News analysis · Published

FTC’s AI Agent Liability Signal: Keep the Principal Visible

By the ELYMENT AI editorial team · Free to read

US Federal Trade Commission Chair Andrew Ferguson said on 25 September 2026 that AI agents should not be treated as independent actors with wills of their own. He suggested that people or developers who instruct agents may bear responsibility when those tools cause harm. The remarks are a policy signal, not a new liability rule or final enforcement action. Businesses should nevertheless make the principal behind every consequential agent action visible by recording who authorised it, what mandate applied, which safeguards ran and who owned the outcome.

A luminous AI agent core routes actions to a visible enterprise principal identity anchor in a dark cyan and indigo control chamber.
Original ELYMENT.AI editorial illustration.

What the FTC chair said

At Reuters Momentum AI Austin on 25 September 2026, FTC Chair Andrew Ferguson rejected language that anthropomorphises AI agents as actors that break loose. Reuters reported that he viewed an agent following instructions as a tool and suggested that the developer or person directing it could be liable for resulting harm. He also said existing US legal tools should be used and suggested that FTC authority around undisclosed data breaches could apply to AI developers.

That does not create a new statutory test. Liability will still depend on the facts, the parties, the product, the jurisdiction and the legal duty involved. But the enforcement direction is commercially important: calling a system autonomous may not separate a business from instructions, permissions, product design or omissions that shaped the result.

Why agent language can hide operating responsibility

Agent systems distribute decisions across prompts, policies, models, tools, data sources and human approvals. When an incident occurs, each party can point elsewhere: the user wrote the task, the vendor supplied the model, the integrator connected tools and the model chose the step. That ambiguity is a control failure before it becomes a legal argument.

The Federal Trade Commission Act already empowers the FTC to act against unfair or deceptive practices in commerce. FTC guidance also says AI companies must honour privacy and confidentiality commitments and that material omissions about data practices may attract enforcement. Those sources do not settle responsibility for every agent incident, but they show why product claims, instructions and disclosures must match actual operation.

Create a principal-action receipt

For each consequential agent action, preserve one compact record that connects the tool back to an accountable principal. It should contain five elements:

  • Principal: identify the company, role and named owner that authorised the workflow, plus the vendor and integrator responsible for supplied components.
  • Mandate: record the approved objective, data and tool scope, prohibited actions, spend or change limits and the expiry of authority.
  • Decision path: retain material prompts, policy decisions, model and tool versions, approvals, exceptions and the final external action.
  • Safeguards: show which access, disclosure, validation, monitoring and stop controls ran, and whether any control failed or was bypassed.
  • Outcome: record affected people or systems, containment, notification, remediation, customer redress and the owner who closed the event.

What leaders should do before scaling agents

Start with workflows that can change prices, send customer communications, move money, access personal data or alter production systems. Assign a business principal before activation and make vendor responsibilities contractual. Test whether logs can reconstruct an action without relying on the agent's narrative. If a reviewer cannot identify the instruction, authority, control decision and accountable owner, the workflow is not ready for higher autonomy.

This builds on ELYMENT AI's guidance for exposure-adjusted incident reporting, agent change budgets and cyber insurance evidence. The practical goal is not to predict a court outcome. It is to prevent the phrase the agent did it from becoming an operating dead end.

ELYMENT AI helps operators design AI workflows with explicit authority, evidence and human accountability. As agent capability grows, the principal-action receipt should remain stable enough for security teams, customers, insurers and regulators to understand what the business authorised and how it responded.

Sources

Continue learning

Frequently asked questions

Did the FTC create a new AI agent liability rule?

No. Andrew Ferguson's 25 September remarks signal an enforcement view, but they are not a new statute, regulation or final adjudication.

Who is the principal behind an AI agent?

Operationally, it is the person or organisation that authorises the workflow and sets its mandate; vendors and integrators may hold separate responsibilities for their components.

What evidence should a business retain for agent actions?

Retain the authorising principal, mandate, prompts and policy decisions, model and tool versions, approvals, safeguards, external action, impact and remediation owner.

Explore ELYMENT AI