@linamkhan: Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted,…

X AI KOLs Following News

Summary

The article discusses how existing laws already allow enforcement against companies for creating dangerous AI products, emphasizing the importance of upholding current regulations while considering new legal frameworks to ensure AI safety and accountability.

Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books — a point @FTC emphasized repeatedly during my tenure. 1. There is an extensive set of laws that govern dangerous and defective products. For example, releasing unvetted AI models or agents can violate consumer protection laws. Shipping flawed AI tools without implementing adequate measures to detect and stop rogue or defective AI agents can be an “unfair or deceptive” act or practice under the FTC Act (and analogous state laws). And some state AGs are already exploring holding AI firms and their CEOs criminally liable when their models participate in criminal activity. 2. Existing laws also prohibit “unfair methods of competition.” This covers instances where AI firms appropriate the competitively sensitive information of their customers, including through tracking their use of various tools. It can also cover instances where firms pursue dangerous behavior, aware that doing so may compel rivals to do the same. As the Supreme Court has noted: “A method of competition which casts upon one's competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal, was thought to involve the kind of unfairness at which the [unfair methods of competition] statute was aimed." 3. The highly concentrated and interconnected structure of these markets could be creating major risks and conflicts of interest. We had started investigating these partnerships and cross-investments across the stack (and released a preliminarily overview of some findings: https://ftc.gov/news-events/news/press-releases/2025/01/ftc-issues-staff-report-ai-partnerships-investments-study…). Both federal and state enforcers should be scrutinizing these opaque relationships and inter-dependencies. We are already seeing how these relationships could undermine accountability. For example, OpenAI could face liability given the Hugging Face incident, but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this — given Nvidia’s strong incentive to see OpenAI continue full speed ahead. 4. As AI tools dramatically change the landscape of cybersecurity risks and hacks, all businesses should be doubling down on having core security protections in place. Firms that fail to invest in adequate data security measures or fix known vulnerabilities can also be breaking the law. A recent analysis showed that around 1/3 of Fortune 100 companies do not even have a way to notify them about security issues. During my @FTC tenure, we sued firms for poor data security practices and held CEOs liable when they were personally responsible. https://this.weekinsecurity.com/dozens-of-americas-largest-companies-have-no-simple-way-to-report-security-flaws/… https://ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million… 5. As policymakers consider new legal regimes, we should be looking to lessons from prior efforts to govern major sectors, such as banking and other networks, platforms, and utilities. Tools like structural separations, nondiscrimination, and supervision could be key, and there’s a rich history of what works and what doesn’t. But we can and must pursue any new efforts alongside enforcing existing laws.
Original Article
View Cached Full Text

Cached at: 09/14/26, 09:27 AM

Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books — a point @FTC emphasized repeatedly during my tenure.

  1. There is an extensive set of laws that govern dangerous and defective products. For example, releasing unvetted AI models or agents can violate consumer protection laws. Shipping flawed AI tools without implementing adequate measures to detect and stop rogue or defective AI agents can be an “unfair or deceptive” act or practice under the FTC Act (and analogous state laws). And some state AGs are already exploring holding AI firms and their CEOs criminally liable when their models participate in criminal activity.

  2. Existing laws also prohibit “unfair methods of competition.” This covers instances where AI firms appropriate the competitively sensitive information of their customers, including through tracking their use of various tools. It can also cover instances where firms pursue dangerous behavior, aware that doing so may compel rivals to do the same.

As the Supreme Court has noted: “A method of competition which casts upon one’s competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal, was thought to involve the kind of unfairness at which the [unfair methods of competition] statute was aimed.“

  1. The highly concentrated and interconnected structure of these markets could be creating major risks and conflicts of interest. We had started investigating these partnerships and cross-investments across the stack (and released a preliminarily overview of some findings: https://ftc.gov/news-events/news/press-releases/2025/01/ftc-issues-staff-report-ai-partnerships-investments-study…).

Both federal and state enforcers should be scrutinizing these opaque relationships and inter-dependencies. We are already seeing how these relationships could undermine accountability. For example, OpenAI could face liability given the Hugging Face incident, but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this — given Nvidia’s strong incentive to see OpenAI continue full speed ahead.

