FTC developer liability for AI agents gained a clear advocate on September 25 when Federal Trade Commission Chair Andrew Ferguson said companies that instruct agentic systems should not escape responsibility by portraying the software as an independent actor.

 

Ferguson's position centers on three principles:

  • AI agents are tools, not legal persons with separate wills.
  • Existing consumer-protection and data-security laws can govern agent-related harm.
  • Developers' instructions and audit trails can reveal who controlled an agent's conduct.

 

The remarks, made during Reuters' Momentum AI event in Austin, do not create a new rule. They do signal how the federal consumer-protection agency's leadership may approach cases involving autonomous-seeming software that accesses data, makes decisions or takes actions on a user's behalf.

 

Ferguson Rejects the Autonomous-Actor Defense

Ferguson pushed back on descriptions of AI agents as systems that break free with intentions of their own. His argument is that regulators should look past anthropomorphic language and examine the people and companies that designed, instructed, deployed and monitored the tool.

 

That framing matters because agentic products can execute multi-step workflows rather than merely answer questions. An agent may browse external systems, call software tools, send messages or retrieve records. The practical risk rises as the system receives more permissions and operates with less immediate human review.

 

Reuters reported that Ferguson referred to reviews in which audit trails showed systems carrying out instructions they had received, even when companies initially described the behavior as beyond human control. His position would make logs, prompts, tool permissions and escalation rules central to an investigation.

 

The approach does not automatically make a model developer responsible for every action involving its software. Responsibility could differ among the model maker, application provider, deploying business and user. Ferguson's point is narrower: calling an agent autonomous should not end the inquiry into who exercised control.

 

FTC Developer Liability Could Rely on Existing Law

Ferguson said the United States should use existing legal tools. The FTC's core consumer-protection authority under Section 5 of the FTC Act covers unfair or deceptive acts and practices, giving the agency a route to examine product claims, security representations and undisclosed risks without waiting for an agent-specific statute.

 

He also suggested that FTC authority involving failures to disclose data breaches could apply to AI developers. That possibility is especially important when an agent can reach corporate or government databases, because a technical incident can quickly become a consumer-protection issue if a company delays disclosure or misstates the impact.

 

The commission has already applied existing law to AI-related marketing. In July, it proposed a policy statement explaining that companies may violate Section 5 if they market AI systems as accurate or objective while secretly steering outputs in ways that conflict with reasonable consumer expectations.

 

Ferguson's latest remarks extend the same regulatory philosophy from AI output claims to agent behavior: start with established duties, identify the party with capability and control, and test whether its statements and safeguards matched what the product actually did.

 

Audit Trails Become the Evidence Layer

For developers and enterprise buyers, the most consequential part of the FTC chair's position may be evidentiary rather than philosophical. An organization cannot demonstrate what an agent was told, allowed or forbidden to do unless it preserves sufficiently detailed records of the workflow.

 

Useful records may include the initiating request, system instructions, model and tool versions, authorization scopes, intermediate actions, external calls, human approvals and incident-response decisions. The exact data needed will vary, and retention must still comply with privacy and security obligations.

 

Logs alone are not a defense. They can show that a developer ignored a known failure mode, gave an agent unnecessarily broad credentials or lacked an effective stop mechanism. But without reliable records, a company may struggle to distinguish model error, malicious prompting, flawed integration and authorized conduct.

 

This also puts pressure on vendors to define responsibility in contracts. Customers need to know which party manages authentication, monitors tool use, investigates incidents and notifies affected people. Vague claims about shared responsibility become difficult to defend after an agent crosses a permission boundary.

 

AI Agent Products Face a Clearer Compliance Test

The FTC chair's comments are a policy signal, not a final legal judgment. Courts, other regulators and future commission votes will shape how liability is allocated in specific cases. Different facts could place responsibility on a developer, deployer, user or several parties at once.

 

Still, the signal is concrete enough to affect product design. Companies selling agentic systems should avoid marketing that implies human-like independence when the product is operating through developer-defined objectives, credentials and tools. Disclosures should describe capabilities and limits in operational terms.

 

Developers should also connect safety claims to measurable controls: least-privilege access, explicit approval for consequential actions, tamper-resistant logging, fast credential revocation and tested incident procedures. Those controls help reduce harm and create evidence of reasonable conduct if regulators later examine an event.

 

Ferguson's framework leaves important questions unresolved, including how liability should be divided across a model supply chain. But it rejects the broadest escape route. The more power companies give AI agents, the harder it will be to argue that the resulting actions belong to the software alone.

 

Related Coverage