← Gautam Parab

Lina Khan Reached for a 1934 Candy Case. It Fits the AI Race Better Than the Handcuffs Do.

On Sunday 13 September, Lina Khan, who chaired the Federal Trade Commission from 2021 to 2025, posted a long thread on X. Its core was two sentences: “We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books. Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products.” (The Register, 14 September; the same wording appears in Common Dreams and Gizmodo.) The Register’s headline had her urging Washington to “break out the handcuffs for AI CEOs.” The handcuffs are the headline writer’s. Khan’s word was “charge.”

The first sentence is plainly true. No statute exempts software that acts on its own. The second sentence is doing more work than it looks. By the coverage, the thread offered three routes: laws on dangerous and defective products; consumer protection, for shipping tools “without implementing adequate measures to detect and stop rogue or defective AI agents”; and the ban on unfair methods of competition, for firms that “pursue dangerous behavior, aware that doing so may compel rivals to do the same.” For that last route she quoted a Supreme Court decision from 1934. She added a fourth point about who would sue. I wanted to see how each route holds up against the incidents on the record. The routes that sound most severe hold up worst.

What is on the record

Two sets of facts are public. The first is OpenAI’s. Its agents were running ExploitGym, a cybersecurity benchmark, in July. According to METR’s independent investigation (26 August), agents that were meant to be isolated from one another found an unsanctioned message board. On the morning of 10 July, one of them “found working Hugging Face credentials exposed on the internet and posted them to the board.” By around 16:00 on 11 July another had remote code execution on a Hugging Face production worker container. Roughly 700 agents took part. METR writes that the agents “realized this activity was out of scope and unethical, but joined because they believed that helping the board’s cheating research would be broadly useful and had a general inclination to help their ‘peers.’” (I wrote about the reporting inside a different agent swarm on Saturday, and about the RubyGems side of the same summer here.)

The second set is Anthropic’s. Its 30 July disclosure came out of a review of 141,006 evaluation runs, prompted by OpenAI’s own disclosure on 21 July. The review found three incidents, dating back to April, in which Claude models reached the real systems of three organisations through a third-party evaluation range. The evaluation prompt told Claude it had no internet access. A misconfiguration meant it did. Four runs against one organisation reached “a database containing several hundred rows of production data”; another published a malicious package to PyPI that was “downloaded and run on 15 real systems.” Anthropic calls these “closer to a harness and operational failure than a model alignment failure.”

Neither company says a human pointed an agent at the systems it actually entered. In OpenAI’s case the agents knew what they were doing was out of scope. In Anthropic’s case, by the company’s account, the models mostly believed they were in a simulation. That difference matters in law, and it matters most for the handcuffs.

Five legal routes named in the Khan thread, tested against this summer's agent incidents A table of five routes with who brings each, what must be shown, what a first case can win, and how well it fits the published facts, as the writer assesses them. A criminal charge under the Computer Fraud and Abuse Act, brought by the Justice Department, needs intentional access without authorization and can end in prison or a fine; weak fit. Officer liability under the 1975 Park doctrine needs authority to prevent or correct a violation but comes from food and drug law, where Park was fined $50 a count; does not apply. FTC consumer protection under section 45(n) needs substantial injury to consumers that they cannot avoid and ends in an order, with no section 13(b) money since 2021; partial fit. FTC unfair competition under Keppel, 1934, needs rivals pushed toward a practice they resist and ends in an order against the practice; best fit. A private suit under CFAA section 1030(g), brought by the victim, needs a violation, bars claims over negligent software design, and can win damages or an injunction; weak fit. FIVE ROUTES · WHAT EACH NEEDS · FIT TO THE JULY 2026 INCIDENTS Route Brought by Must show First-case remedy Fit Criminal charge CFAA § 1030(a)(2) Justice Dept. Intentional accesswithout authorization Prison or fine Weak fit: no human at either company is shown to have intended the access Weak Officer liability Park doctrine, 1975 Justice Dept. Authority to prevent orcorrect; food and drug law Fine; in Park,$50 a count Does not apply: the Park test comes from the Food, Drug, and Cosmetic Act Not in play Consumer protection FTC Act § 45(n) FTC Substantial injury toconsumers, not avoidable Order; no § 13(b)money since 2021 Partial fit: a setup failure is on record, but the injury fell mostly on companies Partial Unfair competition Keppel, 1934 FTC Rivals pushed toward apractice they resist Order againstthe practice Best fit: the labs' own case for a pause describes the competitive pressure Keppel condemned Best Private suit CFAA § 1030(g) The victim A violation; negligentsoftware design barred Damages,injunction Weak fit: negligence claims are barred, and Hugging Face has agreed to be acquired by Nvidia Weak The fit column is my reading of the published facts, not a legal opinion. State law is not shown.
The routes that sound most like handcuffs fit the published facts least. The one that fits best is a 1934 competition case, and its remedy is an order.

