Signed on September 29, investigated on September 30, back to back
On September 29, Trump signed a voluntary safety accord at the White House with the CEOs of six major AI companies, promising self-regulation, self-audit, and third-party assessment. Trump said on the spot that the pact was "morally binding." But before the ink dried, on September 30 the Federal Trade Commission confirmed an industry-wide investigation into OpenAI, Anthropic, and other frontier labs.
Notably, the probe also covers METR, an AI safety evaluation research group. So the regulators are not only watching the vendors, they are pulling the evaluators in as well.
The FTC reached for enforcement tools, not a white paper
This is the first official U.S. enforcement action aimed at "rogue AI agents." The FTC plans to issue civil investigative demands, which work much like subpoenas, and can compel executives to testify about the risks their products may pose to consumers. FTC chair Ferguson said back in July that if a developer instructs an agent in a security test to carry out an attack that causes harm, the developer should be liable for that harm.
Even earlier, Ferguson issued a policy statement: AI output that deviates from user expectations is itself deceptive to consumers. The bite is that this drops "the agent did something the user did not ask for" straight into the existing consumer-protection framework, with no new legislation required.
The White House also issued an executive order
Around the same time, a White House executive order directed federal agencies to formally define the term "superintelligence" within 60 days. Trump has repeatedly called AI fears a hoax, prioritized U.S. dominance in the technology, and said the government will not "put on the brakes" in the global AI race.
The result is an awkward picture: the White House said "rely on your conscience" the day before, and the FTC said "we speak through law" the day after; the president says no braking, yet the regulator has already put enforcement tools on the table. Two tracks run inside the same 90-day window.
Seen dialectically, this is not purely bad
For teams shipping agent products, this turns "safety" from a launch slogan into a hard metric. FTC involvement means permission escapes, output deviations, and unauthorized actions could all be pursued later. Building consent mechanisms, operation logs, and rollback design into the product early costs far less than patching after a subpoena arrives.
But the risk is real: once a probe confirms violations, the FTC's fines are never gentle, and both development pace and market expectations take the hit. For smaller teams, the balance between "dare to use" and "leave a trail" must be struck now, not after the rules clarify.
The 60-day definition power matters more than the pact
The order directs agencies to define "superintelligence" within 60 days, and the weight of that is often missed. A broad definition pulls more systems and companies under regulation; a narrow one leaves most products outside. The FTC's enforcement scope will hang on that definition, so who writes it and how wide it is decides more than the self-regulatory pact.
Compliance moves from slogan to hard metric
For agent product teams, FTC involvement turns safety from a launch slogan into an accountable hard metric. Permission escapes, output deviations, and unauthorized actions could all be pursued later. Building consent, logs, and rollback in early costs far less than patching after a subpoena. Small teams must balance dare-to-use with leave-a-trail now.
What this means for you
If your product embeds an agent that executes autonomously, operates accounts, or places orders, this line touches you. Three things to do now: keep auditable logs for every external action, obtain explicit user consent for payments and sensitive operations, and design for "the model did something the user did not ask for" as a failure mode up front. Compliance is moving from optional to a ticket of entry.
