United States — Federal
FTC AI Enforcement: The Legal Theory Behind "Algorithmic Deception"
The FTC has never needed an AI-specific statute to bring these cases — Section 5's decades-old ban on unfair or deceptive practices already reaches overstated AI claims, and the enforcement record from Rite Aid to DoNotPay shows exactly what draws an action.
The FTC has never once needed a new law to bring an AI enforcement case. Every action it has brought over AI claims — from a facial-recognition retailer to a self-described "robot lawyer" — runs through the same statute the agency has used since long before anyone said "artificial intelligence" in a product pitch: Section 5 of the FTC Act, 15 U.S.C. § 45(a), which bans "unfair or deceptive acts or practices in or affecting commerce." No AI-specific federal statute exists, and the FTC doesn't need one to act. If your compliance review has been waiting for Congress to define the rules before taking AI marketing claims seriously, you've been reviewing against the wrong gap.
That's the point the FTC itself has made explicitly in its own guidance: there is no AI exemption from the laws already on the books. Understanding what actually triggers a case means understanding the legal test underneath "algorithmic deception," not just recognizing the phrase from a headline.
Deception and unfairness are two different tests, not one vague standard
Section 5 gives the FTC two separate legal theories, and knowing which one applies changes what evidence matters.
Deception, defined in the FTC's 1983 Policy Statement on Deception, requires three things: a representation, omission, or practice; that's likely to mislead a consumer acting reasonably under the circumstances; where the misleading element is material — meaning it's likely to affect the consumer's decision. Nothing in that test asks whether the company meant to mislead anyone. It's an objective, effects-based standard. A startup that genuinely believes its own AI hype, and repeats it in marketing copy without ever testing whether the claim holds up, can still be deceptive under Section 5. "We believed it" has never been a defense to this theory.
Unfairness is a different, three-part test from the FTC's 1980 Policy Statement on Unfairness, later written directly into the statute at 15 U.S.C. § 45(n): the practice causes or is likely to cause substantial injury to consumers; that injury isn't one consumers could reasonably avoid themselves; and it isn't outweighed by countervailing benefits to consumers or competition. A biased hiring algorithm might not involve a false statement to anyone — nobody claimed it was unbiased — but if it causes substantial, unavoidable harm with no offsetting benefit, unfairness reaches it anyway. The two theories often show up together in the same complaint, but they don't require the same facts.
The enforcement record: what actually draws a case
The FTC signaled AI claims as a standing enforcement priority on September 25, 2024, with a coordinated sweep it called Operation AI Comply, bringing five actions at once and stating flatly that the law already covers AI-related deception. The specific fact patterns from that sweep and the cases around it are worth knowing, because they repeat.
DoNotPay marketed itself as "the world's first robot lawyer," an AI product that could substitute for an actual attorney — without ever testing whether its output matched what a competent lawyer would produce, and without retaining any lawyers to check its work. The FTC's final order, issued in January 2025, imposed a $193,000 monetary judgment and barred DoNotPay from claiming its product can substitute for a human lawyer without real substantiation behind that claim. Rytr, an AI writing tool, let subscribers generate large volumes of fake consumer reviews and testimonials on demand; the resulting settlement bars Rytr from offering any service built around generating reviews at all. Evolv Technologies sold AI-powered weapons-detection systems into schools and venues with accuracy claims it hadn't substantiated; its December 2024 settlement bans unsubstantiated detectability claims and requires giving some K-12 customers a way out of their contracts.
Notice what's actually common across all three: none of them were punished for "using AI." Each involved a specific, testable capability claim — the tool works like a lawyer, the reviews are genuine, the weapon detection is accurate — made to customers who had no way to verify it themselves, and never substantiated by the company making it. That's the deception theory in its most common current form, and it's the pattern that should worry any team about to ship an "AI-powered" claim it hasn't independently tested.
Algorithmic disgorgement: when the remedy is deleting the model itself
The sharpest tool in the FTC's AI enforcement kit isn't a fine — it's an order to delete the trained model. Algorithmic disgorgement (sometimes called model deletion) requires a company to destroy not just data it obtained improperly, but any algorithm or model built using that data, on the theory that a company shouldn't get to keep the commercial asset it built from a violation just because the underlying data is gone.
The FTC first ordered this against Everalbum, the company behind the "Ever" photo app, in a settlement announced in January 2021. Everalbum told users its facial-recognition feature was off by default and could be deactivated, but ran it regardless and used the resulting facial data to build and improve a commercial facial-recognition product sold under its Paravision brand. The order required deleting not just the improperly used photos, but the facial-recognition models trained on them — a genuinely contested settlement, not a default judgment, which is part of why it's the case most often cited as the template.
The FTC has since applied the same logic outside facial recognition entirely. In its December 2023 action against Rite Aid, the agency alleged the retailer had used AI-powered facial recognition for years to flag suspected shoplifters, generating false matches that disproportionately hit customers at stores in majority-Black and -Asian neighborhoods and led employees to publicly confront people based on those false flags. The settlement banned Rite Aid from using facial recognition for surveillance for five years and required deleting the images collected and any data, models, or algorithms derived from them. And in March 2022, the WW International/Kurbo settlement — a children's-privacy case under COPPA, not a facial-recognition case at all — became the first to require destroying algorithms built from data the FTC said was collected from children without proper parental consent. The pattern holds regardless of which underlying statute or fact pattern triggers it: if the training data was tainted, the model built on it is tainted too.
A worked example: where a fraud-detection claim actually crosses the line
Picture a fictional company, Ledgerline Technologies, selling an AI-powered fraud-detection tool to regional banks, marketed with a specific number: "99% accuracy in flagging fraudulent transactions." Ledgerline never ran that figure against real transaction data — it's an extrapolation from a small internal test set the engineering team assembled to demo the product, not a validated accuracy rate.
