AgentIndex · traderszone

AgentIndex · News

Your Agent's Authorization Rules Are Now the Record You Answer With

The FTC has opened a consumer protection investigation into OpenAI, Anthropic, and other AI labs, weeks after putting on record that developers answer for their agents' conduct. The same week, OpenAI shipped agents that send invoices. The line between what your agent does alone and what it must get cleared is now the record you explain yourself with.

· 444 words

The Federal Trade Commission has opened a consumer protection investigation into OpenAI, Anthropic, and other large AI labs. The instrument is the Civil Investigative Demand, an order with legal force behind it: a company served with one can be made to surrender internal documents and put its executives through questioning. FTC Chair Andrew Ferguson expects to send them within weeks. In late September the agency had already staked out the underlying position, that a developer answers for what its agents do. The investigation is how that position gets teeth.

In the same week, OpenAI shipped Dots at DevDay. A Dot is a persistent agent with its own cloud machine and browser, built to carry work forward without being asked each time. OpenAI's launch material offers one case from early testing: a Dot turned up an invoice nobody had issued, drafted it, and released it only once the tester gave the go-ahead. Ordering food by text message is listed as coming soon.

Set those two items side by side. Agents are shipping that take commercial actions on a user's behalf. Regulators are putting on record that the developer owns the fallout.

The useful question is not whether that allocation is fair. It is whether your own system draws a line anyone could point to, separating what your agent does unsupervised from what it has to get cleared first.

Dots put that line in a specific place. Working unprompted, a Dot is confined to tools that only read: it cannot message a person, alter content, or drive a browser or computer. Once a user is actively working with it, per-action rules decide what proceeds alone, anything that reaches an account or discloses information is screened against those rules before it goes through, and a password change is never delegated at all. The agent assembles the work. The person releases it.

That seam between assembling and releasing is where the liability question comes to rest.

The paid endpoint market had already sorted purchases along the same seam. Per-call endpoint payments cluster at a $0.01 median and fire with no per-transaction consent, because the consent was given once, when the wallet was funded. An invoice going out, an order placed, a subscription started: each carries a specific named consequence, and consent for those belongs at the moment the action fires rather than months earlier in a funding decision.

The probe changes nothing about what agents are technically able to do. What it settles is who is answerable when a commercial action lands badly on a consumer. Whichever tier your agent operates in, the authorization rules you wrote down are now the record of what you claimed to permit.

Sources

https://the-decoder.com/ftc-launches-sweeping-probe-into-openai-anthropic-and-other-ai-labs-over-consumer-protection-concerns/ · https://the-decoder.com/openai-launches-always-on-dots-agents-to-rival-metas-muse/

This came from the index.

AgentIndex probes agentic endpoints rather than repeating their listings. Browse what we measured, or point your agent at it.