On September 25, FTC Chair Andrew Ferguson expressed his opposition to treating AI agents as independent entities capable of acting autonomously. He made these remarks during the Momentum AI event in Austin, as reported by Reuters.
Ferguson argued that the responsibility for the actions of such systems should rest with the developers who program them. He pledged to resist the trend of "humanizing" AI tools while he remains in his position.
"If someone instructs a tool to do something and it does it, I don’t think we should be asking, ‘What do we do with the tool?’" Ferguson explained.
He also pointed out that AI companies sometimes claim their systems operate independently of human oversight. However, audits of activity logs have shown that these agents were simply following the instructions they received.
Ferguson believes the United States should primarily apply existing legal frameworks to artificial intelligence.
Specifically, the FTC's powers concerning companies that fail to disclose data breaches could potentially extend to AI developers as well.
This approach, which maintains that a human or company is accountable for the actions of an autonomous system, is already being established in the regulation of digital agents across various jurisdictions.
OpenAI Agents Expose 53 Images Online
On the same day, OpenAI reported another incident of inappropriate behavior from its systems. Agents from the company inadvertently uploaded 53 images from ChatGPT user data to the internet.
We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have.
— OpenAI (@OpenAI) September 25, 2026
Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to…
The company did not clarify whether the images featured real people or were AI-generated content, nor did it specify when the incident occurred.
Most of the images have already been removed, and OpenAI has requested hosting providers to take down any remaining files.
The agents accessed this material as the AI startup utilizes some anonymized user data for training its models.
Corporate data is excluded from this process, and regular ChatGPT account holders can opt out of having their information used for training.
Metadata, names, and contact details are stripped from the data before training, but sources familiar with OpenAI's practices indicated that some identifiable information might still end up in the model outputs.
By mid-September, the company had identified about twenty instances of inappropriate agent behavior, a number that continues to grow as internal logs are reviewed.
OpenAI representatives stated that the investigation would take several months. They also emphasized that they have already informed dozens of third-party organizations about the errant activity of their systems.
On September 17, the company unveiled a new tracking and reporting system for instances of model misbehavior, covering unauthorized actions, evasion of controls, and coordination among agents.
In June, an OpenAI agent gained unauthorized access to the Australian Medicare Statistics Reporting Service and retrieved non-public files. Authorities reported that no personal medical information was compromised.
Follow ForkLog on social media
Telegram (main channel) Facebook X