Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
FTC Section 5 Enforcement for AI SystemsCompliance & Audit
5 min readFor Legal & Compliance Officers

FTC Section 5 Enforcement for AI Systems

Scope

This guide explains how the Federal Trade Commission (FTC) applies Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices," to AI systems. It's designed for compliance teams to understand what triggers FTC scrutiny, what evidence the agency examines, and how to structure your AI governance program to withstand Section 5 review.

The FTC is actively investigating companies like OpenAI and Anthropic under existing consumer protection statutes. This isn't theoretical, it's happening now and indicates how the agency will approach other AI developers.

Key Concepts and Definitions

Section 5 Authority: The FTC Act prohibits unfair or deceptive acts or practices. Although the statute predates digital computing and doesn't mention AI, machine learning, or algorithms, the FTC interprets it broadly. If your AI system causes consumer harm through deception or unfairness, Section 5 applies.

Deceptive Practice: A representation, omission, or practice likely to mislead consumers acting reasonably, where the misleading claim is material to consumer decisions.

Unfair Practice: An act or practice that causes or is likely to cause substantial injury to consumers, which they can't reasonably avoid, and which isn't outweighed by benefits to consumers or competition.

Consumer Harm: Includes economic injury, health or safety risks, or privacy violations. The FTC doesn't require proof of actual harm; the likelihood of harm is enough.

Requirements Breakdown

What the FTC Examines in AI Systems

The FTC doesn't publish an AI-specific checklist, but enforcement patterns reveal what triggers scrutiny:

Claims about capability or accuracy: If you claim your model achieves a certain accuracy or can perform specific tasks, you need substantiation. Marketing materials, API documentation, and model cards all count as representations.

Data practices: How you collect training data, whether you honor opt-out requests, and whether your data use matches your privacy policy. The FTC can challenge data practices that don't violate a specific privacy statute but still cause consumer harm.

Output quality and safety: If your system generates harmful outputs like misinformation or biased decisions, the question is whether you took reasonable steps to prevent foreseeable harm.

Transparency and disclosure: Not every AI system requires disclosure, but if users would make different decisions knowing they're interacting with AI, non-disclosure may be deceptive.

The "Reasonable" Standard

Section 5 enforcement hinges on reasonableness. Did you act as a reasonable business would, given the known risks? This means:

  • You're expected to know about documented AI risks relevant to your use case.
  • Industry standards like ISO/IEC 42001 and NIST AI RMF establish what's reasonable, even if not legally required.
  • "We didn't know" isn't a defense if the risk was documented in research or reported by others.

Implementation Guidance

Building a Section 5-Resilient AI Program

Document your risk assessment: The FTC will ask what harms you considered and what controls you implemented. ISO/IEC 23894 provides a structured approach, you don't need to follow it exactly, but you need something defensible.

Start with:

  • What could go wrong with this system? (Consider accuracy failures, bias, privacy leaks, misuse)
  • What's the magnitude of potential harm?
  • What controls reduce likelihood or severity?
  • What residual risk remains, and why is it acceptable?

Substantiate performance claims: If you claim 95% accuracy, document:

  • The test dataset and whether it represents real-world deployment conditions.
  • The metric definition (precision, recall, F1).
  • Known limitations or edge cases where performance degrades.

If you can't substantiate a claim, don't make it. "State-of-the-art" and "industry-leading" are vague enough to be defensible; specific percentages aren't.

Create an output monitoring program: You need evidence you're watching for harmful outputs in production. This doesn't mean reviewing every output, it means:

  • Sampling strategies that catch issues before they scale.
  • User feedback mechanisms that surface problems.
  • Automated filters for known harmful output types.
  • Documented escalation procedures when monitoring detects issues.

Align data practices with disclosures: Your privacy policy is legally binding. If it says you don't use customer data for model training, your ML pipeline can't ingest that data, even if you believe it's anonymized or aggregated. The FTC has challenged companies for data uses that technically complied with privacy laws but violated their own policies.

What "Reasonable Measures" Looks Like

The FTC doesn't expect perfection. But you need to show:

Pre-deployment testing: Red teaming for systems that generate content or make consequential decisions. Bias testing for systems that affect people differently based on protected characteristics. Robustness testing for systems exposed to adversarial inputs.

Incident response capability: When something goes wrong, can you detect it, contain it, and fix it? The FTC looks for evidence of preparation, not just reaction.

Ongoing monitoring: Post-deployment performance tracking. If your system's accuracy degrades or bias emerges over time, you need to know about it before users are harmed.

Common Pitfalls

Pitfall 1: Treating Section 5 as a technology-specific rule

Teams often ask, "What's the FTC's AI regulation?" There isn't one. Section 5 applies to business conduct generally. The question isn't "Does this comply with AI rules?" but "Could this harm consumers through deception or unfairness?"

Pitfall 2: Over-relying on disclaimers

Adding "AI-generated content may be inaccurate" doesn't protect you from Section 5 liability. Disclaimers help, but they don't override material misrepresentations or excuse unreasonable harm.

Pitfall 3: Assuming research-stage systems get a pass

If you're offering a service to consumers, even in beta, even for free, Section 5 applies. "Experimental" status doesn't exempt you from consumer protection law.

Pitfall 4: Ignoring third-party components

If you fine-tune a foundation model or integrate a third-party API, you're responsible for the outputs your system produces. "We didn't train the base model" isn't a defense if your service makes deceptive claims or causes unfair harm.

Pitfall 5: Confusing legal compliance with FTC compliance

You can comply with every AI-specific regulation and still violate Section 5. The FTC's authority is broader than most sector-specific rules.

Quick Reference Table

FTC Concern What They Look For Your Evidence
Deceptive capability claims Substantiation for performance statements Test results, validation reports, documented limitations
Unfair data practices Alignment between policy and practice Data flow diagrams, access logs, training data provenance
Harmful outputs Reasonable measures to prevent foreseeable harm Pre-deployment testing records, monitoring dashboards, incident logs
Inadequate disclosure Material omissions about AI use User research showing disclosure effectiveness, A/B test results
Privacy violations Compliance with stated policies Privacy impact assessments, consent records, data retention schedules
Bias and discrimination Testing for disparate impact Fairness metrics across demographic groups, bias mitigation controls

Action Item: Review your most recent model release. Can you document what consumer harms you considered, what testing you performed, and what monitoring you implemented? If not, you're not ready for an FTC inquiry.

The agency's investigations into OpenAI and Anthropic signal a clear strategy: existing consumer protection law applies to AI systems, and the FTC will use Section 5 authority when it sees consumer harm. Your compliance program needs to account for this reality now.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like