Industry Insights 7 min read 29 September 2026

FTC: Businesses Are Liable for AI Agent Actions

The FTC just said AI agents are tools, not actors — your business is liable for what they do. Here's how to prepare for AI agent liability risk.

FTC: Businesses Are Liable for AI Agent Actions

On September 25, 2026, FTC Chairman Andrew Ferguson gave the clearest federal answer yet to a question every business running AI agents has been quietly hoping to avoid: when the agent does something wrong, who's responsible? Speaking at the Reuters Momentum AI event in Austin, Ferguson said he'd resist treating AI agents as autonomous actors that "break loose" with "wills and desires of their own." His framing was blunt: "If someone tells a tool to do something and it does it, I don't think we'll be asking: 'What should we do with the tool?'" In plain terms, an AI agent is a tool, and the business that instructed it is the one that answers for what it did. There's no separate legal category for "the agent decided to do that." There's just you, and the instructions you gave it.

Why This Matters More Than It Sounds Like

It's tempting to read this as a statement about frontier labs and leave it there — OpenAI's or Anthropic's problem, not yours. That's the wrong read. Ferguson's comment applies to every business deploying an agent, whether it's a foundation model provider's product or a workflow a five-person ops team built with a no-code automation tool. The FTC's existing authority over unfair and deceptive trade practices, and its data-breach enforcement powers, don't require a new law to reach an AI agent's actions — they reach the business that deployed it, the same way they'd reach an employee's actions or a piece of software you configured badly. If your agent sends a customer a discount it wasn't authorized to offer, misrepresents your product, or mishandles data it touched along the way, "the AI did it" is not going to be a defense. It's going to be the opening line of the complaint against you.

The Gap Between "It Works" and "We Can Defend It"

Most businesses evaluate an agent by whether it does the job — handles the ticket, books the appointment, drafts the email, closes the loop. Almost none evaluate it by whether they could produce a clean answer if a regulator, a customer's lawyer, or their own board asked: show me exactly what this agent was instructed to do, show me what it actually did, and show me the paper trail connecting the two. That gap doesn't show up in a demo. It shows up the day something goes wrong and there's no record showing the instruction was reasonable, the guardrails were in place, and the outcome was a genuine edge case rather than a foreseeable risk nobody bothered to prevent.

  • Instructions given to the agent that were never written down anywhere a human could review them before or after the fact
  • No log connecting a specific customer-facing action back to the specific instruction or prompt that produced it
  • No defined boundary between what the agent can do autonomously and what requires a human sign-off, tuned to the actual cost of a mistake
  • No one on the team who could explain, today, exactly what every agent currently running has permission to do

The reframe

The FTC just confirmed that regulators will treat an AI agent's actions as your actions. That means the standard isn't "did the agent behave well most of the time" — it's "can you show, after the fact, that you instructed and supervised it the way a responsible business would." That's a documentation and design problem, not a model-quality problem.

What 'Instructed and Supervised Responsibly' Actually Requires

Ferguson's framing puts the emphasis on the instruction, which means the businesses in the best position are the ones that can point to exactly what they told the agent to do and exactly how they constrained it. In practice that means a written, versioned instruction set for every agent in production rather than a prompt someone edited a dozen times and never saved a copy of; a permission boundary that matches the instruction, so an agent told to "answer billing questions" doesn't also hold the ability to issue refunds; a log of the agent's actions tied back to the instruction that produced them, so any single action can be traced and explained; and a defined human-approval threshold for anything with real financial, legal, or customer-facing consequence, so the agent's autonomy stops exactly where your liability exposure starts. None of this is exotic — it's the same operational discipline any regulated business already applies to what its employees are authorized to do. It just hasn't caught up to agents yet at most companies.

A Realistic Scenario

A Wizeb client, a regional insurance brokerage, ran an AI agent that handled inbound policy-renewal inquiries — answering coverage questions, generating renewal quotes, and routing anything unusual to an agent. It worked well, and it had been running for months on an instruction set that existed only as a chat history in the tool the team used to configure it. When we reviewed the deployment, we found the agent's actual permissions were broader than anyone remembered granting — it could apply discretionary discount codes originally added for a single promotional campaign that nobody had removed. No customer had been harmed, but there was no written record of what the agent was supposed to do, no log connecting its quotes back to an approved instruction, and no one who could have produced a clean answer if a regulator or an unhappy customer had asked for one. We rebuilt the deployment around a versioned instruction document, removed the unused discount permission, and added action-level logging that ties every quote back to the instruction that authorized it. The agent does the same job today — the difference is the brokerage can now show, in minutes, exactly what it told the agent to do and why.

Four Questions to Ask Before the FTC Asks Them For You

  1. 1For every AI agent your business runs, could you produce a written instruction set today — not a chat log, an actual document — showing what it's authorized to do?
  2. 2Can you trace any single action an agent took back to the specific instruction that produced it, or would you be reconstructing intent after the fact?
  3. 3Does your agent's permission scope match what you actually meant to authorize, or has it accumulated access over time that nobody has re-reviewed?
  4. 4Is there a defined line where the agent stops and a human signs off, set by the actual financial or legal exposure of a mistake — or is that line just wherever the agent's tool access happens to end?

How Wizeb Approaches This

We build agent deployments assuming that, one day, someone — a customer, a regulator, your own leadership — will ask you to explain exactly what an agent did and why it was allowed to. Every agent Wizeb deploys ships with a versioned, written instruction set, a permission scope that matches that instruction, and action-level logging that ties outcomes back to authorization, so the answer to that question is a five-minute lookup instead of a scramble. The FTC just told businesses that "the AI did it" won't hold up. The fix isn't a legal disclaimer — it's building agents whose instructions, permissions, and actions are documented well enough to defend on the day it matters. Start at wizeb.com/services/ai-agents.

Get your agent deployments audit-ready

Wizeb reviews one AI agent workflow, documents its actual instructions and permissions against what you intended to authorize, and builds the action-level log you'd need to defend it. Book a 30-minute review at wizeb.com/contact.

Ready to act on this?

We build exactly what this article is about.

Tell us about your situation — we'll come back with a realistic assessment.