web analytics
AI Governance

Agency Enforcement

FTC, EEOC, CFPB, SEC, HHS OCR

The one-paragraph answer

AI agency enforcement is the most-active enforcement channel for AI right now in the United States. Five federal agencies (FTC, EEOC, CFPB, SEC, HHS OCR) enforce existing laws against AI misuse under their existing statutory authority. They do not need new AI legislation to act. They have been acting for years, and enforcement is escalating. Anti-AI-washing, disparate impact, adverse action, and misrepresentation cases are all in play right now.

The pain AI agency enforcement is causing our customers

Executives assume they are safe because federal AI legislation has not passed. They are not. Every federal agency with existing enforcement authority is using that authority against AI misuse. The FTC uses Section 5 of the FTC Act. The EEOC uses Title VII, ADA, ADEA, and GINA. The CFPB uses FCRA, ECOA, and UDAAP. The SEC uses securities disclosure rules. HHS OCR uses HIPAA and Section 1557. Companies that thought AI was unregulated at the federal level are learning otherwise, one enforcement action at a time.

What AI agency enforcement actually looks like

The five agencies signed a joint statement in April 2023 clarifying that existing federal laws apply to AI. The joint statement was co-signed by the FTC, EEOC, CFPB, and DOJ Civil Rights Division. It was a warning shot. Since then, enforcement has escalated in every agency, driven by three patterns:

Pattern one, anti-AI-washing: Companies exaggerate AI capabilities in marketing, product claims, and financial disclosures. FTC and SEC treat this as deception and misrepresentation.

Pattern two, disparate impact: AI systems produce discriminatory outcomes in hiring, lending, insurance, healthcare, or housing. EEOC, CFPB, HHS OCR, and DOJ pursue these as violations of existing anti-discrimination law.

Pattern three, inadequate governance: Companies deploy AI without documented risk management, human oversight, or complaint handling. Agencies increasingly ask, "What is your AI governance program?" and treat weak answers as evidence of unfair or deceptive practice.

Click into each agency below for the specific enforcement priorities and case examples.

Why AI agency enforcement matters to you

Every operating company faces at least one of these five agencies' authority. Financial-services firms face CFPB and SEC. Healthcare firms face HHS OCR. Any employer faces EEOC. Any consumer-facing business faces FTC. Building an AI program that anticipates AI agency enforcement is significantly cheaper than responding to it once an investigation opens.

What the research says about agency enforcement

The academic literature on agency enforcement is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“the shortcomings of conventional ex ante and ex post review under current administrative law doctrines”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about agency enforcement arrives from the board, the buyer, or the regulator.

How to get compliant with Agency Enforcement: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under agency enforcement. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities agency enforcement reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation agency enforcement expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, agency enforcement becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about AI agency enforcement

How is AI agency enforcement possible without a federal AI law?

Every federal agency has statutory authority under laws that predate AI. Section 5 of the FTC Act, Title VII, FCRA, ECOA, HIPAA, and securities disclosure rules all apply to AI without any special legislation. The agencies interpret and apply their existing authority.

What is the largest AI agency enforcement action to date?

Enforcement is escalating rapidly. Major FTC settlements have hit AI companies for deceptive claims. CFPB has pursued lenders for AI-driven adverse action failures. EEOC has settled AI hiring bias cases. The trajectory is toward larger, more visible actions.

Where does AI agency enforcement fit in SRJ's work?

The AI Business Enablement Audit™ assesses your AI program against the enforcement priorities of all five agencies. The Communication Alignment Discipline in Volume III of The Operating Discipline for AI Library™ helps executives anticipate and respond to agency inquiries.

What each area of agency enforcement covers

The detail pages below each take one component of agency enforcement and answer the same four questions: what it actually is, what it requires of you, why it matters commercially and legally, and what a defensible position looks like. Read the one that maps to your exposure first. The others become relevant as your AI footprint widens.

  • FTC AI Enforcement. The Federal Trade Commission's active AI enforcement posture. AI-washing, deceptive claims, unfairness.
  • EEOC AI Enforcement. The Equal Employment Opportunity Commission's enforcement of Title VII, ADEA, ADA, and GINA against AI-driven employment decisions.
  • CFPB AI Enforcement. The Consumer Financial Protection Bureau's AI enforcement covering credit, lending, and financial products.
  • SEC AI Enforcement. The Securities and Exchange Commission's AI-washing enforcement and disclosure requirements for public registrants.
  • HHS OCR AI Enforcement. The Office for Civil Rights within HHS enforcing HIPAA and Section 1557 against AI in healthcare.

How to prioritise your work on agency enforcement

Executives ask, reasonably, where to start. The sequence that works is the same one every time, and it is not the sequence most organisations choose. Start with an inventory: you cannot govern AI you cannot list, and almost every organisation we assess is using more AI than its leadership believes. Then rank by consequence, not by volume, because the tool that makes one high-stakes decision a week carries more exposure than the one that drafts a thousand emails.

Only then assign an owner. Not a committee, an owner, named, with the authority to stop a deployment. Governance without a person who can say no is documentation, not control. With those three steps done, the specific requirements of agency enforcement become tractable, because you now know what you have, what matters, and who answers for it.

The organisations that struggle are the ones that begin with the framework and work backwards toward reality. The frameworks are the map. The inventory is the territory. Start with the territory.

Primary sources on agency enforcement

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning agency enforcement that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Deep dives in this category

  • FTC AI Enforcement The Federal Trade Commission's active AI enforcement posture. AI-washing, deceptive claims, unfairness.
  • EEOC AI Enforcement The Equal Employment Opportunity Commission's enforcement of Title VII, ADEA, ADA, and GINA against AI-driven employment decisions.
  • CFPB AI Enforcement The Consumer Financial Protection Bureau's AI enforcement covering credit, lending, and financial products.
  • SEC AI Enforcement The Securities and Exchange Commission's AI-washing enforcement and disclosure requirements for public registrants.
  • HHS OCR AI Enforcement The Office for Civil Rights within HHS enforcing HIPAA and Section 1557 against AI in healthcare.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including Agency Enforcement, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation