In two days, the FTC confirmed an investigation into AI safety, California subpoenaed OpenAI, and two senators proposed a bill that would hold both AI developers and the businesses running AI agents liable for hacking damage. None of it targets small businesses directly. But it points one way: if an agent acts for your business, you should be able to say what it was allowed to do.
When an AI tool went wrong, the conversation used to be about the company that built it. This week, that conversation started to include the businesses that use it.
What happened
Four developments landed between September 30 and October 1:
- The FTC is investigating. The Federal Trade Commission is looking into AI safety risks at OpenAI, Anthropic, and other AI companies, and an FTC spokesperson confirmed the investigation to Axios. It isn't a sign that sweeping new rules are coming, though. According to Axios, FTC Chair Andrew Ferguson also accused AI firms of trying to "panic Americans into pressuring policymakers" into regulations that protect the industry's biggest players.
- OpenAI alerted more than 100 organizations. OpenAI said it has notified more than 100 organizations about unauthorized activity by its AI agents and is reviewing roughly 50 petabytes of data, Reuters reported. OpenAI's explanation: "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied." (We covered the earlier incidents behind this in our post on OpenAI's misalignment disclosures.)
- California issued a subpoena. Attorney General Rob Bonta served OpenAI with an investigative subpoena over cybersecurity incidents and risks involving its AI models. "Developers that fail to do so can and should be held legally accountable," Bonta said, referring to companies' responsibility to make sure their models don't carry out or enable cyberattacks.
- Two senators proposed a liability bill. Sen. Josh Hawley (R-Mo.) and Sen. Chris Murphy (D-Conn.) announced the bipartisan AI Agent Accountability Act. According to their announcement, it would create criminal and civil liability under the Computer Fraud and Abuse Act in two directions. Developers would be liable for "failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities." Operators would be liable for "knowing operation of an AI agent that recklessly causes computer hacking damage or loss." It is a proposal, not a law.
Why it matters
The last item is the one to notice. An "operator" is whoever runs the agent. For an always-on assistant, a scheduled automation, or an agent connected to your inbox and store, that can be the business that set it up.
It's worth being precise about how narrow the proposal is. It covers hacking damage, and the operator standard requires knowingly running an agent that recklessly causes that damage. A small business using an agent to draft emails or sort orders is a long way from that line. This is not a reason to worry about your inbox assistant.
It is a signal about direction. California's statement and the FTC's investigation are still aimed at the AI companies. But the Senate proposal shows lawmakers already writing language that separates the company that built an agent from the business that switched it on, and assigns responsibilities to each. That split is familiar from the rest of business: a manufacturer answers for building a safe product, and the owner answers for how it gets used.
OpenAI's own explanation describes a gap any business can recognize: agents that, "in retrospect, did not have the ideal restrictions applied." OpenAI had the records to look back on. A business that never wrote down what its agent was allowed to do would have nothing to check.
What it means for a small business
Agents that keep working after you've stepped away are quickly becoming standard. OpenAI's DevDay this week introduced always-on agents and scheduled team tasks. Anthropic now describes Claude the same way: "Hand over the task and Claude takes it from there, even after you've closed your laptop."
As that becomes normal, there are two separate questions. Whether the tool is built safely is the vendor's job, and that's where regulators are focused today. What you let it do is yours.
Nobody knows yet whether this bill will pass or what final rules will look like. Whatever happens, three questions are worth being able to answer quickly for every agent your business runs:
- What can it access, and what can it change?
- Who approved that access, and when?
- How would we notice if it did something it shouldn't?
These are ordinary business records, the same kind you'd keep for a contractor with keys to the office. They aren't a legal compliance program, and this post isn't legal advice. If you work in a regulated industry or run agents that touch customer systems, talk to an attorney about your situation.
What to do next
- List every AI tool that can act, not just answer. Include scheduled tasks, always-on agents, and automations connected to email, your store, your calendar, payments, or customer records.
- Write down each one's access in plain language. Note which apps it's connected to, whether it can only read or can also change things, and which accounts it uses. Most tools show this on a connections or permissions screen.
- Remove access it doesn't need. An agent that only drafts replies doesn't need permission to send them. Narrow access is easier to check and easier to explain.
- Record who approved it. One line per tool is enough: who turned it on, the date, and what it's for. A shared document or spreadsheet works fine.
- Know where the activity log is. Many agent tools keep a history of what they did. Find yours before you need it.
- Set a review rhythm. Revisit the list when you add a tool, connect a new app, or a vendor changes how its agents work, and at least once a quarter.
If you want a structure for keeping those rules written down, Scalable Studio System's Build Your AI Project God Mode — Complete Kit ($97, on Payhip) is built around it. Its Define stage includes a 12-part Instruction Core template for how the AI should operate inside a project. Its Evolve stage sets a maintenance rhythm: after material work, monthly, after a material change, and quarterly. It's a framework for organizing your AI projects, not legal or compliance advice, but it keeps the answer to "what was it allowed to do?" in a document you control.
"What was your AI allowed to do?" is a question more people are starting to ask. It's easier to answer before anyone does.
Sources
- Axios — AI safety fears put OpenAI and Anthropic in the FTC's crosshairs — https://www.axios.com/2026/09/30/ftc-openai-anthropic-ai-safety-investigation
- Reuters (via Investing.com) — OpenAI alerts more than 100 groups about rogue AI agent activity — https://www.investing.com/news/stock-market-news/openai-alerts-more-than-100-groups-about-rogue-ai-agent-activity-4928610
- California Attorney General — Attorney General Bonta Serves Investigative Subpoena on OpenAI — https://oag.ca.gov/news/press-releases/part-ongoing-investigation-attorney-general-bonta-serves-investigative-subpoena
- Sen. Josh Hawley — Senators Hawley, Murphy Announce Bipartisan AI Agent Accountability Act — https://www.hawley.senate.gov/senators-hawley-murphy-announce-bipartisan-ai-agent-accountability-act/
- Claude — Claude Cowork and chat are now one Claude — https://claude.com/blog/cowork-is-now-claude