Tag: Business Use of AI

  • FTC’s AI Accuracy Proposal Turns Model Steering Into a Consumer-Protection Issue

    FTC’s AI Accuracy Proposal Turns Model Steering Into a Consumer-Protection Issue

    The Federal Trade Commission's proposed AI accuracy policy statement is not mainly about hallucinations. It is about consumer expectations, model objectives, and undisclosed steering.

    The Commission's theory is that AI companies often market their systems as tools that try to produce the best, most useful, truthful, or accurate output for the user's stated objective. If a company secretly steers the system toward a different objective, the FTC says that may be deceptive under Section 5 of the FTC Act.

    That framing matters because it moves some AI alignment, ranking, suppression, and output-design questions into consumer-protection territory. The proposed statement also takes aim at state AI laws, especially Colorado's revised AI Act, by warning that state-law-driven output changes may still violate Section 5 and may be impliedly preempted if they require deception.

    This is only a proposed policy statement. It is not a final rule, not an enforcement order, and not a litigated holding. But it is still important because it previews how the FTC may analyze AI systems that claim objectivity or accuracy while pursuing undisclosed output objectives.

    What The FTC Proposed

    The FTC issued the proposed policy statement on July 1, 2026. The agency is seeking public comment through July 31, 2026.

    The proposal says consumers reasonably expect AI systems to aim for truthful and accurate outputs that faithfully serve users' stated objectives and the built-in objectives users would reasonably expect from the system.

    The FTC is not saying that every wrong answer is automatically a Section 5 violation. The proposal distinguishes ordinary AI errors or hallucinations caused by technological and resource limits from intentional design choices that suppress accuracy or steer outputs toward unexpected objectives.

    The target is different: undisclosed steering away from the user's expected objective.

    In the FTC's words, an AI company may deceive consumers if it steers AI outputs toward unexpected objectives and away from the objectives set by or reasonably expected by users.

    Why This Is A Deception Theory

    The proposed statement rests on familiar FTC deception principles.

    Under the FTC's deception framework, a practice may be deceptive if there is a representation, omission, or practice likely to mislead reasonable consumers in a material way. The FTC says AI companies can make explicit and implicit representations that their systems are designed to solve users' problems accurately and faithfully.

    Those representations do not have to be magic words. A company may create the same impression through product positioning, accuracy claims, reliability claims, enterprise sales materials, public documentation, benchmark messaging, or statements that the AI is a trusted assistant, truth-seeking system, research tool, or decision-support product.

    If the company then silently optimizes the system for a conflicting objective, the FTC's theory is that consumers may be misled about what they are using and paying for.

    That does not mean an AI system can pursue only one objective. The proposal acknowledges that users may reasonably expect a system to balance accuracy, relevance, clarity, succinctness, safety, formatting, and other product objectives. The legal issue is whether a hidden objective contradicts the claim or consumer expectation that the system is trying to provide the best answer for the user's purpose.

    The Colorado Preemption Signal

    The most aggressive part of the proposal is its treatment of state AI laws.

    The FTC specifically discusses Colorado's AI framework and says an AI company might be tempted to suppress accuracy or interpose other objectives to avoid liability under state law. The Commission then says a company's motive for deception is irrelevant under Section 5, even if the company is acting to comply with state law.

    The proposal goes further: although the FTC Act does not expressly preempt state law, the Commission says state law is impliedly preempted to the extent it conflicts with a federal regulatory scheme. In the FTC's view, a state law that requires an AI firm to deceive consumers would conflict with Section 5's purpose of protecting consumers from deception.

    That is a major federalism signal, not just an AI-marketing point.

    Colorado is already in the middle of AI rulemaking and litigation. Its revised automated decision-making law and chatbot safety law are headed toward implementing rules, while xAI's federal challenge and DOJ's intervention have put the state framework under constitutional pressure.

    The FTC proposal adds another pressure point: even if a state law survives other challenges, the FTC may argue that compliance choices cannot be implemented through undisclosed output manipulation.

    Disclosures May Help, But They Need To Be Real

    The proposal does leave room for disclosure.

    An AI company can shape consumer expectations by truthfully explaining that its system prioritizes objectives different from the user's requested or expected objective. But the FTC says that disclosure would need to be clear and conspicuous enough to change the net impression.

    A buried term in a terms-of-service document is unlikely to do the job. The more the disclosure contradicts the system's marketing, interface, or ordinary value proposition, the more prominent and persistent the disclosure may need to be.

    That matters for product and governance teams. If a model is designed to rank, refuse, demote, rewrite, prioritize, or suppress outputs based on objectives that users would not expect, the disclosure question is not just whether the company has a policy somewhere. It is whether the user is likely to understand the product's actual objective at the moment the user relies on it.

    What This Is Not

    The proposal should not be overread in three ways.

    First, it is not a final rule. It is a proposed policy statement for public comment. The final language could change, and courts are not bound by the FTC's policy framing.

    Second, it is not a general ban on safety controls, content limits, cybersecurity restrictions, or refusal behavior. The proposal expressly recognizes that reasonable consumers would not expect systems to output certain illegal material, and it says nothing should be read to prohibit use limits that prevent cybersecurity attacks.

    Third, it is not a strict-liability rule for AI hallucinations. The proposal distinguishes intentional steering from ordinary incorrect outputs caused by model limitations. Companies can still face risk if they misrepresent hallucination rates or accuracy, but the policy statement's central concern is hidden objective substitution.

    Practical Questions For AI Companies

    Companies operating AI systems should treat the proposal as a prompt to audit objective, accuracy, and neutrality claims.

