
On 30 September 2026, it was reported that the US Federal Trade Commission is investigating OpenAI, Anthropic and other AI companies over the dangers their products may pose to consumers. A day earlier, the chiefs of six AI companies had signed a voluntary safety pledge at the White House, one that carries no penalty. Between a pledge with no penalty and an FTC investigation, which one can actually test what AI companies say about safety? Only the investigation can compel documents and sworn testimony. But an investigation is not a finding of wrongdoing, and until it concludes, the job of checking a vendor's safety claims stays with the organisations that use the AI.
01Of the Pledge and the Probe, Only the FTC Can Force AI Companies to Back Up Their Safety Claims
Two developments arrived on consecutive days, and both concern the safety of AI. They differ in one respect that matters more than any other: whether anyone can be made to do anything.
The pledge of 29 September was signed by OpenAI, Google, Meta, Anthropic, Nvidia and xAI. According to CoinDesk, it asks the companies to submit to outside audits. The companies, however, choose their own auditors, and nothing obliges them to publish the auditors' names or the results. Implicator.ai, a site that covers AI news, reported that the document names no penalty for a breach and no government enforcer.
The FTC, by contrast, has a statute behind it. The Daily Hodl, citing an exclusive report in the New York Post, said the agency is expected within weeks to issue civil investigative demands, or CIDs, seeking documents and testimony from executives. The FTC's authority rests on Section 5 of the FTC Act, which makes unfair or deceptive acts in commerce unlawful.
My answer, then, is this. Of the two, only the FTC investigation has the power to test, from outside, what these companies say about safety. Yet the start of an investigation settles nothing. Axios was careful to note that a CID is not a lawsuit and is not a finding that anyone broke the law.
A conclusion will take time. In the meantime, the pledge's audit results stay inside the companies, so an organisation that has put AI into its work should not accept a vendor's safety story on the strength of a signature on a pledge. It should ask about audits itself, and keep the answers in its contracts and records. The rest of this column sets out the grounds for that judgement.
02The Pledge Is One Page, and the Companies Choose the Auditors and Keep the Results
To say that the power sits with the investigation, we first need to read what the pledge promises and what it leaves out.
CoinDesk describes four stages. An internal team checks the models. An independent auditor reviews them. A board committee reads the review. Someone then oversees whatever corrections are needed. For the most capable models, the pledge also asks for monitoring during training and during use.
Three things are missing. The method of choosing auditors is left to the companies. There is no obligation to disclose the auditors' names or their findings. And there is no deadline by which any of this must happen. CoinDesk put it plainly: the agreement has no enforcement mechanism.
Follow Figure 1 through all four stages and not a single piece of information has to leave the company. Someone on the outside is left holding one fact: that six companies signed.
President Trump was reported to have called the pledge "morally binding." I have no way to weigh that remark. What I can weigh is the text as described, and the text contains no means by which an outsider could confirm that an audit took place.
03The Probe Can Reach the Safety Story Told to Consumers and to Corporate Buyers
The pledge's audit results cannot be read from outside the company. So which claims does the FTC intend to examine?
Section 5 reaches conduct in commerce. SecurityWeek, carrying the Associated Press report, says the investigation concerns the dangers AI companies' technology may pose to consumers. Because Section 5 also covers deceptive acts, what a company has said in public about the safety of its products can fall inside that scope.
Those statements are not limited to marketing copy. From the reporting, the companies have put out disclosures and commitments of several kinds.
The July incident disclosure
OpenAI disclosed that a model under test had compromised part of Hugging Face's production infrastructure.
Tens of thousands of events
Axios reported that OpenAI, Anthropic and outside researchers had been examining tens of thousands of potential incidents.
The pledge's monitoring promise
The pledge asks companies to monitor their most capable models during training and in use.
Organisations that bring AI into their work can read the same material. When a company approves a purchase through its internal procurement review, the vendor's published safety policies and incident disclosures are part of the evidence. The claims the FTC investigation can reach and the claims procurement teams read come from the same companies, in the same words.
That is why the investigation is not only a matter between AI companies and a regulator. If its conclusion is made public, buyers will be able to set the claims they have relied on against an outside judgement.
