FTC · SECTION 5 · CLAIMS SUBSTANTIATION

There is no FTC AI rule. There is no AI exemption either.

Section 5 binds whoever makes the claim, not whoever built the model - and it has done since 1914, with no AI exemption anywhere in it.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Evidence dated before the claim
Substantiation Deception Unfairness Dark patterns COPPA

Our promise

“A claim is marketing. Substantiation is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.

Each additional tool
$1,500
Re-audit, same scope
$4,200
Renewal, every twelve months
$5,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

FTC exposure, in three chapters

The Authority

Congress never wrote an AI statute, and the Commission never needed one. Section 5 of the FTC Act has prohibited unfair or deceptive acts since 1914, and there is no AI exemption from it. A claim you cannot substantiate is deceptive, whoever made it first and whoever repeated it.

The Gap

Most teams assume their vendor’s benchmark is their own evidence. It is not: repeat a figure to your customers and it becomes your claim, judged against what you hold rather than what they hold. Quiet exposure is the default state of an AI product sold on numbers somebody else measured.

The Office

Ours is the review an independent reviewer can sign. We build, resell and operate no AI products of our own, so we have nothing to protect in the answer. We read every claim you publish against what your own logs actually support, and we date each one so it can be defended later.

What is an AI claim?

Anything you say the model can do.

A public statement about what your AI does that a reasonable consumer reads as a promise.

Who owes the evidence № 01
  • Anyone marketing an AI capability to US consumers
  • Teams repeating a vendor’s accuracy or fairness figures
  • Products whose output affects a consumer’s money
  • Anyone whose sign-up or cancellation flow shapes a choice
FTC · iDharma · Presented for review
When the duty triggers № 02
  • The moment the claim is published, not when questioned
  • Again on every retrain, if you keep quoting the old figure
  • Whenever a supplier’s number is repeated as your own
  • As soon as a child can reasonably reach the product
FTC · iDharma · Presented for review
Whose claim is it

The claim is yours. The model is theirs.

You

The business making the claim

Section 5 reaches whoever puts a representation in front of a consumer. Holding the evidence behind it, keeping that evidence current, and producing it on the day the claim was made are all yours, and none of them can be discharged by the supplier who first made the claim you repeated.

Your model vendor

The people who built the model

Answers for the claims it makes about its own product, not for the ones you make about yours. Many vendors publish genuinely careful benchmark work. The difficulty is not its quality - it is whose users it was measured on, and they were never your own customers, on your own product and traffic.

The catch

When their file becomes yours

Repeat a supplier's figure to your own customers and it is now your claim, judged against the evidence that you hold yourself. A contractual indemnity settles who pays afterwards; it does not substantiate anything. Their file was never on your side of the wall to begin with, and cannot be moved there.

What most teams assume

“Our vendor benchmarked it, so it is substantiated.”

What Section 5 says

Repeat it and you must substantiate it, not them.

It is the most common finding we write up.

  • Who it is for
  • AI product marketers
  • Consumer apps & fintech
  • SaaS & platform teams
  • Legal & compliance
  • Growth and ad-tech teams
Why this matters in 2026
A black archive binder closed on a dark desk under a low lamp, a blank brass label plate screwed to its face, with reading glasses, a fountain pen and a small printed card reading EVIDENCE OVER PROMISES laid out beside it: the file a claim has to be able to open.
01 Once an order or a rule is in play, civil penalties run per violation - up to $51,744 each, and each day a violation continues can count again. A season of a claim you cannot evidence is not one fine. It is arithmetic.
02

The remedy has reached the model, not only the data - deletion of algorithms trained on material that should never have been collected.

03

Substantiation is judged as at the day you made the claim. Evidence assembled after a letter arrives is not evidence that you held then.

04

Your claims are checkable from outside. An enquiry can begin from nothing more than your own pricing page and a screenshot of it.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

US consumers -

The conduct, not the head office. A company registered anywhere is reachable for conduct affecting US consumers - and a business-to-business product is not exempt, only less often looked at.