    Useful questions include:

    • What does the company expressly say about accuracy, truthfulness, objectivity, neutrality, reliability, helpfulness, or user control?
    • What does the interface imply about whether the system is trying to answer the user's actual question?
    • Are there hidden system objectives that can override the user's expected objective in ways that materially change output?
    • Are those objectives disclosed clearly enough for the relevant use case?
    • Are refusal, ranking, suppression, personalization, safety, and compliance policies documented and tied to defensible product rationales?
    • Do enterprise customers receive a different explanation than end users?
    • Do state-law compliance controls change outputs in a way users would not expect?
    • Does the company have evidence supporting claims about accuracy, reliability, model behavior, and output controls?

    The documentation point is especially important. If a regulator asks why a system suppressed, altered, or prioritized certain outputs, the company should be able to show the governing policy, the consumer-facing explanation, the product rationale, and the testing record.

    Why Enterprise Buyers Should Care

    The proposal is not only a model-provider issue.

    Enterprise buyers increasingly rely on AI systems for research, customer service, knowledge management, legal workflows, HR support, financial analysis, education, health information, and other consequential contexts. If an AI vendor's system is secretly optimized for objectives the buyer does not understand, the buyer may inherit operational, compliance, and customer-facing risk.

    Procurement teams should ask vendors how they define accuracy, what objectives can override user instructions, how output policies are disclosed, whether customers can configure those policies, and what logs or documentation are available when an output is challenged.

    For regulated buyers, the question is simple: if the AI system is not trying to answer the user's question in the way the user reasonably expects, who knows that, who approved it, and where is it disclosed?

    Bottom Line

    The FTC's proposed AI accuracy policy statement turns hidden model steering into a consumer-protection issue.

    The proposal does not say every AI error is unlawful. It says companies may deceive consumers when they market AI systems as accurate, objective, or faithful to user goals while secretly steering outputs toward different objectives.

    That is a useful warning even before the statement is final. AI governance should not stop at whether a system is powerful or safe. It should also ask whether the system's actual objective matches what users are told.

    Sources

    Sources

  • EU AI Act Transparency Code Turns AI-Generated Content Labels Into Compliance Work

    EU AI Act Transparency Code Turns AI-Generated Content Labels Into Compliance Work

    The European Commission has published the final Code of Practice on marking and labelling AI-generated content.

    The Code is voluntary. Article 50 of the EU AI Act is not.

    That distinction is the whole story. The Code does not create a new legal duty, and it does not replace the AI Act or the Commission's forthcoming Article 50 guidelines. But it gives providers and deployers of generative AI systems a practical framework for showing how they plan to meet transparency obligations that start applying on August 2, 2026.

    For companies, this is not just a question of adding a watermark. It is a governance project involving content provenance, machine-readable marking, deepfake labels, public-interest text, user notices, human review, editorial responsibility, and evidence of compliance.

    For broader AI law tracking context, see Clearon's Laws, Bills & Regulations page.

    What The Code Covers

    The Code has two main sections.

    Section 1 is for providers of generative AI systems. It addresses marking and detection of AI-generated or manipulated audio, image, video, and text content. The Commission's materials describe the focus as machine-readable solutions that are effective, interoperable, robust, and reliable as far as technically feasible.

    Section 2 is for deployers of generative AI systems. It addresses labelling of deepfakes and AI-generated or AI-manipulated text published for the purpose of informing the public on matters of public interest.

    The EU has also published optional icons that deployers may use for AI-generated-content labels.

    That provider/deployer split matters. Some organizations will sit on both sides. A company that offers a generative AI system may have provider obligations. The same company may also be a deployer when it uses generative AI to publish or distribute content.

    What Starts On August 2, 2026

    The Commission says Article 50 transparency obligations for providers and deployers in scope will apply from August 2, 2026. AI systems placed on the market before that date get a transitional period until December 2, 2026.

    From August 2, key obligations include clear labelling in certain cases. Deepfakes and AI-generated or AI-manipulated text published on matters of public interest must be clearly labelled. Users must also be informed when they are interacting with an interactive AI system, such as a chatbot.

    Those requirements are broader than a technical watermarking problem. They require companies to know what content they generate, where it travels, who publishes it, whether the publication is about a matter of public interest, and whether human review or editorial responsibility changes the compliance analysis.

    Why A Voluntary Code Still Matters

    The Code is voluntary, but signing it can matter.

    The Commission says that, after a positive adequacy assessment by the Commission and the AI Board, providers and deployers that sign the Code can rely on its measures to demonstrate compliance with the AI Act's transparency rules for labelling and detection of AI-generated content, deepfakes, and certain text publications.

    By contrast, companies that comply through other means will have to show that their measures are adequate. Those alternative measures may be assessed individually by different market surveillance authorities.

    That creates a practical choice. Signing the Code may offer predictability and a common EU-wide evidence path. Not signing may preserve flexibility, but companies will need their own substantiated compliance record.

    Either way, the work has to be done.

    What Remains Pending

    The Code is not the last word.

    The Commission says the Code is undergoing adequacy assessment by the Commission and the AI Board. It will also be complemented by Commission guidelines on the scope and implementation of Article 50.

    Those guidelines are expected ahead of August 2, 2026. The Commission says they will clarify which providers, deployers, and AI systems are covered; what types of AI-generated or manipulated content fall within scope; how the obligations should be applied in practice; and how compliance may be demonstrated, including through a Code deemed adequate by the Commission and the AI Board.