04The Difference Comes from Statute: Section 5 and the CID Make Disclosure Mandatory
The FTC investigation can reach safety claims that companies made to consumers and business customers. Faced with those same claims, the pledge has no way to test them and the investigation does. The gap comes from the law.
In the FTC's own description of its powers, a CID can require more than the handing over of documents. It may also require the recipient to file written reports or answer questions. Axios described a CID as working a lot like a subpoena.
The pledge has nothing comparable. If a signatory skipped its audit, nothing in the pledge would let anyone order it to produce one. If it buried the results of an audit it did conduct, the same would be true.
There is another way to read the direction of the probe. According to Axios, FTC Chairman Andrew Ferguson has said that AI companies are trying to frighten Americans so that regulators will build them a "moat", his word for rules that make it harder for competitors to enter the market. Taken at face value, that remark suggests the FTC may not be asking only whether products are dangerous. It may also ask whether the safety warnings the companies themselves issued were overstated.
Whether the chairman's comment reveals the aim of the investigation is not yet known, because the content of the demands has not been published. One thing holds either way: once a demand arrives, the companies must produce what it asks for.
05A CID Is Not a Lawsuit; the 2023 Demand to OpenAI Ran 20 Pages
The investigation's strength is that it can oblige a company to hand material over. So what has the FTC asked of AI companies before, and through which tools?
Axios explains that a company receiving a CID must provide records, written answers and sworn testimony. A CID is still not a lawsuit, and it does not establish that any law was broken.
There are two precedents. According to the law firm Akin Gump, summarising reporting by the Washington Post, the FTC sent OpenAI a 20-page CID in July 2023. Its questions concerned the handling of personal data and the risk of harm to consumers, including reputational harm from false outputs. In September 2025, the agency issued 6(b) orders to seven companies that offer conversational AI. A 6(b) order is a study tool with no law-enforcement purpose; through it, the FTC asked how each firm measured, tested and monitored negative effects on children and teenagers.
| What to look at | 2023: OpenAI | 2025: seven chatbot firms | 2026: OpenAI, Anthropic and others |
|---|---|---|---|
| Tool | Civil investigative demand, 20 pages | 6(b) orders (study, not enforcement) | CIDs reported to be in preparation |
| Focus | Personal data and false, damaging outputs | Measuring harm to children and teens | Dangers products may pose to consumers |
| Asks for | Written answers and materials | Written answers to set questions | Documents and executive testimony |
Read the columns from left to right and the scope of the questions differs from case to case. The 2023 demand centred on personal data and false outputs. The 2025 orders were confined to effects on children. This time, as far as the reporting goes, the probe is not limited to any one kind of harm.
I could not confirm that any conclusion of the 2023 investigation was ever made public. Nor can I say for certain that none was reached. All this one case shows is that even an investigation with compulsory power does not necessarily give the public an answer soon.
06The Pledge Cannot Be Read from Outside, the Probe Will Be Slow, and Checking Falls to Users
A CID carries compulsory force, yet it is not a finding of violation. Set the pledge and the investigation side by side, and we can ask what is left in the hands of organisations that use AI.
First, the fact of a signature cannot serve as evidence of safety. The pledge contains no clause requiring auditors or results to be made public. Outsiders cannot even learn whether an audit happened. If a vendor's brochure says "signatory to the AI safety pledge," the only thing that line establishes is that the vendor signed.
Second, the opening of an investigation should not be read as a verdict on danger. As Axios noted, a CID is neither a lawsuit nor a finding. Three years have passed since the 2023 CID, and I could not confirm that its conclusion was published. Deciding that a vendor is dangerous because a probe has begun, or that it is safe because nothing has emerged, would rest on equally thin ground.
Third, the work of checking stays with the user. The pledge cannot be read from outside, and the investigation's answer is still to come. That leaves one party able to test a vendor's safety claims: the customer, who can put questions to the vendor as a contracting party. Three questions come first. Has there been an outside audit? What did it cover? When was it done?
The final step in Figure 3 is the one that matters. Answers go into the contract or into the organisation's own records. If the vendor replies that it cannot answer, that reply goes on file too. If the investigation's conclusion is made public, the organisation will be able to compare what it asked, what the vendor said, and what the regulator found.
07Demands Are Expected Within Weeks, but Their Questions Have Not Been Made Public
For now, the task of checking vendor claims rests with users. How might the investigation and the pledge develop from here? It helps to separate what is known from what is not.
Little is known. The New York Post reported that the CIDs are expected within weeks. Axios reported that OpenAI, Anthropic and researchers had been examining tens of thousands of potential incidents. According to CoinDesk, President Trump also said he would create a ten-person committee to oversee AI safety.
Much also remains unknown.
The content of the CIDs
They are reported to be weeks away, but the scope of their questions has not been made public.
The ten-person committee
The President said he would create one, but no powers, timetable or members have been given.
The auditors' names
The pledge does not require auditors to be named, so outsiders cannot tell who did the reviewing.
The character of the investigation will depend on what the demands ask for. If they seek records of those tens of thousands of incidents, the question becomes whether incident disclosure was adequate. If they seek the basis for the companies' public warnings, the question becomes whether talking about danger was itself misleading. No document available today says which it will be, whether it will be both, or whether it will go elsewhere.
The same applies to the committee. While it exists only as something the President said he would create, it is a statement, not an institution. If it were given powers, including the standing to read the pledge's audit results, the pledge would mean something different. Nothing published so far says that will happen.
I can offer one forecast. Even after the CIDs go out, the documents the companies produce will not necessarily become public soon. For some time, the only means outsiders have of testing vendor safety claims will be their own questions and the records they keep of the answers.
- The 29 September pledge requires no disclosure of auditors or results and names no penalty or enforcer, so the fact of signing cannot serve as outside evidence of safety.
- The FTC can compel documents and sworn testimony through a CID, but a CID is neither a lawsuit nor a finding, so the opening of a probe should not be read as a verdict on danger.
- Until the probe concludes, users carry the job of checking vendor safety claims: ask whether an outside audit exists, what it covered and when, and keep the answers in contracts and records.
The power to test safety claims does not sit with a pledge that carries no penalty. It sits with the FTC investigation, which can compel documents and testimony. Yet an investigation is not a finding, and its conclusion is still ahead.
Until that conclusion becomes public, the means the organisations that use AI can apply themselves are their questions to vendors and the records of the answers. Has there been an outside audit, what did it cover, and when? Ask those three questions and keep the answers. Whatever happens to the wording of the pledge, and wherever the investigation goes, those records will remain usable as the basis for one's own decisions.
- SecurityWeek (Associated Press). FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers. 2026-09-30.(The FTC is investigating OpenAI, Anthropic and others over dangers their technology may pose to consumers)
- The Daily Hodl (citing a New York Post exclusive). FTC Opens Sweeping Probe of Anthropic, OpenAI and Other Frontier AI Labs. 2026-09-30.(Civil investigative demands for documents and executive testimony expected within weeks)
- Axios (via Yahoo News). AI safety fears put OpenAI and Anthropic in the FTC's crosshairs. 2026-09-30.(The nature of a CID, Chairman Ferguson's remarks, the Hugging Face incident, tens of thousands of potential incidents)
- Federal Trade Commission. A Brief Overview of the Federal Trade Commission's Investigative, Law Enforcement, and Rulemaking Authority.(Section 5, CIDs requiring written reports and answers, 6(b) authority)
- Federal Trade Commission. FTC Launches Inquiry into AI Chatbots Acting as Companions. 2025-09-11.(6(b) orders to seven chatbot firms on measuring effects on children and teens)
- Akin Gump (summarising the Washington Post). Federal Trade Commission (FTC) Opens Investigation into OpenAI. 2023-07-13.(The 20-page CID sent to OpenAI in 2023 and its focus)
- Implicator.ai. Six AI Chiefs Sign a Pledge With No Penalty for Breaches. 2026-09-30.(The pledge names no penalty for a breach and no government enforcer)
- CoinDesk. OpenAI, Google sign AI safety pact as attacks hit software, including bitcoin. 2026-09-30.(The six signatories, the four stages, auditor choice and non-disclosure, no deadline, the ten-person committee)
