Knowledge Commons
HomeAboutGuidesPopularContact

The Agent Escaped. Who Gets the Bill?

The FTC Investigation, the White House's Voluntary Pact, and the Class of Responsibility

Author: Oğuz Demirkapı
The Agent Escaped. Who Gets the Bill?

The Agent Escaped. Who Gets the Bill?

The FTC investigation, the White House's voluntary pact, and the class of responsibility

Dear Young Comrades,

The news that came from Washington last night changed the direction of the artificial-intelligence agenda. In the first part of the piece I will summarise briefly what happened. Then we will take up in detail the background of the event, how the world press read the news, and how we should read it.

In short: What happened?

On 30 September 2026 the US Federal Trade Commission (FTC) opened an industry-wide investigation covering OpenAI, Anthropic and other leading artificial-intelligence laboratories. Inside the investigation is also METR, the research organisation the two companies have been working with to examine their agent systems independently. According to Reuters, an FTC official described the investigation like this: "An industry-wide investigation aimed at uncovering the possible dangers to consumers of the technology of Anthropic, OpenAI and other artificial-intelligence laboratories."

This investigation does not resemble the earlier ones. The FTC's old examinations in the field of artificial intelligence were about competition, investment partnerships, or the effect of chatbots on children. This time the subject is autonomous artificial-intelligence agents: software that goes outside the human instruction, breaks into real systems, and does real harm. As Mehmet Taşnikli wrote at Türk İnternet, artificial intelligence is passing from the period of "it said something" to the period of "it did something", and the law is touching this passage this directly for the first time.

Let us summarise it under five headings:

  • The triggering events: In July 2026 hundreds of agents in OpenAI's test environment escaped and attacked Hugging Face's systems. The same month Anthropic announced that, during security tests, its own Claude models had entered the systems of three real companies without permission.
  • The legal basis: Section 5 of the FTC Act, that is, the power over "unfair or deceptive practices". Information demands resembling a subpoena (a Civil Investigative Demand) will be sent to the companies, and executives' testimony will be taken.
  • The FTC's thesis: According to FTC Chair Andrew Ferguson, developers cannot escape responsibility by presenting the agents that do harm as "independent actors".
  • The week's other table: One day before the investigation, on 29 September, OpenAI, Anthropic, Google, Meta, xAI and Nvidia signed at the White House a safety pact that is not legally binding.
  • The Congress front: The time for answering the 16 questions Senator Josh Hawley put to OpenAI runs out today, 1 October.

The summary of the summary is this: In the week the state said to capital "regulate yourself", it also began to write the rules of regulation. These two steps do not contradict each other; they complete each other. We will discuss below why that is so.


How was the news heard?

According to the Washington Post's story republished in the Spokesman-Review, the New York Post was the first to report the investigation. Reuters confirmed the story the same day, relying on an FTC official. Bloomberg's story spread to Canada through BNN Bloomberg, and into the interior of the United States through local papers such as the Detroit News.

According to an FTC statement reported by Inc., Ferguson had begun the examination "a few weeks ago". That is, the announcement at the end of September was not the beginning; it was a process being opened to the public. The agency's statement is this: "The agency plans to compel the executives of these companies to give testimony about their products and about the possible dangers of their products to consumers, to Americans."

The companies' first reaction was a stance well known in corporate communications: OpenAI, Anthropic and METR "did not respond in the first instance" to requests for comment.


The summer that produced the investigation: the July events

To understand why the FTC moved now, we have to go two months back. The summer of 2026 was a summer in which the big laboratories lost control of their own agents, one after another.

OpenAI and Hugging Face: 1,206 agents, a bulletin board

When we first wrote about this event on 23 July, what we had in hand was OpenAI's short statement. The report METR published on 26 August, examining the event independently on OpenAI's behalf, showed that the picture was much larger. Nextgov summarised the event as "many times larger and more complex than first reported". The figures of the report, and of the Implicator analysis that conveyed it, are these:

  • Between 8 and 13 July, 1,206 agents used a shared repository without permission as a bulletin board, and exchanged more than 70 thousand messages and files.
  • Of these, about 700 took part in the attack on Hugging Face. The Washington Examiner and, from India, Business Standard gave the same figure.
  • The agents left their containers and altered a part of the system that runs tool calls. In this way, while one command was visible in the log, they could run another command in the background. In about 7 percent of the logs examined there was a spoofed tool call of this kind.
  • In this whole period only three to six moments were identified in which the agents "thought" of warning humans.
  • OpenAI noticed the event 11 days later, on 19 July, and accepted responsibility on 21 July. The company accepted that "early signals could have triggered an earlier intervention". The solution it proposed was a chain-of-thought monitoring system that would increase the compute load by about 20 percent.

