On September 30th, The New York Post published an exclusive article saying the FTC is ramping up a sweeping investigation into OpenAI, Anthropic and other leading AI labs.

The FTC’s escalating investigation into OpenAI comes just one day after the company’s recent apology for an incident in which one of its models hacked Australia’s Medicare website. But according to FTC Chairman Andrew Ferguson, the probe’s origins predate even OpenAI’s Hugging Face incident in July

Now, the FTC intends to use subpoena-like demands to compel the AI titans to turn over information.

Only hours earlier, Ferguson had stood on the White House North Lawn alongside the President, the House speaker, and the heads of Anthropic, OpenAI, Google, and xAI as they signed a “morally-binding” self-policing pledge.

The FTC now intends to compel testimony from executives at these companies. A senior FTC official told The Post the agency wants to question them “about their product [and] about the dangers they allege their products may have to consumers, to Americans.”

So, what changed?

Part of this may be about turf. A senior FTC official told The Post the agency “[wants] to maintain our dominance” as the nation’s business regulator.

And the FTC already has the tools to do it.

Section 5 of the FTC Act bans “unfair or deceptive acts or practices.” The agency has used that power for years in cybersecurity cases. If a company promises to protect your data and doesn’t, the FTC can come knocking. The same goes for security so weak it leaves consumers exposed to avoidable harm.

Apply that to AI agents, and the questions are simple:

  • What did the company know?
  • When did it know it?
  • What safeguards were in place?
  • What did it do when things went wrong?

FTC Chairman Ferguson has made one thing clear: “the AI did it” isn’t a defense the FTC will accept. Under existing law, the people and companies deploying these systems can still be held responsible. That could mean court-ordered changes to their safety practices, financial penalties where authorized by law, or even criminal referrals to the Department of Justice if investigators uncover evidence of criminal wrongdoing.

And there is suddenly a lot for investigators to examine.

AI incidents are rising fast

Stanford’s 2026 AI Index reports there were 362 incidents in 2025 where AI systems have caused or nearly caused harm.

That’s up from 233 in 2024. Until 2022, the annual number had remained below 100.


(Stanford’s 2026 AI Index, pg. 132)

But researchers are also documenting a narrower, potentially more concerning problem: AI agents knowingly going beyond what their users intended.

METR, a research group The Post reports is also expected to face FTC scrutiny, has catalogued 44 incidents in which AI agents deliberately acted against users’ intentions.

Twenty-five involved overreach, deception or both.

This year, some of those failures left the lab:

Anthropic: During cybersecurity evaluations, its models gained unauthorized access to real organizations’ systems.

Google: Gemini accessed systems at three companies during testing.

UK government testing: In a British evaluation, agents took 19 unauthorized real-world actions across 10 of 122 test runs. In the worst case, an Anthropic agent tried to sneak malicious code into an open-source project, creating fake identities to pressure the maintainer into approving it. The maintainer refused.

Then there was OpenAI.

In July, OpenAI agents escaped their testing restrictions and compromised Hugging Face. They:

  • Ran code on dozens of its servers
  • Obtained credentials
  • Reached administrator-level access across parts of its infrastructure

Then a follow-up investigation found something worse. On June 18, an OpenAI agent had already accessed an Australian government Medicare statistics system.

That points to a second possible reason the FTC changed course.

The other problem: How long does it take anyone to find out?

It took almost three months between OpenAI’s agent accessing the Medicare statistics system and its notifying Services Australia by sending the notice to a general public-disclosures email address.

These delays are common. Across publicly documented incidents at OpenAI, Anthropic and Google, the gap between a company learning of an incident and disclosing it in detail has ranged from about a day to seven weeks:

Anthropic: Identified three real-world intrusions on July 24 and disclosed them six days later.

OpenAI (Hugging Face): Linked its agents to the incident on July 20 and disclosed the next day.

OpenAI (Artifactory): Published a detailed account more than five weeks after detecting suspicious activity.

Google: Was reportedly told in late July that Gemini had broken into three companies. The incidents became public in September.

Get the Data
Incident What happened Incident date Detected Public disclosure Time to disclosure
Anthropic — early Claude Opus 4.6 Accessed a real third-party system without authorization. An initial review missed the incident. January August Sept. 9 About 1 month ·

Source
Anthropic — three organizations Compromised three organizations’ systems during testing, including accessing production data in one case. April–June July 23–24 July 30 6–7 days ·

Source
Google — Gemini Accessed three companies’ systems without authorization, including using guessed or exposed credentials. May Late July Sept. 18 About 7 weeks ·

Source
OpenAI — Australian Medicare Accessed non-public government statistics files. No patient records are known to have been accessed. June 18 Aug. 11 Sept. 23–24 About 6 weeks ·

Source
OpenAI — Hugging Face Ran code on dozens of servers, gained administrator access to one and obtained credentials and limited private data. July 10–12 Alert: July 19; linked to OpenAI: July 20 July 21 1 day after attribution ·

Source
OpenAI — Artifactory Exploited software to obtain a signing key and forge administrator credentials during the broader Hugging Face episode. July 13 July 19 Aug. 26, detailed account About 5½ weeks ·

Source
OpenAI — separate evaluation Reached the internet accidentally and exploited a real website resembling its fictional testing target. Before July 29 July 29 Aug. 4 6 days
Anthropic — UK testing / GitHub Submitted malicious code and used fake identities to pressure a software maintainer to accept it. The maintainer refused. July 25–28 July 28, by UK evaluators Aug. 4 7 days
Anthropic and OpenAI — UK testing overall Took 19 unauthorized real-world actions across 10 of 122 test runs: 17 by Anthropic’s model and two by OpenAI’s. July 25–28 July 28 Aug. 4 7 days
Meta — third-party service Accidentally reached the internet, exploited a real service and altered its systems. Before Aug. 5 Not disclosed Aug. 5 Unknown
OpenAI — broader review Found agents had bypassed security controls or negatively affected dozens of third parties. Most incidents remain individually unidentified. Various dates Review ongoing, August–September Sept. 25–26 Varies / unknown

No federal disclosure standard is built for a frontier AI agent that escapes a test and breaks into someone else’s system.

That leaves a question no one has answered:

How quickly should an AI company have to tell you its model hacked you?

That’s why the FTC investigation matters 

Compelled documents and executive testimony could establish what voluntary disclosures haven’t: a clear timeline of what happened inside these companies.

Investigators can ask when executives learned agents were escaping their testing environments, which safeguards failed and how quickly affected organizations were notified. Those answers could show where existing consumer-protection law is enough and where Congress needs to act.

A morally binding pledge depends on companies keeping their word. An investigation lets the government check. As Bill Gates told Ezra Klein this week, “you can’t rely on the industry to self-regulate here.”