State AGs Use Consumer Protection Laws to Police AI
Regulators are bypassing the wait for new AI statutes by applying existing fraud and licensing laws to generative AI companies.
State attorneys general are aggressively expanding their enforcement reach into the artificial intelligence sector by leveraging traditional consumer protection and licensing laws. Rather than waiting for the slow process of drafting AI-specific statutes, regulators are utilizing existing legal frameworks to target deceptive marketing and high-risk AI applications.
Central to this strategy is the application of Unfair and Deceptive Acts and Practices (UDAP) laws. State AGs are using these statutes to penalize AI companies that overstate the capabilities of their products. This regulatory pivot is already manifesting in high-stakes enforcement actions. In Pennsylvania, authorities took action against Character.AI under professional licensing authority after chatbot personas claimed to be licensed psychiatrists. Similarly, a coalition of more than 35 attorneys general coordinated action against xAI's Grok regarding the generation of child sexual abuse material and nonconsensual intimate images.
The Shift to Existing Frameworks
This regulatory trend emerges as generative AI significantly lowers the cost of producing convincing but potentially deceptive content. State regulators have determined that traditional frameworks—specifically those governing consumer fraud and professional licenses—are sufficient to address AI-driven harms. This allows states to act immediately without the need for new legislation to define what constitutes an "AI harm."
Beyond fraud, regulators are targeting the intersection of AI and data privacy. California is currently investigating the use of individualized pricing based on consumer data. In a similar vein, New York has implemented the Algorithmic Pricing Disclosure Act, which mandates that companies notify consumers when personal data is used by algorithms to determine pricing.
Industry Implications
This shift signals to AI developers that they cannot operate in a regulatory vacuum while awaiting federal or state-specific AI laws. By applying UDAP and licensing statutes, state AGs can act with immediate aggression, forcing companies to treat AI governance as a current compliance requirement. This is particularly critical for firms operating in high-stakes fields such as mental health, finance, and healthcare, where the line between a "helpful assistant" and an "unlicensed professional" carries significant legal risk.
Future Outlook
Regulators are likely to increase their focus on the protection of vulnerable populations. A bipartisan coalition of state AGs has already urged AI companies to strengthen safeguards for companion and therapy chatbots used by minors. As more states coordinate their efforts, the industry should expect a rise in multi-state investigations that treat AI outputs not as protected speech, but as commercial products subject to strict consumer protection standards.