The full map: securities, insurance, state AGs — and how to read it
Lesson 5 of 5 in Sectoral Enforcement: FTC, EEOC, CFPB, FDA, and Financial Regulators.
Four more enforcers complete the map. The SEC brought the first pure ‘AI-washing’ cases in March 2024: investment advisers Delphia and Global Predictions claimed AI-driven strategies they did not have and paid $400,000 combined — small money, loud signal: AI claims to investors are securities statements. FINRA issued guidance reminding broker-dealers that supervisory and record-keeping duties cover generative-AI use. NYDFS — regulator of Wall Street’s banks and insurers — issued October 2024 guidance treating AI-specific threats (deepfake social engineering, AI-enhanced attacks) under its cybersecurity regulation, and a circular requiring insurers using external data and AI in underwriting to prove they do not unfairly discriminate. And the NAIC’s Model Bulletin on insurers’ AI use (December 2023) has been adopted by well over half the states — a governance-program expectation (write an AIS program, govern vendors, test for unfair discrimination) spreading through insurance commissioners rather than legislatures.
Finally, the wildcard enforcers: state attorneys general. Texas AG Paxton’s settlement with Pieces Technologies (September 2024) is the archetype — a healthcare GenAI company advertising a ‘severe hallucination rate’ below one in 100,000 could not substantiate the metric, and settled under Texas’s ordinary deceptive-trade-practices act with duties to disclose meaning and limits of its accuracy claims. Massachusetts AG Campbell’s April 2024 advisory declared existing consumer-protection, anti-discrimination, and data-security law fully applicable to AI. Forty-plus AGs jointly warned AI companies over chatbot harms to minors. Every state has a UDAP statute; every AI claim is a potential target.
| Enforcer | Legal authority | Core AI theory | Landmark action |
|---|---|---|---|
FTC | FTC Act §5 (UDAP); 6(b) studies; COPPA | Deceptive AI claims (‘AI washing’); unfair reckless deployment; algorithmic disgorgement | Rite Aid facial-recognition ban (2023); Operation AI Comply sweep (2024); companion-chatbot 6(b) study (2025) |
EEOC / private Title VII suits | Title VII; ADA; ADEA | Disparate impact and treatment via algorithmic screening; ADA screen-out; vendor-as-agent liability | iTutorGroup settlement (2023); Mobley v. Workday ADEA collective action (2025) |
CFPB | ECOA / Regulation B; UDAAP (Dodd-Frank) | Specific adverse-action reasons — no black-box excuse | Circulars 2022-03 and 2023-03 (status post-2025 retrenchment: verify — the underlying statute binds regardless) |
FDA | FDCA device authorities | AI software as medical device; lifecycle control of adaptive models | 1,200+ AI-enabled devices authorized; PCCP framework; Jan 2025 draft guidances |
Fed / OCC | Safety-and-soundness supervision | Model risk management: effective challenge, validation, inventories, vendor models | SR 11-7 / OCC 2011-12 (2011) — applied to banks’ AI/ML models |
SEC / FINRA | Advisers Act & securities-fraud provisions; FINRA rules | AI-washing to investors; supervision of GenAI use in broker-dealers | Delphia & Global Predictions (Mar 2024, $400k) |
NYDFS / NAIC states | NY financial-services & insurance law; state insurance codes | AI cybersecurity threats; unfair discrimination in AI underwriting; insurer AI governance programs | NYDFS AI cyber guidance (Oct 2024); insurance circular on underwriting; NAIC Model Bulletin (Dec 2023), widely adopted |
State AGs (+ NYC DCWP) | State UDAP statutes; state civil-rights law; city ordinances | Unsubstantiated AI accuracy claims; chatbot harms; local bias-audit mandates | Texas AG v. Pieces Technologies (Sept 2024); Massachusetts AG advisory (Apr 2024); NYC LL144 enforcement via DCWP |
Interactive sorting exercise: Route each scenario to the enforcer with primary jurisdiction. Run the jurisdiction question first: what conduct, in what sector, under whose statute?
Zoom out and the agencies converge on the same expectations, whoever holds the pen. Substantiate every claim — accuracy numbers are legal representations (FTC, SEC, Texas AG). Tell people — notices at the point of decision (ECOA) and interaction. Test and monitor — untested deployment is the unfairness (Rite Aid), unvalidated use is the finding (SR 11-7). Own your vendors — agency liability (Mobley), vendor-model validation, third-party diligence. And documentation cuts both ways: the risk program that shows reasonableness is the same file an enforcer will read against you — write it like both audiences are coming, because they are.
Those five themes are, not coincidentally, the NIST AI RMF’s Measure and Manage functions restated as enforcement doctrine. That is the deep continuity of US AI law: the voluntary framework and the enforcement regime describe the same program — one as guidance, the other as consequences.
Tool: AI Incident Tabletop — Run the Incident Tabletop: an AI failure lands on your desk and you must identify every enforcer with jurisdiction, in order, before the clock runs out.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.