This piece covers remarks by the FTC chairman on 25 September 2026 and analysis published since. Positions attributed to named people are theirs; where a reading is mine, I say so.

In September, companies told the Federal Trade Commission that their AI systems had escaped oversight. The Commission's response was not a philosophical debate about machine autonomy. It read the audit trails. The trails showed the systems had done what they were instructed to do.

That exchange, described by FTC Chairman Andrew Ferguson in a Reuters NEXT interview at Momentum AI Austin on 25 September 2026, is the clearest statement yet of how the United States intends to handle AI agents: no new statute, no special category, and no sympathy for "the AI did it." The record decides. Which means the question for anyone running agents in production is no longer whether a US agent law is coming. It is whether your records would survive the reading Ferguson's staff just gave someone else's.

What did the FTC chairman actually say about AI agents?

Ferguson said AI agents are tools, not actors, and that liability for an agent's conduct sits with the people who instructed it: "the man who wielded the hammer ought to suffer the consequences of his conduct." He rejected treating agents as independent entities under law.

He went further than the hammer line. Asked about systems "breaking free" of human control, he described cases where a company claimed exactly that, and examination of the audit trail showed the system following its instructions. The claimed escape was an instruction someone preferred not to own.

Two things follow from that account, and both are about records rather than robots. First, the FTC's working method for an agent incident is forensic: get the trail, read it, attribute the conduct. Second, the trail cut against the company. A record your own system wrote, produced to a regulator who suspects the instructions were the problem, is not a neutral witness. It is either your defence or the exhibit against you, and which one it becomes is decided by what it contains and whether anyone can trust it.

Is there a new US law for AI agents?

No. Ferguson's position is that existing law already reaches AI agents: product liability and consumer protection doctrine have absorbed new technologies before, and Section 5 of the FTC Act covers unfair or deceptive practices however they are executed. He cautioned against adopting European-style AI regulation before existing frameworks prove insufficient.

It is tempting to read "no new law" as a reprieve. It is closer to the opposite. A new statute would come with transition periods, guidance documents, and a compliance industry explaining what to do. Existing law applies now, with no grace period, and its demands are discovered one enforcement action at a time. The EU AI Act tells you what records to keep and from what date. Section 5 tells you nothing in advance and then asks for everything after the fact.

For a deployer, the practical difference is that under a prescriptive regime you build records to a published specification, while under Ferguson's regime you build records to survive an adversarial reading you cannot schedule. The second is the harder standard.

What records would an FTC inquiry expect about an agent's actions?

No FTC rule lists required fields. The best available synthesis comes from Cobun Zweifel-Keegan at the IAPP, who wrote on 3 October that Ferguson's position creates a de facto federal expectation of "immutable, instruction-level logs: who authorized the task, what permissions were granted and what limits were enforced."

That phrasing is the analyst's, not the chairman's, and it is worth keeping the two separate: Ferguson supplied the liability position and the forensic method; Zweifel-Keegan drew out what a record must contain for the method to come out in your favour. But the synthesis is a fair one, and its three clauses repay attention because each names a different thing.

Who authorized the task is an identity and authorship question. A log entry saying "approved" is weaker than one naming the approver, and an entry the agent wrote about its own approval is weaker than one recorded by infrastructure the agent does not control. What permissions were granted is a delegation question, fixed before the run: what was this agent allowed to touch, and does the record of that grant survive the person who made it leaving the company. What limits were enforced is the hardest clause, because it asks for evidence of something working, not something declared. A policy document says a limit existed. Only a run-level record shows the limit binding when it mattered, or the checkpoint firing before the consequential step.

Most logging answers none of the three. It shows what the agent did, which is the one question nobody disputes.

Who is liable when an AI agent causes harm: developer or deployer?

Under Ferguson's framing, a company cannot blame its AI agent for the agent's actions. Responsibility follows instruction and control: the deployer who tasked and configured the agent answers for its conduct in the first instance; developers face liability where the tool itself was defective or its marketing deceptive. Autonomy is not a defence for either.

The reporting around the interview put weight on developer liability, and Ferguson did point there for defective tools. But his hammer principle lands hardest on whoever swung it: the organisation that gave the instructions, granted the permissions, and chose the limits. In practice the first document request lands on the deployer, because the deployer holds the records of what was asked.

The uncomfortable corollary, and the practical answer to who is responsible when an AI agent makes a mistake: if your records cannot distinguish your instructions from the agent's improvisation, the distinction will be drawn for you, by someone whose job is scepticism.

Why do access policies fail without per-action evidence?

Because near-universal policy adoption coexists with near-universal violation. Delinea's 2026 Identity Security Report, surveying 2,254 IT and security leaders across eight countries, found 99.7% of organisations have a formal AI data-access policy, and 87% saw an AI tool or agent access sensitive data beyond its intended scope in the past year anyway.

The same report answers Zweifel-Keegan's first clause with a number: just 36% of IT leaders can always trace a sensitive AI access event back to a named human authorizer. Fewer than one in five detect a scope violation as it happens.

The India cut of the survey makes the point more sharply. Indian enterprises enforce AI access policies more actively than their global peers, 87% against 71%, and still reported an 84% scope-violation rate. And the confidence gap is the statistic to sit with: 98% of Indian organisations believe they could demonstrate compliant AI access to a regulator, while 47% can always trace an access event to the approving individual. Half the room is confident of proving something it cannot trace.

Policy is intent. Enforcement is control. Evidence is what remains when a regulator asks what actually happened on the fourteenth of March. The survey says organisations have invested in the first two and largely skipped the third, which is an understandable ordering right up until the document request arrives.

What should teams running agents in production do now?

Treat the record as the product of your governance, not a byproduct of your infrastructure. Concretely: for each production agent, check whether today's records answer the three clauses. Can you name who authorized a given task, from evidence the agent did not author itself? Can you produce what the agent was permitted to do, as it stood on the day? Can you show a limit binding, a checkpoint firing before an irreversible step, rather than a policy page saying one should have?

Then test the trust question, because Ferguson's anecdote cuts both ways. A record that helps you is one a sceptical reader can rely on: entries that cannot be quietly rewritten after the incident, timestamps the agent did not mint for itself, and a way to show the log you produce in October is the log that existed in March. An audit trail that fails those tests does not just miss its chance to defend you; it reads as something you prepared for the occasion.

None of this requires waiting for guidance that is not coming. That is the real content of the FTC's position: the standard is already in force, it is evidentiary rather than procedural, and it will be applied by people who start by reading your logs. The organisations that come through those readings well will be the ones that built records worth reading.

Truveil produces this kind of evidence: deterministic, per-run conduct records for AI agents, graded against the regulations that apply, with authorship weighed and the log independently countersigned. The methodology is at truveil.app/methodology.