FTC Opens AI-Agent Probe, Plus 3 Tech Stories
The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other AI developers over risks their systems may pose to consumers. That would be noteworthy on its own. It lands at an especially interesting moment, though, because researchers have also documented another case of AI agents probing government systems in ways their operators apparently did not intend.
The FTC opens an AI-agent investigation
The FTC AI agent investigation is the first U.S. enforcement inquiry focused this directly on the problem of autonomous systems taking actions outside the boundaries people thought they had set. An FTC spokesperson confirmed the investigation to the Associated Press. Reuters reports that the agency is looking at multiple AI labs and may issue formal demands for documents and executive testimony.
There is a temptation to turn every one of these stories into “the AI escaped” or “the AI became a hacker.” That framing is dramatic. It also skips over the part that actually matters.
Transluce, an AI-safety research group, says it found 899 requests made against Library and Archives Canada on May 28 and June 9. Thirteen of those requests contained what the researchers describe as attack payloads, including basic tests for SQL injection and cross-site scripting. Transluce believes the attempts failed. Canada’s federal cybersecurity agency says there is no indication government systems were compromised.
I’m going to be careful with the attribution, too. Transluce says the activity resembles other agent behavior it has previously tied to OpenAI, but it explicitly says it cannot confidently attribute the Canadian attempts to OpenAI. OpenAI told Reuters it is reviewing the findings.
So what do we actually know? Agents tasked with finding obscure public information appear to have started treating a government website less like a library catalog and more like something to probe when ordinary queries did not get them where they wanted to go. That does not require consciousness, malicious intent or a robot twirling an imaginary mustache. A goal-driven system can still choose a bad route toward a perfectly ordinary goal.
That is the practical security problem. A prompt saying “do not access anything you are not supposed to access” is guidance. It is not an access-control system. Businesses deploying agents need the same boring controls we already use everywhere else: least-privilege credentials, network boundaries, allowlists, human approval before consequential actions, and logs that make it possible to reconstruct what the agent actually did. The FTC investigation will matter because it may help answer a question that is getting harder to avoid: when software is given authority to act, how much responsibility follows the company that gave it that authority?
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Cisco says attackers are already exploiting an SD-WAN flaw
Cisco has a much more conventional security problem today, and if you run Catalyst SD-WAN Manager, this one is actionable.
CVE-2026-76504 is a CVSS 9.8 authentication-bypass flaw in the API session-management code for Cisco Catalyst SD-WAN Manager. Cisco says attackers are already exploiting it. There is no workaround.
The mechanism is worth understanding because it is a good example of why security rules have to agree with the application about what a request means. The flaw involves improper handling of URI encoding. In plain English, a request can be written in an encoded form that slips past the authentication rule, then gets decoded later into the API path the rule was supposed to protect. The result is about as bad as it sounds: an unauthenticated remote attacker can reach the API with administrator privileges.
Cisco has fixed releases for each supported software train and says vulnerable Managers should be upgraded immediately. Its remediation guidance goes a step further, which is important because active exploitation changes the job. Cisco recommends collecting admin-tech diagnostic bundles before the upgrade, upgrading every affected Manager, then opening a TAC case so Cisco can scan those bundles for indicators of compromise.
That last step matters. Installing the fixed version answers “can this happen again?” It does not answer “did this already happen?” If an SD-WAN Manager was exposed to the internet while attackers were using the flaw, patching is the beginning of the cleanup, not evidence that there is nothing to clean up.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
A judge pauses New York’s algorithmic rent law
Yesterday I wrote about McDonald’s using AI-assisted pricing to recommend local menu prices. Today the algorithmic-pricing argument has moved from burgers to rent — and into federal court.
U.S. District Judge Valerie Caproni has temporarily blocked New York from enforcing a state law that prohibited landlords and real-estate professionals from using certain algorithmic pricing tools to set residential rents. RealPage challenged the law on First Amendment grounds, arguing that New York was restricting the use of pricing recommendations produced by its software.
This is a preliminary injunction, not a final ruling that New York’s law is unconstitutional. Caproni called it a “close call” and said RealPage was only “marginally” likely to succeed on the merits. That distinction is important because early court orders have a habit of getting summarized as if the entire case has already been decided.
There is also a real policy tension underneath the legal argument. New York says coordinated pricing software can facilitate anticompetitive rent-setting. RealPage says the law sweeps too broadly and blocks ordinary commercial decisions simply because software helps produce the recommendation. Separately, RealPage recently settled with the U.S. Justice Department and agreed to restrict its software from using non-public competitor data to generate price recommendations.
The technology question is becoming familiar: when software recommends a price, is it merely helping a business analyze a market, or is it creating a coordination mechanism that changes how that market behaves? Housing makes the stakes much larger than a fast-food menu, but the underlying argument is going to keep showing up.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
California vetoes a smart-glasses recording bill
California, meanwhile, will not be adding a new smart-glasses recording law — at least not through Senate Bill 1130.
Governor Gavin Newsom vetoed the bill, which would have penalized people who secretly recorded others with smart glasses in places such as changing rooms and doctors’ offices. Beginning in 2028, it also would have required wearable recording devices to include a light, sound or other indicator when recording and would have barred products designed to hide that signal.
Newsom said the definition of a wearable recording device was too broad and pointed to existing California laws that already restrict recording people without consent in spaces where privacy is expected. Supporters of the bill argued that smart glasses create a practical problem those laws do not solve very well: a phone held up in front of somebody is obvious. Glasses that happen to be recording are not.
That is the part worth watching. The veto does not make secret recording legal in private spaces, and the bill would not have solved every privacy problem simply by adding an indicator light. It does show how quickly an old privacy rule can become harder to enforce when the camera stops looking like a camera.
The hardware is changing faster than the social cue. The law is still trying to catch up.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Associated Press: FTC is investigating OpenAI and Anthropic over possible risks to consumers
- Reuters: FTC opens probe into AI giants including Anthropic and OpenAI
- Transluce: AI Agents Targeted U.S. and Canadian Government Websites
- Reuters: AI agents tried to hack a Canadian government website, research firm says
- Cisco: Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- Cisco: Remediate Catalyst SD-WAN Security Advisory — September 2026
- Reuters: Judge blocks New York rent-setting software ban
- Associated Press: Newsom vetoes smart-glasses recording measure
Photo by Priscilla Du Preez on Unsplash.

macOS Full Disk Access Gets Tighter for AI Agents | Raymond Tec
October 3, 2026 @ 10:57 am
[…] What the announcement does settle is the broader design problem. “This app can read everything I can read” is a very different permission when the app is a passive backup utility than when it is software designed to observe context, make plans, use tools, and act on your behalf. We’ve been circling that issue all week, including in Thursday’s look at the FTC’s AI-agent investigation. […]