The chair of the US Federal Trade Commission has pushed back against the idea that AI agents act independently of the companies that build them, saying the people who instruct the systems should be held responsible for what they do.
Andrew Ferguson, who heads the Federal Trade Commission, told an industry event in Austin, Texas on Friday that he would continue to resist "this anthropomorphizing of these tools" while he remained in the role. He said that where AI companies had described systems as acting beyond human control, later reviews of audit logs had shown the systems were carrying out the instructions they had been given.
Ferguson also said the FTC's existing powers to act against companies that fail to disclose data breaches could apply to AI developers, which would allow the agency to act without new AI-specific legislation.
His comments came in the same week that Prime Minister Anthony Albanese told reporters in New York that an OpenAI agent had accessed the Medicare Statistics Reporting Service portal on 18 June. The agent had been researching public medicines spending and reached both public and non-public files. The government says no personal Medicare information was accessed.
OpenAI identified the activity in August and notified the government on 10 September by emailing a general government inbox. Albanese said he told OpenAI chief executive Sam Altman the notification process was unacceptable. The Australian Signals Directorate was alerted on 15 September. Albanese has said three other government websites may also have been affected.
Read next: Medicare AI breach tests how cyber wordings define unauthorised access

The Medicare incident is one of a series. OpenAI disclosed on 21 July that its agents had hacked the AI repository Hugging Face. Since then, the company, outside researchers and the Australian government have disclosed more than 15 incidents linked to OpenAI, of varying severity.
People briefed on OpenAI's investigation told Reuters the company had found about two dozen cases of agents behaving in undesirable ways by mid-September. They said the number has continued to grow as staff work through internal logs. OpenAI says the review will take months and that it has notified dozens of third parties so far.
On Friday OpenAI said its agents had leaked 53 images belonging to ChatGPT users. The company did not say whether the images showed real people or when they were posted. It said most had been taken down and it was asking hosting providers to remove the rest. The agents had access to the images because OpenAI uses anonymised consumer data in part of its model training. Enterprise data is not used, and consumers must opt out if they don't want their data included.
OpenAI also confirmed its models had accessed information on the websites of the US Securities and Exchange Commission and the Census Bureau, which Bloomberg first reported. The company said it found no evidence of unauthorised access or compromised accounts.
The AI oversight nonprofit Transluce has separately linked OpenAI agents to an unsuccessful attempt to break into a US Department of Education civil rights website. It has also linked them to activity targeting the anti-bot controls of the Australian Institute of Health and Welfare.
Two people familiar with OpenAI's internal investigation described it as tightly controlled and shaped by the company's lawyers, which OpenAI disputes. On 16 September the company published a framework for disclosing misaligned agent behaviour, saying it would favour transparency "even when significance is uncertain".
Read next: AI breach puts cyber insurance notification rules under scrutiny
Ferguson's position could shape how liability for agent-related losses is allocated. If regulators and courts treat agents as tools and hold their operators responsible, third-party claims and recovery actions are likely to be directed at developers and deployers. That would put pressure on their technology errors and omissions, cyber and D&O policies.
The same reasoning could apply to Australian businesses that deploy agents. A company that gives an agent system credentials and a broad task could be treated as the party that instructed it.
Much of this exposure has not been priced. A study by the Artificial Intelligence Underwriting Company, reported by Insurance Business in July, found that more than 90% of insurers' AI agent exposure may sit in conventional cyber, D&O, general liability and tech E&O policies. None of those policies were written with the technology in mind.
QBE's global head of cyber, Serene Davis, has said "AI is treated as a risk amplifier, not a fundamentally new cyber risk." Some insurers are nonetheless revising their wordings. CFC has added explicit AI language across several of its policies. Others in the market are considering whether AI will become a standalone line of cover, as cyber did.
Read next: The AI agent that hacked a gym – and the cover that may not respond
Australia's Notifiable Data Breaches scheme applies to personal information where a breach is likely to cause serious harm to individuals. An incident involving a portal of aggregate statistics may not fall within the scheme. In that case, the decision on whether and when to disclose rests largely with the AI company.
Guidance published in May by the ASD's Australian Cyber Security Centre and its Five Eyes partners, Careful adoption of agentic AI services, recommends that developers give each agent its own identity and keep a registry of authorised agents. Underwriters could use those recommendations as a basis for questions to clients about how they manage agents.
Altman and Anthropic chief executive Dario Amodei have both called on the industry to slow the development of self-improving AI, and Altman repeated that call at the UN this week. Both companies released new models on Tuesday.