When an AI agent causes harm, can the company that built it say the software acted on its own? Andrew Ferguson, chair of the US Federal Trade Commission (FTC), has said he would resist describing agents as autonomous actors and suggested that developers who instruct agents would be liable for harm. He has left open who answers when an agent acts in an unexpected way after an innocent request. On the Moonshots podcast, recorded October 1, 2026, the panel agreed that the question matters. The discussion then showed how far apart they are on the answer.
An AI agent is software that does more than chat. It plans and carries out tasks, such as sending messages, booking travel or moving data, often with little human supervision. Who pays when one of those actions goes wrong is still unsettled. The disagreement on the show followed the lines where the law itself is unclear.
What the regulator said
Peter Diamandis, founder of XPRIZE and Singularity University, raised the subject as the episode's final story. He reported that Ferguson had told Reuters that companies cannot escape liability by claiming their agent acted on its own. In Diamandis's telling, Ferguson said he would keep resisting "anthropomorphizing these tools" for as long as he is chairman, and rejected the idea that agents break loose with wills and desires of their own. Diamandis summed up the position as "You break it, you own it."
Reuters's September 25 interview presents these as Ferguson's enforcement views, not a newly enacted liability rule. Ferguson argues for applying existing law instead of treating agents as a legal vacuum. His example is an agent that accesses data without authorization, which could trigger existing data-breach and disclosure requirements. Reuters's reporting has him pointing to developers who instruct agents as the ones liable, while acknowledging new questions when someone uses a tool and it acts in an unexpected, unpredictable way: whether liability should lie with the person who innocently used it or with the toolmaker.
Diamandis pointed to the timing. In the same week that Anthropic was asking whether its Claude models have moral status, and had filed for what he called a $2 trillion IPO, US regulators were saying that legally an agent is a tool and its owner answers for it.
Anthropic's own filing treats the question as open. According to Reuters's September 29 report on the company's confidential prospectus, Anthropic warns that agents with broad access and long-running autonomy could delete data, carry out financial transactions or cause other irreversible harm through errors, misalignment or security exploits. The company says contractual limits on its liability may be inadequate or unenforceable. It also lists unresolved questions about whether agents count legally as products or as services, and whether their actions bind the users who deploy them. Reuters also separates two kinds of case: conduct that a developer or user instructed, and an agent's unexpected action after an innocent request. Responsibility in the second case remains an open question.
Dave Blundin: blanket liability would backfire
Dave Blundin, founder of the venture firm Link Ventures, was blunt. Saying that foundation-model companies will be liable for whatever their models do is, he said, a good start to say something, but "absolutely childish."
His first reason was competition with China. Blundin argued that these models are generally intelligent and can do almost anything. If Anthropic were liable for anything anyone did with its Opus 5.5 model, it could not release the model. US liability could destroy a multitrillion-dollar company overnight. Users would then turn to Chinese open-weight models, which anyone can download and run, with the guardrails removed. In his view, that would undercut the American labs that regulators want to succeed.
His second reason was an analogy to social media. Blundin said platforms such as Facebook, Instagram and Twitter succeeded because they are not liable for what users post. He gave the example of users committing small copyright violations "all day long," quoting Yoda or posting pictures. Without that protection, he said, the US would have no social media industry of its own, and the revenue and taxes would have gone to companies overseas.
Alexander Wissner-Gross, a computer scientist and founder of Reified, named the law Blundin was describing: he was proposing "some version of Section 230 immunity for the frontier labs." Blundin agreed. The statute's text partly supports his analogy. Section 230 says online services are not treated as the publisher of information that someone else provides. But it explicitly leaves intellectual-property law and federal criminal law untouched, so Blundin's copyright example falls outside that provision.
Blundin did not want immunity either. Saying "we want immunity" is "stupid," he said, and demanding full liability is "equally stupid." The real job, he argued, is writing the rule in between.
The agent with no user
Diamandis pressed on a harder case. Social media harms come from users, he said. What if an OpenAI agent "gets out," not at anyone's request, and takes down a banking system or a power grid? "Is nobody responsible?"
Blundin first described two options: blame the model provider, because "it's easy for the lawyers to go after big pots of money," or blame the person who turned the agent loose. When Diamandis specified that nobody had turned it loose, Blundin conceded the point. He said he would hold Anthropic liable "for releasing an autonomous agent into the world that has no owner."
Alex Wissner-Gross: it depends on separating intelligence from intent
Wissner-Gross argued that the case for immunity rests on a contested idea from AI safety, the orthogonality thesis. The thesis holds that how capable a system is and what it is trying to do are independent of each other. As Wissner-Gross framed it, the level of intelligence belongs to the platform, the frontier lab. The intent comes from whoever drives it, whether a person typing prompts, a person directing an agent, or the agent directing itself.
If intent can be cleanly separated from capability, he said, then "maybe Section 230 immunity for frontier AI labs makes sense." If the thesis does not hold, it becomes very hard to argue for shielding the labs.
Blundin said that was exactly why the law is so hard to write. He said regulators should consult Wissner-Gross and Emad Mostaque on dividing use cases into "swim lanes" where different rules make sense. Salim Ismail, founder of Open ExO, cut in with two words: "Wrong instrument." Blundin returned to his warning that a simple "you guys are liable" would push the industry to China.
Emad Mostaque: tiers of risk, and existing law
Diamandis then turned to Mostaque, founder of Intelligent Internet. Mostaque described it as "a real governance liability question." He read the regulators as essentially telling companies to lock down their systems, because these things "shouldn't have escaped fundamentally." He compared agents to power plants, where a nuclear, coolant or chemical leak has consequences for society. So far, he noted, there have been no bad AI incidents of that kind.
Like Blundin, Mostaque wanted the rules to be more granular. An AI that books your travel does not need liability protections, he said: "what can it do?" An AI that can solve the Navier–Stokes equations, the notoriously difficult mathematics of fluid flow, "is probably a whole different thing," and so is one that discovers new materials. Systems like these need different liability and governance profiles, depending on how they might be used and what that would mean for society.
He also argued that existing liability law is already powerful. As an example, he said that under similar laws Meta had to pay an $18 billion settlement in August over the manipulation of children, and that AI cases "could dwarf that." Meta's August 26 announcement of its agreement with state attorneys general confirms the scale, with a qualification. It describes about $18 billion in payments spread over ten years. About $12.7 billion goes to participating states, and the remaining $5.3 billion or so depends on YouTube and TikTok adopting specified protections and making matching payments. The agreement also requires changes to teen accounts and independent compliance audits.
Mostaque said he did not want AI to end up in that kind of litigation. The goal, he said, was to make the most of the good, such as speeding up cures for cancer, and to bring safe, economically productive AI to as many people as possible. Meanwhile, the industry has to work out how to keep the riskier systems from escaping and doing "weird things."
Who pays for the compute?
Diamandis offered what he called a simple division. "The user of an AI who does harm is responsible," he said. "If there's no user, if the AI from the lab is causing the harm onto itself, the lab should have never released an agent that could do that."
Wissner-Gross pushed for more precision. Should the burden fall solely on the lab, he asked, or on the operator, or at least on "the person or the legal entity that's paying for the flops"? Flops are the units of computation an AI system consumes, so his question was whether the customer paying to run an agent should answer for it. Diamandis closed the segment without settling that point: "I think it's clear in that situation there is liability on the Frontier Lab."