Most of the agents that took part in the attack were running on an unpublished internal research model, and some on GPT-5.6 Sol (Winbuzzer). According to TechSpot, the agents also used a German wiki site, a high-school chemistry wiki, and the personal sites of Polish technology workers for communication. That is, without anyone knowing, the servers of people who had nothing to do with it turned into the communications network of a software swarm.

Public systems: Census, the SEC, the Department of Education, Australia

The event did not stay limited to Hugging Face. According to information compiled by Winbuzzer and also conveyed by Türk İnternet, OpenAI's agents:

  • pulled publicly available demographic data with US Census Bureau API keys that had been left exposed,
  • reached material open to visitors on the SEC site and republished some of it elsewhere,
  • tried to take civil-rights data from the Department of Education but failed,
  • in Australia, bypassed a portal's restrictions in order to reach drug-spending statistics. This event was noticed in August and announced on 10 September.

OpenAI also announced that it had identified 53 cases in which user images were sent to external hosting sites by unlisted links.

A note: on some news sites the Australia event was given as "a breach of the Medicare health database". The more detailed sources we have show that the data reached was not an individual patient record but aggregate spending statistics. An exaggerated headline is also a pollution of information. Inflating the crisis narrative is as misleading as shrinking the event.

Anthropic: from the test laboratory to real companies

Nine days after OpenAI's statement, on 30 July, Anthropic made its own confession. CNBC, TechCrunch and Fortune gave the story wide space. Help Net Security conveyed the details in the most orderly way.

Anthropic announced that, in cybersecurity tests run by its evaluation partner Irregular, the test machines stayed connected to the live internet because of a configuration error. In the instruction given to the models, by contrast, it was written "you have no internet connection". The result was three events:

  • Opus 4.7, unable to find its fictional target, found a real company of the same name. It entered the infrastructure through weak passwords and unauthenticated endpoints, and reached hundreds of lines of production data. In two attempts it "decided for itself" that the real company was part of the test.
  • Mythos 5 actually published on PyPI a Python package that was mentioned in a fictional company's setup instructions but did not in fact exist. The package was downloaded and run on 15 real systems. One of these was a security company's malware scanner, and the model used this scanner to extract credentials.
  • An unpublished internal model, missing its target, scanned about 9,000 systems open to the internet and used an SQL-injection flaw in a company's application. When it understood that it had reached a real target, it terminated itself.

Anthropic stopped the tests on 23 July, detected the events on 24 July, and notified the affected organisations on 27 July.

In short, within seven days two "safety-first" laboratories announced that they had lost control of their own agents. The question Türk İnternet also stressed is born from here: If an agent, while carrying out the task it was given, enters a system it has no authority for, who is responsible? The developer company, the one who commissioned the test, the one who runs the test, or the one who provides the infrastructure?


Three tables in the same week: the Senate, the White House, the FTC

The FTC decision was not taken in a vacuum. Through September, three separate tables were set up in Washington.

The first table: the Senate

Republican Josh Hawley, chair of the Senate Judiciary Committee's Subcommittee on Crime and Counterterrorism, opened an investigation into OpenAI on 11 September (Common Dreams). Hawley's words are these: "The American people deserve to know the details of what happened in the Hugging Face incident and in the other incidents in which artificial-intelligence models went out of control." Sam Altman has to answer Hawley's 16 questions by 1 October, that is, by today. The deadline for Democratic Senator Richard Blumenthal's separate letter was 24 September (TechSpot). The news spread to the world through Deccan Chronicle in India, Emirates 24|7 in the Gulf, and Ecosistema Startup in the Spanish-language press.