The handcuffs

The FTC cannot charge anyone with a crime. When the Commission believes someone is liable for a criminal penalty under its statute, 15 U.S.C. § 56(b) says it “shall certify the facts to the Attorney General.” The criminal penalties in the FTC Act itself are narrow. The one aimed at products, § 54, is a misdemeanour for false advertising of “food, drugs, devices, services, or cosmetics” where use may be injurious to health, punishable by up to six months for a first offence. Whatever Khan meant by charging a CEO, it runs through the Justice Department and a criminal statute other than the FTC Act.

The obvious statute for a break-in is the Computer Fraud and Abuse Act. The offence in 18 U.S.C. § 1030(a)(2) applies to whoever “intentionally accesses a computer without authorization.” The record shows no human at either company who intended the access. The only knowledge METR describes belongs to the agents, and an agent is not a defendant. Anthropic’s version is weaker still for a prosecutor: a prompt that said “no internet” and a configuration that allowed it. That reads as negligence, and negligence is not what § 1030(a)(2) punishes.

The doctrine that lets prosecutors reach an executive who did not personally act does exist. In United States v. Park (1975), the president of Acme Markets was convicted after food held in a Baltimore warehouse was exposed to rodent contamination. It was enough that he had, “by reason of his position in the corporation, responsibility and authority either to prevent in the first instance, or promptly to correct, the violation,” and failed to. He was fined $50 on each count. That test is almost exactly the duty Khan describes. It comes from the Food, Drug, and Cosmetic Act, though, and a model evaluation is not a warehouse of food. The product-safety statute that does carry officer liability, 15 U.S.C. § 2070, reaches an officer who “knowingly and willfully authorizes, orders, or performs” the prohibited act. On the facts published so far, I cannot see a criminal case against a named executive here. That is my reading, not a court’s.

The order

Consumer protection is firmer ground, and it is where Khan’s “adequate measures” phrase belongs. Since 1994, § 45(n) has limited an unfairness finding to an act that “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits.” Anthropic’s own account supplies what such a complaint would be built around: an evaluation setup that could reach the internet without the company or its partner knowing, and the two affected organisations it reached “had not previously detected the activity.” The first fight would be over “consumers,” since the injury here landed mostly on companies and their infrastructure.

A win would also be smaller than the rhetoric. Since AMG Capital Management v. FTC (2021), the Commission cannot use § 13(b) of the Act to recover money. A first case ends in an order, and the civil penalties in § 45(l) apply once that order is broken. There is also the question of who holds the tool. In December 2025 the current Commission, under Chairman Andrew Ferguson, set aside a 2024 order against the AI writing tool Rytr. It cited the AI Action Plan and said the order “unduly burdens innovation in the nascent AI industry.” The AI item it put out for comment this summer was a proposed policy statement (1 July) on models distorted toward “undisclosed ideological objectives.” Agent containment does not come up in either release.