  1. As AI tools dramatically change the landscape of cybersecurity risks and hacks, all businesses should be doubling down on having core security protections in place. Firms that fail to invest in adequate data security measures or fix known vulnerabilities can also be breaking the law. A recent analysis showed that around 1/3 of Fortune 100 companies do not even have a way to notify them about security issues. During my @FTC tenure, we sued firms for poor data security practices and held CEOs liable when they were personally responsible.

https://this.weekinsecurity.com/dozens-of-americas-largest-companies-have-no-simple-way-to-report-security-flaws/…

https://ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million…

  1. As policymakers consider new legal regimes, we should be looking to lessons from prior efforts to govern major sectors, such as banking and other networks, platforms, and utilities. Tools like structural separations, nondiscrimination, and supervision could be key, and there’s a rich history of what works and what doesn’t. But we can and must pursue any new efforts alongside enforcing existing laws.

FTC Issues Staff Report on AI Partnerships & Investments Study

Source: https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-issues-staff-report-ai-partnerships-investments-study The Federal Trade Commission today issued a staff report on the corporate partnerships and investments formed between the largest cloud service providers (CSPs)—Alphabet, Inc., Amazon.com, Inc., and Microsoft, Corp.—and two of the most prominent generative AI developers—Anthropic PBC and OpenAI OpCo, LLC.

Thereportdetails key aspects regarding the structure of the CSP and AI developer partnerships, such as the equity and revenue-sharing rights retained by CSPs in these partnerships and certain consultation, control, and exclusivity rights CSPs gained through their investments with AI developers.

The report outlines some potential competition implications, including that: the partnerships may impact access to certain inputs, such as computing resources and engineering talent; the partnerships may increase switching costs for the AI developer partners; and the partnerships provide CSP partners access to sensitive technical and business information that may be unavailable to others.

“As companies rapidly deploy generative AI technologies, enforcers and policymakers must stay vigilant to guard against business strategies that undermine open markets, opportunity, and innovation,” said FTC Chair Lina M. Khan. “The FTC’s report sheds light on how partnerships by big tech firms can create lock-in, deprive start-ups of key AI inputs, and reveal sensitive information that can undermine fair competition.”

The staff report stems fromFTC ordersissued in January 2024 under Section 6(b) of the FTC Act. The orders were sent to five companies involved in three separate multi-billion-dollar investments: Microsoft and OpenAI, Amazon and Anthropic, and Alphabet and Anthropic.

The FTC’s report is aimed at helping the Commission, the public, and policymakers deepen their understanding of the corporate partnerships between the generative AI developers and CSPs. The report’s findings also help equip the FTC to better evaluate the attributes and potential implications of partnerships involving large technology companies and the impact they may have on hundreds of millions of consumers, countless businesses, and huge segments of the economy.

Key Findings

The report highlights several key terms of the AI partnerships, which include:

  • Significant equity and certain revenue-sharing rights for CSP partners in their AI developer partners;
  • Certain consultation, control, and exclusivity rights CSP partners hold to varying degrees with respect to their AI developer partners;
  • Commitments that require AI developers to spend a large portion of their CSP partner’s investment on cloud services from their partner;
  • Sharing of key resources and information including access to large amounts of computing resources at discounted rates; assets and IP related to AI developers’ cutting-edge models; and certain financial and training data; and
  • Opportunities to expand current products including through integration of AI models into CSPs’ products or deployment of AI models on CSPs’ platforms.

In addition, the report highlights the following areas to watch regarding potential implications of the AI partnerships:

  • Their ability to impact access to certain inputs, such as computing resources and engineering talent, in ways that could affect competition for both AI developer partners and non-partner AI developers;
  • The potential to increase contractual and technical switching costs for AI developer partners, making it more difficult for them to change CSPs or restricting their use of multiple CSPs; and
  • CSP partners’ access to sensitive technical and business information that may be unavailable to others, such as information related to generative AI models, AI development methods, confidential chip co-design, partner finances, and customer usage and revenue numbers.

Findings in the report represent information available to staff as of September 2024 as well as publicly available information through January 2025.

The Commission voted 5-0 to allow staff to issue the report. Chair Lina M. Khan will be issuing a statement. Commissioner Andrew N. Ferguson issued a concurring and dissentingstatementjoined by Commissioner Melissa Holyoak. Commissioner Holyoak issued a concurring and dissentingstatementjoined by Commissioner Ferguson.

Similar Articles