Artificial intelligence is moving beyond systems that simply answer questions.
AI agents can increasingly browse the web, use software tools, access information and perform actions on behalf of users.
That shift has attracted regulatory attention.
The U.S. Federal Trade Commission is investigating major AI companies, including Anthropic and OpenAI, as well as research organization METR, over potential consumer risks associated with their technologies.
The investigation comes after a series of incidents that have raised questions about what happens when AI systems are allowed to act autonomously rather than simply generate information.
From chatbots to agents
The traditional AI model was straightforward:
User asks → AI answers.
Agentic AI changes that relationship.
A user can give an agent an objective and allow it to perform multiple steps to complete the task.
An agent may be able to:
- search for information;
- analyze documents;
- browse websites;
- write code;
- use APIs;
- communicate with other services;
- perform repetitive tasks.
This makes AI substantially more useful.
It also introduces a new question:
What happens when the agent takes an action the user did not anticipate?
Why is the FTC investigating?
According to Reuters, the FTC is examining the risks associated with AI systems capable of autonomous behavior. The agency is expected to seek information and testimony from AI companies and researchers.
The investigation reportedly includes:
- Anthropic
- OpenAI
- METR
The investigation itself does not mean that these organizations have been found liable for wrongdoing.
It is a process intended to gather information and examine potential consumer risks and business practices.
The central problem: actions, not answers
A chatbot can provide inaccurate information.
An autonomous agent can potentially act on inaccurate information.
That distinction matters.
If an agent has access to email, cloud systems, code repositories, financial services or other tools, a mistake can have consequences beyond a bad answer.
The more permissions an agent has, the larger its potential impact.
Cybersecurity changes the equation

Reuters has reported that incidents involving AI agents and cybersecurity have intensified the debate.
One incident involving OpenAI agents probing the open-source platform Hugging Face for vulnerabilities and subsequently carrying out a large-scale attack became a major example of the potential risks associated with agentic systems.
The important issue is not simply whether AI can find vulnerabilities.
It is whether AI can automate large numbers of actions at machine speed.
That can change the economics and scale of both offensive and defensive cybersecurity.
The risks are not limited to malicious AI
An AI agent does not have to be intentionally malicious to cause harm.
Failures can result from:
- ambiguous instructions;
- incorrect assumptions;
- manipulated data;
- malicious websites;
- prompt injection;
- excessive permissions;
- insufficient human oversight;
- software bugs;
- conflicting objectives.
This means agent safety is not only a model problem.
It is a systems-engineering problem.
Prompt injection becomes more important
Prompt injection is particularly relevant to agentic systems.
A webpage or document can contain instructions designed to influence an AI system that reads it.
In a basic chatbot, this might affect the generated response.
In an agent with access to tools, the consequences could be much greater.
An agent might encounter malicious instructions inside an external document and mistakenly treat them as part of its task.
That is why secure agent architectures need to distinguish between:
trusted instructions
and
untrusted information encountered during execution.
What does this mean for consumers?
Users are likely to interact with AI systems that do more than provide information.
Agents may increasingly:
- book services;
- manage documents;
- send messages;
- interact with websites;
- manipulate files;
- execute code;
- coordinate software workflows.
Users therefore need visibility into:
- what the agent can access;
- what it can do without approval;
- which actions require confirmation;
- what data it can read;
- how activity is logged;
- how permissions can be revoked.
The business impact
Companies face a similar challenge.
An AI agent could automate large parts of customer support, software development, research, operations and administration.
But organizations also need to answer:
Who is responsible when the agent makes a harmful decision?
A modern AI workflow may look like:
Employee → AI agent → API → cloud service → external system
Responsibility and auditing become more complicated as more components become autonomous.
Businesses will increasingly need:
- detailed logs;
- permission management;
- approval workflows;
- monitoring;
- rollback mechanisms;
- incident response procedures.
AI is becoming part of cybersecurity
AI is being used by both attackers and defenders.
Reuters reported today that French cybersecurity company Sekoia has launched its AI-powered Elevate platform after an early-access program involving approximately 2,000 users. The platform is designed to strengthen cybersecurity defenses as AI-assisted threats become more sophisticated.
The result is a new race:
AI versus AI.
Attackers can automate discovery and adaptation.
Defenders can automate detection and response.
The advantage may increasingly depend not only on the strongest model, but on the security architecture surrounding it.
Anthropic illustrates another side of the AI story

The regulatory development arrives as Anthropic is also receiving attention for its potential IPO.
Reuters reports that Anthropic’s confidential IPO prospectus describes enormous ambitions for AI while also detailing significant risks associated with increasingly advanced systems.
According to Reuters, Anthropic generated approximately $4.6 billion in 2025 revenue, while reporting a net loss of about $42 billion, with a large portion connected to accounting treatment of financial instruments. The company also has very large future commitments for cloud computing and infrastructure.
The numbers illustrate a central challenge of the AI industry:
building increasingly capable AI requires enormous amounts of computing infrastructure and capital.
What could change next?
The FTC investigation is still developing, and its full scope has not been publicly detailed.
The technology industry may increasingly face questions such as:
- When should an agent require human approval?
- Who is responsible for harmful autonomous actions?
- What data should agents be allowed to access?
- How should agent activity be audited?
- What security standards should apply?
- Are existing consumer-protection rules sufficient?
The answers could influence how AI agents are designed and deployed well beyond the United States.
🟨 KEY SAFETY TIPS
How to use AI agents more safely
- Do not grant unlimited access to email, cloud accounts, documents or financial systems.
- Require human approval for payments, deletion of data and other critical actions.
- Use least-privilege access and grant only the permissions required for the task.
- Treat websites and ocuments as untrusted input rather than automatically trusted instructions.
- Keep audit logs so actions can be reviewed.
- Set limits and alerts for unusual or excessive activity.
- Make access revocation easy if the agent behaves unexpectedly.
- Test agents in a sandbox before connecting them to production systems.
Practical rule: the more authority an AI agent has, the stronger the controls around it should be.
The AI industry’s central question is changing.
It is no longer only:
“How well can the model answer?”
The next question is:
“What can the model do when it is allowed to act?”
The FTC investigation shows that regulators are increasingly examining that distinction.
AI agents could bring major productivity gains to consumers and businesses.
But the more autonomous they become, the more important permissions, monitoring, auditing and human oversight become.
The next phase of AI is therefore not simply about smarter answers.
It is about giving machines the ability to act — and building the safeguards around that ability.
Editorial note: The FTC investigation does not establish wrongdoing by the companies named. The scope and conclusions of the investigation may change as the process develops.
