State AGs Put Businesses on Notice: Existing Laws Already Apply to AI

AI Regulation

AI compliance teams take note: You don’t need to violate AI-specific statutes to face regulatory scrutiny. State attorneys general increasingly are using existing consumer protection, privacy and professional licensing laws to police artificial intelligence.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    As Congress has yet to enact comprehensive AI legislation, states have moved aggressively to fill the regulatory vacuum. More than 250 AI-related bills had been introduced across the states by mid-2025, addressing issues including deepfakes, automated decision-making, employment, healthcare and government use of AI, according to a Reuters legal analysis.

    For businesses deploying AI, however, the more immediate compliance risk may come from laws already on the books.

    State AGs possess broad authority under consumer protection, data privacy, anti-discrimination and professional licensing statutes. Those laws can apply regardless of whether the conduct at issue involves conventional technology or sophisticated AI models.

    That principle is becoming increasingly important as businesses rush to integrate AI into customer interactions, underwriting, hiring, advertising and data analytics. Regulators are focusing particularly on AI systems that collect or analyze sensitive consumer data, make consequential decisions, produce misleading claims or perform functions traditionally reserved for licensed professionals.

    Several states are also adopting targeted AI laws. Colorado has regulated automated systems used in “consequential decisions” involving education, employment, housing, financial services, insurance, healthcare and government benefits, with violations enforceable by the state attorney general as deceptive trade practices.

    California has adopted broad rules addressing automated decision-making and algorithmic discrimination, while Connecticut recently enacted legislation governing employers’ use of AI-driven tools in recruiting, screening and workforce management. Republican-led states including Texas, Alabama, Arkansas and South Dakota have generally pursued narrower measures focused on areas such as elections, intellectual property and obscenity.

    Political differences may matter less as AI-related harms become more visible, however. A coalition of 42 state AGs in December urged major technology companies and AI developers to strengthen protections against potentially harmful AI chatbots, signaling the possibility of multistate enforcement even without uniform legislation.

    Recent cases illustrate where businesses face the greatest exposure, per Reuters.

    In Texas, the attorney general used the state’s Data Privacy and Security Act in 2025 against an insurer accused of developing software that collected consumers’ location, movement and speed data through third-party mobile applications. AI allegedly helped aggregate the information into a massive driving-behavior database that was then used to support insurance premium increases. A jurisdictional challenge remains pending.

    Massachusetts regulators, meanwhile, reached a $2.5 million settlement with a student loan company accused of using AI models that automatically rejected applications based on immigration status and produced higher denial rates and loan costs for Black and Hispanic applicants.

    Professional licensing is another emerging enforcement front. In May, Pennsylvania’s attorney general sued Character.AI, seeking to stop the company from allegedly presenting AI companion bots as licensed medical professionals capable of providing medical advice. The company pointed to disclaimers stating that its characters were fictional and their statements should not substitute for professional advice.

    Federal enforcement provides another warning. The Federal Trade Commission previously acted against Rite Aid over allegedly inaccurate facial-recognition technology and separately targeted businesses accused of making deceptive AI claims or using AI to facilitate fraudulent reviews and other schemes.

    The practical message for businesses is that AI compliance cannot wait for Congress or state legislatures to establish comprehensive new frameworks. Companies should evaluate whether AI deployments comply with existing rules governing privacy, discrimination, advertising, consumer protection, professional services and consequential decision-making.

    For state AGs, the technology may be new. The legal tools for policing it often are not.