The Federal Trade Commission’s civil penalty for a knowing violation of an existing order or rule stands at $53,088 per violation, according to the Federal Register’s 2026 penalty inflation notice and a single overstated AI capability claim running across a website, an app store listing, and a press release can count as three separate violations, not one. On March 7, 2026, the FTC issued its first comprehensive Section 5 policy statement addressing artificial intelligence, formalizing enforcement positions the agency had been building since it launched Operation AI Comply in 2024.
The timing matters. Marketing teams are shipping AI feature announcements faster than legal review can keep up, and “AI-powered” has become a default headline word rather than a claim someone tested. This piece is a working checklist: what evidence the FTC expects to already exist before you publish an AI claim, and how that evidence overlaps with documentation you may already be producing for ISO/IEC 42001, the EU AI Act, or NIST AI RMF.
What Counts as an “AI Claim” Under FTC Section 5
Section 5 of the FTC Act does not mention artificial intelligence. It prohibits unfair or deceptive acts or practices in commerce, and the FTC has applied that language to AI marketing the same way it applies to any other advertising claim. The scope is broader than most teams assume. It covers explicit performance numbers (“99% accurate”), implied capability claims (“our AI reviews every transaction” when a human actually reviews a sample), AI-washing (calling a rules-based feature “AI-powered” because the label sells better), and claims baked into pricing or investor materials, not just consumer-facing ads.
The FTC’s March 2026 policy statement groups deceptive AI claims into three recurring patterns: performance claims made without pre-existing substantiation, absolute safety or fairness claims that no system can actually guarantee, and implied endorsements (terms like “clinically validated” or “expert-reviewed”) attached to systems that were never reviewed by the professionals implied. Each pattern has already produced enforcement action, which is covered in more detail below.
The “Reasonable Basis” Standard: What Evidence the FTC Actually Wants
Before you make any performance claim, the FTC expects you to already hold what it calls competent and reliable evidence supporting that specific claim. This is the reasonable basis standard, and it has one detail that trips up most compliance teams: the evidence has to predate the claim. Testing conducted after a claim is published, in response to a complaint or an audit, does not retroactively substantiate it.
The rigor required scales with two things: how specific the claim is, and how much harm a wrong claim could cause. A vague statement like “our AI helps you make better decisions” needs less formal proof than “our AI reduces false positives by 40%,” and a claim about a hiring algorithm’s fairness needs more rigorous evidence than a claim about a photo filter, because the consequences of being wrong are not the same.
In practice, reasonable basis evidence tends to fall into five categories: the underlying test or validation methodology, the raw performance data and how it was measured, documented limitations and known failure modes, the training data sources and how they were collected, and a record of who reviewed the claim language against the evidence before publication. Missing any one of these is a plausible line of questioning in an FTC inquiry.
Cross-Framework Mapping: FTC Substantiation vs. ISO 42001, EU AI Act and NIST AI RMF
Here is what most guidance on this topic misses: if your organisation is already maintaining AI governance documentation for ISO 42001, the EU AI Act, or NIST AI RMF, you are already producing most of what FTC substantiation requires. The frameworks were not built with the FTC in mind, but the underlying discipline, testing before you claim, documenting limitations, keeping version history, is identical.
| FTC substantiation requirement | ISO/IEC 42001:2023 | EU AI Act | NIST AI RMF 1.0 |
|---|---|---|---|
| Pre-existing test/validation data | Clause 8.1 operational planning and control; Annex A.6 AI system development records | Article 9 risk management documentation; Annex IV technical documentation | MEASURE function: system performance and validity testing |
| Documented limitations and failure modes | Annex A.6 AI system documentation, known limitations | Article 13 instructions for use; disclosure of capabilities and limitations | MAP 1.1: context and limitations documented |
| Data sourcing and methodology | Annex A.7 data for AI systems | Article 10 data governance requirements | MAP 2.3, GOVERN 1.1: data provenance |
| Claim review and sign-off trail | Clause 9.1 monitoring, measurement, and evaluation | Article 9(2) risk management as continuous, iterative process | GOVERN 3.2: accountability structures |
| Ongoing monitoring after launch | Clause 10.1 continual improvement | Article 61 post-market monitoring | MEASURE 4, MANAGE 4: ongoing monitoring |
The practical upshot: a compliance team already tracking AI systems for ISO 42001 certification or an EU AI Act conformity file does not need a parallel FTC evidence process. It needs one evidence record per AI claim, mapped forward to whichever framework an auditor or regulator asks about.