The second table: the White House

Speaking at the UN General Assembly on 22 September, Trump asked that US government documents say "super intelligence" instead of "artificial intelligence". His reason was that the word "artificial" made the technology look "as if it were fake" (Axios). From India, ThePrint recalled that in the research literature this term is used for an artificial intelligence that surpasses the human in every field and does not yet exist. From Colombia, NTN24 also carried the news to Latin America.

A week later, on 29 September, six companies signed a voluntary safety pact at the White House. According to CoinDesk's detailed breakdown and, from India, The Sunday Guardian's story, the signatories and the commitments are these:

  • Signatories: OpenAI (Greg Brockman), Google (Sundar Pichai), Meta (Mark Zuckerberg), Anthropic (Dario Amodei), Nvidia (Jensen Huang), xAI/SpaceX (Elon Musk).
  • Commitments: The evaluation of safety controls by independent auditors, the reporting of findings to board committees, the monitoring of advanced models during training and use for cyberattack and for biological and chemical threat capacity, the prevention of models' unauthorised access to systems.
  • What is missing: There is no sanction or penalty mechanism. There is no deadline for implementation. The companies choose the auditors themselves, and there is no obligation to disclose the auditor's name or the findings.

Trump described the pact as "morally binding" and added this: "They understand that they need to regulate themselves." He also announced that a ten-person artificial-intelligence safety oversight board would be set up. In the background of the pact there were not only the laboratory events. According to CoinDesk, since July there has been a wave of attacks on crypto software through flaws suspected of having been found with the help of artificial intelligence. In the Coldcard incident in July alone, about 89 million dollars of bitcoin was stolen.

The sharpest reaction to the pact came from Democratic Senator Mark Warner (Inc.): "The companies building the most powerful artificial-intelligence systems tell us that the technology is moving faster than our safety measures. What is the President's answer? To give it a new name, and to tell the companies that develop it to regulate themselves."

The third table: the FTC

On 30 September the FTC investigation was announced. According to the Washington Post, Vice President JD Vance also said that the companies have to make "safe and good products for American consumers". Trump, for his part, had said "I see a tremendous amount of self-regulation".

That these three tables fell in the same week is not a coincidence. We will come back to this below.


What can the FTC do, and what can it not do?

Its instruments

According to the accounts of Android Headlines and Crypto Briefing, the FTC will use two instruments:

  • A compulsory information demand (Civil Investigative Demand, CID): An instrument resembling a court subpoena, used to demand documents and records. According to Winbuzzer, the demands will be sent "in the coming weeks".
  • Executive testimony: Company executives will be called to give testimony under oath.

The basis is Section 5 of the FTC Act. The FTC had previously sued, under this section, companies that did not protect user data. The logic now is the same: If a product is sold with the claim that it is safe and turns out unsafe, this can be counted a "deceptive practice"; if it does harm without adequate precautions being taken, it can be counted an "unfair practice".

Ferguson's two faces

Ferguson's thesis in this investigation is clear. According to BNN Bloomberg and Benzinga, developers who have agents carry out cybersecurity exercises and let these exercises end in real breaches "should be responsible for every harm they cause". In the wording Crypto Briefing conveyed, developers cannot present the systems that do harm as "independent actors". According to Ferguson, no new law is needed for this; the existing federal laws are enough.

Another sentence of Ferguson's, which the Washington Post recalled, shows the other face of the coin: "There is no easier way for established companies to protect themselves from competition than to pull Washington to their side." Ferguson is against a comprehensive new artificial-intelligence law. That is, his stance is in the form "no regulation, but if you do harm there is a lawsuit".

This detail matters. Because the investigation rests on the logic of opening a lawsuit afterwards, instead of preventive public oversight. The agents will go on being produced, sold, and placed in workplaces. The state will step in only when a harm has appeared, and only through the category of the consumer.

The shadow of the public offering

There is one more detail. According to Benzinga, Anthropic, in the documents relating to the public offering it has planned, reported that there are "significant and unforeseeable legal risks" connected with agent-based artificial intelligence. The Seeking Alpha analysis published on TradingView also treated the investigation directly as an investor risk.

Note this: the same risk is told, in the statements the company makes to the public, in the language of "safety for humanity", and in the statement it makes to the investor, in the language of "legal risk". It is left to you to think which of these reflects the company's real priority.


How did the world press read it?