    That means companies should not treat the Code as a final standalone compliance manual. They should treat it as the first concrete implementation framework and then reconcile it with the final guidelines when they are published.

    The Compliance Workstream

    Companies should start with an inventory.

    For providers, the inventory should identify which systems generate audio, image, video, or text outputs; what marking or detection methods are already used; whether those methods are machine-readable; and whether they are effective, interoperable, robust, and reliable enough to defend.

    For deployers, the inventory should identify where the organization publishes or distributes AI-generated or AI-manipulated content, including marketing content, public reports, news-like content, social posts, synthetic audio or video, and content that may qualify as public-interest text.

    The harder questions are operational:

    • Who decides whether content is a deepfake?
    • Who decides whether text informs the public on a matter of public interest?
    • What counts as sufficient human review?
    • What records show that editorial responsibility exists?
    • Where should labels, disclaimers, or icons appear?
    • How will labels survive syndication, reposting, formatting changes, or downstream distribution?
    • How will product, legal, trust and safety, marketing, and publishing teams coordinate?

    Those questions should not wait until August 2026.

    What Companies Should Do Now

    A practical Article 50 readiness plan should include:

    • mapping provider and deployer roles for each generative AI system and content workflow;
    • identifying AI-generated and AI-manipulated audio, image, video, and text outputs;
    • documenting existing watermarking, metadata, provenance, detection, and labelling controls;
    • deciding whether the company is likely to sign the Code;
    • tracking the Commission and AI Board adequacy assessment;
    • tracking the final Article 50 guidelines;
    • designing labels, disclaimers, or icons for relevant content types;
    • creating rules for deepfakes, public-interest text, human review, and editorial responsibility;
    • testing whether labels remain visible and understandable across distribution channels; and
    • keeping evidence that the organization evaluated and implemented proportionate transparency controls.

    The key is to treat AI-generated-content transparency as a cross-functional compliance process, not a last-minute design ticket.

    Bottom Line

    The EU AI Act transparency Code turns Article 50 from an abstract deadline into a working plan.

    The Code is voluntary, but it points to the evidence regulators may expect: provider-side marking and detection, deployer-side labelling, clear treatment of deepfakes and public-interest text, and a record showing how the organization chose and implemented its controls.

    Companies do not need to wait for the final guidelines to start the inventory. By the time Article 50 applies, the hard part will not be knowing that labels are required. It will be proving that the right content was identified, labelled, marked, reviewed, and documented.

    Sources

    Sources

  • AI Companion Safety Laws Are Becoming a Real Compliance Category

    AI Companion Safety Laws Are Becoming a Real Compliance Category

    AI companion safety is no longer just a product-policy issue.

    New York has announced that its AI companion safeguards are now in effect. California has already enacted a companion chatbot law. Oregon has now chaptered SB 1546 as another companion-chatbot law with disclosure duties and a private enforcement path. The FTC has opened a federal inquiry into companion chatbots and children. Florida's lawsuit against OpenAI and Sam Altman puts chatbot safety, minors, addiction, self-harm, and consumer protection into a state enforcement complaint.

    The common thread is clear: regulators are starting to treat emotionally responsive chatbots as a distinct risk category.

    That does not mean every chatbot is an AI companion. It does mean that products designed to simulate friendship, romantic connection, coaching, therapeutic support, or persistent emotional engagement should be reviewed differently from ordinary search, drafting, support, or productivity tools.

    New York's Effective Law Is The Immediate Hook

    New York Governor Kathy Hochul announced that the state's AI companion safeguards are now in effect and that companies received an open letter notifying them of the requirements.

    The New York announcement describes AI companions as systems designed to simulate human relationships, including products that may pose as an AI friend or romantic partner, remember personal details, adapt to user preferences, and keep users engaged.

    Under New York's General Business Law Article 47, AI companion operators must implement safety protocols when a user expresses suicidal ideation or self-harm, including referral to crisis service providers. They must also notify users that they are interacting with AI, not a human, including conspicuous notices at the start of a session and recurring notices every three hours of continued companion use.

    The law is enforceable by the New York Attorney General, and penalties collected for noncompliance support suicide-prevention programs.

    That is a different regulatory model from a generic AI disclosure rule. It is a targeted law for products that use AI to sustain emotionally salient interaction.

    California Adds A Second State Model

    California's SB 243 points in the same direction, but with its own structure.

    The law adds a companion chatbot chapter to the California Business and Professions Code. It defines a companion chatbot as an AI system with a natural language interface that provides adaptive, human-like responses and is capable of meeting a user's social needs, including by exhibiting anthropomorphic features and sustaining a relationship across multiple interactions.

    The California law requires nonhuman disclosures where a reasonable person could be misled into believing they are interacting with a human. It also imposes requirements directed at known minors, suicide or self-harm protocols, publication of protocol details, annual reporting beginning July 1, 2027, and a private civil action for injury in fact caused by noncompliance.

    California's law includes exclusions for ordinary customer service, business operations, productivity and analysis related to source information, internal research, technical assistance, certain video-game bots, and some standalone voice-assistant devices.

    Those exclusions matter. They show that the emerging target is not "all chatbots." The target is a narrower category of systems that can create persistent relationship-like interaction and foreseeable emotional dependency.

    Oregon Adds A Third State Model

    Oregon's SB 1546 is now chaptered as Chapter 85.

    The law adds another enacted state model for companion-style AI. It requires notice when a reasonable person would believe they are interacting with a natural person, and the official state materials indicate a harmed user can seek damages and injunctive relief.

    That matters because it shows the category is no longer a two-state outlier. It is becoming a repeat legislative pattern with similar disclosure and safety logic.