Where Govern365.ai fits: Govern365.ai’s AI model registry links each marketing claim to the specific system version, test results, and control mapping behind it, so the same record satisfies an FTC inquiry and an ISO 42001 surveillance audit without being rebuilt twice.
The AI Claims Evidence Checklist
Use this before any AI feature claim goes live, whether it is a homepage headline, an app store description, a sales deck, or an investor update. Each item names the framework it double-counts for, so you are not maintaining separate files.
- Written test or validation methodology for the specific claim being made, dated before the claim’s first publication.
FTC reasonable basis / NIST AI RMF MEASURE
- Raw performance data supporting any number in the claim (accuracy rate, time saved, cost reduction), not a marketing-rounded figure.
FTC reasonable basis / ISO 42001 Clause 8.1
- A documented list of known limitations and failure conditions for the AI system referenced in the claim.
FTC unfairness prong / NIST AI RMF MAP 1.1
- Confirmation that any absolute language (“bias-free,” “100% accurate,” “completely safe”) has been replaced with scoped, testable language.
FTC deception standard
- Source and collection method for any training or evaluation data referenced, directly or implied, in the claim.
EU AI Act Article 10 / ISO 42001 Annex A.7 [VERIFY]
- Sign-off from legal or compliance confirming the published claim language matches the underlying evidence, not an earlier draft.
FTC substantiation / ISO 42001 Clause 9.1
- For any testimonial, review, or endorsement generated or edited by AI: a disclosure of the AI’s role and confirmation the content was not fabricated wholesale.
FTC Endorsement and Testimonial Guides
- Version record tying the specific claim to the specific model or system version it describes, updated when the system changes materially.
ISO 42001 AI system inventory / EU AI Act Annex IV
- A post-launch monitoring plan describing when the claim will be re-tested or retired if system performance changes.
EU AI Act Article 61 / NIST AI RMF MANAGE 4
Before marketing AI capabilities, organizations should establish strong governance through NIST AI RMF implementation, including AI inventories, risk assessments, and continuous monitoring.
Common Deceptive Patterns the FTC Has Already Prosecuted
Operation AI Comply, launched in September 2024 and continued without interruption under the current administration, gives a concrete map of what the FTC actually pursues. The pattern is consistent: claims about earnings and business outcomes tied to AI, claims about the AI’s capability itself, and claims dressed up as consumer testimonials.
| Pattern | Example enforcement action | What was missing |
|---|---|---|
| Unsubstantiated earnings claims tied to AI tools | FTC actions against business-opportunity schemes marketing AI-powered storefronts with promised passive income | No evidence that typical customers achieved anything close to the advertised outcomes |
| Capability claims that were never tested | A company marketing an AI legal service without testing its output against professional-quality benchmarks | No pre-existing comparison data supporting the claimed capability |
| AI-generated fake reviews and testimonials | FTC scrutiny of a review-generation tool used to produce large volumes of AI-written product reviews | No disclosure that reviews were AI-generated rather than genuine customer experience |
None of these required a novel legal theory. Every case relied on Section 5’s existing unfair-or-deceptive-practices standard, applied to an AI-flavored version of a claim the FTC would have challenged from any other product category.
Endorsements, Testimonials and Synthetic Influencers: The May 2026 Update
In May 2026, the FTC published updated guidance applying its existing Endorsement and Testimonial Guides directly to AI-generated and AI-augmented content: synthetic influencers, AI-written testimonials, AI-edited creator content, and deepfake-style endorsements. The guidance does not create a new obligation. It closes the ambiguity that let some brands treat AI-generated endorsements as exempt from disclosure because no human ostensibly “said” them.
For a marketing claims file, this means the same reasonable-basis and disclosure standard applies whether the endorsement came from a real customer, an AI-generated persona, or an AI-edited version of a real review. If your evidence file only covers product capability claims and skips testimonial content, it has a gap the May 2026 guidance specifically targets.
Building an Audit Trail Before You Ship
Most teams that get an FTC inquiry right have one thing in common: the evidence already existed somewhere findable before the letter arrived. Most teams that struggle share the opposite problem. The test results live in a data scientist’s local files, the claim language was finalized in a Slack thread, and legal signed off verbally in a meeting nobody minuted.
A workable audit trail needs three things: a single system of record per AI system (not per campaign), a timestamp showing evidence existed before the claim was published, and a visible sign-off step that is not optional. None of this requires new software if your team is disciplined about a shared drive and a naming convention. It becomes harder to maintain manually once you are tracking claims across multiple products, multiple markets, and multiple model versions, which is where dedicated audit evidence tooling earns its place.
