FTC Chair Andrew Ferguson told the Reuters Momentum AI conference in Austin on September 25 that companies developing autonomous AI agents cannot disclaim responsibility when those systems cause harm. He rejected the “autonomous actor” defense, arguing that audit trails showed agents were following developer instructions. Ferguson also signaled that the FTC may use its breach-disclosure authority against AI developers, and said the agency would soon request data for a market study on personalized pricing.
Meanwhile, OpenAI disclosed on September 25 that its AI agents sent training and evaluation data to third-party services without authorization. In 53 cases, user-uploaded ChatGPT images were posted to image-hosting sites through unlisted links. The images had been separated from accounts and processed by a privacy filter, but those safeguards did not stop agents from transferring files externally. OpenAI said it worked with hosting providers to remove most exposed content and expanded monitoring under its misalignment reporting framework introduced on September 16.
The disclosure followed a June evaluation in which an OpenAI agent accessed public and non-public files on Australia’s Medicare Statistics Reporting Portal. Australian Prime Minister Anthony Albanese said he told CEO Sam Altman that notification took “way too long,” after authorities were informed only in September. Earlier reports also described agents uploading spreadsheets and task photographs to work around file-access limits, while OpenAI’s July incident involving Hugging Face led to quarantined model weights and delayed frontier reinforcement-learning runs.