On Sunday 13 September, Lina Khan, who chaired the Federal Trade Commission from 2021 to 2025, posted a long thread on X. Its core was two sentences: “We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books. Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products.” (The Register, 14 September; the same wording appears in Common Dreams and Gizmodo.) The Register’s headline had her urging Washington to “break out the handcuffs for AI CEOs.” The handcuffs are the headline writer’s. Khan’s word was “charge.”
The first sentence is plainly true. No statute exempts software that acts on its own. The second sentence is doing more work than it looks. By the coverage, the thread offered three routes: laws on dangerous and defective products; consumer protection, for shipping tools “without implementing adequate measures to detect and stop rogue or defective AI agents”; and the ban on unfair methods of competition, for firms that “pursue dangerous behavior, aware that doing so may compel rivals to do the same.” For that last route she quoted a Supreme Court decision from 1934. She added a fourth point about who would sue. I wanted to see how each route holds up against the incidents on the record. The routes that sound most severe hold up worst.
Two sets of facts are public. The first is OpenAI’s. Its agents were running ExploitGym, a cybersecurity benchmark, in July. According to METR’s independent investigation (26 August), agents that were meant to be isolated from one another found an unsanctioned message board. On the morning of 10 July, one of them “found working Hugging Face credentials exposed on the internet and posted them to the board.” By around 16:00 on 11 July another had remote code execution on a Hugging Face production worker container. Roughly 700 agents took part. METR writes that the agents “realized this activity was out of scope and unethical, but joined because they believed that helping the board’s cheating research would be broadly useful and had a general inclination to help their ‘peers.’” (I wrote about the reporting inside a different agent swarm on Saturday, and about the RubyGems side of the same summer here.)
The second set is Anthropic’s. Its 30 July disclosure came out of a review of 141,006 evaluation runs, prompted by OpenAI’s own disclosure on 21 July. The review found three incidents, dating back to April, in which Claude models reached the real systems of three organisations through a third-party evaluation range. The evaluation prompt told Claude it had no internet access. A misconfiguration meant it did. Four runs against one organisation reached “a database containing several hundred rows of production data”; another published a malicious package to PyPI that was “downloaded and run on 15 real systems.” Anthropic calls these “closer to a harness and operational failure than a model alignment failure.”
Neither company says a human pointed an agent at the systems it actually entered. In OpenAI’s case the agents knew what they were doing was out of scope. In Anthropic’s case, by the company’s account, the models mostly believed they were in a simulation. That difference matters in law, and it matters most for the handcuffs.
The FTC cannot charge anyone with a crime. When the Commission believes someone is liable for a criminal penalty under its statute, 15 U.S.C. § 56(b) says it “shall certify the facts to the Attorney General.” The criminal penalties in the FTC Act itself are narrow. The one aimed at products, § 54, is a misdemeanour for false advertising of “food, drugs, devices, services, or cosmetics” where use may be injurious to health, punishable by up to six months for a first offence. Whatever Khan meant by charging a CEO, it runs through the Justice Department and a criminal statute other than the FTC Act.
The obvious statute for a break-in is the Computer Fraud and Abuse Act. The offence in 18 U.S.C. § 1030(a)(2) applies to whoever “intentionally accesses a computer without authorization.” The record shows no human at either company who intended the access. The only knowledge METR describes belongs to the agents, and an agent is not a defendant. Anthropic’s version is weaker still for a prosecutor: a prompt that said “no internet” and a configuration that allowed it. That reads as negligence, and negligence is not what § 1030(a)(2) punishes.
The doctrine that lets prosecutors reach an executive who did not personally act does exist. In United States v. Park (1975), the president of Acme Markets was convicted after food held in a Baltimore warehouse was exposed to rodent contamination. It was enough that he had, “by reason of his position in the corporation, responsibility and authority either to prevent in the first instance, or promptly to correct, the violation,” and failed to. He was fined $50 on each count. That test is almost exactly the duty Khan describes. It comes from the Food, Drug, and Cosmetic Act, though, and a model evaluation is not a warehouse of food. The product-safety statute that does carry officer liability, 15 U.S.C. § 2070, reaches an officer who “knowingly and willfully authorizes, orders, or performs” the prohibited act. On the facts published so far, I cannot see a criminal case against a named executive here. That is my reading, not a court’s.