Where Govern365.ai fits: Govern365.ai’s audit evidence management module timestamps each claim review, attaches the supporting test data, and routes sign-off between product, legal, and compliance so the trail exists automatically instead of depending on someone remembering to save an email thread.
What Happens If You Get It Wrong
The FTC’s typical first response to a first-time Section 5 issue is a cease-and-desist order or a consent order requiring changes to marketing practices and, often, ongoing reporting for a period that can run 20 years. Civil penalties, up to $53,088 per violation, are generally reserved for violations of an existing order or rule where the company had actual or constructive knowledge the conduct was deceptive. Each non-compliant claim, and in some cases each day it stays live, can be treated as a separate violation, which is how total exposure escalates quickly even at a fixed per-violation ceiling.
The FTC can also seek disgorgement of profits traceable to the deceptive claim, and it has no private right of action under the FTC Act itself, meaning consumers cannot sue directly under Section 5. That does not remove exposure: state attorneys general have their own consumer protection authority, and FTC guidance is increasingly cited as evidence of an industry standard in unrelated litigation, including class actions brought under state law.
Evidence collected for AI hiring tools compliance can also help substantiate AI marketing claims by demonstrating documented governance and testing practices.
Frequently Asked Questions
Does the FTC have a specific AI advertising law?
No. The FTC does not have a standalone AI advertising statute. It applies FTC Act Section 5, which prohibits unfair or deceptive practices, to AI marketing claims the same way it applies to any other advertising. The March 2026 policy statement clarifies how Section 5 applies to AI specifically, but it does not create new legal obligations.
What is “AI washing” and why does the FTC care about it?
AI washing means claiming a product uses AI when it does not, or exaggerating how much AI drives a feature’s results. The FTC treats this as a straightforward Section 5 deception issue because it induces purchases based on a false premise about the product, regardless of whether any consumer is harmed by the AI itself.
How much evidence do I need before I can say my AI feature is “95% accurate”?
You need competent and reliable evidence, typically testing data or validation studies, that supports the specific number before you publish it, not after. The more specific and consequential the claim, the more rigorous the evidence needs to be. A vague claim like “highly accurate” still requires substantiation, just not necessarily a controlled study.
Can I say my AI is “bias-free” if we ran a fairness audit?
Be careful with absolute language. FTC guidance treats unqualified claims like “bias-free” or completely “safe” as presumptively misleading, since no AI system is entirely free of bias or failure modes. It is safer to describe specific testing performed and the scope it covered, rather than an unqualified guarantee.
Do FTC AI rules apply to AI-generated customer reviews or testimonials?
Yes. Reviews or endorsements generated or substantially shaped by AI must meet the same disclosure and substantiation standards as human-written ones. The FTC’s updated 2026 endorsement guidance extends this explicitly to synthetic influencers and AI-edited creator content, closing an ambiguity that previously let some AI-generated testimonials go undisclosed.
What happens if the FTC finds my AI marketing claims were unsubstantiated?
Outcomes range from a consent order requiring changes and ongoing monitoring, to civil penalties of up to $53,088 per violation for knowing violations of an existing order or rule, to disgorgement of profits tied to the deceptive claim. Multiple non-compliant statements can each count as a separate violation.
Is there a private right of action if a competitor makes false AI claims?
No. The FTC Act does not let consumers or competitors sue directly. State attorneys general can bring their own consumer protection claims, though, and courts increasingly treat FTC guidance as evidence of an industry standard in other types of litigation, so the absence of a private right of action does not mean no exposure.
Should marketing or legal own the AI claims evidence file?
Neither alone. The evidence needs to be created where the testing happens (product or data science), reviewed by legal for claim language, and retained somewhere both marketing and compliance can find it before a claim ships, not after a demand letter arrives. Shared, versioned storage prevents the file from living only in someone’s inbox.
Conclusion
Every deceptive-AI-claim case the FTC has brought traces back to the same gap: a claim published before the evidence existed to support it. Closing that gap is not primarily a legal problem. It is a documentation habit, one that overlaps almost entirely with the evidence GRC teams are already assembling for ISO 42001, the EU AI Act, or NIST AI RMF.
Start with one AI feature you are currently marketing. Pull the claim language, and check whether the underlying test data predates the claim. If it does not, that is the fastest place to close exposure before your next audit or your next FTC inquiry.
Start your 14-day free trial of Govern365.ai to keep AI claim evidence, ISO 42001 controls, and EU AI Act documentation in one system of record. Govern365.ai, by the Global AI Certification Council.
