Congress never wrote an AI statute, and the Commission never needed one. Section 5 of the FTC Act has prohibited unfair or deceptive acts since 1914, and there is no AI exemption from it. A claim you cannot substantiate is deceptive, whoever made it first and whoever repeated it.
There is no FTC AI rule. There is no AI exemption either.
Section 5 binds whoever makes the claim, not whoever built the model - and it has done since 1914, with no AI exemption anywhere in it.
Our promise
“A claim is marketing. Substantiation is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditFTC exposure, in three chapters
Most teams assume their vendor’s benchmark is their own evidence. It is not: repeat a figure to your customers and it becomes your claim, judged against what you hold rather than what they hold. Quiet exposure is the default state of an AI product sold on numbers somebody else measured.
Ours is the review an independent reviewer can sign. We build, resell and operate no AI products of our own, so we have nothing to protect in the answer. We read every claim you publish against what your own logs actually support, and we date each one so it can be defended later.
Anything you say the model can do.
A public statement about what your AI does that a reasonable consumer reads as a promise.
- Anyone marketing an AI capability to US consumers
- Teams repeating a vendor’s accuracy or fairness figures
- Products whose output affects a consumer’s money
- Anyone whose sign-up or cancellation flow shapes a choice
- The moment the claim is published, not when questioned
- Again on every retrain, if you keep quoting the old figure
- Whenever a supplier’s number is repeated as your own
- As soon as a child can reasonably reach the product
The claim is yours. The model is theirs.
The business making the claim
Section 5 reaches whoever puts a representation in front of a consumer. Holding the evidence behind it, keeping that evidence current, and producing it on the day the claim was made are all yours, and none of them can be discharged by the supplier who first made the claim you repeated.
The people who built the model
Answers for the claims it makes about its own product, not for the ones you make about yours. Many vendors publish genuinely careful benchmark work. The difficulty is not its quality - it is whose users it was measured on, and they were never your own customers, on your own product and traffic.
When their file becomes yours
Repeat a supplier's figure to your own customers and it is now your claim, judged against the evidence that you hold yourself. A contractual indemnity settles who pays afterwards; it does not substantiate anything. Their file was never on your side of the wall to begin with, and cannot be moved there.
“Our vendor benchmarked it, so it is substantiated.”
Repeat it and you must substantiate it, not them.
It is the most common finding we write up.
- Who it is for
- AI product marketers
- Consumer apps & fintech
- SaaS & platform teams
- Legal & compliance
- Growth and ad-tech teams
The remedy has reached the model, not only the data - deletion of algorithms trained on material that should never have been collected.
Substantiation is judged as at the day you made the claim. Evidence assembled after a letter arrives is not evidence that you held then.
Your claims are checkable from outside. An enquiry can begin from nothing more than your own pricing page and a screenshot of it.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your scope check
Twenty weeks, and not in the order you’d guess.
Each phase closes an area the Commission has actually charged - so they run in sequence, and the first one is the one that stops the bleeding.
-
Substantiate
Weeks 1-4Every public claim collected and dated, then matched against the evidence you held on the day it was made.
-
Test
Weeks 5-10Performance re-measured on your own population, and disparity tested across the groups the product touches.
-
Secure
Weeks 11-16Training and inference data mapped against the notices you gave, with each mismatch written up.
-
Design out
Weeks 17-20Consent flows, cancellation and defaults reviewed - plus the age signals, wherever a child can reach you.
Teams book the fairness testing for week ten and leave the claim running from week one. Substantiation is judged as at the day the claim was made - so a test finished in March does nothing for a sentence you published in January. Pull the claim, or date the evidence first.
What the authority asks, what we ship
12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.
- Whose claim it is The seller of the claim - never the model vendor
- A written determination of who owns each public claim, so a vendor's benchmark is never mistaken for your evidence.
- Adopted vendor claims Repeat a figure and it becomes yours
- An assessment of every figure taken from a supplier - and what you must hold in order to keep saying it.
- Claim inventory Site, decks, contracts, release notes, support
- A dated register of every public statement about what the AI does, gathered from where claims actually live.
- Substantiation Evidence held before the claim was made
- For each claim, the evidence that existed on the day - tested against how a reasonable consumer reads it.
- Performance claims Measured on your users, not on a benchmark
- Accuracy figures re-tested against the population the product actually serves, with the gap stated where there is one.
- Fairness claims "Unbiased" is an absolute claim
- Disparity testing across the groups your product touches, and a rewrite of any claim the evidence will not carry.
- Outcome harm Unfairness reaches results, not only words
- A monitoring plan with thresholds and named owners, so a drift into avoidable consumer harm is caught before a complaint is.
- Data privacy and consent What you collected against what you promised
- Training and inference data mapped to the notices given, with every mismatch listed as a finding rather than a footnote.
- Data provenance How the training data was obtained
- A provenance record per dataset, written to survive a remedy that has reached the models built on improper material.
- Dark patterns Design that obstructs the choice it offers
- Consent flows, cancellation and defaults reviewed against the practices the Commission has actually charged.
