Start Free Trial
Home/Regulations/FTC Act / Section 5 (Privacy) — Regulatory Reference
Regulatory Reference
Technology Federal (US) medium

FTC Act / Section 5 (Privacy) — Regulatory Reference

Unfair/deceptive AI data practices — safeguards rule, model risk management, and audit trail for enforcement.

Key Provisions
  • 15 USC § 45 — unfair or deceptive acts or practices
  • FTC Safeguards Rule for non-bank financial institutions
  • 2023 guidance on AI claims and substantiation
  • Order remedies including algorithmic disgorgement in recent settlements
How AutoPIL Enforces It
  • Audit chain provides substantiation for AI claims under FTC scrutiny
  • Pre-retrieval enforcement prevents AI from consuming categories that would create deceptive practice risk
  • Agent registry supports algorithmic disgorgement scoping if ordered
Audit LogPolicy EngineSensitivity LabelsAlert Rules
AutoPIL Policy IDs
TEC-FTC5-SUB-001AI Claim Substantiation Evidence
TEC-FTC5-DG-001Algorithmic Disgorgement Scope
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does the FTC Act Section 5 require for AI agents handling consumer data?
Under 15 USC § 45, the FTC prohibits unfair or deceptive acts or practices, which the agency has applied directly to AI systems. The FTC's 2023 AI guidance requires companies to substantiate claims made by or about AI models — including claims about fairness, accuracy, and data handling. For AI agents specifically, this means organizations must be able to demonstrate that an agent accessed only the data it was authorized to access, that the agent's decisions were consistent with stated policies, and that the underlying data practices were not deceptive. Organizations that cannot produce this evidence face enforcement risk, including civil penalties and consent orders requiring operational changes.
When does FTC Section 5 apply to AI agent deployments in technology companies?
FTC Section 5 applies to any technology company that deploys AI agents in consumer-facing products or internal systems where data handling could affect consumers directly or indirectly. This includes companies using AI agents for personalization, content recommendation, customer support, fraud scoring, or any function that involves processing consumer data and producing outputs that influence consumer outcomes. The FTC has been explicit that AI-related practices are subject to its existing unfairness and deception authority — no sector-specific AI regulation is required for FTC jurisdiction to attach. Companies operating under prior FTC consent orders face heightened scrutiny when they introduce AI agents.
What is algorithmic disgorgement and how does it affect AI systems?
Algorithmic disgorgement is an FTC-ordered remedy requiring a company to delete not just improperly collected data, but also any models, algorithms, or systems trained on that data. The FTC has applied this remedy in multiple enforcement actions — including against companies that trained AI models on data collected without adequate notice or consent. For organizations with deployed AI agents, this creates a direct risk: if an agent accessed sensitive data categories outside its authorized scope during training or inference, the entire model or downstream artifacts could be subject to a disgorgement order. The scope of what must be deleted hinges on what data the agent actually accessed and when — which is exactly the record an audit chain provides.
How does AutoPIL help technology companies with FTC Section 5 compliance?
AutoPIL addresses FTC Section 5 risk at three points. First, its pre-retrieval policy engine enforces access controls before sensitive data enters the agent's context window — preventing the unauthorized data consumption that creates deceptive practice risk. Second, its tamper-evident audit chain produces a verifiable record of every agent decision, providing the substantiation evidence the FTC requires when it scrutinizes AI claims. Third, the agent registry supports algorithmic disgorgement scoping: if an order is issued, the registry identifies exactly which agents accessed which data categories and when, bounding the disgorgement footprint. Policy IDs TEC-FTC5-SUB-001 and TEC-FTC5-DG-001 map directly to these enforcement scenarios.
What are the enforcement risks and penalties under FTC Section 5 for AI violations?
The FTC's primary enforcement tools under Section 5 are consent orders, civil penalties for order violations (up to $51,744 per violation per day), and mandatory operational remedies. In AI-related enforcement, remedies have included algorithmic disgorgement, mandatory privacy programs with third-party audits, and prohibitions on specific data uses for fixed periods. Companies that previously operated under FTC consent orders and subsequently introduced AI agents without updating their data handling programs have faced additional penalties for consent order violations. The FTC has signaled through its 2023 AI policy guidance and enforcement activity that substantiation of AI claims and data practice transparency are active enforcement priorities, not aspirational standards.
Covered Industries

The FTC Act Section 5 applies to any company in commerce that handles consumer data through AI systems — spanning technology, financial services, retail, and telecom. As the FTC has expanded its AI enforcement posture, any organization deploying AI agents that influence consumer outcomes needs a defensible record of what data those agents accessed and under what authorization.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries