FTC · SECTION 5 · CLAIMS SUBSTANTIATION

The FTC does not regulate AI. It regulates what you say about it.

There is no FTC AI statute. There is a long-standing prohibition on unfair or deceptive practices, and an AI claim you cannot substantiate is a deceptive practice with a model attached. That is the whole exposure, and it is larger than it sounds.


A printed standards report on a dark desk showing compliance by standard, top requirement gaps and a standard alignment matrix Illustrative materials
The claim is the product, legally speaking
Substantiation Deception Unfairness Disparate impact Vendor claims

What is the FTC's position on AI?

That existing law already covers it. The Commission's authority over unfair or deceptive acts and practices reaches AI claims without needing new legislation, and it has said repeatedly that there is no AI exemption from consumer protection law.

  • Instrument Existing authority No AI-specific statute. Consumer protection law applied to AI claims.
  • Core test Substantiation Can you prove the claim was true when you made it?
  • Second test Unfairness Substantial harm consumers cannot reasonably avoid, not outweighed by benefits.
  • Notable remedy Model deletion The Commission has required deletion of models and data derived improperly.

Who is exposed?

Anyone who says anything about what their AI does. Which, in practice, is everyone selling one.

  • Anyone marketing AI capability Accuracy figures, "AI-powered", bias claims and performance comparisons are all claims requiring substantiation.
  • Organisations deploying vendor AI Repeating a vendor's claim to your customers makes it your claim. Their evidence is not automatically your defence.
  • Anyone whose model affects consumers Unfairness reaches outcomes as well as statements — a model causing avoidable consumer harm is exposed regardless of what was advertised.
  • Data-acquisition practices How training data was obtained matters, and the remedy has extended to models built on improperly collected data.
How we help

How iDharma supports FTC exposure review

A claims review is unusual among our engagements in that it starts with your marketing rather than your architecture.

Area What the review does
Claim inventoryEvery public statement about what the AI does — website, sales decks, contracts, support content and release notes. It is always more than the marketing team remembers.
SubstantiationFor each claim, what evidence existed when it was made, and whether that evidence supports the claim as a reasonable consumer would read it.
Performance claimsWhether accuracy figures reflect the population the product actually serves rather than the benchmark it was measured on.
Fairness claimsThe single most dangerous category. "Unbiased" is a claim requiring evidence, and almost nobody has evidence sufficient to support it.
Vendor claimsWhat you repeat from suppliers, and whether you hold the evidence for statements you have adopted as your own.
Data provenanceHow training data was obtained, and whether that story would survive scrutiny given the remedies available.
Outcome harmWhere the model causes consumer harm that is substantial, unavoidable and not outweighed — the unfairness limb rather than the deception one.

“Our AI is unbiased” is the claim to look at first. It is easy to write, almost impossible to substantiate, and it converts a technical shortcoming into a consumer protection matter. Most of the value in this review is finding that sentence before someone else does.

The exposure

Six places the exposure actually sits

None of these require an AI-specific rule. All of them are reachable under authority that has existed for decades.

Unsubstantiated performance

Accuracy and capability

A figure measured on a benchmark and quoted for a product is a claim about the product. The evidence has to fit what was said, to the population it was said about.

Fairness claims

The dangerous one

"Unbiased", "fair" and "non-discriminatory" are absolute claims. Substantiating them requires evidence most organisations do not have and cannot easily get.

AI-washing

Saying AI when you mean rules

Describing a rules engine as AI, or overstating autonomy, is deceptive on the same terms as any other product exaggeration.

Adopted vendor claims

Their claim becomes yours

Repeating a supplier's performance figure to your customers makes you responsible for it. A contractual indemnity is not substantiation.

Data provenance

How you got it

Improperly obtained training data has attracted remedies reaching the models built on it, which is a materially different risk from a fine.

Unfair outcomes

Beyond what you said

Substantial consumer harm that is not reasonably avoidable and not outweighed by benefits is reachable regardless of how carefully you worded the marketing.

The fix

Four habits that close most of it

Claim register

Every public claim listed, with the evidence and the date it was substantiated attached.

Substantiate before publishing

Evidence dated before the claim, not assembled after a letter arrives.

Delete absolute claims

Comparative and qualified claims are defensible. "Unbiased" and "always accurate" are not.

Measure on your population

Benchmark numbers describe the benchmark. Quote figures measured on the users you actually have.

Getting there

A claims review that finishes

  1. Phase 1

    Collect

    Find every claim

    • Website, decks and contracts
    • Support content and release notes
    • Vendor claims you have adopted
    • Statements made in sales calls
  2. Phase 2

    Test

    Evidence against each

    • What evidence existed, and when
    • Whether it fits the claim as read
    • Population match for performance figures
    • Flag absolute and fairness claims
  3. Phase 3

    Fix

    Qualify or substantiate

    • Rewrite what cannot be supported
    • Generate evidence where it is worth it
    • Remove adopted vendor claims
    • Align contract language with marketing
  4. Phase 4

    Hold the line

    Keep it from recurring

    • Claim register with owners
    • Sign-off before new claims ship
    • Re-substantiate on a cadence
    • Provenance recorded for training data
Questions

Frequently asked questions

1 The exposure
Is there an FTC AI regulation?

No, and that is the point people miss. The Commission applies existing consumer protection authority to AI, which means the exposure exists now rather than after some future rulemaking.

What is algorithmic disgorgement?

A remedy requiring deletion not just of improperly obtained data but of models and algorithms derived from it. It is worth understanding because it changes the risk calculation entirely — losing a trained model is a different order of harm from paying a penalty. Confirm its current status before relying on any summary.

Does this apply outside the US?

It applies to conduct affecting US consumers. Where you are incorporated is not the test.

2 Claims
Can we say our AI is unbiased?

We would advise against it, strongly. It is an absolute claim about an empirical property that is difficult to define and harder to prove, and it converts a technical limitation into a consumer protection problem. Qualified, evidenced statements about specific testing you have actually done are both more defensible and more credible.

Our vendor gave us these accuracy figures. Are we covered?

No. Repeating a claim to your customers makes it your claim, and their evidence is not automatically yours. Either obtain the substantiation, or stop repeating the figure.

What if the claim was true when we made it?

That is the right question, and it is why claims carry dates. Substantiation is judged against what you had at the time — which is an argument for a claim register with dated evidence rather than a reconstruction afterwards.

Get started

Ready to review what you claim?

A claim register, dated evidence behind each one, and the absolute claims removed before someone else finds them.

This page is guidance on how we scope an assessment, not legal advice. US counsel should confirm anything you intend to rely on.