The rule most people want stated is simple: a customer testimonial that no customer ever gave is deceptive, and generating it with a model does not change that. What is worth the page is the second question — which instrument bites, and therefore whether the exposure is an order to stop or a civil penalty per violation.
Two instruments, not one
The FTC has two things in this area and they behave differently.
The Endorsement Guides, 16 CFR Part 255, were revised in 2023. They are administrative interpretations, not rules: they tell you how the Commission reads Section 5 of the FTC Act, 15 U.S.C. 45, which prohibits unfair or deceptive acts or practices. Violating a Guide is not itself unlawful; the Guides describe conduct the Commission considers deceptive under Section 5. The 2023 revision is the one that matters here because it broadened the definition of an endorsement in §255.0 to make clear that an endorser can be a virtual or fabricated persona, and it expanded the treatment of fake and manipulated reviews. Current text: 16 CFR Part 255 on eCFR.
The Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, is a legislative rule finalised in August 2024 and effective from 21 October 2024. It is binding, and because it is a rule the Commission can seek civil penalties for violations, in addition to the equitable relief available under Section 5. Text: 16 CFR Part 465 on eCFR.
This is a description of two federal instruments, not legal advice. The civil penalty maximum under 15 U.S.C. 45(m) is adjusted for inflation annually, so any figure quoted in a secondary source is likely to be out of date; take the current amount from the Commission’s own published adjustment, and take advice on your own facts.
Where an AI testimonial becomes a fake review
Part 465 prohibits, among other conduct, creating, purchasing or disseminating a consumer review or testimonial that materially misrepresents that it was written by someone who does not exist, or by someone who did not have the experience described. The rule’s treatment of AI is not a separate provision bolted on: a review attributed to a person who does not exist is caught whether that person was invented by a copywriter or by a model. The generation method is irrelevant to the prohibition and relevant only to how much of it you did at scale.
The rule also reaches conduct around reviews rather than only the text of them: buying positive or negative reviews, insider reviews given without a clear disclosure of the relationship, company-controlled review websites presented as independent, unfounded suppression of negative reviews, and misrepresenting indicators of social media influence such as bought followers or engagement. Several of these are the ones a generative workflow makes cheap, which is why the rule and the AI question arrived at the same time.
Two boundaries are worth being precise about. A model used to clean up a genuine review that a genuine customer wrote and approved is not a fabricated review; the experience exists and the attribution is true. A model used to compose a review that a customer then signs off on is closer to the line and turns on whether the review accurately reflects that person’s actual experience — the requirement in §255.1 that an endorsement reflect the honest opinions of the endorser. A model used to generate a persona, a face and an experience is over it.
Liability for supplying the tool
This is the part that reaches AI companies rather than advertisers. The Commission has used a means-and-instrumentalities theory: a party that provides others with the means to commit a deceptive act can itself be liable, even where the deception is carried out by the customer. In September 2024 the Commission announced a set of AI-related actions under the banner of Operation AI Comply, one of which concerned a service that generated testimonial content and was alleged to have furnished users with the means to produce deceptive reviews at scale.
That theory is the one to understand if you build generation tooling. It does not make every text generator liable for every misuse — the allegations turned on a service marketed for producing testimonials specifically, producing content with fabricated specifics that users had no basis for. But it does mean that a feature whose output is, by design, a first-person account of an experience the user did not have is a feature with a regulatory theory attached to it. The Commission’s complaints, consent orders and dissents in these matters are published in the FTC’s case and proceedings library, and reading the actual complaint is worth more than reading coverage of it — in this instance the dissenting statements set out a narrower reading of the theory that is itself informative about where the boundary is contested.
Consent orders bind the respondent, not the industry. A settled FTC matter tells you what the Commission was prepared to allege and what the respondent was prepared to accept; it does not decide the law, and no court has ruled on the theory in that posture. Treat it as posture, not precedent.
The cases that are not obvious
- The AI-generated spokesperson. A synthetic presenter reading approved marketing copy is the advertiser speaking, not an endorser, and the endorsement analysis largely falls away. The problem starts the moment the synthetic figure is presented as an independent customer, expert or user — then the Guides treat it as an endorsement by a person who does not exist.
- The composite testimonial. A quote assembled from several real customers and attributed to one named person misrepresents the endorser even though every underlying experience was real.
- The translated or localised review. Machine translation of a genuine review is generally fine; machine “localisation” that adds specifics the original reviewer never mentioned invents experience.
- The synthetic before-and-after. A generated image depicting a result no customer achieved is a performance claim, and it needs substantiation on its own terms independently of the endorsement rules.
- The disclosed AI persona. Disclosure helps with deception about identity. It does nothing for the underlying claim: a clearly labelled AI character asserting that a product cured something still requires substantiation.
What this changes in practice
For a company generating marketing content, the workable controls are unglamorous and mostly about provenance of the claim rather than provenance of the pixels. Keep the chain from a real customer to a published quote — who said it, when, in what channel, and what was changed on the way. Prohibit generation of first-person experience in the tooling itself rather than in a policy document, because a policy that a prompt template can violate is not a control. Where a persona is synthetic, label it and keep it out of the endorsement frame.
And keep this separate from the adjacent enforcement theory about claims made about your AI, which is a different provision and a different fact pattern — see AI washing under Section 5 and the general law on AI marketing claims. A bot that fails to identify itself in a commercial conversation is a third theory again, with a state-law source: California’s bot disclosure law.
Top comments (0)