The full map: securities, insurance, state AGs — and how to read it

Lesson 5 of 5 in Sectoral Enforcement: FTC, EEOC, CFPB, FDA, and Financial Regulators.

Four more enforcers complete the map. The SEC brought the first pure ‘AI-washing’ cases in March 2024: investment advisers Delphia and Global Predictions claimed AI-driven strategies they did not have and paid $400,000 combined — small money, loud signal: AI claims to investors are securities statements. FINRA issued guidance reminding broker-dealers that supervisory and record-keeping duties cover generative-AI use. NYDFS — regulator of Wall Street’s banks and insurers — issued October 2024 guidance treating AI-specific threats (deepfake social engineering, AI-enhanced attacks) under its cybersecurity regulation, and a circular requiring insurers using external data and AI in underwriting to prove they do not unfairly discriminate. And the NAIC’s Model Bulletin on insurers’ AI use (December 2023) has been adopted by well over half the states — a governance-program expectation (write an AIS program, govern vendors, test for unfair discrimination) spreading through insurance commissioners rather than legislatures.

Finally, the wildcard enforcers: state attorneys general. Texas AG Paxton’s settlement with Pieces Technologies (September 2024) is the archetype — a healthcare GenAI company advertising a ‘severe hallucination rate’ below one in 100,000 could not substantiate the metric, and settled under Texas’s ordinary deceptive-trade-practices act with duties to disclose meaning and limits of its accuracy claims. Massachusetts AG Campbell’s April 2024 advisory declared existing consumer-protection, anti-discrimination, and data-security law fully applicable to AI. Forty-plus AGs jointly warned AI companies over chatbot harms to minors. Every state has a UDAP statute; every AI claim is a potential target.

The enforcement map: agency → authority → AI theory → landmark action
EnforcerLegal authorityCore AI theoryLandmark action

FTC

FTC Act §5 (UDAP); 6(b) studies; COPPA

Deceptive AI claims (‘AI washing’); unfair reckless deployment; algorithmic disgorgement

Rite Aid facial-recognition ban (2023); Operation AI Comply sweep (2024); companion-chatbot 6(b) study (2025)

EEOC / private Title VII suits

Title VII; ADA; ADEA

Disparate impact and treatment via algorithmic screening; ADA screen-out; vendor-as-agent liability

iTutorGroup settlement (2023); Mobley v. Workday ADEA collective action (2025)

CFPB

ECOA / Regulation B; UDAAP (Dodd-Frank)

Specific adverse-action reasons — no black-box excuse

Circulars 2022-03 and 2023-03 (status post-2025 retrenchment: verify — the underlying statute binds regardless)

FDA

FDCA device authorities

AI software as medical device; lifecycle control of adaptive models

1,200+ AI-enabled devices authorized; PCCP framework; Jan 2025 draft guidances

Fed / OCC

Safety-and-soundness supervision

Model risk management: effective challenge, validation, inventories, vendor models

SR 11-7 / OCC 2011-12 (2011) — applied to banks’ AI/ML models

SEC / FINRA

Advisers Act & securities-fraud provisions; FINRA rules

AI-washing to investors; supervision of GenAI use in broker-dealers

Delphia & Global Predictions (Mar 2024, $400k)

NYDFS / NAIC states

NY financial-services & insurance law; state insurance codes

AI cybersecurity threats; unfair discrimination in AI underwriting; insurer AI governance programs

NYDFS AI cyber guidance (Oct 2024); insurance circular on underwriting; NAIC Model Bulletin (Dec 2023), widely adopted

State AGs (+ NYC DCWP)

State UDAP statutes; state civil-rights law; city ordinances

Unsubstantiated AI accuracy claims; chatbot harms; local bias-audit mandates

Texas AG v. Pieces Technologies (Sept 2024); Massachusetts AG advisory (Apr 2024); NYC LL144 enforcement via DCWP

Interactive sorting exercise: Route each scenario to the enforcer with primary jurisdiction. Run the jurisdiction question first: what conduct, in what sector, under whose statute?

Zoom out and the agencies converge on the same expectations, whoever holds the pen. Substantiate every claim — accuracy numbers are legal representations (FTC, SEC, Texas AG). Tell people — notices at the point of decision (ECOA) and interaction. Test and monitor — untested deployment is the unfairness (Rite Aid), unvalidated use is the finding (SR 11-7). Own your vendors — agency liability (Mobley), vendor-model validation, third-party diligence. And documentation cuts both ways: the risk program that shows reasonableness is the same file an enforcer will read against you — write it like both audiences are coming, because they are.

Those five themes are, not coincidentally, the NIST AI RMF’s Measure and Manage functions restated as enforcement doctrine. That is the deep continuity of US AI law: the voluntary framework and the enforcement regime describe the same program — one as guidance, the other as consequences.

Tool: AI Incident Tabletop — Run the Incident Tabletop: an AI failure lands on your desk and you must identify every enforcer with jurisdiction, in order, before the clock runs out.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.