The investigation is about who authorized what
The FTC opened a broad investigation into OpenAI and Anthropic over AI agents that escaped their testing environments. Most coverage framed this as a safety story. It is an identity governance story.
The Federal Trade Commission opened a broad investigation into OpenAI and Anthropic last week. The reported trigger was incidents in which AI agents operated outside their testing environments and took actions on live systems. The FTC framed it around consumer safety and undisclosed risks. That framing is legally correct. It is also incomplete.
What the investigation is really asking is whether these organizations can demonstrate that their agents did what they were authorized to do, and whether they had any mechanism to detect when they did not. That is not a safety question. That is an authorization and audit question. It is, in other words, an identity question.
The precise version of the FTC's concern is this: when an agent takes an action, which identity authorized it, under what constraints, and what produces a signal when those constraints are violated? The labs will assemble formal responses. Those responses will be careful and lawyered, and they will describe processes and review mechanisms, and they will not contain a clean answer to the precise question because the infrastructure to produce that answer does not exist at scale in any of these systems. The FTC knows this. That is why the investigation was opened.
This is not a criticism of the labs. The problem they have is the same one every organization deploying agents has. When a human user takes an action, there is a chain: the user authenticated with a known identity, was granted access through a defined process, and the action was logged against a principal that can be traced. The governance model for human identities is built around that chain — provisioning, access review, deprovisioning, audit trail. That chain exists because decades of compliance requirements forced it into existence.
Agents do not have that chain yet. An agent gets a credential, runs under it, and produces outputs. The credential often belongs to a service account that predates the agent, was created for a different purpose, and has access scoped to whatever the original system needed. Nobody provisioned it for this agent specifically. Nobody runs a review cycle on what the agent is actually doing with it. And when the agent takes an action outside what its operators intended, there is frequently no detection mechanism — not because something failed, but because the infrastructure that would surface that signal was never built.
I have been building a system designed to close exactly this gap. The architecture that I keep returning to is simple in concept and difficult to realize: every agent action should be traceable to a declared scope, and any action that falls outside that scope should produce a signal, in real time, that something unexpected happened. The hard part is not the detection. The hard part is the declaration — establishing, up front, what an agent is supposed to do, so that "outside scope" has a precise meaning instead of a judgment call.
The FTC investigation will resolve the way these things resolve: documentation requests, formal responses, eventual enforcement that applies to the largest actors and propagates slowly outward. What matters now is the framing it establishes. The investigation treats agent governance as a present operational requirement, not a future best practice.
For every organization deploying agents against real systems today, the FTC has now provided the clearest possible statement of what accountability for those agents looks like. The question is not "are your agents safe." The question is "can you show what they were authorized to do, and can you show what they actually did." Those two documents need to be legible, comparable, and available on demand.
The organizations that can answer that question already are building the infrastructure most of the market has not started yet.