FTC AI advertising claims, sensitive data, federal privacy debate

  • AI GovernanceFTC EnforcementPrivacy Regulations
  • Episode 3
  • March 2, 2023
 

Summary

As AI becomes embedded in products and business operations, regulators are applying existing legal frameworks — not waiting for new ones. The FTC has signaled clearly that advertising claims about AI capabilities are subject to the same deceptive trade practice standards as any other claim: both express statements and implied messages must be substantiated before they are made. This applies equally to B2B and consumer-facing companies. The regulatory landscape is further complicated by the fact that AI intersects different bodies of law depending on its application — lending, housing, advertising, and insurance each carry their own statutory frameworks, creating layered exposure for businesses that deploy algorithmic decision-making across multiple contexts. The consequences of getting AI wrong extend well beyond financial penalties. Regulators have required companies to delete not only improperly collected data but also the models and algorithms built on it — effectively erasing years of investment. Consent decrees impose highly prescriptive operational constraints that can limit business flexibility for two decades and handicap competitiveness against firms that operate without such restrictions. The recurring theme is that proactive compliance — building systems correctly from the start — is far less costly than operating under a government-imposed remediation regime, which strips companies of the discretion to implement practices on their own terms. Bias in AI systems is a primary enforcement vector because existing anti-discrimination statutes in credit, housing, and insurance give regulators ready-made legal hooks. But the scope is expanding: regulators are increasingly examining how algorithmic personalization that uses sensitive personal information — health data, children's data, inferences derived from non-sensitive inputs — can result in discriminatory pricing or differential consumer experiences. On the legislative front, a House Energy and Commerce Committee hearing revisited the bipartisan federal privacy bill that failed to advance in the prior term, but California's Attorney General, Privacy Protection Agency, and governor's office filed a joint letter opposing preemption of state law, reflecting the enduring tension between a national standard and state-level regulatory investment.