    The FTC Is Asking The Same Questions

    The FTC's companion-chatbot inquiry gives the federal overlay.

    In September 2025, the Commission issued 6(b) orders to seven companies that provide consumer-facing AI chatbots. The orders seek information about how companies measure, test, and monitor potentially negative impacts on children and teens.

    The FTC said companion chatbots can mimic human characteristics, emotions, and intentions, and may prompt some users, especially children and teens, to trust and form relationships with them.

    The inquiry asks about monetization of user engagement, processing of user inputs and outputs, character development and approval, pre- and post-deployment testing, mitigation of negative impacts, disclosures to users and parents, compliance with age restrictions and community rules, and use or sharing of personal information from chatbot conversations.

    That list is useful even outside the FTC inquiry. It reads like a regulator's checklist for companion-chatbot governance.

    Florida Shows The Enforcement Bridge

    Florida's lawsuit against OpenAI and Sam Altman is not a companion-chatbot statute. It is a state enforcement lawsuit built around consumer protection, child data, product design, warnings, safety claims, and alleged public-health harms.

    But it belongs in the same conversation.

    Florida alleges, among other things, that OpenAI marketed ChatGPT to the public, including minors, while concealing or downplaying serious risks. The complaint pleads state unfair-practices theories, COPPA-related allegations, negligence, product-liability theories, fraudulent misrepresentation, and public nuisance. Those are allegations, not findings of liability.

    The significance is that state enforcers may not wait for companion-specific statutes. If a chatbot is marketed as safe, emotionally responsive, helpful, or suitable for younger users, existing consumer-protection and product-liability theories may become the enforcement vehicle.

    Companion chatbot laws are one lane. State AG lawsuits are another. The risk category is converging.

    What Makes A Companion Chatbot Different

    The emerging legal concern is not simply that a chatbot talks.

    It is that a chatbot can create the appearance of a relationship, remember intimate details, personalize responses over time, initiate or sustain emotionally charged conversation, and monetize continued engagement.

    That makes the compliance analysis different from a basic AI assistant.

    Key questions include:

    • Does the product present itself as a friend, romantic partner, confidant, coach, therapist-like support, or emotionally available persona?
    • Can it remember personal details or sustain a relationship across sessions?
    • Is the product designed to increase session length, emotional reliance, or daily engagement?
    • Can minors access the product, or can the operator reasonably know the user is a minor?
    • Does the product discuss self-harm, eating disorders, sexual content, mental health, violence, substance use, medical advice, legal advice, or financial advice?
    • Are users repeatedly reminded that they are interacting with AI rather than a human?
    • Is there a tested crisis-intervention protocol, and does it work in practice?
    • Are parents or guardians given meaningful notice, controls, or escalation paths where minors are involved?

    Those questions are becoming legal questions, not just UX questions.

    The Compliance Baseline Is Taking Shape

    Across New York, California, Oregon, the FTC inquiry, and the Florida lawsuit, several expectations are starting to repeat.

    First, nonhuman disclosure is becoming table stakes. A buried one-time disclaimer is less persuasive for a product designed around relationship-like engagement. Recurring reminders may become the default expectation for sustained companion use.

    Second, crisis-intervention protocols need to be operational, not aspirational. Regulators are asking whether systems detect suicidal ideation or self-harm, what they do next, whether they refer users to crisis resources, and whether the process is documented and tested.

    Third, minor-specific safeguards are moving from policy statements into law. Age gates, age assurance, parental notice, sexual-content restrictions, and youth-specific warnings are likely to draw scrutiny.

    Fourth, engagement design is becoming relevant. If the business model depends on maximizing time spent with an emotionally responsive system, regulators may ask whether product incentives increase foreseeable harm.

    Fifth, safety claims need substantiation. If a company says its companion is safe, supportive, appropriate for teens, or beneficial for mental health, it should be able to show testing, limits, incident review, and warning design that support those claims.

    What Companies Should Do Now

    Companies offering companion chatbots should build a dedicated review path for emotionally engaging AI systems.

    That review should cover:

    • product definitions and whether the system fits state companion-chatbot statutes;
    • age gating, age estimation, minor-account flows, and parental controls;
    • recurring AI-identity disclosures and session-duration notices;
    • crisis-detection and escalation protocols for self-harm and suicide-related content;
    • restrictions on sexual content, manipulation, dependency, and high-risk advice for minors;
    • logging and incident-review workflows for serious safety events;
    • pre-launch and post-launch testing for known risk categories;
    • marketing claims about safety, companionship, emotional support, wellness, therapy-like benefits, minors, or family use;
    • data collection, retention, personalization, memory, and sharing practices for sensitive conversations;
    • reporting obligations, including California's future annual reporting requirement; and
    • documentation showing how design choices were evaluated before release.

    The documentation point is important. In this area, "we have safeguards" is unlikely to be enough. Companies should be able to explain what the safeguards are, why they were chosen, how they were tested, what limits remain, and how incidents are handled.

    Bottom Line

    AI companion safety is becoming its own compliance category.

    New York, California, and Oregon are turning relationship-like chatbots into a statutory subject. The FTC is studying how companion chatbots affect children and teens. State attorneys general are testing broader consumer-protection theories against chatbot safety claims, minors, data practices, and product design.

    For companies building consumer AI, the practical lesson is direct: do not review companion products like ordinary chat interfaces.

    If the product is designed to feel human, keep users engaged, and support emotional reliance, it needs a companion-safety file before a regulator asks for one.