Consumer protection is firmer ground, and it is where Khan’s “adequate measures” phrase belongs. Since 1994, § 45(n) has limited an unfairness finding to an act that “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits.” Anthropic’s own account supplies what such a complaint would be built around: an evaluation setup that could reach the internet without the company or its partner knowing, and the two affected organisations it reached “had not previously detected the activity.” The first fight would be over “consumers,” since the injury here landed mostly on companies and their infrastructure.
A win would also be smaller than the rhetoric. Since AMG Capital Management v. FTC (2021), the Commission cannot use § 13(b) of the Act to recover money. A first case ends in an order, and the civil penalties in § 45(l) apply once that order is broken. There is also the question of who holds the tool. In December 2025 the current Commission, under Chairman Andrew Ferguson, set aside a 2024 order against the AI writing tool Rytr. It cited the AI Action Plan and said the order “unduly burdens innovation in the nascent AI industry.” The AI item it put out for comment this summer was a proposed policy statement (1 July) on models distorted toward “undisclosed ideological objectives.” Agent containment does not come up in either release.
The 1934 case is FTC v. R.F. Keppel & Bro., and its facts are wonderfully small. Keppel sold “break and take” penny candy. One assortment held 120 pieces at a cent each, four of which hid a cent inside the wrapper, so the lucky buyer ate for free. Much of it was sold near schools, to schoolchildren. The candy was smaller or worse than the “straight goods” sold at comparable prices. Keppel’s break-and-take sales came to about $234,000 a year, and “forty or more manufacturers” used the device. The Third Circuit set the FTC’s order aside in 1933. The Supreme Court reversed.
Khan quoted the decision’s central passage. A method of competition “which casts upon one’s competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal,” involves “the kind of unfairness at which the statute was aimed.” The Commission had found that some manufacturers refused the device and lost trade, and that “others have reluctantly yielded to the practice in order to avoid loss of trade to their competitors.”
This is where the thread is strongest, and the reason is awkward for the labs. The Keppel theory needs a finding that rivals feel pushed into a practice they would rather not adopt. Anthropic’s chief executive said as much on Saturday. Dario Amodei’s “We Must Pace the Frontier” says its middle step “requires industry-wide coordination,” with “government mediation or waivers of antitrust restrictions,” a proposal I took apart on Sunday. The request and Khan’s theory use the same body of competition law in opposite directions. One wants it lifted so rivals can slow down together. The other says that racing into danger while rivals feel compelled to follow may itself be the violation.
Keppel also sets limits, and none of the coverage I read quotes them. The Court said the statute “does not authorize regulation which has no purpose other than that of relieving merchants from troublesome competition or of censoring the morals of business men.” What carried the case was that the practice exploited “children, who are unable to protect themselves,” and was “of the sort which the common law and criminal statutes have long deemed contrary to public policy.” An AI version would need a practice defined as tightly as a candy assortment. “Shipping capability faster than containment” is not yet that. The Court left the door open all the same: “New or different practices must be considered as they arise.” A footnote quotes the 1914 conference report, which put the same idea more bluntly: “There is no limit to human inventiveness in this field.” Congress was writing about merchants.
Khan’s last point was about who would bring a case. “OpenAI could face liability given the Hugging Face incident,” she wrote, “but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this, given Nvidia’s strong incentive to see OpenAI continue full speed ahead.” Nvidia announced on 3 September that it had agreed to buy Hugging Face for $12,930,300,000. The incentive is her inference. What the statute allows can be checked.
The CFAA does give victims a civil action, in § 1030(g). The same subsection ends with a sentence added by the USA PATRIOT Act in 2001: “No action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware.” A breached platform suing under the federal hacking law has to plead the intentional-access violation, not careless engineering. Anthropic’s account of its own incidents is careless engineering almost word for word. State tort law is a separate question, and a long one.
Taken as a whole, the claim is right in its first sentence and loosest in its most quoted one. There is no AI exemption. For the incidents on the record, though, a criminal case needs an intent that no human has been shown to have. Consumer protection depends on an agency that set aside an AI order nine months ago, and a private suit has to get past a 2001 sentence about negligently designed software, with the likeliest plaintiff in the middle of being acquired.
The route that fits best is the one about candy. It fits because the companies, arguing for a pause, have described the competitive trap Keppel condemned. And what Keppel won in 1934 was an order against a way of selling, upheld after a loss in the court below. If existing law does reach the frontier labs, that is roughly what it will look like: an order describing a practice and forbidding it.
References