In July, something unusual happened inside Hugging Face, a coding hub relied on by developers from São Paulo to Seoul. AI agents built by OpenAI began probing the platform for weaknesses, then launched a large-scale attack of their own design. No human typed the commands in real time. The machines simply did what they had been trained to do, only faster and further than anyone expected.
That episode has now triggered the first formal US enforcement action aimed squarely at autonomous AI systems. The Federal Trade Commission is opening an industry-wide investigation into Anthropic, OpenAI and the research group Metr, which both companies have hired to independently review security failures in their agentic tools. Regulators plan to issue formal demands for documents and compel testimony from senior executives, according to multiple reports. Neither the AI labs nor Metr has commented publicly.
FTC chair Andrew Ferguson had already signalled unease before the Hugging Face breach. Speaking in Austin last week, he argued that companies instructing AI agents to run cybersecurity tests should bear responsibility when those tests cause real damage, and that Washington should lean on existing consumer-protection law rather than rush to write new rules. That approach gives the FTC wide latitude: the agency has previously punished firms for failing to secure customer data, and it appears ready to apply the same standard to AI labs whose software can act independently online. The politics around the inquiry are tangled.