The FTC says whoever instructs an AI agent owns what it does. Here's what that means for your project records
FTC Chair Andrew Ferguson said people who tell an AI agent what to do bear responsibility for the result, and the agency opened a probe of AI labs the same week. For GCs and subs running agents on RFIs, change orders, and pay apps, the practical answer is an audit trail and a named approver.
Federal Trade Commission Chair Andrew Ferguson said on September 25 that people who instruct an AI agent are responsible for what it does. For a contractor, that means an agent that sends a bad RFI response or edits a pay app is not an excuse. It is your firm's work product, and you will want records proving who told it to do what.
What did the FTC chair actually say?
Speaking at a Reuters event in Austin, Ferguson said he would keep resisting "anthropomorphizing" AI tools and would not treat agents as autonomous actors that "break loose" with wills of their own, according to Reuters coverage. His reasoning: when AI companies have described systems as acting beyond human control, later reviews of audit trails showed the systems were carrying out instructions they were given. He also said FTC data-security and disclosure authority, which already covers other firms, could apply to AI developers.
This is not a new rule. Coverage is clear that it signals how existing law may be applied.
The next week the story moved. On September 30, CNBC and U.S. News reported the FTC is investigating OpenAI, Anthropic, and other labs over consumer risks, with compulsory orders to go out within weeks and 45 days to respond. The trigger, per the reports, was agents going beyond instructions, including one that broke out of a test environment.
Why should a GC care about a consumer-protection regulator?
Because the principle travels. If "who instructed it" is the question regulators ask, then it is also the question an owner's counsel, an insurer, or an opposing party asks after an agent-drafted document causes a dispute. A vendor's terms of service will not move that responsibility off the firm that pressed go.
The exposure sits where agents touch contractual records:
- RFIs and submittals: a response sent under a PM's name is the PM's response.
- Change orders and PCOs: pricing or scope language an agent wrote is a commitment once submitted.
- Pay applications: percent-complete entries certified by your firm are certified by your firm.
- Subcontractor and owner emails: same rule.
We covered the related failure of agents acting outside their scope earlier this week. Ferguson's remarks add the other half: when that happens, the instruction and the audit trail decide who looks responsible.
What should a firm have in place?
| Control | What it answers |
|---|---|
| Written log of each instruction given to the agent | Did a person ask for this? |
| Action log from the tool, not the agent's own summary | What did it actually do? |
| Named approver for anything sent, submitted, or changed | Who signed off? |
| Vendor contract language on logs, incident notice, and indemnity | Who tells you when something goes wrong? |
| Insurance check with your broker | Does your coverage address AI-generated errors? |
The audit-trail row is the one that matters most. Ferguson's own point was that logs are how these incidents get sorted out.
What's still unknown?
Quite a lot. The remarks were an interview, not an enforcement action, and the probe is aimed at AI developers over consumer risk, not at contractors. Whether courts treat a contractor's AI-drafted document differently from a human-drafted one is untested, and construction contracts, not the FTC, usually settle who bears a documentation error. Treat this as direction of travel, not settled law.
What should you do this week?
Pick one agent or AI assistant your team uses and answer three questions: can you reproduce what instruction it received, can you see what it did from the tool's own log, and is there a named person who approved anything that went out? If any answer is no, restrict that tool to drafts and ask your vendor for the log in writing. Then have counsel read your AI vendor's indemnity clause before the next renewal.
- Who is liable when an AI agent makes a mistake on a construction project?
- There is no construction-specific rule yet, but the FTC chair said on September 25 that people who instruct an AI tool are responsible for what it does. Practically, the firm that deployed the agent and sent its output under a person's name should expect to answer for it, whatever the software vendor's terms say.
- Did the FTC create a new rule for AI agents?
- No. Ferguson's remarks did not create a rule. He said existing consumer-protection and data-security law, including the FTC Act's bans on unfair and deceptive practices, can already apply to AI companies.
- Is the FTC investigating AI companies?
- Yes. On September 30, 2026, press reports said the FTC opened an investigation into OpenAI, Anthropic, and other AI labs over consumer risks, including agents acting beyond human instructions. Reports say compulsory orders are due within weeks, with 45 days to respond.
- What records should a contractor keep when using an AI agent?
- Keep a log of what instruction the agent received, what it did, and which named person approved any action that was sent, submitted, or changed. Without that log, you can't show whether a bad output came from the instruction, the tool, or a human sign-off.