Everyone Is Reading the New AI Laws. The Enforcement Is Coming From an Old One.
State attorneys general do not need an AI statute to reach an AI product. They have general unfair-and-deceptive-practices authority, no rulemaking requirement, compulsory investigative powers before any case is filed, and jurisdiction over every state your signup form accepts.
The compliance calendars are pointed at the wrong thing. Teams are tracking effective dates for statutes that phase in over years, while the authority most likely to be exercised on them has been in force for decades and has no effective date to wait for. It applies today, to the marketing page that is live right now, and the first sign of it is not a lawsuit — it is a document demand with a three-week deadline.
Five Theories That Already Reach You
None of these were written for AI. All of them fit it without amendment, which is exactly why they get used first.
Deception — the capability claim
The doctrine: A representation is deceptive when it is likely to mislead a reasonable consumer acting reasonably, and it is material to their decision. No intent to deceive is required.
The AI shape it takes: Accuracy percentages with no stated test set, 'fully automated' for a workflow with a human queue behind it, 'trained on your data only' where a shared base model is involved, and demo videos edited to remove retries. The claim does not have to be false in the lab; it has to be misleading to the buyer who read it.
Deception — the omission
The doctrine: Failing to disclose a fact is actionable where disclosure would be material to the transaction. Silence is a representation when the buyer would reasonably assume otherwise.
The AI shape it takes: Not disclosing that outputs are generated rather than human-authored, that a chat agent is not a person, that inputs are retained for model improvement, or that a headline feature is in limited beta for most accounts.
Unfairness — the practice, not the statement
The doctrine: A practice can be unlawful even when every statement about it is true, where it causes substantial injury consumers cannot reasonably avoid and the injury is not outweighed by benefits.
The AI shape it takes: This is the theory that reaches design. Defaults that opt users into training-data collection, retention that survives deletion in the interface but not in the pipeline, and automated adverse decisions with no reachable human. Truthful disclosure in a settings page does not answer an unfairness count.
Substantiation — the missing file
The doctrine: An objective claim must be supported by evidence held at the time it was made. The question is not whether the claim is true now; it is what you had when you published it.
The AI shape it takes: Nearly every AI marketing site makes an objective claim — faster, more accurate, saves N hours — and almost none has a substantiation file. The first demand letter asks for it by name, and the absence is itself the finding.
Borrowed statutes — the multiplier
The doctrine: State consumer protection acts commonly treat violations of other statutes and rules as per se unfair or deceptive practices, importing the penalty structure of the consumer act.
The AI shape it takes: A privacy, biometric, auto-renewal, telemarketing or licensing violation stops being a standalone problem and becomes a count under the consumer act, with its own civil penalties per violation and attorney-fee provisions. This is how a modest technical lapse becomes an expensive one.
What an Investigation Actually Looks Like
The mental model most founders carry is a lawsuit with a press conference. The real sequence is quieter, starts earlier, and the decisions that determine the outcome are all made in the first fortnight.
Before anything arrives
Complaints and market monitoring
Offices open matters from consumer complaint portals, referrals from sister agencies, competitor letters, press coverage and their own review of marketing sites. A single articulate complaint about a refused cancellation or a wrong automated decision is enough to start a file.
Day 0
Civil investigative demand or subpoena
A compulsory document and interrogatory demand issued without a court filing and without any finding of wrongdoing. It is not a lawsuit and it is not public, but it is enforceable, and the response deadline is typically weeks rather than months.
Weeks 1-2
Preservation and scoping
The obligation to preserve attaches immediately and covers systems most teams forget: model versions, prompt templates, evaluation runs, A/B test configurations, support macros and internal chat. Routine deletion policies that keep running after receipt become their own problem.
Weeks 2-8
Production and narrowing
Most demands are negotiated down in scope, but only by counsel who can describe what the systems actually hold. The technical answer to 'can you produce every version of the ranking model in the period' determines the cost of the entire matter.