    Sources

  • Florida v. OpenAI Turns Chatbot Safety Into a State Consumer-Protection Case

    Florida v. OpenAI Turns Chatbot Safety Into a State Consumer-Protection Case

    Florida's lawsuit against OpenAI and Sam Altman is a state attorney general trying to turn chatbot safety into a consumer-protection, child-data, product-liability, and public-nuisance case.

    The complaint is only allegations. OpenAI and Altman have not been found liable. But the filing is still important because it shows how state enforcers may try to use existing legal tools against AI products without waiting for a comprehensive AI statute.

    The theory is direct: if a company markets a consumer chatbot as safe, reliable, useful for minors, or emotionally responsive, then product design, warnings, age controls, data collection, and safety testing may become consumer-protection issues.

    What Florida Filed

    The Florida Attorney General announced a civil action against several OpenAI entities and Sam Altman in Florida state court. The release describes it as a first-in-the-nation state-led lawsuit against OpenAI and its CEO.

    The state alleges that OpenAI knowingly released and aggressively marketed ChatGPT to the public, including children, while concealing serious risks and downplaying the danger of the product.

    The complaint seeks damages, civil penalties, injunctive relief, and abatement of an alleged public nuisance. It also says the state is pursuing the civil action separately from an ongoing Office of Statewide Prosecution criminal investigation relating to chat logs reviewed after the Florida State University shooting.

    That distinction matters. The civil lawsuit is not a criminal charge. It is also not a court finding that ChatGPT caused any specific harm. It is an enforcement complaint that still has to survive litigation.

    The Claims Are Broader Than Deception

    The complaint starts with Florida's Deceptive and Unfair Trade Practices Act, but it does not stop there.

    Florida pleads several FDUTPA theories. It alleges unfair practices, unconscionable practices, deceptive practices, and a FDUTPA theory tied to alleged violations of COPPA and its implementing regulations.

    The complaint also pleads negligence, gross negligence, strict liability for design defect, strict liability for failure to warn, fraudulent misrepresentation, and public nuisance.

    That mix is the real story. Florida is not only saying "the marketing was misleading." It is saying the chatbot's design, deployment, safeguards, age access, warnings, and data practices belong inside the enforcement case.

    For AI companies, that is the move to watch. State AGs do not need an AI-specific statute if they can plead old claims around new product behavior.

    The Minor-Data Theory

    One of the most concrete parts of the complaint is the child-data theory.

    Florida alleges that OpenAI has actual knowledge that children under 13 use ChatGPT, that users can input false dates of birth, and that OpenAI collects personal data through user conversations. The complaint says OpenAI fails to provide adequate notice to parents and fails to obtain verifiable parental consent before collecting or using children's personal information.

    Florida frames that as a FDUTPA issue by pointing to COPPA. The complaint says the state is not bringing a direct COPPA enforcement claim. Instead, it alleges that conduct violating COPPA and its rules can serve as an unfair practice under Florida law.

    That is a practical warning for consumer AI products. Even when the immediate lawsuit is brought under a state unfair-practices statute, federal child-privacy standards may still shape what the state calls unfair.

    The risk is especially sharp for products that:

    • are available to minors;
    • collect conversational, audio, image, location, health, or other personal data;
    • use memory or personalization features;
    • do not require robust age assurance;
    • depend on voluntary parental linking rather than default parental oversight; or
    • are marketed as helpful, supportive, educational, or safe for young users.

    The Safety-Representation Theory

    Florida also attacks safety messaging.

    The complaint alleges that OpenAI represented safety as part of its mission and made statements suggesting ChatGPT helps keep teens safe by default. Florida says those statements were misleading because, in its view, ChatGPT can produce dangerous responses, encourage unhealthy use, and create risks for minors and vulnerable users.

    This is a familiar consumer-protection structure applied to an AI product. A company does not need to promise perfection to create legal exposure. If it makes safety a selling point, regulators may ask whether the product design, warnings, testing, and deployment record match the claim.

    That is why AI companies should treat safety language like a substantiation problem. Claims such as "safe," "trusted," "reliable," "age appropriate," "guardrailed," "supervised," or "keeps teens safe" should be tied to evidence, limits, and current product behavior.

    The more sensitive the use case, the more careful the claim needs to be.

    The Product-Liability Move

    The complaint also tries to treat ChatGPT as a product for purposes of strict product liability.

    Florida alleges design defect and failure to warn. It says ordinary consumers would not expect a generative AI chatbot to proactively provide suggestions about self-harm or violence, or to contribute to cognitive decline or behavioral addiction in teenagers. It also alleges that risks could have been reduced by reasonable alternative designs and better safety testing.

    Those are allegations, and they raise hard questions that courts will have to confront. Is a generative AI service a product for strict-liability purposes? What counts as a design defect in a probabilistic model? What warnings are adequate for a general-purpose chatbot? How should courts treat intervening user conduct, misuse, and causation?

    Those questions are unsettled. But the fact that a state AG is pleading them matters.

    The next wave of AI litigation will not be limited to privacy claims or deceptive marketing. Plaintiffs and regulators will test whether product-liability doctrines can reach model behavior, release decisions, safety tradeoffs, and warning design.

    The Public-Nuisance Theory

    Florida's public-nuisance claim is also worth watching.

    The complaint alleges that the design and function of ChatGPT, including alleged encouragement of self-harm, violence, eating disorders, AI addiction, cognitive decline, and other harms, created a public nuisance affecting health and safety in Florida.