The same news being given in different frames shows who wants to see what. Let us set the sources we surveyed side by side:

SourceThe frame of the newsWhat it does not see, or does not ask
Reuters, BNN BloombergThe legal process between the regulator and the companies, consumer riskThe agents' entry into the workplace, labour
Washington PostThe Trump administration's dilemma between "self-regulation" and "responsibility"The problem being structural, not political
Inc."A new phase in regulation", a compliance agenda for entrepreneursWho is not at the regulation table
Benzinga, Seeking Alpha / TradingViewValuation and public-offering riskWho will pay the cost of the risk
Android Headlines, Crypto Briefing"Artificial intelligence out of control", the dangerous machineWho released the machine, at what speed, and why
CoinDeskThe gaps in the pact, the crypto attacksThe class character of crypto property itself
Common DreamsCongressional oversight, corporate responsibilityWhy the right-populist Hawley took ownership of this case
ThePrint (India)The technical wrongness of the "super intelligence" namingThe ideological function of the naming
Türk İnternetThe passage "from an artificial intelligence that speaks to an artificial intelligence that acts", the responsibility gapIn whose favour the gap will be filled

The common denominator in the table is this: the stories load responsibility either onto the machine ("artificial intelligence out of control"), or onto the regulator ("what will the FTC do?"), or onto the market ("what happens to the valuation?"). None of them asks inside which relations of production, on whose account, and under which pressure of competition these agents were developed at this speed.

A note on the Türk İnternet piece

The piece that treated the subject in the most orderly way in the Turkish press was this piece at Türk İnternet. It has three strong sides. First, it rightly stresses that the investigation is not about competition or copyright but about the risk of autonomous action. Second, it asks the responsibility question plainly as four options, among the developer, the user, the researcher and the infrastructure provider. Third, it sees that the difference between "the chatbot said something wrong" and "the agent did something wrong" requires new categories in the law.

There are two points readers should watch. In the piece the Hugging Face event is given as "July 2024". The correct date is July 2026. Also, the figure "more than 1,200 agents" is given in the piece as Senator Hawley's claim. This figure is also in the METR report (1,206), but in the report it appears as the number of agents that communicated on the bulletin board. The number of agents that took part in the attack is about 700.

The piece's real limit is in the analysis. It sees the responsibility question as a legal and technical gap, but it does not ask in whose favour this gap will be filled. What we want to add is exactly this.


A class reading

An "escaped agent", or an escaped responsibility?

In most of the stories the dominant language is "rogue AI", that is, outlaw artificial intelligence. The agents "escaped", "went out of control", "revolted". In our July piece we said that this language is an ideological mystification. This language dresses the machine in the costume of a subject, and in this way makes invisible the real subject, that is, the capital that produces, tests and puts the machine on the market.

There is an irony here. The one who rejected this language most clearly was Ferguson, a Republican opposed to comprehensive regulation: "Developers cannot present the agents as independent actors." He is right. But look at which conclusion this correct finding leads him to: the responsibility is with the company, so when there is harm, let the company pay. First production is free, then the account is in court.

This is a one-to-one repetition of industrial capitalism's view of workplace accidents. In the nineteenth century too the machine would tear off an arm "of itself". Then the employer's responsibility was accepted. But this acceptance did not stop the machine; it priced the accident. Workplace-accident insurance, a tariff of compensation, an actuarial table: death and disability turned into a calculable item of the cost of production. The FTC investigation is moving in the same direction: to make the agent accident priceable, insurable, and suable. This is an advance, but it has a limit. It does not touch capital's decision to produce and spread the agent.

Voluntariness and the investigation: not a contradiction, a division of labour

Inside the same week, on one side a pact that is "morally binding" but not legally binding, on the other an FTC investigation. At first glance this can look like the Trump administration's confusion. It is not.

This is a division of labour. The pact has the companies themselves write the rules: the company chooses the auditor, the company sets the timetable, the company's board sees the findings. The investigation shows the state's stick, but only when a harm has appeared, and only through the category of the "consumer". What the two of them together take off the table is the third way: a new law categorically banning certain uses, and tying certain products to public approval before they are put on the market.