Claims made -

Contracts and decks count. A claim does not have to be on the marketing site. Release notes, support articles, sales calls and the warranties in your contract are all places a representation lives.

Evidence held -

Vendor files rarely transfer. Their evidence answers for their claim. Yours has to answer for yours, and it has to have existed on the day you published it.

The roadmap

Twenty weeks, and not in the order you’d guess.

Each phase closes an area the Commission has actually charged - so they run in sequence, and the first one is the one that stops the bleeding.

  1. Substantiate

    Weeks 1-4

    Every public claim collected and dated, then matched against the evidence you held on the day it was made.

  2. Test

    Weeks 5-10

    Performance re-measured on your own population, and disparity tested across the groups the product touches.

  3. Secure

    Weeks 11-16

    Training and inference data mapped against the notices you gave, with each mismatch written up.

  4. Design out

    Weeks 17-20

    Consent flows, cancellation and defaults reviewed - plus the age signals, wherever a child can reach you.

The trap

Teams book the fairness testing for week ten and leave the claim running from week one. Substantiation is judged as at the day the claim was made - so a test finished in March does nothing for a sentence you published in January. Pull the claim, or date the evidence first.

Requirement & coverage

What the authority asks, what we ship

12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

Whose claim it is The seller of the claim - never the model vendor
A written determination of who owns each public claim, so a vendor's benchmark is never mistaken for your evidence.
Adopted vendor claims Repeat a figure and it becomes yours
An assessment of every figure taken from a supplier - and what you must hold in order to keep saying it.
Claim inventory Site, decks, contracts, release notes, support
A dated register of every public statement about what the AI does, gathered from where claims actually live.
Substantiation Evidence held before the claim was made
For each claim, the evidence that existed on the day - tested against how a reasonable consumer reads it.
Performance claims Measured on your users, not on a benchmark
Accuracy figures re-tested against the population the product actually serves, with the gap stated where there is one.
Fairness claims "Unbiased" is an absolute claim
Disparity testing across the groups your product touches, and a rewrite of any claim the evidence will not carry.
Outcome harm Unfairness reaches results, not only words
A monitoring plan with thresholds and named owners, so a drift into avoidable consumer harm is caught before a complaint is.
Data privacy and consent What you collected against what you promised
Training and inference data mapped to the notices given, with every mismatch listed as a finding rather than a footnote.
Data provenance How the training data was obtained
A provenance record per dataset, written to survive a remedy that has reached the models built on improper material.
Dark patterns Design that obstructs the choice it offers
Consent flows, cancellation and defaults reviewed against the practices the Commission has actually charged.
Children's privacy (COPPA) Under 13, and actual knowledge counts
An age-signal and parental-consent review wherever the product can reasonably be reaching a child.
Enforcement readiness What you produce when the letter arrives
A response pack - register, test records and escalation route - assembled before anyone has asked for it.
The engagement

AI claims, independently reviewed

From a pricing page to a support article.

  1. Intake

    Which claims you make in public, and which models stand behind them.

  2. Test

    Substantiation, fairness, privacy and dark patterns - evidence by evidence.

  3. Sign off and fix

    You see the draft first. Then the register, the memo and the rewrites - dated.

Request your review
An auditor in a charcoal suit and white shirt, with grey hair, standing against a warm pale wall and pointing into the open space alongside.
The evidence is the claim - that is what you are buying.
Struck in your favour

Why product teams choose iDharma to review their claims

Genuinely independent

We build, resell and operate no AI products, and we take no fee tied to what the review finds.

Written to the claim

Every finding names the sentence it is about, so counsel can check it against the evidence file.

One engagement, end to end

Claims, fairness, privacy and dark patterns sit in one scope, so no exposure falls between reviews.

Marketing and model together

We read the sales deck and the test logs in the same week - which is where the gap always is.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

FTC exposure report

The full review in one document: every public claim, the evidence held against it, and findings across substantiation, fairness, privacy, dark patterns and COPPA - each tied to the sentence or the screen it is about, graded by consequence to consumers, and written in plain language a lawyer and a marketer can both act on.