    Public nuisance has become a common tool in large public-harm litigation, but it is also heavily contested. Courts have not uniformly accepted efforts to use nuisance law for products or technology platforms. OpenAI will almost certainly challenge the theory.

    Even so, the claim signals how state enforcers may frame AI harm: not only as individual injury, but as a public-health and public-safety problem.

    That framing fits the broader state trend around companion chatbots, minors, crisis-intervention protocols, and recurring AI disclosures.

    For a closer look at that related trend, see Clearon's analysis of AI companion safety as an emerging compliance category.

    Why This Is Different From A Private Product Case

    The lawsuit matters partly because of who filed it.

    A private plaintiff usually has to prove individual injury, causation, damages, and standing. A state attorney general can frame the case around public enforcement, civil penalties, injunctive relief, public interest, and statewide consumer harm.

    That changes the litigation posture. It also changes the remedy discussion.

    Florida is asking for orders that would stop alleged misrepresentations, restrict collection and processing of data from children under 13 without notice and verifiable parental consent, require warnings about risk, and impose monetary relief. The complaint also seeks civil penalties up to $10,000 per FDUTPA violation and other damages or equitable relief.

    Whether Florida can obtain those remedies is a merits question. But the requested relief shows what state enforcers may want from consumer AI companies: not just money, but changes to product design, data handling, warnings, and minor-safety defaults.

    What AI Companies Should Do Now

    The safest response is not to treat this as a one-off Florida fight.

    Consumer AI companies should review:

    • safety claims in marketing, help pages, launch posts, investor materials, and teen/minor-facing materials;
    • age-gating, age-estimation, and minor-account flows;
    • parental notice, consent, and oversight features;
    • memory, personalization, and conversational-data retention practices;
    • chatbot responses involving self-harm, violence, eating disorders, mental health, drugs, weapons, legal advice, medical advice, and financial advice;
    • release-readiness records for major model updates;
    • incident escalation and red-team documentation;
    • warnings and user-facing disclosures for risky uses; and
    • how crisis-intervention protocols work in practice.

    This does not mean every chatbot is illegal or every safety failure is an unfair practice. It does mean that consumer AI products should be able to explain what they knew, what they tested, what they warned, what they blocked, and how they treated minors.

    That record will matter if an AG, plaintiff, regulator, or court asks whether the product was marketed and deployed responsibly.

    Bottom Line

    Florida v. OpenAI is early-stage litigation, not a judgment.

    It is still a concrete sign that state AGs are beginning to treat chatbot safety as ordinary consumer protection, not as a futuristic AI policy question.

    For companies building consumer-facing AI, the lesson is simple: safety claims, child-data practices, warnings, and release decisions are legal artifacts. They should be reviewed like legal artifacts before they become exhibits.

    Sources

    Sources

  • FTC’s Active Listening Settlement Turns AI-Washing Into a Privacy Problem

    FTC’s Active Listening Settlement Turns AI-Washing Into a Privacy Problem

    The Federal Trade Commission's proposed "Active Listening" settlements connect three risks that often travel together: AI-washing, adtech targeting claims, and weak consent theories.

    The FTC says Cox Media Group and two marketing firms falsely claimed to offer an AI-powered service that could target localized ads based on conversations captured from consumers' smart devices. According to the FTC, the service did not use voice data at all. It allegedly resold data-broker email lists at a markup and did not accurately place ads in customers' desired locations.

    That would be a straightforward deception case on its own. But the FTC went further. It also said the companies misled customers by claiming consumers had opted into the alleged listening service. And the agency added a point that should get the attention of every company making privacy-sensitive AI claims: if the service had actually worked as advertised, collecting and using consumers' voice data from inside their homes without adequate consent would itself violate Section 5 of the FTC Act.

    In other words, the problem was not only that the AI claim was false. The claimed AI capability was itself a privacy-risk representation.

    What The FTC Alleged

    The FTC announced proposed settlements with CMG Media Corporation, doing business as Cox Media Group, plus MindSift LLC and 1010 Digital Works LLC. The alleged customers were businesses buying advertising and marketing services, not the consumers whose supposed smart-device conversations were described in the pitch.

    The companies allegedly marketed an "Active Listening" advertising service that could listen in on consumer conversations overheard by smart devices, detect relevant conversations in real time, and use that information to target ads to consumers in specific geographic areas.

    The FTC says that was not true. According to the agency, the service was not based on voice data, did not listen to consumer conversations, and did not accurately place ads in the customers' desired locations. Instead, the service allegedly consisted of reselling email lists obtained from data brokers.

    The agency also says the companies told customers that consumers had opted into the service. But the FTC says the companies did not seek or obtain consumer consent. The agency specifically rejected the idea that consumers "opted in" by clicking through mandatory app terms of service.

    That consent point is the heart of the case for AI governance teams. Many AI products rely on layered data flows, third-party data, contractual assurances, or generalized platform terms. The FTC's framing says those shortcuts may not support privacy-sensitive claims, especially where the asserted capability involves intimate in-home voice data.

    The Settlement Terms

    The proposed orders require a total of $930,000 in payments: $880,000 from CMG and $25,000 each from MindSift and 1010 Digital Works. The money is intended to provide redress to CMG customers affected by the alleged practices.

    The proposed orders would also prohibit each defendant from making misrepresentations about:

    • the qualities or features of advertising or marketing services;
    • the collection and use of voice data, including whether consumers consented to collection, use, or disclosure; and
    • the geographic targeting capabilities of advertising or marketing services.

    The FTC issued the proposed administrative complaints and accepted the consent agreements by a 2-0 vote. The agreements remain subject to a 30-day public-comment period after publication in the Federal Register. If the orders become final, each violation may lead to a civil penalty of up to $53,088.