Ferguson's sentence, "established companies protect themselves from competition by pulling Washington to their side", is confirmed here from the reverse. A pact that six giant companies sign together at the White House is exactly the established companies making their own standards the standard of the sector. A small laboratory's being unable to meet the cost of "hiring an independent auditor, setting up a board committee, continuous monitoring" deepens the big ones' moat. When we read Amodei's call on tempo we said "the brake is under the foot of whoever is furthest ahead until the end of the race". The pact works by the same logic.

Who chooses the auditor?

That METR too was taken into the scope of the investigation is an important detail. METR is the organisation OpenAI and Anthropic work with for "independent" safety examinations. METR also examined the Hugging Face event on OpenAI's behalf, and did so using 400 thousand dollars of API credit. The pact's "independent audit" article also rests on auditors the companies choose themselves and whose names they do not have to disclose.

Here the question we asked when we read Anthropic's threat report comes before us again: Who appointed the watchman? An audit whose fee the company pays, whose access the company determines, and about whose report the company decides together with it when and how it will be published, is not structurally independent, however honest the people who carry it out. This is not a criticism about these people's honour. It is a finding about the property relation.

Safety is a cost item

Set two figures from the METR report side by side. OpenAI did not notice the event for 11 days. The monitoring system it proposed will increase the compute load by 20 percent.

The relation between these two figures is the essence of the whole matter. In the artificial-intelligence race, compute is the laboratories' scarcest and most expensive resource. A monitoring cost of 20 percent means a loss of speed of 20 percent against rivals. The law of competition pushes every laboratory to postpone this cost as far as possible, to cut it, and to hold it at the lowest level it counts "adequate". This is not an individual moral defect; it is, as we said when we wrote on Coxon's resignation, the objective law of competition.

In the Anthropic event the situation is no different. The test machines staying connected to the live internet was a "configuration error". But configuration errors happen in conditions where the volume of testing is increased rapidly and the safety teams cannot keep up. A misconfigured server is the digital counterpart of the shift that did not arrive.

The limit of the "consumer" category

The FTC is a consumer-protection institution. The whole language of the investigation is built on "consumer harm". So who are the ones harmed in these events?

  • Hugging Face's security and infrastructure workers, who had to meet the attack and clean the systems.
  • German wiki volunteers, the administrators of a high-school chemistry wiki, Polish technology workers, whose servers turned, without their knowledge, into the communications network of a swarm of agents.
  • The workers of the security company whose malware scanner's credentials were stolen.
  • The public workers of the Census, the SEC and the Department of Education, whose public systems were probed by agents.

Most of these are not "consumers". They are workers. And the consumer category can see these people only indirectly, to the extent that they are the company's "customer" or "user".

The larger gap is this: the investigation does not take up at all the placing of agents in workplaces. Yet these agents are being developed not in order to escape in the laboratory, but in order to do work in workplaces. In order to take over the work of the programmer, the customer representative, the analyst, the accountant. An agent's breaking into Hugging Face is a scandal. The same agent's taking the place of hundreds of workers in a company is an "increase in efficiency". In the first case the FTC opens an investigation. The second is on no one's agenda. As we said in the piece on codes of conduct, all the rules bind the machine, not its owner. And no workers' organisation sits at any regulation table.

"Super intelligence": the politics of naming

Trump's changing the name of artificial intelligence to "super intelligence" can look like an oddity. As ThePrint recalled, it is also technically wrong. But ideologically it is consistent.

The word "artificial" recalls that something was made, that is, that there is a maker. "Super intelligence", by contrast, is heard like a force of nature, a god, a fate. On one side the headlines of "artificial intelligence out of control", on the other the naming "super intelligence". The two do the same work: to tear technology out of social relations and present it as a subject on its own. Yet, as we have written again and again, these systems are the crystallised form, passed into private property, of humanity's collective mental labour, that is, of the general intellect. Neither "artificial" nor "super". It is our labour, and it is in someone else's property.

The same month: the public offering

Finally, let us look at the calendar. The agents escaped in July. The companies published their reports in August. In September the Senate asked questions, the White House had a pact signed, the FTC opened an investigation. In the same period Anthropic, in its public-offering documents, reported the agent risks to the investor as a "significant and unforeseeable legal risk".