Months 2-9
Interviews and follow-on demands
Offices ask for the people who wrote the claim, not only the people who run the company. Product marketing and the engineer who owns the evaluation harness are the two interviews that decide the theory.
Resolution
Assurance of discontinuance, consent judgment, or suit
Most matters end in a negotiated assurance with injunctive terms, a payment and reporting duties. The injunctive terms outlast the payment by years and are what actually constrains the product roadmap.
Four Postures, and Why the Arithmetic Differs
The same practice produces wildly different exposure depending on how many offices are looking at it and in what configuration. This is the part that is worth understanding before you need it.
Single-state inquiry
What starts it: Local complaints, a state-specific statute, or an office with a standing interest in the sector.
The math: Narrow scope, resolvable, and a useful signal about what the marketing site says. The mistake is treating it as trivial — the response becomes the record every later office reads.
Multistate coalition
What starts it: A sector-wide practice, national marketing, or a matter that gets shared through the standing coordination channels between offices.
The math: One practice, many statutes, and civil penalties calculated per violation per state. A defensible practice in one jurisdiction can be indefensible in aggregate simply because the penalty arithmetic changes.
Parallel federal and state
What starts it: A federal agency opens on the same facts, or state offices act after a federal matter narrows.
The math: State authority is independent. Resolving with a federal regulator does not resolve state claims, and settlement terms that do not contemplate state releases leave the exposure open.
Private class action in the wake
What starts it: The assurance or complaint becomes public and reads as a roadmap of admitted facts.
The math: Many state consumer acts carry private rights of action with statutory damages and fee-shifting. The public document from the state matter is the plaintiff's first exhibit.
Six Documents That Decide It
An investigation is resolved on artefacts, not on explanations. Every item below either exists before the demand arrives or does not exist at all — none of them can be credibly created afterwards.
The marketing site as of the claim date
The first thing requested and the easiest to produce against you. Offices pull archived captures independently, so a quietly edited claim is visible as an edit.
The substantiation file
Evaluation methodology, test set description, dates and the person who signed off. If this does not exist as a document before the demand, it cannot be created after it.
The consent and disclosure flow, as rendered
Screenshots of the actual screens in the actual order, not the policy text. Offices reconstruct the flow and ask why the material fact appeared two screens after the commitment.
Support tickets on the disputed feature
Where the internal knowledge of a limitation lives. A macro telling agents how to explain a known failure is evidence you knew, dated.
The deletion pipeline, end to end
Deletion in the interface is not deletion in backups, logs, evaluation sets or a fine-tuned checkpoint. The gap between the promise and the pipeline is the most common single finding.
Model and prompt version history
Establishes what the product did on the date of the consumer's transaction. Teams that cannot reconstruct a past version concede the factual question by default.
The cheapest defensive work available to a small AI company is not a policy. It is a dated substantiation note attached to every objective claim on the marketing site, written by the person who ran the evaluation, stored where it can be found in a week. That single habit answers the request that opens most of these matters.
Questions Teams Actually Ask
Can a state attorney general act against us with no AI statute in place?
Yes, and this is the central point most teams miss. Every state has a consumer protection statute prohibiting unfair or deceptive acts and practices, written in general terms precisely so it applies to commerce that did not exist when it was passed. Nothing in that authority is technology-specific, so no new AI law is needed — a misleading capability claim is deceptive on the same terms as a misleading claim about a mattress. Two features make it faster than a new statute: it requires no rulemaking, so there is no comment period or phase-in to plan around, and it carries investigative powers exercisable before any complaint is filed. Companies waiting for their state's AI act to take effect are usually already inside the authority that will actually be used on them.
What is a civil investigative demand, and how is it different from being sued?
It is a compulsory pre-suit request for documents, written answers and sometimes testimony, issued under the office's own authority without filing anything in court. It carries no finding of wrongdoing and is generally not public. It is still enforceable, and a late or ignored response is the fastest way to convert an investigation into a filed matter. Three practical differences shape the response: deadlines are set by the office rather than negotiated between parties, scope is broader than discovery in a filed case because relevance is measured against an investigation rather than pleaded claims, and the preservation duty attaches on receipt across systems nobody thinks of as documents — model checkpoints, prompt templates, feature flags, evaluation runs. Scope is almost always negotiable, but only by someone who can describe accurately what your systems hold.
