There is no federal AI statute behind the Federal Trade Commission’s AI cases. There is one sentence written in 1938, a pair of policy statements from the 1980s, and a doctrine about advertising substantiation that predates the technology by half a century. Understanding those three is enough to predict most of what the Commission does here.
The statute and the two standards
Section 5(a) of the FTC Act, 15 U.S.C. § 45(a), declares unfair or deceptive acts or practices in or affecting commerce to be unlawful. The text is published by the Office of the Law Revision Counsel at uscode.house.gov. Two separate standards live in that sentence and the Commission has defined each of them.
Deception is set out in the Commission’s 1983 Policy Statement on Deception: a representation, omission or practice that is likely to mislead a consumer acting reasonably in the circumstances, and that is material — meaning likely to affect the consumer’s conduct or decision. There is no intent element. A claim can be literally true and still deceptive if the net impression it creates is misleading, and the net-impression rule is why disclaimers in small print rarely save a headline claim.
Unfairness is narrower and is codified at 15 U.S.C. § 45(n): the practice must cause or be likely to cause substantial injury to consumers, which is not reasonably avoidable by consumers themselves, and which is not outweighed by countervailing benefits to consumers or to competition. Most AI cases are pleaded as deception because deception is easier; unfairness appears where the harm is a consequence of the product rather than of the claims about it.
This page describes an enforcement theory and the cases it has appeared in. It is not legal advice, and enforcement priorities at the Commission change with its composition. Take advice on your own claims.
Substantiation is the part that bites
The doctrine that actually decides AI-washing cases is substantiation, set out in the Commission’s 1984 Policy Statement Regarding Advertising Substantiation. An objective product claim carries an implied representation that the advertiser had a reasonable basis for it at the time the claim was made. Lacking that basis is itself the deception, independent of whether the claim later turns out to be true.
Two consequences follow that are specific to AI marketing. First, the level of substantiation required tracks the claim: a specific quantified claim — “98% accurate”, “detects 99% of weapons” — requires evidence matching that specificity, and where the claim is about efficacy or performance the Commission typically demands competent and reliable evidence, described in consent orders as testing conducted in an objective manner by qualified persons using procedures generally accepted in the profession to yield accurate and reliable results. A benchmark run on a hand-picked evaluation set does not meet that description.
Second, an implied claim counts. Describing a product as “AI-powered” when the work is done by human contractors, or as “automated” when a human reviews every output, is a claim about the product’s nature that the seller has to be able to support. The Commission has been explicit in business guidance since February 2023 that it will ask whether a product does what is claimed, whether it does better than a non-AI product if that is the claim, whether the risks were known, and whether the product uses AI at all.
Where the theory has been applied
The Commission grouped several matters under the banner Operation AI Comply, announced on 25 September 2024 and described in the Commission’s own announcement. The matters fall into three recognisable shapes.
- The capability overstated. The DoNotPay matter concerned a service marketed as “the world’s first robot lawyer”; the Commission alleged the service had not been tested against the work of a human lawyer and that the legal documents it produced were not adequately substantiated. The proposed consent order, finalised in early 2025, carried a monetary payment and a requirement to notify subscribers.
- The quantified claim. Matters involving AI security screening and AI content detection turned on specific accuracy figures — a weapons-detection claim and a content-detector accuracy claim — where the Commission alleged the evidence did not support the number as stated for the conditions consumers would encounter.
- AI as the pitch for a business-opportunity scheme. Several matters in the same sweep were ordinary money-making-opportunity cases in which “AI-powered” was the hook. These are the easiest to bring and the least interesting doctrinally: the AI claim is incidental to a scheme that would have been unlawful with any other adjective.
Read the orders rather than the press releases where you can. Consent orders are where the operative definitions live — what counts as competent and reliable testing, what has to be retained, for how long — and they are the closest thing to a compliance specification the Commission publishes.
The means-and-instrumentalities extension
The most contested theory in this area is not about a seller’s own claims at all. Under the means-and-instrumentalities doctrine, a person who provides another with the tools to deceive can be liable under Section 5 even where the provider makes no deceptive claim to the consumer. The Commission applied that theory in 2024 to a generative writing tool whose feature produced volumes of testimonial-style reviews, on the reasoning that supplying a means to generate false reviews is itself a violation.
That matter drew dissents from two Commissioners, who argued that liability requires more than supplying a general-purpose tool that a subscriber might misuse, and that the theory as applied would sweep in ordinary software. The disagreement is genuine and it is unresolved: no court has tested the theory against a general-purpose model provider, and the composition of the Commission changed in January 2025 in a direction that makes the narrower reading more likely to prevail. Anyone building on the assumption that a model provider is liable for what a customer generates — or on the assumption that it is not — is guessing.
Why these cases rarely produce money
This is the part that changes how the whole programme behaves and it is usually left out. In AMG Capital Management, LLC v. FTC, 593 U.S. 67 (2021), a unanimous Supreme Court held that Section 13(b) of the FTC Act authorises injunctive relief only and does not permit the Commission to obtain equitable monetary relief such as restitution or disgorgement. The Commission’s main route to consumer money in a straightforward Section 5 case was closed.
What remains is narrower. Civil penalties are available for violating an existing order or a Commission rule, and Section 19 permits redress for rule violations and for conduct after a final cease-and-desist order. That is why the Commission has invested in rulemaking — the Rule on Unfair or Deceptive Fees and the rule on consumer reviews and testimonials both create penalty-backed obligations that touch AI marketing directly — and why it revived Penalty Offense Notices, which put recipients on notice that conduct has already been found unlawful in litigated Commission proceedings and thereby expose them to civil penalties under Section 5(m)(1)(B) for repeating it.
The practical reading for a company shipping an AI product: the first Commission action against you is likely to seek an order rather than money, and the order is the thing to be afraid of, because it lasts for twenty years, binds your officers, requires compliance reporting, and converts every later slip into a civil-penalty case. The equivalent state-law exposure is often larger and arrives sooner — Chapter 93A in Massachusetts carries per-violation penalties and private treble damages that the FTC Act does not, and the securities-law version of the same theory is covered in the SEC AI-washing page.
Top comments (0)