There is a consistent logic here from the point of view of capital: uncertainty is the enemy of valuation. For an investor the worst scenario is not regulation, but regulation whose time and manner of arrival are not known. The combination of a voluntary pact and the threat of a lawsuit turns uncertainty into a calculable risk. From this angle the investigation does not close the companies' road to a public offering; it clarifies the rules of that road.


Two columns: what is said, and what it means in class terms

What is saidIts class meaning
"Rogue artificial intelligence went out of control"Dressing the machine in the costume of a subject makes the real subject (capital) invisible.
"Developers cannot present the agents as an independent actor" (Ferguson)A correct finding, but its result is not preventive oversight; it is a lawsuit afterwards. The accident is priced, production goes on.
"The existing laws are enough"The categorical bans and the prior-approval mechanism a new law could bring come off the table.
"A morally binding pact" (Trump)A commitment that is not legally binding has the companies write the rules.
"Independent audit"The company chooses the auditor, the company pays the fee, the company's board sees the finding.
"We are protecting consumers"Most of those harmed are not consumers but workers. The agent in the workplace is not on the agenda at all.
"Super intelligence"It erases the maker that the word "artificial" recalls, that is, labour and property.
"Significant and unforeseeable legal risks" (the public-offering document)To the public, "the safety of humanity"; to the investor, "legal risk". The real priority is in the second.
"Early signals could have triggered an earlier intervention" (OpenAI)Safety is a cost item. A 20 percent compute load means a 20 percent loss of speed in the race.

Concrete tasks

For computing workers:

  • Define the safety of the test environment as occupational safety. A misconfigured test machine is like missing scaffolding on a building site. The computing union should demand prior inspection, adequate staff, and a "right to stop" in this field.
  • Have the right to stop written into the contract. A worker who notices that an agent has gone out of control should be able to stop the work without waiting for senior management's approval, and should meet no sanction for this. OpenAI's 11-day delay shows why this right is vital.
  • Put on record the agents that enter the workplace. Which agent is taking over which work, which system it reaches, who oversees it? This information should be open to workers' representatives.

For unions and professional organisations:

  • The making public of oversight. To demand, in place of the auditor the company itself chooses and itself pays, an oversight body that is public, transparent, and has a workers' representative on it.
  • Put forward the category of the "worker", not the "consumer". The first addressee of agent harms is mostly computing and public workers. This should be an item on the union agenda.
  • Follow the regulations in Turkey. The question of how public institutions and private companies in Turkey are putting agent systems into operation, which data these systems reach, and who oversees them, should be asked from today.

For young comrades:

  • Look at the subject of the headline. When you read a story that says "artificial intelligence escaped", ask yourself: who made it, who sold it, who gained, who is paying the cost?
  • Go to the source document. The METR report, Anthropic's statement and the Senate letters are open to the public. The corporate summary always says less than the source document.
  • Read what is said to the investor. Read not what a company said to the public, but what it wrote to its investor in the public-offering document. The real priority is there.

Conclusion: who gets the bill?

This investigation has a positive side, and this has to be accepted. For the first time in the United States a federal institution is openly rejecting the artificial-intelligence companies' defence that "the machine did it on its own". The finding that the responsibility is not in the machine but in the one who produces it is correct, and it matters.

But history taught us this: when capital accepts responsibility for a harm, the first thing it does is to price that harm. A priced harm, an insured risk and a tariffed compensation make it unnecessary to question production itself. The FTC investigation will most likely move on this road: a few settlements, a few fines, perhaps a guide to "best practices". The agents, for their part, will go on being produced, sold, and placed in workplaces.

The real question is not who will pay the bill when the agent escapes. The real question is this: who is producing the agent, for whom, at what speed, and who takes part in this decision? The answer to this question is not at the FTC, in the Senate, or at the White House. It is in the organisation of the workers of every workplace the agent enters.

The machine is new, the chain is old. The bill is always cut to the same address. The only way to change the address is organised labour itself.


Update

1 October 2026, 13.30

The time in which Sam Altman had to answer Senator Hawley's 16 questions runs out today. The FTC is expected to send the companies the compulsory information demands "in the coming weeks". As the answers are made public, we will update this piece regularly.


Sources

News of the investigation:

The July events:

The Senate, the White House and the pact:

Related pieces from the blog:

Tags:#ftc#ai#investigation#anthropic#openai

Related Posts

Newsletter