The US inquiry into AI firms, and what UK businesses should ask

A US regulator is asking if leading AI firms misled people about risk, so a UK buyer should test those claims before signing.

AI Development
Tech Team
1 October 2026
5 min read
Two colleagues in a meeting room reviewing printed pages beside a laptop
AI business solutions
AI software development
business AI
UK GDPR

The US Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other artificial intelligence companies. Early reporting, first carried by US outlets and then confirmed by the agency to several newsrooms, says the inquiry looks at whether products and public claims about risk amount to unfair or deceptive conduct. That is an investigation, not a finding. No penalty has been announced, and the companies' full responses were not public when the news broke. For a UK business choosing a tool, the useful part is the question the regulator is asking: did the seller's account of the risk match the product?

What is being examined

The FTC's job includes unfair and deceptive practices that harm consumers. Reporting says this probe, opened earlier in the summer and made public at the end of September 2026, is aimed at the safety of leading models and at possible harm when those systems do something the seller did not prepare people for. Coverage has also described formal demands for documents and for testimony from executives. An agency spokesperson declined, in at least one report, to name every company in scope. OpenAI and Anthropic are the names consistently reported.

An agency spokesperson confirmed the investigation to CNBC, and declined to name the other companies in scope. The inquiry sits in the same week as the rest of this news: a newer OpenAI model held back, researchers warning about systems that may improve themselves, and a regulator asking whether the public was given a straight account. None of that proves a deception. It does mean a sales line such as "safe enough to run your business" needs a second look.

A US case, and a UK buying decision

The FTC does not regulate a firm in Birmingham. A finding in Washington, if one ever arrives, will not automatically rewrite a contract signed under UK law. The crossover is the software. Many UK teams already use models from these companies, often through a reseller, a website plugin or a product that hides the supplier's name. If the supplier overstated what the tool will not do, the UK customer still carries the operational mess and, where personal data is involved, the UK GDPR duty.

Personal data in prompts, uploaded files and chat logs is still personal data. "The vendor said it was enterprise-grade" is not a record of what you sent, where it was stored, or who can open it. That design question is the same one we use for any AI development work: a clear boundary, secure handling, and compliance with UK data protection requirements.

Questions worth asking before you sign

You can run a smaller version of the regulator's question without waiting for a US outcome.

  • What does the vendor say the tool will never do, and where is that written in the contract rather than on a marketing page?
  • What incidents has it disclosed, and what changed afterwards?
  • Can staff see a log of actions, and can you turn the feature off without losing the rest of the system?
  • Where is customer data processed, and is that processing described in a way your privacy notice can repeat honestly?
  • If the tool drafts a customer email or a price, who has to approve it?

If those answers are missing, the tool is not ready to sit on a customer journey. A focused assistant that answers from your own pages, or a workflow inside software you operate, is easier to explain to a customer and to a regulator than a general assistant with a login to everything.

Put the answers where the next person can find them

Staff change, and a trial that lived in one person's inbox disappears with them. Write a short note when you accept a tool: the job it is allowed to do, the data it may see, the person who approves anything customer-facing, and the date you will look again. That note is not a legal opinion. It is how the business remembers what it was told, which is the only way to notice later if the product behaves differently from the pitch.

Share it with whoever handles enquiries and whoever handles the website. A marketing trial that pastes customer emails into a chatbot is a data decision, even when it is described as a content experiment. If you cannot explain the note to a colleague in a few minutes, the tool is still too vague to put in front of customers.

Claims to treat as unproven

An investigation is a reason to slow a purchase, not a reason to invent a verdict. Do not tell your own customers that a named lab has been found to have misled the public. That has not been established. Do not drop a working tool overnight because a headline arrived. Do write down what you were told, and test it against one real task.

The same care applies after you go live. A setting that was acceptable in a trial can drift once staff paste real customer detail into the box. Maintenance and support includes looking again at what a feature is connected to, not only at whether the page still loads.

Web Works Rise is a UK-led team. The office is in Birmingham, and a development hub in Tunisia adds delivery capacity for that UK work. If you are comparing an off-the-shelf assistant with something narrower, contact the team with the job you want done and the data it would touch. Those two facts decide more than the logo on the login screen.

Common questions

Does a US investigation into an AI company affect our UK business?

Not directly. The FTC does not regulate a UK firm, and a US finding would not automatically rewrite a contract signed under UK law. What carries over is the software: if a supplier overstated what its tool will not do, you still carry the operational problem and, where personal data is involved, the UK GDPR duty.

What should we ask an AI vendor before signing?

What the tool will never do, and where that sits in the contract rather than on a marketing page. What incidents the vendor has disclosed and what changed afterwards. Whether staff can see a log of actions. Where customer data is processed. And who has to approve anything the tool drafts for a customer.

Is text typed into an AI tool personal data?

Yes, where it identifies someone. Enquiry text, uploaded files and chat logs are personal data, and UK GDPR applies to them. A vendor saying the product is enterprise-grade is not a record of what you sent, where it was stored, or who can open it afterwards.

Ready to transform your business?

Let our team help you implement these technologies and strategies to move your business forward.