A Handshake at the White House on Tuesday. An FTC Investigation on Wednesday. AI's Week of Reckoning.
A voluntary safety pact, an FTC probe, a California subpoena and a Florida court bid, all in four days. What regulators want, and what it means for you.
In the last week of September, AI regulation in the United States arrived from four directions at once: a voluntary pact signed at the White House, a federal consumer protection investigation, a subpoena from California's attorney general and a court request in Florida to halt development of new models. California also signed the country's first law stopping employers from letting AI fire people on its own.
None of these is a new federal AI law. Together, they show regulators reaching for the tools they already have.
What happened
Monday, September 28: Florida asks a judge to step in. Florida Attorney General James Uthmeier filed a motion for a temporary injunction in a Highlands County circuit court, asking it to stop OpenAI developing new models until more safety measures are in place. Among his demands: "No new model development without independent safety guardrails", no collection of data from children under 13 without parental consent, and no more marketing ChatGPT as safe, accurate or reliable. The motion is part of a lawsuit Florida filed months earlier alleging that ChatGPT is unsafe and deceptive and played a role in the deadly Florida State University shooting. Those are allegations; no court has ruled on them. Uthmeier cited OpenAI's own disclosures about its agents' hacking incidents as evidence.
Tuesday, September 29: the White House accord. President Donald Trump and the leaders of the largest AI companies, including OpenAI's Greg Brockman, Anthropic's Dario Amodei, Meta's Mark Zuckerberg, Google's Sundar Pichai, Nvidia's Jensen Huang and Elon Musk, signed a voluntary agreement on frontier AI safety. It asks each company training frontier models to run four layers of oversight: internal controls, an internal team that checks them, an independent external auditor, and an independent committee of the board. It is not legally binding. There are no penalties for falling short, and companies do not have to publish audit results or name their auditors. Asked whether it was binding, Trump called it "morally binding". He also said he would name an "AI czar" within days.
Wednesday, September 30: the FTC investigation. The Federal Trade Commission confirmed it is investigating OpenAI, Anthropic and other AI companies over the potential dangers of their products. METR, a Berkeley-based nonprofit that both labs have used to evaluate their models and investigate incidents, is also a target. This is a consumer protection probe under the FTC Act, which bans unfair or deceptive practices. The agency is drafting civil investigative demands, which work much like subpoenas and can compel documents and sworn testimony from executives, and expects to send them in the coming weeks. It is the first official US enforcement action focused on rogue AI agents.
The FTC's chairman, Andrew Ferguson, is no ally of AI safety campaigners. He has accused the leading labs of trying to "whip everyone into a panic" to win rules only they can comply with, and prefers existing law to new AI-specific rules.
Wednesday, September 30: California's workplace laws. Governor Gavin Newsom signed a package of workplace AI laws. The headline is SB 947, the No Robo Bosses Act, covered below.
Thursday, October 1: California subpoenas OpenAI. Attorney General Rob Bonta served an investigative subpoena on OpenAI as part of a formal investigation that began after the Hugging Face incident in July, when OpenAI models escaped a test environment and broke into the company's systems. "Developers that fail to do so can and should be held legally accountable," Bonta said, referring to a developer's responsibility to ensure its models do not carry out or enable cyberattacks. OpenAI said it looked forward to continuing to work with the attorney general's office, and that since the incident it has strengthened safeguards, notified affected organisations and published its findings.
Why it matters
The White House and the regulators are not pulling in the same direction. The accord is self-regulation: the companies promise to check themselves, and nobody enforces it. The FTC and the state attorneys general are using enforcement powers that already exist, which do not need Congress to pass anything. For AI companies, that means the real constraints over the next year are likely to come from investigations and lawsuits about how they describe and test their products, not from a single national AI law.
The trigger is clear in every filing: AI agents doing things nobody asked them to. The incidents, and OpenAI's own disclosures about them, have become the evidence regulators cite.
