Newsroom
AI Platforms & Regulation · April 1, 2026

The FTC's AI Enforcement Playbook: No New Law, Just Old Authority Applied with Force

Without new legislation or regulation, the FTC is using its century-old Section 5 authority to pursue companies that make false AI claims and deploy deceptive AI systems. Operation AI Comply has produced permanent bans and millions in judgments. The enforcement record reveals how the agency is policing a new technology with tools that predate it by a century.

At a Glance

  • A December 2025 Executive Order directed the FTC to issue a policy statement applying Section 5 of the FTC Act to AI systems. As of early April 2026, the Commission has not publicly released such a statement. What the record shows instead is a sustained enforcement campaign demonstrating how existing Section 5 authority already reaches AI-related conduct.
  • The FTC's enforcement approach does not require new regulations. The existing prohibition on unfair or deceptive acts or practices already reaches AI-related commercial conduct, and the agency is applying it through case-by-case enforcement.
  • Operation AI Comply, launched in September 2024, has produced enforcement actions resulting in permanent operator bans, asset turnover, and monetary judgments. Air AI reached a proposed settlement in March 2026 carrying an $18 million monetary judgment and a permanent ban on marketing business opportunities.
  • Based on its enforcement posture and a September 2025 inquiry into AI companion chatbots, the FTC appears to be treating AI agents — autonomous systems that interact with consumers or make decisions affecting them — as an emerging enforcement priority.
  • The FTC uses a conduct-based enforcement approach, focusing on outcomes and impacts rather than attempting to regulate the technology itself. Claims about AI capabilities must be substantiated; systems that produce deceptive or unfair outcomes face enforcement regardless of how novel the technology.
  • A December 2025 Executive Order on AI policy directed development of a national AI framework and a legislative recommendation that could eventually preempt state-level AI regulation. The EO did not itself preempt state law, and the FTC's Section 5 authority rests on its existing statutory mandate.

A small company called Air AI promised entrepreneurs that its artificial intelligence phone system could replace human sales agents and generate substantial earnings. The pitch was persuasive. The technology was real. The claims, according to the Federal Trade Commission, were not. On March 24, 2026, Air AI and its owners agreed to a proposed settlement of FTC charges that they had misled consumers about earnings potential and refund guarantees. The proposed settlement carried an $18 million monetary judgment and a permanent ban on marketing business opportunities. It was the latest in a series of enforcement actions under a campaign the FTC calls Operation AI Comply. And it illustrated something that many companies building or deploying AI products have not fully absorbed: the FTC does not need new legislation to regulate artificial intelligence. It already has what it needs.

A Century-Old Law Meets a New Technology

Section 5 of the Federal Trade Commission Act, first enacted in 1914, prohibits unfair or deceptive acts or practices in or affecting commerce. It is one of the broadest consumer protection statutes in American law. It does not define the technologies it covers because it was never meant to be technology-specific. It covers conduct.

A December 2025 Executive Order on AI policy directed the FTC Chairman to issue a policy statement applying Section 5 to AI systems across their lifecycle. As of early April 2026, the Commission has not publicly released such a statement. What exists in its place is a pattern of enforcement actions — stretching back to September 2024 — that collectively demonstrate how the FTC already reads its existing authority to reach AI-related commercial conduct.

The enforcement record suggests the FTC treats Section 5 as reaching AI-related conduct across multiple phases of commercial activity. Enforcement actions have targeted misleading marketing claims about AI capabilities, unsubstantiated earnings projections tied to AI systems, and representations that AI tools could perform professional services they were not equipped to provide. The agency's pattern of cases does not trace the outlines of a formal policy statement — it reflects the conduct-based logic of Section 5 itself.

The FTC does not need new legislation to regulate artificial intelligence. It already has what it needs.

Operation AI Comply: The Enforcement Record

The enforcement campaign began in September 2024 when the FTC launched Operation AI Comply, a national initiative targeting companies that use AI in deceptive or unfair ways. The campaign has produced a string of enforcement actions that collectively define the contours of what the FTC considers unacceptable AI-related business conduct.

The cases follow a pattern. The Commission identifies companies making specific, verifiable claims about what their AI products can do. It investigates whether those claims are substantiated. When they are not, it brings enforcement actions that carry consequences designed to deter repetition.

Air AI: The Earnings Promise

Air AI and its owners, Caleb Maddix, Ryan O'Donnell, and Thomas Lancer, marketed an AI-powered phone system as a business opportunity. According to the FTC's complaint, filed in August 2025, the company had falsely claimed since at least February 2023 that purchasers of its services would likely earn substantial income and that a refund or buy-back guarantee protected their investment. The proposed settlement, announced March 24, 2026, carried an $18 million monetary judgment. The operators were required to pay $50,000 to the Commission for consumer relief, based on their stated inability to pay the full amount, and were permanently banned from marketing business opportunities.

DoNotPay: The Robot Lawyer

DoNotPay marketed itself as an AI service that could substitute for licensed attorneys. According to the FTC, the company did not conduct testing to determine whether its AI chatbot's output was comparable to the work of a human lawyer, and it did not hire or retain any attorneys. The Commission voted to finalize the order on January 16, 2025; the order was published in the Federal Register on February 11, 2025. The order required DoNotPay to pay $193,000 in monetary relief, prohibited it from claiming its tools perform comparably to or can replace licensed legal professionals, and required the company to notify past subscribers of the FTC action.