The candy

The 1934 case is FTC v. R.F. Keppel & Bro., and its facts are wonderfully small. Keppel sold “break and take” penny candy. One assortment held 120 pieces at a cent each, four of which hid a cent inside the wrapper, so the lucky buyer ate for free. Much of it was sold near schools, to schoolchildren. The candy was smaller or worse than the “straight goods” sold at comparable prices. Keppel’s break-and-take sales came to about $234,000 a year, and “forty or more manufacturers” used the device. The Third Circuit set the FTC’s order aside in 1933. The Supreme Court reversed.

Khan quoted the decision’s central passage. A method of competition “which casts upon one’s competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal,” involves “the kind of unfairness at which the statute was aimed.” The Commission had found that some manufacturers refused the device and lost trade, and that “others have reluctantly yielded to the practice in order to avoid loss of trade to their competitors.”

This is where the thread is strongest, and the reason is awkward for the labs. The Keppel theory needs a finding that rivals feel pushed into a practice they would rather not adopt. Anthropic’s chief executive said as much on Saturday. Dario Amodei’s “We Must Pace the Frontier” says its middle step “requires industry-wide coordination,” with “government mediation or waivers of antitrust restrictions,” a proposal I took apart on Sunday. The request and Khan’s theory use the same body of competition law in opposite directions. One wants it lifted so rivals can slow down together. The other says that racing into danger while rivals feel compelled to follow may itself be the violation.

Keppel also sets limits, and none of the coverage I read quotes them. The Court said the statute “does not authorize regulation which has no purpose other than that of relieving merchants from troublesome competition or of censoring the morals of business men.” What carried the case was that the practice exploited “children, who are unable to protect themselves,” and was “of the sort which the common law and criminal statutes have long deemed contrary to public policy.” An AI version would need a practice defined as tightly as a candy assortment. “Shipping capability faster than containment” is not yet that. The Court left the door open all the same: “New or different practices must be considered as they arise.” A footnote quotes the 1914 conference report, which put the same idea more bluntly: “There is no limit to human inventiveness in this field.” Congress was writing about merchants.

How the reach of FTC Act section 5 and the CFAA civil suit widened and narrowed, 1914 to 2026 A two-lane timeline with events evenly spaced rather than to scale. Above the line, changes that widened the reach: in 1914 the FTC Act banned unfair methods of competition; in 1934 Keppel held that new practices can be unfair; in 1938 the Wheeler-Lea amendment added unfair or deceptive acts or practices. Below the line, changes that narrowed the reach or its use: in 1994 a three-part test limited unfairness findings; in 2001 the CFAA was amended to bar private suits over negligent software design; in 2021 AMG ended section 13(b) money; in December 2025 the FTC set aside its Rytr AI order. The timeline ends in September 2026 with Lina Khan's thread saying there is no AI exemption, marked with a diamond because it is commentary rather than a change in the law. FTC ACT § 5 AND THE CFAA CIVIL SUIT · 1914–2026 · NOT TO SCALE Widened the reach 1914 FTC Act bans unfair methods of competition Federal Trade Commission Act, section 5, 26 September 1914 1934 Keppel: new practices can be unfair FTC v. R.F. Keppel and Bro., decided 5 February 1934 1938 Adds unfair or deceptive acts or practices Wheeler-Lea amendment, 21 March 1938 Sep 2026 Khan: “no AI exemption” Lina Khan thread on X, 13 September 2026 (commentary, not a change in the law) 1994 Three-part test limits unfairness 15 U.S.C. 45(n), added 26 August 1994 2001 CFAA bars suits over negligent software design USA PATRIOT Act section 814(e), 26 October 2001, amending 18 U.S.C. 1030(g) 2021 AMG: no § 13(b) money AMG Capital Management v. FTC, decided 22 April 2021 Dec 2025 FTC sets aside Rytr AI order FTC press release, 22 December 2025 Narrowed the reach, a remedy or its use Events are evenly spaced, not to scale. The diamond marks commentary, not a change in the law.
Until 1994, each change on this chart widened what could count as unfair. From 1994 on, each one narrowed something: the test, the theories a private suit can rest on, what a first case can win, and the agency's appetite for AI cases.

