Congress has failed to pass a federal AI law — everyone knows that. The Trump administration's AI policy framework advocates "light-touch regulation" and is still trying to use federal power to suppress state-level legislation.
But one thing many have missed: federal enforcement agencies have long stopped waiting for legislation. They are starting to go after AI companies using the tools they already have.
A recent report from Morgan Lewis sums up the trend: federal AI enforcement has outpaced federal AI legislation.
FTC: Deceptive AI Claims Fall Under Section 5
The Federal Trade Commission has no specific AI provision, but it has a hammer it has used for decades: Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices."
What are the most common pitfalls for AI companies?
- Product claims that exaggerate AI capabilities ("100% accurate," "completely unbiased")
- AI making decisions affecting users without their knowledge
- AI customer service that does not clearly inform users it is a machine
- Vague privacy terms that actually use user data to train models
All of these fall under Section 5. The FTC has already begun scrutinizing AI companies' advertising and data practices. If it determines a claim is false advertising, it can impose fines directly, without waiting for new laws.
SEC: AI Washing Is a New Financial Risk
The Securities and Exchange Commission has a different focus: AI hype in capital markets.
AI washing, simply put, is when public companies or companies planning to go public exaggerate or fabricate their AI capabilities in communications with investors.
This became a real problem after the AI concept took off in 2025. A wave of companies began stuffing annual reports, IPO materials, and investor presentations with AI jargon: "We are fully AI-driven," "AI increased our revenue by X%" — but these numbers either lack methodological support or are outright fabricated.
The SEC's AI washing investigations are already underway, and several cases are expected to reach formal penalties in the first half of 2026. For AI companies preparing for an IPO, this is a legal risk that needs serious attention, not just a public relations issue.
DOJ: The False Claims Act in Government Contracts
The Department of Justice takes a more targeted approach, focusing on AI projects that use government funds.
The False Claims Act allows the government and whistleblowers to sue those who make false claims or commit fraud on government contracts. If a company takes a government contract, claims to have deployed a certain AI system to improve efficiency or security, but has not done so, or the effect is significantly overstated, it can trigger an investigation.
The US federal government spends a very large amount each year on IT and AI project procurement. Many defense, healthcare, and infrastructure projects are using AI. This is a significantly underestimated legal risk, especially for companies that both sell AI to the government and exaggerate their capabilities.
Antitrust: Algorithmic Pricing Is Under Scrutiny
Antitrust regulators are focusing on a very specific issue: multiple companies simultaneously using the same AI pricing tool.
Even if there is no explicit collusion agreement between these companies, if the result is coordinated price increases across the industry, it could trigger an antitrust investigation. This year, the hotel and rental platform industries have already been named in investigations, with the core question being: do companies using the same AI pricing algorithm constitute a "digital cartel"?
There is currently no clear precedent on this issue, but several cases are moving forward, and the outcome will affect the compliance boundaries of the entire AI pricing tool market.
States Fill the Gap: Three New Laws Passed Last Week
With federal legislation stalled, states have been acting on their own.
Last week (the week of April 7-13), three more states passed new laws:
- Nebraska: AI chatbots must clearly disclose to minors that they are AI, cannot impersonate humans, and cannot claim to provide mental health services.
- Maryland: Regulates AI algorithmic pricing, requiring companies to disclose AI pricing mechanisms.
- Maine: AI cannot be used for psychological counseling; the legal definition of practicing without a license is expanded to cover AI tools.
Combined with New York's Algorithmic Pricing Disclosure Law and Colorado's AI Act (which requires risk assessments, documentation, and governance reports for high-risk AI decisions), the US now has a patchwork of scattered but real AI regulations in effect across various states.
Enforcement and Litigation Form a Feedback Loop
The Morgan Lewis report offers a noteworthy observation: these federal enforcement actions are not just about fines; they are reshaping how courts interpret existing laws.
An FTC penalty can trigger follow-up lawsuits in related industries; a court ruling can provide new enforcement grounds for regulators. This creates an "enforcement-litigation feedback loop" — without new legislation, existing legal tools, through enforcement practice, are producing increasingly clear AI compliance boundaries.
What does this mean for AI companies?
Don't wait for Congress; track regulatory agency actions first. The moves of the FTC, SEC, and DOJ are more worth tracking in real time than Congress passing an AI bill.
Compliance Advice Has Changed
Based on advice from legal firms, here are the most practical actions for AI companies right now:
- Every claim must be backed by data: Especially public claims about AI capabilities, which must be supported by verifiable methodologies and test results.
- Do not transmit competitively sensitive data through shared AI platforms: Your pricing strategy and supplier information, if transmitted through public AI tools, could trigger an antitrust investigation.
- Document modeling and training processes: How the model was trained, what bias assessments were done — regulators may ask to see this at any time.
- Establish an AI governance committee: Have dedicated personnel responsible for internal AI compliance so you can explain things clearly if something goes wrong.
Congress hasn't moved. But federal enforcement agencies have started to act, shifting regulatory pressure from the legislative level to the enforcement level. This is actually a more uncertain and harder-to-predict compliance environment — because there are no clear legal provisions to follow, only the dynamic standard of "how existing laws are being interpreted."
Sources: AI Enforcement Accelerates as Federal Policy Stalls and States Step In (Morgan Lewis); Proposed State AI Law Update: April 13, 2026 (Troutman Pepper Privacy + Cyber + AI); CocoLoop, U.S. Tech Legislative & Regulatory Update – First Quarter 2026 (Global Policy Watch)