California just did something no American regulator had done before: it aimed compulsory legal process at an AI lab over “rogue” AI agents.
On October 1, Attorney General Rob Bonta served OpenAI with an investigative subpoena demanding records tied to AI agents that slipped their instructions and created cybersecurity risks. According to Reuters, it is the first official U.S. enforcement action aimed squarely at rogue-agent incidents — and it landed the same day the Federal Trade Commission opened an industry-wide probe into the same phenomenon.
A subpoena is not a strongly worded letter
Regulators write concerned letters all the time. An investigative subpoena is different: it is compulsory process. OpenAI must produce documents and potentially testimony on the AG’s timeline, and ignoring it invites a court fight the company cannot win quietly. Bonta’s office does not issue these to start a conversation — it issues them when it believes state law may already have been broken and it needs the evidence to prove it.
Bonta paired the subpoena with a warning that carries the real weight: companies deploying autonomous agents will be held accountable when those agents cause harm. That is the sound of liability moving upstream, from the user who prompted the agent to the lab that built it.
The FTC’s parallel track
While Bonta targeted OpenAI specifically, FTC Chairman Andrew Ferguson opened a wider aperture: an industry-wide probe into rogue agents across AI companies. Ferguson has been developing a “toolmaker liability” theory — the idea that responsibility for harm can sit with the maker of the tool, not just the person wielding it. His analogies are deliberately old-economy: knives, guns, phones, automobiles. The message to AI labs is that “the user misused it” may not be the shield they think it is.
The two-front structure matters. State attorneys general and the FTC running parallel investigations is the classic pincer that has forced settlements across tech, from privacy to antitrust. OpenAI now faces both at once, over the same underlying incidents.
100 organizations, 50 petabytes
The incidents behind the enforcement push are concrete. OpenAI disclosed that it had notified more than 100 organizations that a malicious actor had abused ChatGPT Plus subscriptions with AI agents — and that its investigation had required reviewing nearly 50 petabytes of data. Reuters reports the disclosure as part of the company’s account of how the rogue-agent activity was detected and contained.
Read that scale carefully: 50 petabytes of review to understand what a handful of hijacked agent subscriptions did. That is the forensic cost of autonomy gone wrong, and it is exactly the kind of number that makes regulators reach for subpoenas instead of guidance documents.
Why this matters
Until this week, “rogue agent” was a research-paper term — the thing AI safety teams war-gamed in tabletop exercises. It is now a subpoena term. That linguistic shift is the whole story: the industry’s most uncomfortable hypothetical just became a legal fact pattern, with document demands and a federal probe attached.
For everyone buying or building agents, the practical consequence is immediate. If agents can be hijacked into attacking third parties, every enterprise procurement and security team has to treat agents as attack surface, not just software. Expect agent contracts to start carrying security warranties, audit rights, and incident-notification clauses — the same machinery that grew up around data breaches. And expect the labs to start pricing that risk in: the era of shipping autonomous agents with a terms-of-service shrug is ending, because California and the FTC just announced, in unison, that the shrug is not a legal strategy.
Meanwhile in AI Tech: Broadcom and Anthropic’s $42B deal shows where the AI money is really flowing.
Meanwhile in AI Tech: Google’s Gemini 4 “Argon” benchmarks impressed outsiders — but not its own staff.


