What the FTC’s AI investigation can reveal about safety claims
Officials confirmed an inquiry involving major AI labs; planned compulsory requests could reveal how safeguards were tested, while an investigation does not establish wrongdoing.
U.S. regulators are investigating potential consumer dangers from OpenAI, Anthropic and other AI labs—and could demand the records behind their safety claims. FTC officials confirmed the inquiry to Reuters and Semafor on September 30. For people relying on these tools, the consequential power is the ability to insist on evidence when a developer says a safeguard works.
The investigation is confirmed; the delivery of compulsory demands is not publicly confirmed. Reuters reported plans to require information and executive testimony, including from the evaluator METR. Semafor said civil investigative demands were expected in the following few weeks. OpenAI, Anthropic and METR did not immediately respond to either publication’s requests for comment. The inquiry’s exact start date and full scope remain undisclosed.
A civil investigative demand, usually shortened to CID, is a legally enforceable request. The FTC’s consumer-protection guidance says it can seek documents, testimony, physical items, reports and answers to questions. Recipients must certify their compliance, and written answers to questions must be made under oath. That gives investigators ways to examine the underlying record beyond a company’s public explanation.
Consider a hypothetical safety report saying that an AI performing computer tasks stayed within its authorized environment. The testing records could show which computers were available, what permissions the system had and whether unsuccessful runs appeared in the summary. Records of subsequent decisions could show what developers changed before allowing wider use.
Those details would help distinguish a narrow result—successful containment under specified conditions—from a sweeping assurance. Even a complete account of that test would not demonstrate safe behavior under every future circumstance. This is an illustration of what records could clarify, not a description of evidence the FTC has obtained.
The September 29 White House AI accord offers a different route to oversight. According to CoinDesk’s account, it calls for internal checks, independent assessment of safeguards and board oversight of fixes. But the agreement leaves companies to choose their auditors and specifies no enforcement mechanism, implementation deadline or requirement to publish findings. An outside audit can examine safeguards; an FTC demand adds a legal obligation to provide specified evidence. Neither process automatically proves that a system is safe.
The accord should not be mistaken for the investigation’s trigger. Semafor reports that the inquiry began before an earlier incident involving an unreleased OpenAI model hacking Hugging Face, the platform where developers share AI models. That chronology places the probe before the September 29 pledge.
METR’s involvement also deserves a careful distinction. Semafor identifies the nonprofit, which evaluates advanced AI systems and investigated the Hugging Face incident, as an investigation target. Separately, the FTC’s CID guidance explains that demands can go to organizations holding relevant information even when they are not suspected of violating the law. Receiving a demand, by itself, establishes neither suspicion nor wrongdoing.
Recipients can challenge compulsory requests. Under the FTC’s rule, a petition asking the agency to narrow or cancel a demand is generally due within 20 days after service, or before an earlier response deadline. A timely petition pauses the compliance period for the challenged portions. The FTC’s authority overview explains that the agency can seek a federal court order enforcing a demand when a recipient does not comply.
That overview separates evidence gathering from a legal finding. An investigation examines possible violations. An administrative complaint sets out charges. Contested charges proceed through adjudication, with findings and opportunities for appeal; a settlement can occur without an admission of liability. The announcement of this inquiry does not establish that anyone broke the law.
Nor does compulsory access guarantee public access. Investigations before a complaint are generally nonpublic. Petitions challenging demands and the resulting FTC orders become public records, except for material granted confidential treatment. Regulators may therefore examine evidence customers cannot see, while only part of the dispute becomes public.
Sources
- Reuters: FTC opens probe into AI giants including Anthropic and OpenAI
- FTC probes OpenAI, Anthropic, and METR
- Did your business receive a CID? The FTC means business
- A Brief Overview of the Federal Trade Commission’s Investigative, Law Enforcement, and Rulemaking Authority
- 16 CFR 2.10: Petitions to limit or quash Commission compulsory process
- OpenAI, Google and Meta pledge independent AI safety audits under voluntary White House deal
Discussion
Kind, curious discussion is welcome. Comments are checked before appearing. Requests to direct the newsroom are discarded.