Which claims on our site draw scrutiny first?
Objective, quantified capability claims, because they are checkable and because substantiation is required at the time the claim is made. Accuracy percentages with no disclosed methodology, comparisons against named competitors, savings figures derived from one friendly customer, and 'autonomous' applied to a workflow with a human queue are the recurring four. A second category draws scrutiny for a different reason: claims about data. That inputs are never used for training, that data stays in a region, that deletion is immediate — these are factual representations about your architecture and they are verifiable against your own documents. The pattern is rarely lying. It is a page written from an engineering aspiration that was later descoped, with nobody assigned to update the page.
Does a disclaimer in our terms fix a deception problem?
Rarely, and relying on it is a structural error. The analysis looks at the net impression the whole advertisement creates for a reasonable consumer, and a qualification only works when it is clear, conspicuous and near the claim it qualifies. A contradiction buried in a checkbox agreement does not cure a headline. There is also a category disclaimers cannot reach at all: unfairness examines the practice rather than the statement, so a fully disclosed practice causing substantial injury consumers cannot reasonably avoid is still reachable. The useful version of the instinct is to fix the claim rather than qualify it — an accuracy figure with its test conditions stated in the same sentence is both more defensible and, in enterprise sales, more persuasive.
We are small and sell nationally. How many states can reach us?
In principle every state where you have consumers, because these statutes protect residents regardless of where the seller sits. Self-serve signup means your footprint is set by your user table rather than by any market-entry decision you made. The practical exposure is more concentrated than the theoretical one — offices differ in sector focus and capacity, and matters cluster. But two structural realities matter more than the state count. Penalties are usually per violation, and a violation is often counted per consumer or per transaction, so arithmetic rather than severity drives exposure for an automated product with many small transactions. And offices share information, so how you handle the first inquiry is read by the ones that follow.
What do we do in the first week after a demand arrives?
Four things, and the first two are technical rather than legal. Suspend automated deletion across every system in scope — model artefacts, logs, analytics, internal chat — and document that you did it with a timestamp, because spoliation turns a document dispute into a credibility one. Freeze the marketing pages under scrutiny rather than editing them; archived captures make edits visible and a post-receipt edit reads as consciousness of the problem. Then engage counsel who has run one of these, and assign a single technical owner who can describe your systems accurately, because scope negotiation succeeds or fails on that description. What not to do is equally specific: no informal call to the office to explain, no internal email speculating about liability, no new claims published while the old one is under review.
Do these end in fines, and what else comes with a resolution?
Most end in a negotiated assurance of discontinuance or consent judgment, and the payment is usually not the expensive part. The injunctive terms are, because they run for years and bind the product rather than the balance sheet. Common terms include substantiation before any objective claim is published, mandated disclosure language and placement, an accessible human review path for automated decisions, deletion verification, annual compliance reporting to the office, and retention obligations that outlast your normal policy. Two consequences follow: your roadmap acquires a compliance gate reviewed by the office rather than your team, and breaching an assurance is separately enforceable with escalated penalties. Resolutions are usually public, which is where the private class action and the next office's inquiry both begin.
The Three-Week Test
Pick the boldest number on your own homepage. Now assume you have three weeks to produce, in writing, the evaluation that supports it, the date it was run, the data it was run on, and the name of the person who approved publishing it.
If that exercise produces a scramble rather than a file, you already know the outcome of the first request in any demand you ever receive — and unlike almost everything else on this page, it is fixable this afternoon.
Related Reading
- AI washing and marketing claims — the claim-side exposure, from the federal direction.
- FTC AI enforcement actions — the parallel authority that does not release state claims.
- CCPA penalties and fines for AI businesses — a statute whose breach is commonly imported as a per se unfair practice.