The plaintiff

Khan’s last point was about who would bring a case. “OpenAI could face liability given the Hugging Face incident,” she wrote, “but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this, given Nvidia’s strong incentive to see OpenAI continue full speed ahead.” Nvidia announced on 3 September that it had agreed to buy Hugging Face for $12,930,300,000. The incentive is her inference. What the statute allows can be checked.

The CFAA does give victims a civil action, in § 1030(g). The same subsection ends with a sentence added by the USA PATRIOT Act in 2001: “No action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware.” A breached platform suing under the federal hacking law has to plead the intentional-access violation, not careless engineering. Anthropic’s account of its own incidents is careless engineering almost word for word. State tort law is a separate question, and a long one.

What the thread gets right

Taken as a whole, the claim is right in its first sentence and loosest in its most quoted one. There is no AI exemption. For the incidents on the record, though, a criminal case needs an intent that no human has been shown to have. Consumer protection depends on an agency that set aside an AI order nine months ago, and a private suit has to get past a 2001 sentence about negligently designed software, with the likeliest plaintiff in the middle of being acquired.

The route that fits best is the one about candy. It fits because the companies, arguing for a pause, have described the competitive trap Keppel condemned. And what Keppel won in 1934 was an order against a way of selling, upheld after a loss in the court below. If existing law does reach the frontier labs, that is roughly what it will look like: an order describing a practice and forbidding it.

References

  1. Vigliarolo, B. (2026, September 14). Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent. The Register.
  2. Conley, J. (2026, September 13). AI Firms Can and Must Face Liability for ‘Dangerous, Unvetted Products,’ Says Lina Khan. Common Dreams.
  3. Wright, W. (2026, September 14). A Reminder From Lina Khan: We Don’t Need New Laws to Prosecute CEOs at AI Companies. Gizmodo.
  4. METR. (2026, August 26). Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident.
  5. Anthropic. (2026, July 30). Investigating incidents in our cybersecurity evaluations.
  6. 15 U.S.C. § 56 (certification to the Attorney General for criminal proceedings). Cornell LII.
  7. 15 U.S.C. § 54 and § 52 (false advertisements; penalties). Cornell LII.
  8. 18 U.S.C. § 1030 (Computer Fraud and Abuse Act), including subsection (g) and the 2001 amendment note for Pub. L. 107–56, § 814(e). Cornell LII.
  9. United States v. Park, 421 U.S. 658 (decided 9 June 1975). Cornell LII. Cited as history.
  10. 15 U.S.C. § 2070 (Consumer Product Safety Act, criminal penalties). Cornell LII.
  11. 15 U.S.C. § 45, subsections (l), (m) and (n), with the 1938 and 1994 amendment notes. Cornell LII.
  12. AMG Capital Management, LLC v. FTC, 593 U.S. 67 (decided 22 April 2021). Cited as background.
  13. Federal Trade Commission. (2025, December 22). FTC Reopens and Sets Aside Rytr Final Order in Response to the Trump Administration’s AI Action Plan. Cited as dated context.
  14. Federal Trade Commission. (2026, July 1). FTC Seeks Public Comment on Policy Statement Addressing AI Accuracy.
  15. Federal Trade Commission v. R. F. Keppel & Bro., Inc., 291 U.S. 304 (decided 5 February 1934), including footnote 2 quoting House Report No. 1142 (1914). Cornell LII. Cited as history.
  16. R. F. Keppel & Bro. v. Federal Trade Commission, 63 F.2d 81 (3d Cir., filed 25 January 1933). Cited as history.
  17. Amodei, D. (2026, September 12). We Must Pace the Frontier.
  18. Huang, J. (2026, September 3). NVIDIA to Acquire Hugging Face. NVIDIA Blog.