- Children's privacy (COPPA) Under 13, and actual knowledge counts
- An age-signal and parental-consent review wherever the product can reasonably be reaching a child.
- Enforcement readiness What you produce when the letter arrives
- A response pack - register, test records and escalation route - assembled before anyone has asked for it.
AI claims, independently reviewed
From a pricing page to a support article.
-
Intake
Which claims you make in public, and which models stand behind them.
-
Test
Substantiation, fairness, privacy and dark patterns - evidence by evidence.
-
Sign off and fix
You see the draft first. Then the register, the memo and the rewrites - dated.
Why product teams choose iDharma to review their claims
Genuinely independent
We build, resell and operate no AI products, and we take no fee tied to what the review finds.
Written to the claim
Every finding names the sentence it is about, so counsel can check it against the evidence file.
One engagement, end to end
Claims, fairness, privacy and dark patterns sit in one scope, so no exposure falls between reviews.
Marketing and model together
We read the sales deck and the test logs in the same week - which is where the gap always is.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
FTC exposure report
The full review in one document: every public claim, the evidence held against it, and findings across substantiation, fairness, privacy, dark patterns and COPPA - each tied to the sentence or the screen it is about, graded by consequence to consumers, and written in plain language a lawyer and a marketer can both act on.
Claim register
Every public claim in one sheet with its source, its owner, its evidence and its date - the artefact that makes the next claim cheap to clear.
Substantiation file
The proof behind each surviving claim, indexed to the claim it supports, so your own counsel can answer a letter without calling us first.
Fairness test results
Outcome rates and disparities by group on your own population, in a workbook your analysts can reproduce cell by cell without asking us for it.
Dark-pattern review
Screen by screen through sign-up, consent, billing and cancellation - what a consumer is actually able to choose, and where the design says otherwise.
Remediation shortlist
What to rewrite, retest or rebuild, and in what order. Ranked by consequence to consumers rather than by how easy each one is to fix.
Vendor-claim assessment
Which supplier figures you have adopted as your own, what evidence you would need to keep quoting them, and which ones to stop repeating today.
Real numbers, upfront.
- Scope
- Your claim register, counted
- Evidence
- Your claims and test records
- Re-review
- Every rolling twelve months - $5,500 against your known baseline
The register is counted before anything is charged, so the fee is flat - nothing to meter until you approve it.
Request this review- Claim register and substantiation file
- Fairness testing on your own population
- Dark-pattern and consent review
- Remediation shortlist, ranked
Four things you have to be able to produce
Section 5 is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The register,
dated
Every public claim about the AI, with the evidence behind it and the day it was checked. A claim carrying no date is a claim carrying no defence when one is asked for.
The evidence,
first
Test records that existed before the claim shipped. Assembling them after a letter arrives is not substantiation; it is a reconstruction, and it shows.
The consent,
real
A choice a consumer can actually make - and, where a child can reach you, verifiable parental consent rather than a checkbox that assumes one has been given.
The numbers,
by group
Results by group for the population you actually serve, not a benchmark set. Unfairness reaches what the model does, not only what the marketing said it would do.
Four cards, and the date on each one is part of the card.
Plain answers
Whose claim it is, and what it costs to be wrong. Answered straight.
Request this reviewOur model vendor published benchmarks. Are we covered?
No - this is the most common misreading. Repeat a figure to your own customers and it becomes your claim, judged against the evidence you hold rather than the evidence they hold.
What counts as an AI claim?
Any public statement about what the AI does, how well it does it, or how fairly. Accuracy figures, "AI-powered", autonomy and bias claims all require evidence you held when you said it.
Can we say our AI is unbiased?
We would advise against it, strongly. It is an absolute claim about an empirical property that is hard to define and harder to prove - and it converts a technical limitation into a consumer protection matter.
How long does a review take?
Typically four to six weeks from hand-over for a single product, longer where the claim inventory turns out to be bigger than expected - which it usually does. Scope is agreed with you before anything is charged.
What are the penalties?
Section 5 alone carries no civil penalty for a first offence - the money attaches to violating a Commission order, a trade rule or COPPA, at up to $51,744 per violation, per day. The remedies are the harder part.
Request your claims review
Tell us what you claim and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this comes out of your marketing site and your test folder in an afternoon, and we tell you which extracts before you commit.
- Every page and deck that describes what the AI does
- Any accuracy, capability or fairness figures you publish
- The test records behind them, with the dates they ran
- Whether children under 13 can reach the product
- Your sign-up, consent and cancellation flows
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Section 5 of the FTC Act (15 U.S.C. § 45)
- COPPA and the FTC’s enforcement actions
- Section 5 since
- 26 September 1914
- COPPA since
- 21 April 2000
What it means
- General information about what the Commission’s existing authority reaches — not legal advice, and no professional relationship.
- Where a claim is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Civil-penalty maxima are adjusted for inflation each year, and Section 5 alone carries none for a first-time act. Check the current figure with counsel.
- It covers Section 5 alone — state UDAP laws and sector rules reach the same claims.
- Use this as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom