The FTC: deception, unfairness, and the delete-your-model remedy

Lesson 2 of 5 in Sectoral Enforcement: FTC, EEOC, CFPB, FDA, and Financial Regulators.

The Federal Trade Commission is the closest thing America has to a general-purpose AI regulator, and its power flows from a 1914 statute. Section 5 of the FTC Act prohibits ‘unfair or deceptive acts or practices’ — two words, two distinct theories:

Deception — a representation likely to mislead reasonable consumers. Applied to AI, this catches ‘AI washing’ (claiming AI that doesn’t exist or doesn’t work as advertised), overstated accuracy claims, and undisclosed material limitations. Deception cases are the FTC’s volume business because they need no proof of injury — just a misleading claim.

Unfairness — a practice causing substantial consumer injury that consumers cannot reasonably avoid and that isn’t outweighed by benefits. This is the heavier theory: it reaches deploying a harmful AI system carelessly, even where every marketing claim was true. Add the 6(b) study power — compulsory information demands on whole industries without alleging any violation — and the FTC can see inside AI markets before deciding whether to act.

Rite Aid (Dec 2023) — unfairness and the blueprint order

Rite Aid ran facial-recognition systems in stores to flag suspected shoplifters — with thousands of false matches that disproportionately hit women and people of color, based on low-quality watchlist images, no accuracy testing, and no vendor diligence. The FTC’s theory was pure unfairness: reckless deployment, not false advertising. The order banned Rite Aid from facial-recognition surveillance for five years and prescribed a full risk-management program for any future biometric system — testing, monitoring, human review, vendor oversight. Read that order once: it is the FTC writing an AI governance program into binding law for one company, and a template for every company.

Operation AI Comply (Sept 2024) — the deception sweep

Five simultaneous actions announced as a message: DoNotPay claimed to be ‘the world’s first robot lawyer’ that could substitute for attorneys — it couldn’t, and settled with refunds and claim bans; Rytr sold an AI tool whose ‘testimonial’ generator did one thing well: mass-produce fake reviews (the complaint framed providing the means of deception as itself a violation); Ascend Ecom and others sold get-rich schemes on AI-powered storefront hype. None of these needed an AI statute — just Section 5 and the substantiation doctrine: claims require evidence before you make them.

Evolv Technologies (Nov 2024) — safety claims meet Section 5

Evolv marketed AI weapons-scanners to schools as detecting all weapons; the FTC alleged the accuracy claims were deceptive — scanners missed knives that later injured students. The lesson generalizes: safety-critical AI marketing is still marketing, and every quantitative claim (‘detects X%’, ‘reduces incidents by Y’) is a substantiation target.

The companion-chatbot 6(b) inquiry (Sept 2025) — the study power

The FTC ordered major AI companion-chatbot providers to disclose how they design, test, and monetize bots interacting with children and teens — measuring engagement techniques, harm testing, and data practices. No violation alleged; that is the point of 6(b). Study orders map an industry and often seed the next wave of cases. Child-safety-focused AI enforcement is the most durable bipartisan theme in the field.

Then there is the remedy that concentrates minds: algorithmic disgorgement — an order to delete not just unlawfully collected data but the models trained on it. The FTC built the doctrine across Cambridge Analytica (2019), Everalbum (2021, face-recognition models trained on photos users never consented to), and WW/Kurbo (2022, models trained on children’s data collected in violation of COPPA). The logic: if the data was poison, the model is fruit of the poisoned tree — otherwise violators keep the competitive advantage the violation bought.

For a company whose core asset is a trained model, disgorgement is an existential remedy. It is the single strongest legal argument for data provenance discipline: know what went into every model, because you may one day have to prove it — or delete it.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.