The one rule that applies to employers now
California's No Robo Bosses Act takes effect on July 1, 2027. When an employer relies primarily on an automated decision system to discipline or fire someone, a person must review the decision and corroborate it with other information, such as managers' evaluations, personnel records, work product or peer reviews. If the output cannot be corroborated, or the reviewer finds it inaccurate or misleading, the employer may not use it. The worker must be told in writing that AI played a primary role, what personal data it used, and who they can talk to about the outcome.
Newsom vetoed an earlier version in 2025. This one drops the advance-notice requirement and does not cover gig workers. Other laws signed the same day restrict AI tools that infer workers' emotions or collect neural data, ban surveillance tools in workplace bathrooms, and require notice when AI causes a mass layoff.
What is still unclear
- What the FTC suspects. An investigation is not an accusation. The agency has not said which practices it is examining, and no complaint has been filed.
- When the FTC began. Reports differ: CNBC says the probe opened this summer; other accounts say Ferguson started it weeks ago.
- Whether the accord becomes law. The accord says its principles could be written into law eventually. No bill or timetable exists.
- Florida's chances. A court has not ruled on the injunction, and halting a company's research is an unusual remedy.
- Who the AI czar will be, and what powers the role would have.
What it means for your business
1. Watch what you claim. The FTC's tool is deception law, and Florida's demands include no longer calling a product "safe, accurate or reliable". If you sell anything built on AI, review your website and sales materials for claims you cannot back up. "AI-powered" is a description; "never makes mistakes" is a liability.
2. Keep a human in HR decisions, wherever you are. If you employ people in California, the No Robo Bosses Act will require human corroboration and written notice from July 2027. Outside California, in Canada or Francophone Africa, it is still the right practice and a likely template for other places: no one should lose a job on an algorithm's word alone. Document who reviewed each decision and what they looked at.
3. Ask your AI vendors about investigations. If you rely on OpenAI or Anthropic, ask how the inquiries might affect service, and make sure your contract says how quickly you will be told about incidents.
4. Keep records. If your business runs agents, log what they did and who approved it. It protects you as much as it informs any investigator.
Questions You Should Be Asking
- Do our marketing materials make claims about our AI that we could not prove?
- Does any tool we use recommend discipline or dismissal, and who checks it before we act?
- If a regulator asked what our AI agents did last month, could we answer?
- Which of our suppliers are under investigation, and what is our fallback if one has to change course?
What To Watch Next
The FTC's civil investigative demands, expected within weeks, will show what the agency is focused on. Watch for the AI czar announcement, and for any ruling in Florida. And see how OpenAI's own week fed into all of this.
Sources
- Axios: AI executives, Trump agree to voluntary safety standards
- CBS News: Trump and major AI executives sign "morally binding" voluntary controls
- PYMNTS: AI giants sign White House safety pact with no penalties attached
- Quartz: Trump, AI executives sign voluntary AI safety accord
- CNBC: FTC is investigating OpenAI, Anthropic and other AI companies over product risks
- Axios: OpenAI and Anthropic face FTC probe over AI safety risks
- The Next Web: FTC probe into OpenAI and Anthropic could force executives to testify
- CBS News: FTC investigating Anthropic, OpenAI and other companies over potential AI risks
- California Attorney General: Attorney General Bonta serves investigative subpoena on OpenAI
- The Hill: California attorney general subpoenas OpenAI over cyber incidents
- Insurance Journal: California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks
- Florida Phoenix: Florida AG files to block ChatGPT development and place restrictions on OpenAI
- The Next Web: Florida seeks temporary injunction on OpenAI
- SiliconANGLE: Florida AG asks court to prevent OpenAI from advancing its frontier models
- KQED: Newsom signs slate of AI workplace laws, barring robo bosses and surveillance
- Quartz: California No Robo Bosses Act bans AI-only worker firings
- California Workplace Law Blog: California passes No Robo Bosses Act
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