Transcript

**Jonathan:** Hey, Alysa. How are you? Good to see you again. **Alysa:** Hey, JJ. Good to see you. **Jonathan:** We're back from DC. It was good to see you there last week. **Alysa:** Yes. In person off screen. So much fun. So much fun. **Jonathan:** I got the three D version. Yeah. **Alysa:** It was awesome. I'm a real person. **Jonathan:** So there's cool stuff going on this week. Last week we talked about digging deeper in AI and how the regulators are thinking about that. Some of the consequences. Keen to do that. Sounds like it's still hot around sensitive and personal data, kids data, health data, and of course some movement right on the federal law. Maybe we could talk about movement. Something to talk about on that front in any event. **Alysa:** Yeah, no there's a there is a lot happening and you just mentioned two of the shiniest objects being discussed at the moment. **Jonathan:** Awesome. We're looking forward to getting into it. One of the questions I had for you is how are regulators thinking about AI? What are the ways brands should think about some of what they're building in AI? **Alysa:** Right, so AI I think is the shiny object, right, that everybody is talking about in terms of how it can be used and all the ways it can power or take over things. But regulators, well for the most part they tend to be reactive, right? They're usually an out a year or so after the event. I mean we've certainly seen regulators talk about AI in a whole lot of different ways over the years. That was the big data when we were talking about big data. The FTC had a big data report out with a lot of considerations that continue to apply today. But I think if you fast forward to the present, we have the FTC recently put out a blog post on reminding companies that when you're making advertising claims around your AI capabilities, that's regulated. There's still whether your practices are deceptive and that means both what you say expressly about your AI capabilities, but also what implied messages are communicated. And, you know, the FTC is super aggressive these days. So, it's certainly something you think about from your marketing materials, even if your marketing materials are really B2B focused. So that's one. That's just one regulator. We've got others. **Jonathan:** What does that mean if we unpack that in a release? Like are they saying, don't say you're using AI for something if you're not? Like what is it how do we unpack that statement? **Alysa:** Well, so in advertising law, right, it's how, what do you say about your claims? And if it's objective, right, it can be proven, then you have to have evidence that supports that. And so when you're talking about your AI powered platform, your AI powered XYZ, whether you're selling it again to consumers or to businesses, that's got to be supported. And I think it continues to surprise businesses in terms of those obligations and exactly what kind of evidence they need. And they need it before they make the advertising claims, not after. **Jonathan:** Does it get into some murky technical ground where it's like what is AI exactly? Are you just pattern matching? Or is it like when does technology actually become AI? Have regulators grapple with where that line is? **Alysa:** Yes, I think they're quite adept to grapple with that line. Know there's offices of technology that are really stationed in now many government teams on this front, but I would say maybe a bigger issue is AI comes in a lot of different packages, right? When we're talking about AI, really talking about algorithmic decision making. When we talk about personalization, right? User kind of figuring out what really interests users and be able to serve up the right content at the right time, that's AI powered. And so, as we think about what are the different ways that that mechanism is used, it's in all different kinds of contexts. It could be in advertising, it could be in granting loans, it could be in housing. And you pull in different laws that have different exposures depending on how you're applying your AI powered mechanism. **Jonathan:** Oh, gotcha. Thanks. And any have they shed any light on the consequences of getting this wrong? **Alysa:** Oh yes, we have a few different examples, right? What we've seen already is the FTC has gone after a number of companies where they've said your practices are deceptive or unfair. They've made them delete their data and delete their algorithm, right? So thinking not just data that they can replenish, but really a lot of the models that they built on that. So that is a potential remedy and we've seen a few cases with that applied. So that's one, but honestly just being under a settlement order with a lot of really detailed injunction terms that tell you what you can and cannot do, that is an imposition on businesses and it sometimes can really impair them in being competitive, right, with others who don't have those same kind of restraints. Now what we haven't yet seen, all the new state privacy laws, they speak about data protection impact assessments. There's a lot of aspects that really do relate to AI and use of AI and how that will be enforced. They tend to go after what we'll call the low hanging fruit and that's where maybe you're using AI in a way that really involves very sensitive personal information, health information, kids information, or it has really big impacts for consumer experiences, right? Do they not get the best offers for mortgages? Right? That they're being there's bias in or discrimination in those efforts. **Jonathan:** That was a super interesting point when I heard you on stage last week. When you were making this point about — so let me so let me step take a step back. One of the things we do we don't do at Ketch is talk about the fines. Hey. There are fines coming. You should worry about these fines because the reality is the fines may not be that significant for massive brands. I'm not going to worry about one point three million dollars or whatever the case may be. But what you were saying last week, think you said again, but do you want the FTC and regulators basically in your shorts telling you and prescribing exactly how you need to do things? That seems to be a massive motivator to get this right, right? If we're thinking if you're using the stick not carrot. **Alysa:** It really is. And I'm going to keep saying it because when we are defending companies who are investigated and we're in negotiating a settlement and they're really brass tacks, right? Thinking about if they have to live under and they do have to live under these terms, it really changes how their business is going to be operating. And sometimes it's for the better, right? It's tighter compliance and that can have a lot of really positive benefits that's flowing from that, but it can also, you know, be a limiter. **Jonathan:** And it sounds more expensive than the alternative of just doing it right up front. **Alysa:** Yeah. I think you'd want the discretion to do it right and roll it out in the way you'd prefer as opposed to how a regulator would tell you how to do it. **Jonathan:** Gotcha. No thanks. And the other thing I've been wondering about with AI is are the regulators thinking about bias there? Like where does it how far does it go? Bias as a result of the algorithm and whatnot? **Alysa:** They often usually go to bias first because you have particular laws that make it illegal to discriminate, right, in unfair ways. And so if you are using bias in a way that does affect credit or housing or insurance, there's just some more go to's for the regulators as an enforcement tool. But we've started to see discussions that really go a little bit outside of that scope, right? Bias in are you using sensitive personal information and people are getting really very different prices or very different experiences in a way that could be discriminatory. And so I think that is something that we're just going to continue to see a whole lot more dialogue about and probably some use cases. Sometimes they'll pull out the worst use cases to say, you know, set the example of really being thoughtful about how you use your AI and what's your quality assurance there. **Jonathan:** Gotcha. Thanks, Alysa. What else is going on? I think you mentioned kids data and health data seem to be still hot topics. **Alysa:** Yeah, so I think sensitive personal information under the state privacy laws. I've seen FTC do some enforcements recently, and so it's really raised this question of what is sensitive personal information? You have what the statutes say, but companies derive inferences from data that they don't get from consumers. And now this is super regulated data and really the quandary of what do I do with this data? How much do my business practices change? Do I have to reach out to consumers to get their consent for data I already have? Can I use this data for marketing? And there's some real world impacts to that, right? Like data could be about certain prescriptions or medications. If those, if consumers don't know about that, that could be a loss, but it also raises, yes, this is sensitive data. You have a responsibility in how you're processing it and who you're sharing it with. So I think we're just seeing a whole lot of consternation and really some varied practices going forward and how companies think about the new privacy laws and implement that into their business. **Jonathan:** Last we talked, there's been some movement on federal privacy law. **Alysa:** Well, movement. There's discussion. There's discussion. Right? So there is a hearing today in the House Energy and Commerce Committee where they talked about the bill that had, you know, did not make it in the last term, a bipartisan federal legislation via nationwide privacy law. But you also had California again, right? The governor, the privacy protection agency and the AG's office write a pretty robust letter saying, Do not preempt our law. And there continues to be that, really that conflict on whether, yes, the nationwide standard, but do you do it at the, you know, instead of allowing states to really experiment and have different standards? So I don't know, we still have a lot of foes on federal privacy law and I don't think we're at consensus yet, but it's still an active discussion point and so we'll just continue to monitor. **Jonathan:** And then I think you said a couple weeks ago, right, the investment that California regulators are making here just makes preemption a nonstarter for them, right? And this is just evidence of that. Thanks, appreciate it. **Alysa:** It's budget. I mean, think about how many, the FTC has a budget that gets pretty limited already. And so, if they are now tasked with more regulations and more enforcement, can their existing budget really cover that? Probably not. You have California, for example, that's got the CPPA and the AG and budget to support that. Does that suddenly not become a useful enforcement angle? Things to be worked out. **Jonathan:** Yeah, gotcha. Thanks, Alysa. As always, I appreciate these huddles. I wanted to ask you about flow down obligations, what they are, but let's do that next week. **Alysa:** Oh, that's good teaser. All right. **Jonathan:** Great to chat with you. Have a good one.

Next step

See permissioning infrastructure in action

Walk through the platform with a Ketch architect, or launch the free CMP today.

Get Started Free

Get started in less than 5 min