web analytics
Agency Enforcement

FTC AI Enforcement

Anti-AI-Washing, Deceptive Practices, Section 5

The one-paragraph answer

FTC AI enforcement uses Section 5 of the FTC Act, which prohibits unfair or deceptive acts and practices in commerce. The FTC has been the most vocal federal agency on AI, publishing guidance since 2020 and pursuing cases against companies that make deceptive AI claims ("AI-washing"), harm consumers through AI-driven practices, or fail to protect data used in AI systems. Enforcement is escalating and has produced settlements requiring model deletion, data disgorgement, and significant civil penalties.

The pain FTC AI enforcement is causing our customers

Marketing teams overstate AI capabilities. Product teams overstate accuracy. Sales teams overstate what AI can do. Every one of those overstatements is a Section 5 exposure. The FTC has explicitly warned that inflated AI claims are deceptive under existing law. When a customer buys a product because of an AI claim that turns out to be exaggerated, that is an actionable deception. The pain is that companies are still marketing AI the way they marketed cloud in 2012, and the FTC has caught up.

What the FTC actually enforces

Section 5: Unfair or deceptive acts and practices

The core statutory hook. If an AI claim is likely to mislead consumers, materially, and cannot be substantiated, it is deceptive under Section 5. If AI causes substantial consumer injury that consumers cannot reasonably avoid and the injury is not outweighed by benefits, it is unfair.

The FTC Act and privacy

Failure to protect consumer data used in AI training, or failure to honor representations about how data is used, is enforceable under Section 5. This has produced FTC orders requiring companies to delete AI models built on improperly obtained data (the "algorithmic disgorgement" remedy).

Sectoral authority

The FTC also enforces FCRA (against AI-driven consumer reporting), COPPA (against AI systems collecting data from children under 13), and other sectoral rules that apply to AI.

Enforcement patterns

AI-washing

Exaggerating AI capabilities in product marketing, financial disclosures, or investor communications. The FTC has explicitly warned companies against this and has pursued cases where AI marketing exceeded actual capability.

Automated harm

AI systems that cause direct consumer harm, such as fraudulent chatbots, AI voice clones used in scams, or AI-driven deceptive practices at scale.

Data misuse

AI models built on data obtained deceptively or in violation of user representations. Remedies include model deletion, training-data destruction, and civil penalties.

Weak governance

The FTC is increasingly treating inadequate AI risk management, weak monitoring, and slow incident response as evidence of unfair practices.

Why FTC AI enforcement matters to you

The FTC's authority reaches essentially every consumer-facing business. If you make AI claims to consumers, the FTC can investigate you. If AI hurts consumers, the FTC can act. If your data practices are inconsistent with representations, the FTC can act. The reach is broad, the authority is well-established, and the enforcement is escalating.

The FTC proposed policy statement on AI accuracy (July 2026)

On July 1, 2026, the FTC published a proposed policy statement in the Federal Register (FR 2026-13628, docket FTC-2026-0859) arguing that AI companies secretly modifying model outputs to advance undisclosed ideological objectives engage in unfair or deceptive acts under Section 5 of the FTC Act. The statement was issued pursuant to Executive Order 14365 (December 2025), which directed the FTC to analyze state laws that compel alteration of "truthful outputs of AI models." The statement names the Colorado AI Act as a candidate for implied federal preemption. Comment period closes July 31, 2026. Vote was 2-0 under Chairman Andrew Ferguson.

The policy statement is the FTC's first concrete signal on AI output manipulation. Companies whose AI systems shape outputs through content moderation, fairness filters, or state-compliance tuning should assess whether those practices align with their consumer-facing representations, and consider whether the tuning is disclosed.

The preemption argument is worth watching closely, and the Colorado case shows why. The FTC named the Colorado AI Act as a preemption candidate. Colorado repealed that law in May 2026, under combined pressure from a constitutional challenge, a Department of Justice AI Litigation Task Force, and this federal posture. Federal preemption pressure did not need to win in court to change a state statute. Any compliance roadmap that treats state AI laws as fixed obligations is mispricing that dynamic.

What the research says about FTC AI enforcement

The academic literature on FTC AI enforcement is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“Algorithmic biases can result in discriminatory outcomes, reinforcing societal inequalities and reputational risks for businesses.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about FTC AI enforcement arrives from the board, the buyer, or the regulator.

How to get compliant with FTC AI Enforcement: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under FTC AI enforcement. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities FTC AI enforcement reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation FTC AI enforcement expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, FTC AI enforcement becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about FTC AI enforcement

What is "AI-washing"?

Marketing or product claims that overstate AI involvement, accuracy, or capability. Similar to "greenwashing." The FTC has been explicit that AI-washing is Section 5 deception.

What is "algorithmic disgorgement"?

An FTC remedy that requires a company to delete AI models trained on improperly obtained data. First imposed against Everalbum in 2021, since used in additional cases.

Does the FTC coordinate with other agencies?

Yes. FTC often works with EEOC on employment AI, CFPB on financial AI, and DOJ on discrimination cases. See Agency Enforcement.

Where does FTC AI enforcement fit in SRJ's work?

The AI Business Enablement Audit™ includes an FTC exposure assessment covering marketing claims, data practices, and consumer-harm risk. Volume III of The Operating Discipline for AI Library™ addresses FTC readiness in the AI Communication Alignment Protocol™.

Primary sources on FTC AI enforcement

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning FTC AI enforcement that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including FTC AI Enforcement, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation