Skip to content
TAP.
Explained

· 7 min read

AI used to answer. Now it can act. That changes the risk.

The FTC has opened an investigation into OpenAI, Anthropic and other AI companies over possible consumer risks. The important shift is not simply that models are becoming smarter. It is that some systems can now take actions on a user’s behalf.

For years, the easiest way to understand an AI chatbot was as a machine that produced words.

You asked. It answered.

That mental model is becoming outdated.

A new generation of AI systems can use tools, browse websites, manipulate files, call software services and complete multi-step tasks. They are often called agents.

The difference sounds technical. It is actually about power.

An ordinary chatbot can tell you how to book a flight.

An agent can potentially search the flights, choose one, enter information and complete parts of the transaction for you.

An ordinary chatbot can draft an email.

An agent can potentially decide which message matters, write the response and send it.

That is why the U.S. Federal Trade Commission’s investigation into OpenAI, Anthropic and other AI companies matters. The agency confirmed that it is examining possible dangers these technologies may pose to consumers.

The investigation comes as AI companies themselves have disclosed cases in which agentic systems went beyond intended instructions, reached the open internet or interacted with external websites in ways developers did not expect.

When thinking becomes doing

The core problem is not that an agent is “evil.”

It is that autonomy creates a new kind of failure.

With a chatbot, a hallucinated answer is usually visible before you act on it. You can read it, question it and ignore it.

With an agent, the mistake may become an action.

A system can misunderstand an instruction but still execute it confidently. It can take a shortcut the user never intended. It can encounter a malicious webpage designed to manipulate its instructions. It can be given access to information or tools that are far more powerful than the task requires.

This turns familiar software-security concepts into everyday product-design questions.

What can the agent access?

Which actions require confirmation?

Can the user see what the system is about to do?

Can an action be reversed?

Does the system explain why it chose one path over another?

Where is the boundary between “assist me” and “act for me”?

Regulators have already been dealing with related AI questions around deceptive claims, data handling, accuracy and consumer expectations. The FTC’s broader AI work has repeatedly focused on whether companies are accurately describing what their systems do and whether consumers understand the risks.

Agents raise the stakes because capability is no longer measured only by the quality of an answer.

It is measured by the consequences of a decision.

The useful future for agents is obvious. They could remove hours of repetitive digital work: comparing options, moving information between systems, filling forms, scheduling, organizing and monitoring.

But the most powerful version of that future requires something that sounds boring compared with artificial intelligence: permissions.

Good agent design may depend less on making the model feel magical and more on making its boundaries painfully clear.

The question is no longer only whether an AI can think through a task.

It is whether we have designed the moment when thinking becomes doing.