Ascend Ecom and Ecommerce Empire Builders: The Business Opportunity Schemes

Ecommerce Empire Builders resolved in May 2025, with its operator Peter Prusinowski permanently banned from marketing business opportunities and required to turn over assets for consumer redress; the court entered the final order on May 8, 2025. In the Ascend Ecom matter, the FTC alleged more than $25 million in consumer losses tied to deceptive AI-related marketing claims; the agency obtained a temporary halt and asset freeze in September 2024; a final order banning Ascend Ecom and its owners from business opportunity marketing was entered in June 2025. FBA Machine, a related operation, resolved in July 2025 with its operators permanently banned from selling business opportunities and assets turned over for consumer redress.

Taken together, the FTC's enforcement record reflects a sustained campaign. Since 2023, the agency has brought at least eight AI-related enforcement actions — a pace that predates Operation AI Comply and has accelerated since the initiative's September 2024 launch. The FTC maintains a public case tracker documenting these actions, and the pattern they reveal is consistent: substantiation failures, earnings misrepresentations, and unfair practices tied to AI systems draw enforcement regardless of the underlying technology's novelty.

Why Conduct-Based Enforcement Matters

The FTC's approach is deliberately conduct-based rather than technology-based. The Commission does not attempt to define what AI is, to classify systems by risk level, or to impose prescriptive technical requirements. Instead, it asks a simpler set of questions: Did the company make claims about its AI product? Were those claims substantiated? Did the AI system produce outcomes that were unfair or deceptive under existing law?

This approach has strategic advantages. It avoids the definitional problems that have plagued legislative attempts to regulate AI. It does not require the Commission to keep pace with rapidly evolving technology. And it allows enforcement to reach conduct that legislators may not have anticipated, because the legal standard is not tied to a specific technology but to the commercial practice surrounding it.

The disadvantage is unpredictability. Companies operating in good faith may not know in advance whether their AI-related claims or practices will trigger enforcement. Enforcement actions provide guidance, but they are not safe harbors. The FTC retains discretion to bring cases on a case-by-case basis, and the boundaries of acceptable conduct are defined primarily by the enforcement actions the Commission chooses to bring.

Timeline of FTC Operation AI Comply enforcement actions from 2024 through 2026
Operation AI Comply enforcement actions have accelerated since its September 2024 launch, with settlements and bans continuing through March 2026.

AI Agents in the Crosshairs

The FTC's evident interest in AI agents as an emerging enforcement priority is new and significant. AI agents are autonomous or semi-autonomous systems that can take actions on behalf of users: booking travel, negotiating prices, managing communications, executing transactions. As these systems become more capable and more widely deployed, they create novel consumer protection questions. When an AI agent makes a purchase decision on behalf of a consumer, who is responsible if the decision is based on deceptive information? When an AI agent interacts with another AI agent in a commercial transaction, does the absence of a human in the loop change the analysis?

The FTC's enforcement posture — evidenced by its cases and by a September 2025 inquiry into AI companion chatbots — suggests the agency views these questions through a familiar lens: the same Section 5 framework applies regardless of whether commercial conduct involves humans, AI systems, or some combination. A deceptive claim made by an AI agent is still a deceptive claim. An unfair outcome produced by an autonomous system is still an unfair outcome. The agency appears to have no intention of treating automation as a defense.

The Federal Preemption Pressure

The FTC's enforcement posture exists within a broader political context. On December 11, 2025, the White House issued an Executive Order on AI policy that, among other things, signaled a preference for a national framework that could preempt state-level AI regulation. Several states, most prominently Colorado with its SB 24-205 requiring high-risk AI impact assessments, have been developing their own AI regulatory frameworks. The Executive Order adds pressure for federal uniformity.

The EO did not amend Section 5, did not preempt state AI statutes, and did not instruct the FTC to halt or modify its enforcement activity. Its principal direction on preemption was a charge to develop recommendations for federal legislation — not an exercise of existing preemption authority. The FTC's Section 5 authority derives from a statute that Congress enacted; it does not rise and fall with executive policy. The practical effect is that companies face potential enforcement from the FTC at the federal level and from state regulators and attorneys general at the state level, with no single framework providing comprehensive guidance.

What This Means for Companies Using AI

The enforcement record delivers a clear message: the FTC will act against companies whose AI-related claims are unsubstantiated, whose AI systems produce deceptive or unfair outcomes, or whose AI agents interact with consumers in ways that violate existing consumer protection standards. It will do so without waiting for Congress to pass AI-specific legislation.

For businesses deploying AI products, the practical implications are concrete. Marketing claims about AI capabilities must be substantiated by evidence, not by aspiration. If an AI system is described as producing fair, unbiased, or accurate results, there must be testing to support those claims. If an AI agent acts on behalf of consumers, the company deploying it bears responsibility for the agent's conduct. And the enforcement consequences are not theoretical. They include monetary judgments, permanent bans on business activities, asset forfeiture, and court-supervised compliance.

The FTC has made clear through its actions that it views the AI enforcement landscape not as a gap requiring new legislation, but as a space where existing authority is sufficient. For the companies in the agency's path, that distinction is academic. The consequences are the same either way.


This article is a summary prepared for general information and discussion purposes only. It does not constitute legal advice, is not a full analysis of the matters presented, and may not be relied upon as a substitute for competent legal counsel. Wright Law Firm, PLC provides no warranties, express or implied, regarding the accuracy or completeness of this information. Consult an attorney for advice specific to your situation. This article reflects the author's analysis of emerging developments and trends in artificial intelligence law and policy. It should not be read as a statement of settled legal authority.

Topics
FTC Artificial Intelligence Section 5 Operation AI Comply AI Agents Consumer Protection Enforcement Business Compliance

Source Notes

Attorney review note: The FTC policy statement on AI and Section 5 directed by the December 2025 Executive Order has not been publicly confirmed as issued as of the publication date of this article. All claims about the agency's enforcement posture are drawn from publicly available enforcement actions, complaints, and consent orders. Dates, monetary figures, and case procedural postures should be independently verified against current FTC docket records before republication.