FTC Investigates OpenAI Over AI Hallucinations and Data Security
The Federal Trade Commission is probing whether ChatGPT's false outputs and a March security breach violated consumer protection laws.
The Federal Trade Commission (FTC) has launched a civil investigation into OpenAI to determine if the company's AI products violated consumer protection laws. The probe focuses on whether ChatGPT caused "reputational harm" by generating false, misleading, or disparaging statements about individuals.
As part of the inquiry, the FTC issued a 20-page demand letter requiring OpenAI to schedule a telephonic meeting within 14 days. The agency is seeking detailed records regarding complaints of misinformation and documentation on a security incident from March. During that breach, a bug allowed some users to view the chat histories and payment-related information of other users.
The Data Dilemma
This regulatory scrutiny follows testimony from FTC Chair Lina Khan before the House Judiciary Committee. Khan stated that AI services like ChatGPT are being fed a "huge trove of data" but lack sufficient checks on the specific types of data being inserted into the systems. This lack of oversight is central to the agency's concern regarding the reliability of AI outputs.
Industry Implications
This investigation marks one of the first major regulatory actions targeting the real-world consequences of AI "hallucinations." If the FTC concludes that OpenAI engaged in deceptive or unfair business practices that caused tangible consumer harm, the company could face significant penalties. Such a finding could force OpenAI to disclose proprietary training methods and data sources, creating a legal precedent for how AI-generated misinformation is handled in the U.S.
What's Next
The outcome of the probe remains uncertain, but it places OpenAI under intense pressure as CEO Sam Altman continues to advocate for AI regulation globally. The industry is now watching to see if the FTC will mandate stricter data verification standards or impose new transparency requirements on how large language models are trained and monitored. The case highlights the growing tension between the rapid deployment of generative AI and the existing legal frameworks designed to protect consumers from fraud and defamation.