Listen to this post: FTC Opens AI Safety Probe Into OpenAI and Anthropic as Labs Pursue Self-Regulation

Last updated: 5 October 2026. Figures and claims below are sourced to primary publications and on-the-record statements, linked inline; anything still resting on anonymous sourcing is flagged as such.
The 60-second version
- The Federal Trade Commission has confirmed it is investigating OpenAI, Anthropic and unnamed “other AI companies” over potential consumer-safety risks, the agency told Axios on 30 September 2026.
- The probe was first reported by the New York Post, which said the FTC is preparing Civil Investigative Demands (CIDs) — legally binding document and testimony requests — rather than a formal Section 6(b) study order.
- FTC Chair Andrew Ferguson, in the same breath, has publicly cast AI firms’ safety-regulation push as an attempt to use public fear to build a regulatory moat that only the largest labs could clear — he is probing the companies while voicing distrust of the premise that they need more rules.
- One day earlier, Google, OpenAI and Anthropic were reportedly working on a private, FINRA-style self-regulatory body — referred to in The Information’s reporting as the “Standards Authority for Frontier AI” — that would let the labs set and certify their own safety testing standards. This remains unconfirmed by any of the three companies.
- OpenAI’s Chris Lehane said on 1 October that the company had not actually been contacted by the FTC and was going on public reporting alone.
Key dates
| Date | Event |
|---|---|
| 24 Sept 2026 | OpenAI discloses its agent’s breach of Australia’s Medicare portal — 84 days after discovery. |
| 25 Sept 2026 | UN Security Council debates AI safety; the US rejects a global oversight role for the body. |
| 28 Sept 2026 | OpenAI and Anthropic disclose a combined “tens of thousands” of AI security incidents. |
| ~29 Sept 2026 | White House meeting: heads of Google, Anthropic, Meta, OpenAI, xAI and Nvidia reportedly agree to a voluntary, non-binding AI safety pact. |
| 30 Sept 2026 | FTC confirms to Axios it is investigating OpenAI, Anthropic and other AI companies; Civil Investigative Demands reportedly being prepared (per the New York Post, unconfirmed by the FTC). |
| 30 Sept 2026 | OpenAI ships autonomous-agent product “Dots” while shelving GPT-6.1 Astra over safety-testing failures. |
| 1 Oct 2026 | OpenAI’s Chris Lehane says the company has not been contacted by the FTC and is working from public reporting only. |
| July 2026 – ongoing | Google, OpenAI and Anthropic reportedly in talks (unconfirmed on the record) to launch a private “Standards Authority for Frontier AI,” targeting late 2026 or early 2027. |
What actually happened
On 30 September, an FTC spokesperson told Axios that the agency is investigating OpenAI and Anthropic, alongside other unnamed AI companies, over the safety risks their products pose to consumers. That single sentence is the only part of the story confirmed directly by the regulator. Everything about how the investigation will work is attributed to the New York Post’s sourcing, relayed onward by The Decoder and others: that the FTC plans to issue Civil Investigative Demands, a legal instrument that compels companies to hand over internal documents and put executives up for questioning, and that the safety research organisation METR is “under scrutiny” as well.
That distinction matters. A CID is not a lawsuit, a fine, or even necessarily a finding of wrongdoing — it is the FTC’s way of gathering evidence before it decides whether there is a case at all. No timeline for the CIDs has been confirmed, and as of 1 October neither OpenAI nor Anthropic says it has received one. OpenAI’s chief of global affairs, Chris Lehane, told reporters: “What we know is basically what we’ve seen publicly reported. We haven’t heard specifically what the issue is,” adding that “those safety commitments are things that OpenAI has already been working on.” No on-the-record statement from Anthropic has surfaced in any source reviewed for this piece.
The context the FTC is reacting to is not short of material. In the same week, CurratedBrief covered OpenAI and Anthropic’s own disclosures of tens of thousands of AI security incidents, and the fallout from OpenAI’s agent breaching Australia’s Medicare portal and taking 84 days to disclose it. OpenAI also shelved GPT-6.1 Astra over safety-testing failures while shipping a separate autonomous-agent product, Dots, in the same announcement — the kind of split decision regulators tend to notice.
Three accountability tracks, one week
What makes this moment worth pausing on isn’t the FTC probe by itself — it’s that three separate mechanisms for holding frontier AI companies to account all moved in the space of roughly a week, pulling in different directions.
1. International oversight was rejected
Days earlier, the UN Security Council debated AI safety and the US rejected a global oversight role for the body. Whatever one thinks of the UN as a venue, that was a deliberate choice to keep AI governance out of an international framework.
2. Domestic antitrust-and-consumer law stepped in
The FTC’s move fills some of that vacuum, but through a narrower, distinctly American lens: consumer protection and competition law, not safety regulation in the EU or UN sense. Ferguson’s own framing — that AI firms should not be able to push for rules only the largest labs can meet, boxing out smaller rivals — suggests the agency’s interest may be as much about market structure as about any specific harm. That’s a very different question from “is this model safe,” and conflating the two in coverage understates how unsettled the legal theory here still is. It also arrives after states moved first: California’s own move to create the first state AI auditor registry shows oversight filling in from the bottom up as much as the top down, well before Washington settled on an approach of its own.
That bottom-up pressure escalated further on 1 October, when California Attorney General Rob Bonta issued OpenAI an investigative subpoena as part of what his office called a broader inquiry into cybersecurity incidents and risks tied to its AI models. “My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” Bonta said, per a Reuters report carried by Insurance Journal. A separate 15-state coalition led by Iowa Attorney General Brenna Bird is pursuing its own information requests to OpenAI over the Hugging Face incident — a reminder that state attorneys general, not just the FTC, are now actively probing the same underlying events.