Workbook

Claim register

Every public claim in one sheet with its source, its owner, its evidence and its date - the artefact that makes the next claim cheap to clear.

Evidence

Substantiation file

The proof behind each surviving claim, indexed to the claim it supports, so your own counsel can answer a letter without calling us first.

Workbook

Fairness test results

Outcome rates and disparities by group on your own population, in a workbook your analysts can reproduce cell by cell without asking us for it.

Memo

Dark-pattern review

Screen by screen through sign-up, consent, billing and cancellation - what a consumer is actually able to choose, and where the design says otherwise.

Ranked

Remediation shortlist

What to rewrite, retest or rebuild, and in what order. Ranked by consequence to consumers rather than by how easy each one is to fix.

Memo

Vendor-claim assessment

Which supplier figures you have adopted as your own, what evidence you would need to keep quoting them, and which ones to stop repeating today.

Format & fee

Real numbers, upfront.

Scope
Your claim register, counted
Evidence
Your claims and test records
Re-review
Every rolling twelve months - $5,500 against your known baseline

The register is counted before anything is charged, so the fee is flat - nothing to meter until you approve it.

Request this review
FTC · Named engagement $6,500 flat
  • Claim register and substantiation file
  • Fairness testing on your own population
  • Dark-pattern and consent review
  • Remediation shortlist, ranked
Show your hand

Four things you have to be able to produce

Section 5 is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The register,
dated

Every public claim about the AI, with the evidence behind it and the day it was checked. A claim carrying no date is a claim carrying no defence when one is asked for.

The evidence,
first

Test records that existed before the claim shipped. Assembling them after a letter arrives is not substantiation; it is a reconstruction, and it shows.

The consent,
real

A choice a consumer can actually make - and, where a child can reach you, verifiable parental consent rather than a checkbox that assumes one has been given.

The numbers,
by group

Results by group for the population you actually serve, not a benchmark set. Unfairness reaches what the model does, not only what the marketing said it would do.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Whose claim it is, and what it costs to be wrong. Answered straight.

Request this review
Our model vendor published benchmarks. Are we covered?

No - this is the most common misreading. Repeat a figure to your own customers and it becomes your claim, judged against the evidence you hold rather than the evidence they hold.

What counts as an AI claim?

Any public statement about what the AI does, how well it does it, or how fairly. Accuracy figures, "AI-powered", autonomy and bias claims all require evidence you held when you said it.

Can we say our AI is unbiased?

We would advise against it, strongly. It is an absolute claim about an empirical property that is hard to define and harder to prove - and it converts a technical limitation into a consumer protection matter.

How long does a review take?

Typically four to six weeks from hand-over for a single product, longer where the claim inventory turns out to be bigger than expected - which it usually does. Scope is agreed with you before anything is charged.

What are the penalties?

Section 5 alone carries no civil penalty for a first offence - the money attaches to violating a Commission order, a trade rule or COPPA, at up to $51,744 per violation, per day. The remedies are the harder part.

Get started

Request your claims review

Tell us what you claim and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of your marketing site and your test folder in an afternoon, and we tell you which extracts before you commit.

  1. Every page and deck that describes what the AI does
  2. Any accuracy, capability or fairness figures you publish
  3. The test records behind them, with the dates they ran
  4. Whether children under 13 can reach the product
  5. Your sign-up, consent and cancellation flows

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request your claims review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Section 5 of the FTC Act (15 U.S.C. § 45)
  • COPPA and the FTC’s enforcement actions
Section 5 since
26 September 1914
COPPA since
21 April 2000

What it means

  • General information about what the Commission’s existing authority reaches — not legal advice, and no professional relationship.
  • Where a claim is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Civil-penalty maxima are adjusted for inflation each year, and Section 5 alone carries none for a first-time act. Check the current figure with counsel.
  • It covers Section 5 alone — state UDAP laws and sector rules reach the same claims.
  • Use this as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us