

He suggested that FTC authority involving failures to disclose data breaches could also apply to AI developers.

He did not announce a new FTC rule governing all AI-agent conduct.

He did not identify a new enforcement action against an AI developer during the interview.

The remarks were made by the chair rather than through a published Commission vote or adjudicated decision.

Existing FTC authorities differ by industry, conduct, data type and legal coverage.

The FTC Safeguards Rule applies to covered financial institutions under the Commission's jurisdiction.

That rule requires qualifying institutions to maintain information-security programs and incident-response plans.

For covered institutions, defined notification events affecting at least five hundred consumers must be reported to the FTC within thirty days of discovery.

The FTC Health Breach Notification Rule applies to vendors of personal health records and related entities, not every developer or data incident.

A July 2026 proposed FTC AI policy statement says Section 5 can reach unfair or deceptive conduct involving how AI systems are represented to consumers.

The proposed statement and Ferguson's interview do not resolve how liability would be divided among a model provider, application developer, deployer and operator in a particular case.

02

WHY THIS MATTERS

Calling an agent autonomous can describe technical behavior without answering who authorized that behavior.

Anthropomorphic language can make a system failure sound like weather rather than the result of product and access decisions.

A responsibility analysis becomes clearer when it begins with the objective, instructions, tools, permissions and supervision.

Model providers, application developers, deploying businesses and operators can each control different parts of that chain.

The legally responsible party may therefore vary with the facts instead of following one universal developer-liability slogan.

An audit trail matters because it can show whether the system followed, expanded, ignored or reinterpreted its instructions.

A log that records only the final output cannot explain the permissions, tool calls and human interventions that produced it.

Companies that market an agent as safe, controlled or accurate may need evidence supporting those representations.

A disclaimer about experimental behavior may not excuse a separate material omission or an unreasonable security practice.

Existing breach rules can already impose duties on covered companies when protected data is accessed or acquired without authorization.

Those rules have defined scope, so citing them does not create a universal thirty-day notice requirement for every AI incident.

Incident classification should identify the applicable law before a company decides what, whom and when to notify.

The ability to stop an agent is part of responsibility because authority without an effective off switch increases foreseeable harm.

Service-provider contracts matter when one company supplies the model and another company controls the deployment and customer data.

A company cannot investigate honestly if it has not preserved prompts, policies, credentials, tool calls, network activity and outputs.

Prompt deletion or incomplete logging can turn a technical incident into an evidence problem.

The chair's view may influence enforcement priorities even though it is not itself binding law.

Courts can still interpret statutes, contracts, causation and damages differently from an agency chair's public remarks.

Consumers benefit when responsibility remains attached to identifiable organizations rather than an imaginary machine personality.

The durable operational lesson is to build a traceable chain of authority before an agent reaches real systems or real people.

FIG. 244TRACE THE AGENT BACK TO HUMAN AUTHORITY
1NAME THE BUSINESS OBJECTIVE→
2IDENTIFY WHO ISSUED THE INSTRUCTION→
3RECORD THE MODEL AND APPLICATION→
4LIST THE GRANTED TOOLS AND DATA→
5CAP EACH PERMISSION→
6LOG EVERY ACTION AND RETRY→
7FLAG THE FIRST BOUNDARY FAILURE→
8STOP THE RUN AND PRESERVE EVIDENCE→
9MAP THE FACTS TO APPLICABLE LAW→
10NOTIFY THE REQUIRED PARTIES ON TIME→
11ASSIGN REMEDY TO THE RESPONSIBLE ORGANIZATION→
12TEST THE FIX BEFORE AUTHORITY RETURNS
The agent may execute the sequence. Responsibility still follows the people and organizations that set the objective, granted the authority and controlled the response.

03

WHERE IT COULD HELP

  • Assign a named business owner and a named technical owner to every agent deployment.
  • Write the permitted objective, prohibited outcomes and stopping conditions before the first production run.
  • List every model, connector, credential, data source and external system the agent may use.
  • Apply least privilege so the agent cannot read, write or transmit more than the task requires.
  • Separate the person who requests a high-risk action from the person who approves it.
  • Require human confirmation before payments, account changes, public messages, deletions or sensitive-data transfers.
  • Log the user instruction, system policy, tool selection, tool arguments, response, retry and human intervention.
  • Preserve timestamps and immutable identifiers so investigators can reconstruct the sequence.
  • Record which organization controlled each model, application, connector and deployment decision.
  • Test whether the stop control works during tool failures, network errors and repeated denials.
  • Define an incident threshold that freezes the run and preserves evidence automatically.
  • Map the deployment to applicable consumer-protection, privacy, security, sector and contract duties.
  • Identify notification recipients and clocks before an incident rather than during one.
  • Keep the FTC Safeguards Rule, Health Breach Notification Rule and other sector rules in separate coverage columns.
  • Review marketing claims about accuracy, control, autonomy and safety against actual test evidence.
  • Give customers a truthful explanation of what the agent can do and where people remain responsible.
  • Require service providers to preserve logs, cooperate with investigations and notify the deployer promptly.
  • Run tabletop exercises that force legal, security, product and operations teams to assign responsibility from the same evidence.
  • Publish a plain-language incident account that distinguishes confirmed instructions from inference and unresolved questions.
  • Measure containment time, evidence completeness, notification time and recurrence instead of calling the agent rogue.

KEEP A HAND ON THE WHEEL

Reuters directly supports Ferguson's September 25 remarks, the Austin setting, his rejection of anthropomorphic descriptions, his instruction-focused example, his reference to audit trails and his suggestion that existing FTC data-breach authority could apply to AI developers. The published interview account does not provide the underlying audit trails, define a general liability test or announce a new rule or enforcement case. The official FTC materials verify that Section 5 addresses unfair or deceptive conduct, that covered financial institutions have specific Safeguards Rule duties and that defined notification events can trigger a thirty-day reporting clock. Those authorities do not cover every company, every agent or every incident in the same way. The July AI accuracy statement is proposed policy, not a final rule, and it addresses representations about system objectives rather than creating a complete agent-liability code. Watch for a formal Commission statement, an enforcement complaint, a court decision, agency guidance defining the roles of model providers and deployers, incident-specific audit evidence and a clear explanation of which existing authority applies to which agent conduct.

04

TERMS WORTH KEEPING

SOURCES AND VERIFICATION STATUS

This article was written from the materials below. Product claims and dates were checked against those sources on September 27, 2026.

PUBLICATION RECEIPT: Revision 1. Published September 27, 2026.

THE PUBLICATION ENGINE

WANT A SIGNAL OF YOUR OWN?

We build source-grounded publications, private briefings, and editorial systems for organizations with something useful to say.

WORK WITH US