    As usual, the settlements resolve allegations. They are not admissions of liability or litigated findings.

    Why The Money Is Procedurally Important

    The $930,000 payment should not be read as the FTC simply using Section 13(b) to disgorge money from the companies.

    That route is no longer available after the Supreme Court's 2021 decision in AMG Capital Management, LLC v. FTC. In AMG, the Court held that Section 13(b) of the FTC Act authorizes the FTC to seek prospective injunctive relief, but does not authorize courts to award equitable monetary relief such as restitution or disgorgement for past conduct.

    That matters here because the FTC is resolving the Active Listening allegations through proposed administrative consent orders, not by relying on Section 13(b) alone to obtain monetary relief in federal court.

    If the parties agree, the FTC can include monetary terms in a settlement package. If they do not agree and the FTC wants monetary relief for an ordinary unfair or deceptive act or practice, the post-AMG route is more cumbersome. The FTC generally must proceed administratively under Section 5, obtain a final cease-and-desist order, and then seek consumer redress under Section 19 if the statutory standard is met, including that a reasonable person would have known under the circumstances that the conduct was dishonest or fraudulent.

    Civil penalties are different again. A first-time Section 5 deception allegation does not automatically produce civil penalties simply because the FTC believes the conduct was deceptive. Penalties typically require an independent penalty hook, such as violation of a final FTC order, violation of certain rules, or another statutory basis. That is why the FTC's release says that if these proposed orders become final, future violations of the orders may carry civil penalties of up to $53,088 per violation.

    So the practical sequence is:

    • settlement now, if the parties agree to money and conduct restrictions;
    • prospective injunctive relief under Section 13(b), but not standalone disgorgement or restitution after AMG;
    • administrative Section 5 proceedings followed by Section 19 redress for qualifying deceptive or unfair practices if there is no settlement; and
    • civil penalties later if a final order, rule, or other penalty-triggering authority is violated.

    What About AT&T?

    There are two AT&T references that can get confused.

    The Supreme Court's FCC v. AT&T Inc. decision does not do much work here. That case addressed whether corporations have "personal privacy" interests under FOIA Exemption 7(C). It is not an FTC Act remedies case and does not change the AMG limit on Section 13(b), the Section 5 administrative route, or the Section 19 redress path.

    The more relevant AT&T case for FTC authority is FTC v. AT&T Mobility LLC, the Ninth Circuit's 2018 en banc decision about the FTC Act's common-carrier exemption. The Ninth Circuit held that the exemption is activity-based, not status-based: a company is outside FTC Section 5 authority only to the extent it is engaged in common-carrier activity.

    That issue is not central to the Active Listening settlements because CMG, MindSift, and 1010 Digital Works are being treated as marketing and advertising-service defendants, not common carriers. But the case would matter if a telecom, broadband, or smart-device company raised a common-carrier defense to an FTC challenge involving AI-powered targeting, voice data, or marketing claims. In that setting, the question would be whether the challenged conduct is common-carrier activity or a non-common-carrier advertising, data, or marketing practice.

    Why This Is More Than an AI-Washing Case

    AI-washing cases usually focus on whether a product actually uses AI, whether the claimed performance is substantiated, or whether the term "AI-powered" is being used as a sales shortcut.

    This case adds a different lesson: the advertised AI function may create its own legal problem.

    If a company claims it can listen to private conversations through smart devices, the claim is not just a product-capability statement. It is a statement about data collection, surveillance, consent, security, and consumer expectations inside the home.

    The FTC's line is unusually direct. It says mandatory app terms do not equal opt-in consent for an invasive service or for the use of consumers' voice data from inside their homes.

    That matters even for companies that are not doing audio targeting. The same logic can apply to AI claims involving:

    • biometric inference;
    • location-based targeting;
    • health or mental-health signals;
    • children's or teens' behavior;
    • financial vulnerability;
    • workplace monitoring;
    • emotion detection;
    • private-message analysis; or
    • household-device data.

    When the marketed AI feature depends on sensitive data, the claim must be true, substantiated, and backed by a consent theory that fits the sensitivity of the data.

    The "Means and Instrumentalities" Piece

    The FTC also charged MindSift and 1010 Digital Works with providing CMG the "means and instrumentalities" to deceive customers through marketing materials, sales pitches, and responses to customer questions.

    That is an important vendor and partner lesson. A company does not necessarily avoid risk because another company owns the customer relationship. If it supplies misleading AI claims, sales materials, or talking points that others use with customers, it can become part of the deception theory.

    Adtech and AI vendors should treat this as a documentation and channel-control problem. Marketing claims should be reviewed not only on the vendor's website, but also in partner decks, reseller scripts, pitch emails, FAQs, demos, and objection-handling materials.

    What Companies Should Do Now

    The FTC's case points to several practical controls.

    First, inventory AI capability claims. Identify every place the company says an advertising, analytics, targeting, personalization, monitoring, or customer-intelligence product is "AI-powered," "real time," "listening," "detecting," "predicting," or "consent based."

    Second, match each claim to evidence. The proof should show not only that the technology can do what the company says, but that the deployed product actually does it in the advertised context.

    Third, separate data-source claims from model claims. Saying a system uses AI does not prove what data it uses. Saying a system uses a data source does not prove that consumers consented to that use.

    Fourth, review consent language with sensitivity in mind. Broad mandatory terms may not support claims about invasive data collection. If the advertised feature involves voice, biometrics, location, children, health, finances, or household data, the consent record needs to be much stronger.

