State AGs Target AI With Existing Laws, Not Waiting for New Rules
A coalition of 42 attorneys general is using consumer protection statutes to hold AI companies accountable now.
State attorneys general are done waiting for Congress to write AI-specific laws. On December 9, 2025, a coalition of 42 AGs sent coordinated demands to 13 major AI companies, proving existing consumer protection statutes provide immediate enforcement authority.
The December Ultimatum
The coalition's letter targeted OpenAI, Google, Meta, Microsoft, Apple, Anthropic, xAI, Character.ai, Replika, Perplexity AI, Chai AI, Nomi AI, and Luka. The 16-point demand gave companies until January 16, 2026 to implement specific chatbot safety measures.
The AGs cited documented harms tied to AI chatbot interactions, including deaths. The message was clear: existing legal frameworks already provide enforcement authority, and regulators intend to use them.
California Leads Enforcement Push
California's Attorney General reinforced this approach in February 2026 by establishing a dedicated AI accountability unit. The office immediately put the new team to work, sending a cease-and-desist letter to xAI over explicit image generation capabilities in its Grok chatbot.
This pattern signals that AI companies cannot rely on the absence of specialized AI legislation to avoid liability. Broad consumer protection and civil rights statutes give state regulators immediate enforcement tools against algorithmic bias, deceptive marketing, or unsafe AI features.
Why Traditional Laws Work
The strategy exploits a key reality: most AI harms fit existing legal categories. Deceptive AI marketing falls under consumer protection laws. Discriminatory algorithmic decisions trigger civil rights statutes. Unsafe chatbot interactions can violate duty-of-care principles already on the books.
By pivoting to these established frameworks, state AGs bypass the slow legislative process and maintain oversight as AI integration accelerates across business operations. The regulatory gap created by absent or insufficient AI-specific laws becomes less exploitable when prosecutors can reach for tools they already possess.
What Comes Next
The December coalition action and California's enforcement unit represent early moves in what industry observers expect to be sustained state-level pressure. With 42 states signaling coordinated interest in AI safety, companies face a patchwork of potential enforcement actions rather than a single federal standard.
For AI developers, the takeaway is straightforward: compliance cannot wait for perfect legislation. Regulators are prepared to evaluate AI systems through traditional legal lenses—and they're already filing the paperwork.