In a rapidly evolving regulatory landscape, state attorneys general are increasingly applying existing consumer protection and privacy laws to artificial intelligence technologies, even in the absence of comprehensive federal legislation. With over 250 AI-related bills introduced across various states by mid-2025, businesses deploying AI must recognize that compliance risks extend beyond newly enacted statutes. The focus is particularly acute on AI systems that handle sensitive consumer data, make significant decisions, or produce misleading information, which could lead to enforcement actions under established legal frameworks.

For instance, states like Colorado and California have begun implementing specific regulations targeting automated decision-making processes, while others like Texas and Massachusetts have taken enforcement actions against companies for alleged violations of privacy and discrimination laws. These cases highlight the potential liabilities businesses face as they integrate AI into critical functions such as hiring, underwriting, and customer interactions. The recent coalition of 42 state AGs calling for stronger protections against harmful AI applications underscores the urgency for companies to reassess their compliance strategies.

As federal entities like the Federal Trade Commission also ramp up scrutiny, businesses must proactively evaluate their AI deployments against existing laws governing privacy, discrimination, and professional services. The message is clear: compliance cannot wait for new legislation; organizations must act swiftly to align their AI practices with current legal standards to mitigate risks and avoid costly penalties.

Source: PYMNTS