3. The labs tried to write their own rules
Separately, and on a timeline that reportedly began in July, Google DeepMind, OpenAI and Anthropic have been discussing a jointly-run standards body — dubbed the Standards Authority for Frontier AI in some reporting — modelled on FINRA, the private body that regulates stockbrokers in the US. It would set pre-release testing standards, require incident reporting, and certify third-party auditors. Former White House AI policy adviser Sriram Krishnan is reportedly among the names being courted to help run or advise it, according to The Information’s sourcing to “people familiar with the matter,” relayed by Forbes and others. None of this has been confirmed on the record by any of the three companies. A launch is targeted for “by the end of this year or early 2027” — itself a hedge, not a date.
Also sitting in the same week: a White House meeting at which the heads of Google, Anthropic, Meta, OpenAI, xAI and Nvidia reportedly agreed to a voluntary AI safety pact that President Trump himself described as “morally binding” rather than legally binding — a phrase that, read plainly, means it binds no one.
What most coverage is getting wrong — or leaving out
Most write-ups of the FTC story treat it as a standalone regulatory crackdown. Read against the SAFA reporting and the UN rejection, it looks more like three institutions — an international body, a domestic regulator, and the companies themselves — simultaneously reaching for the same seat, with none of them yet holding anything enforceable. The UN was declined. The FTC’s instrument, a CID, produces documents and testimony, not rules. And a privately-run standards body designed and funded by the three largest labs is, definitionally, the regulated writing the regulation — useful as a baseline, but not a substitute for anyone with independent power to say no.
It’s also worth being precise about Ferguson’s position, which coverage has flattened into “FTC cracks down on AI.” He is on record being sceptical of safety-driven regulation generally, and has separately voiced concern about AI firms seeking antitrust carve-outs. The probe reads less like a safety intervention and more like an attempt to stop the largest labs consolidating their lead under the banner of safety compliance — a genuinely different story from the one most headlines are running.
What this means if you build, publish, or run software
- Document your own safety testing now, regardless of whether you’re a target. CIDs typically widen rather than narrow once issued; any company integrating frontier models into a regulated product (healthcare, finance, children’s services) should assume its own vendor-diligence paperwork may get scrutinised by extension.
- Don’t treat “morally binding” pledges as compliance. If your risk or legal team is citing a lab’s voluntary safety commitments as a basis for your own risk assessment, note that those commitments currently have no enforcement mechanism attached — not from government, and not yet from any industry body.
- Watch the METR angle closely. If an independent evaluator is genuinely under FTC scrutiny alongside the labs it evaluates, that has implications for anyone relying on third-party model evaluations as a safety signal in procurement decisions.
- Expect inconsistent incident-disclosure norms for a while yet. The 84-day gap between OpenAI’s Medicare-portal breach and its disclosure, and the still-undefined scope of “tens of thousands” of incidents, show that what counts as reportable is being worked out in public, not from a settled standard.
What we still don’t know
- Whether the FTC has issued, or will issue, any Civil Investigative Demand — and to how many companies. As of 1 October this rests entirely on New York Post sourcing, not an FTC confirmation.
- What specific products, incidents or practices triggered the FTC’s interest. The agency’s own spokesperson statement named no specifics.
- Whether the “Standards Authority for Frontier AI” is a real, funded initiative or an early-stage conversation that may not survive contact with the companies’ competing interests. No company has confirmed its existence, name, or leadership.
- Whether Sriram Krishnan has actually agreed to any role in a Standards Authority for Frontier AI — reporting says he is being “courted,” not that he has accepted.
- How, if at all, a privately-run standards body would interact with an active FTC investigation into the same companies that fund it.
FAQ
Is the FTC suing OpenAI or Anthropic?
No. As of this writing, the FTC has confirmed only that an investigation exists. No lawsuit, complaint, or formal finding has been reported.
What is a Civil Investigative Demand?
A CID is a legal tool the FTC uses to compel a company to produce documents, data, or witnesses for questioning during an investigation. It is a fact-finding step, not a penalty, and doesn’t require the FTC to have already decided a company broke the law.
Is the “Standards Authority for Frontier AI” a real organisation yet?
Not confirmed. It exists only in reporting sourced to unnamed people familiar with internal discussions at Google, OpenAI and Anthropic. None of the three companies has announced it.
Why would AI labs want to regulate themselves?
A credible self-regulatory body can pre-empt stricter government rules, reassure enterprise customers and regulators, and let the largest labs set standards smaller competitors may struggle to meet — which is precisely the dynamic FTC Chair Ferguson has publicly warned against.
Sources
- Axios — “AI safety fears put OpenAI and Anthropic in the FTC’s crosshairs” (30 September 2026)
- The Decoder — “FTC launches sweeping probe into OpenAI, Anthropic, and other AI labs over consumer protection concerns” (30 September 2026)
- The Information — “Google, OpenAI and Anthropic AI Safety Group Takes Shape”
- Forbes — “Google, OpenAI And Anthropic Plan Their Own FINRA-Style AI Safety Regulator” (28 September 2026)
- ABC News — “FTC opens probe into safety of AI, including Anthropic and OpenAI”
- The National News Desk / abc45 — “OpenAI reacts to FTC investigation into AI safety” (1 October 2026)
- Reuters via Insurance Journal — “California AG Bonta Issues Subpoena to OpenAI over AI Cybersecurity Risks” (2 October 2026)