Run both prongs against those facts. Deception: "99% accuracy" is a specific, material representation — the exact kind of number a bank's own compliance team would rely on when deciding whether to reduce manual fraud review, and reasonable buyers have no independent way to check it before relying on it. That the claim wasn't malicious doesn't matter; it was never substantiated, and it was likely to mislead. Unfairness: banks that adopted the tool based on that number and scaled back manual review face a substantial injury — undetected fraud losses — that they couldn't reasonably have caught themselves, since Ledgerline controlled the only data that could have revealed the gap. A realistic consent order would require actual substantiation testing before making the claim again, redress to customers who relied on the unverified number, and — if Ledgerline had trained its detection model using bank transaction data obtained under a misleading "opt-out anytime" promise it didn't honor — disgorgement of that specific model, not just a data-deletion order.
What this means for your own AI claims
The practical discipline this creates is simple to state and easy to skip under launch pressure: test a capability claim before it ships, not after a customer complains. If a claim is quantified — an accuracy rate, a time savings, a bias-reduction figure — it needs a real test behind it, not an internal demo or a vendor's marketing deck repeated verbatim. Don't let a product get called "AI-powered" if what it actually runs is a simpler rule set; the FTC has treated inflated AI labeling itself as a deceptive practice, independent of whether the underlying claim about performance was accurate. The same discipline applies if your company is a registered adviser or a public issuer rather than a consumer-facing seller — the SEC has brought its own string of "AI-washing" cases using the Advisers Act and Exchange Act instead of Section 5, but the underlying failure it's punishing is identical: a specific AI capability claim nobody tested before it went out.
The governance documentation work most compliance teams already do for other reasons — the kind of accountability and testing trail described in the NIST AI RMF's Govern function — becomes directly relevant here: a company that can produce a dated testing record showing how an accuracy claim was validated is in a fundamentally different position than one that can't, regardless of whether the claim itself turns out to be accurate. And while Colorado has gone the route of writing a statutory duty of care directly into law, the FTC's approach shows the same substantive standard can be enforced without any new statute at all — which means "we're not in Colorado" or "there's no federal AI law yet" is not the same thing as "we have no AI compliance exposure." For the fuller picture of how federal agencies beyond the FTC apply existing law to AI, see our overview of US federal AI regulation.
Finally, remember that Section 5 itself gives the FTC exclusive enforcement authority — there's no private right of action under this specific statute, so a consumer can't sue your company directly under it. That's real, but it's not the whole exposure picture: most states have their own consumer-protection statutes modeled on the same deception/unfairness standard, and several of those do let private plaintiffs sue. An AI claim built to survive FTC scrutiny is, not coincidentally, also the one built to survive everything downstream of it — and the same "old law, no AI exemption" logic runs through the EEOC's approach to algorithmic hiring tools under Title VII and the ADA, even after the EEOC pulled its own guidance pages in 2025, through the CFPB's position that an AI underwriting model has to produce a specific, accurate reason for a credit denial even after its own explanatory circulars came down in the same year, and through the FCC's 2024 ruling that an AI-cloned voice is still an "artificial voice" under the decades-old TCPA, closing the same kind of "the old statute doesn't quite cover this new technology" argument before it could take hold.
Frequently asked questions
- Does the FTC need a specific AI law to bring an AI-related enforcement action?
- No. The FTC's AI enforcement runs through FTC Act Section 5 (15 U.S.C. § 45(a)), which bans 'unfair or deceptive acts or practices in or affecting commerce' — a broad, technology-neutral standard the agency has applied to AI claims without any AI-specific legislation. The FTC has said directly that there's no AI exemption from the laws already on the books.
- What's the difference between 'deceptive' and 'unfair' under the FTC Act?
- Deception, under the FTC's 1983 policy statement, requires a representation or omission that's likely to mislead a reasonable consumer and is material to their decision. Unfairness, under the 1980 policy statement later codified at 15 U.S.C. § 45(n), requires substantial consumer injury that isn't reasonably avoidable and isn't outweighed by countervailing benefits. They're separate legal theories, and the FTC can bring either one alone or both together against the same conduct.
- Can a company violate Section 5 even if it didn't intend to deceive anyone?
- Yes. The deception test is objective and effects-based — whether the claim was likely to mislead a reasonable consumer — not whether the company meant to deceive. A capability claim the company genuinely believed, but never actually tested, can still violate Section 5 if it turns out to be misleading and material.
- What is 'algorithmic disgorgement' and has the FTC actually ordered it?
- It's a remedy that goes beyond deleting improperly obtained data to also requiring deletion of any model or algorithm trained on it. The FTC has ordered it repeatedly: against Everalbum/Paravision in 2021 for facial-recognition models, against Rite Aid in 2023 for surveillance models built on improperly retained data, and against WW/Kurbo in 2022, the first children's-privacy case to require algorithm destruction.
- Can a consumer sue a company directly under FTC Act Section 5?
- No. Section 5 doesn't create a private right of action — only the FTC itself can bring a case under it. Many states have their own consumer-protection statutes modeled on Section 5's standard, sometimes called 'Little FTC Acts,' and some of those do allow private lawsuits, so the absence of federal private enforcement doesn't mean the absence of all private exposure.
Sources & references
Suggested next reading
regulations us
US Federal AI Regulation: What Actually Exists Today
regulations us colorado
Colorado AI Act (SB 205)
regulations us
EEOC Guidance on AI in Employment Decisions, Explained
regulations us
SEC AI-Washing Enforcement: What Counts as a Violation
regulations us