    Fifth, audit partner materials. Vendors and agencies should not assume that downstream sales claims are someone else's problem. Resellers should not repeat vendor claims without understanding what the product actually does and what evidence supports the claim.

    Finally, avoid "it would be worse if true" marketing. A privacy-invasive capability can create legal risk even when it is imaginary. If a company would need strong consent, privacy notices, security controls, and compliance review to lawfully operate the feature, it should not casually advertise that capability as a sales hook.

    Bottom Line

    The FTC's Active Listening settlements show how quickly AI marketing can become a privacy and consumer-protection case.

    The alleged service did not listen to consumers' conversations. But the FTC still treated the claim as serious because customers were told the service used AI to target ads from smart-device conversations and that consumers had opted in.

    That is the lesson for AI products generally: do not sell a capability the product does not have, and do not claim sensitive-data consent that the company cannot prove. When the AI story depends on surveillance-like data, the marketing review is also a privacy review.

    Sources

    Sources

  • Institutional Knowledge May Be Legal AI’s Main Competitive Layer

    Institutional Knowledge May Be Legal AI’s Main Competitive Layer

    The Harvey-DeepJudge partnership offers a clear picture of where legal AI is heading next: toward institutional knowledge.

    Harvey brings the workflow layer. DeepJudge brings prior work, negotiated positions, internal expertise, and permissions-aware access to what a firm or legal department already knows. Put together, the pitch is simple: AI should do more than produce a plausible answer. It should reflect how the organization actually practices.

    What is actually at stake

    A lot of legal AI value will be won or lost here.

    If a system cannot reflect prior positions, accepted language, internal judgment, and ethical-wall-aware access rules, the output may be fast but still generic. Useful, maybe. Institutional, no.

    The deeper buyer question is shifting from model quality alone to whether the model can operate inside the knowledge, permissions, and standards that make a legal team distinctive.

    What the partnership signals

    Harvey and DeepJudge are betting that the next wave of legal AI will be less about raw model performance and more about context control.

    That means legal teams should pay closer attention to:

    • how AI reaches internal knowledge
    • whether permissions and ethical walls stay intact
    • how prior work informs drafting and analysis
    • whether outputs reflect firm-specific or department-specific standards

    The bigger shift

    This fits the same broader pattern visible across iManage, Harvey, Anthropic, and other legal AI players. The market is moving away from model quality alone and toward workflow ownership, governed context, and knowledge grounding.

    That may sound less flashy than another reasoning benchmark. It is also much closer to where real legal advantage lives.

    Practical guide: Legal AI Workflows: A Governance Checklist for Legal Teams

  • Governed Context May Be Legal AI’s Main Infrastructure Layer

    Governed Context May Be Legal AI’s Main Infrastructure Layer

    iManage's latest platform shift puts a spotlight on a layer that much legal AI coverage still underrates: governed context.

    At ConnectLive 2026, iManage described a platform built around a context fabric, AI-specific controls, agent monitoring, and MCP-based access to institutional knowledge. Strip away the branding and the message is simpler: legal AI infrastructure is not only the model. It is also the system that controls what the model can safely reach.

    Where this gets real

    For law firms and in-house teams, a good demo is not enough. If AI cannot reach the right knowledge, respect permissions, preserve confidentiality boundaries, and leave a reviewable trail, the polish of the answer does not matter much.

    Governed context deserves more attention than the phrase usually gets.

    • knowledge access
    • permissions
    • monitoring
    • auditability
    • workflow control

    What buyers should watch

    iManage is trying to own that layer. That is a sensible strategy, but buyers should still test the claims carefully.

    The real diligence questions are whether the controls are granular, whether agent activity is actually visible, and whether firms can connect multiple AI tools without losing control of client and matter boundaries.

    The bigger shift

    The legal AI market is moving away from “AI as a feature” and toward “AI as a workflow and knowledge infrastructure problem.”

    That may sound less exciting than model hype. It is also where the durable power probably sits.

    Practical guide: Legal AI Workflows: A Governance Checklist for Legal Teams

  • OpenAI Is Moving Into Government Legal Workflows Through Eudia

    OpenAI Is Moving Into Government Legal Workflows Through Eudia

    OpenAI's partnership with Eudia offers a useful clue about where legal AI is heading next.

    This is a workflow story more than a chatbot story. Eudia says the partnership is aimed at government legal and acquisition teams, combining OpenAI's models with Eudia's operating layer for regulated work.

    What matters here is not simply which model sounds smartest. It is who gets inside the workflow and becomes hard to replace.

    Government is where this gets real

    Government legal and acquisition work is where AI stops feeling like a novelty and starts looking like infrastructure.

    Once AI touches contracting, legal review, and mission-critical decisions, buyers need to ask harder questions about:

    • control
    • auditability
    • permissions
    • human review
    • vendor concentration risk

    Those are not side issues. They are the real product.

    What buyers should take from it

    The public announcement is still high level, and it does not answer every diligence question. But it is a useful signal.

    Frontier-model companies are not staying behind the curtain. They are moving into legal and acquisition workflows through specialized partners that already understand the operating environment.

    For legal and procurement teams, that means the smarter evaluation lens is no longer just model quality. It is whether the workflow around the model is governable, reviewable, and defensible.

    The bigger shift

    This is one more sign that legal AI is moving beyond the demo layer.

    The winners may not be the companies with the flashiest model. They may be the ones that control the workflow around it.

    Practical guide: Legal AI Workflows: A Governance Checklist for Legal Teams