Why the FTC, Not Congress, Is Regulating AI Now
Randy Hall, CEO

AI regulation for MSPs is not waiting on Congress or a new statute to take effect. It is already here, arriving through the Federal Trade Commission's enforcement of existing deceptive advertising law against unsubstantiated AI claims, which means every "AI-powered" line in your own sales materials already carries legal exposure regardless of what any state or federal AI bill eventually does.
Regulation didn't wait for a law
While lawmakers in Washington argue over a federal AI framework and states amend their own AI statutes on the fly, the FTC has been quietly building an enforcement record using authority it already has. Section 5 of the FTC Act bars unfair and deceptive practices, and the agency has decided that applies fully to claims made about artificial intelligence, whether or not any AI-specific law exists yet.
The FTC's "Operation AI Comply" initiative has run since 2024 and continued without pause into 2026 under new leadership, a signal that this enforcement priority is not tied to one administration's agenda. By May 2026, the agency had filed its thirteenth AI washing case since the initiative began, this one against three marketing companies over an "Active Listening" tool marketed as AI powered. The pattern is consistent across nearly every case: a company claims its software does something autonomous and intelligent, and the actual product does not hold up to that description.
What did the FTC actually go after?
In January 2026, the FTC resolved its case against Growth Cave, an operation that marketed an "AI software" as able to automate nearly 100 percent of running an online course business. The FTC's complaint said the tool actually required customers to manually upload advertisements, set appointments, and write outbound messages themselves. The settlement totaled 48.6 million dollars, partially suspended based on the defendants' ability to pay, with the rest earmarked for consumer redress.
The violation was not that the product used AI. It was that the marketing claimed a level of autonomy and reliability the product could not actually deliver.
Why does this matter more than the state law fight?
The state by state AI law patchwork and the federal preemption push both matter, but they share one thing in common: nothing about them is settled, and nothing about them changes what you can legally claim about a product today. FTC enforcement is different. It does not depend on which state your client sits in, whether a governor delays a bill, or whether Congress ever passes a national standard. It applies the moment you make a claim, in any state, right now.
That makes it the more immediate compliance question for most MSP owners, not the less important one. A state AI statute might apply to a narrow set of high risk automated decisions. Federal deceptive advertising law applies to every sentence in your website copy, your sales deck, and your proposal templates that describes what an AI feature does. If you sell, resell, or white label anything you describe as AI powered, that description is a claim the FTC's substantiation standard already covers.
How much exposure do MSPs actually carry?
More than most owners assume, because the FTC's substantiation standard reaches implicit claims, not just explicit ones. A line like "our AI handles ticket triage so your team doesn't have to" implies a level of autonomy that needs to be true, not just aspirational, before you put it in writing. If a vendor's underlying tool still needs a technician to review flagged tickets, and your own marketing drops that detail to sound more impressive, the exposure is yours, not the vendor's, because you are the one making the claim to the client.
This is a real risk for the specific business model this platform serves. White labeling AI tools means you are putting your name and your reputation behind claims about functionality you did not build and may not fully control. Before you repeat a vendor's marketing language in your own proposals, verify it against what the tool actually does in production, not what the vendor's data sheet says it does in ideal conditions.
The cost of getting this wrong is not limited to a regulatory fine, and for most MSPs a fine was never the realistic outcome anyway. The more likely cost is a client who feels misled after an "AI powered" service turns out to need the same manual review they were told it would eliminate, and who brings that complaint to a competitor, a review site, or a renewal conversation instead of the FTC. A defensible claim protects the sale as much as it protects you from enforcement risk.
Is federal procurement pulling the same lever?
A separate but related pressure is building through government contracting rather than enforcement. The NIST AI Risk Management Framework remains voluntary for private companies, but the General Services Administration has proposed a federal contract clause that maps AI system documentation and governance requirements directly onto the roles NIST's framework already defines for developers, deployers, and integrators. Contractors serving federal agencies are increasingly expected to show NIST aligned AI governance as a condition of doing business, and that expectation flows down to subcontractors and vendors in the supply chain behind them.
If any part of your client base touches federal, state, or local government work, this is worth tracking even though it is not yet a hard legal requirement everywhere. A framework that starts as a procurement preference in one agency has a track record of becoming a baseline expectation across the public sector within a few contract cycles, the same way cybersecurity frameworks like CMMC moved from recommended to required.
What should you actually do about your own marketing?
Start by treating every AI claim in your current materials as something you would need to defend with evidence if the FTC or a client's lawyer asked you to. Pull your website copy, sales deck, and proposal templates and flag every sentence that describes an AI feature doing something autonomously. For each one, confirm it is true in production today, not true in a demo environment or true of a future release the vendor has promised.
Keep a simple record of what substantiates each claim: a vendor's technical documentation, your own testing notes, or a client outcome you can actually verify without overstating it. That file does not need to be elaborate, but having it before a claim gets challenged is the difference between a quick answer and a drawn out dispute. Avoid language that promises full automation or "no human required" unless that is literally accurate, since those are exactly the phrases the FTC has targeted in every case so far.
None of this is a reason to undersell what your AI tools actually do. It is a reason to describe it accurately, since accurate claims are also the ones that hold up when a prospect asks a hard question in a sales call. Getting your whole team, not just marketing, aligned on what you can and cannot say about AI functionality is a training problem as much as a legal one, and Forge University's certification tracks are built to give account managers and technicians a working command of that line before it costs you a client's trust or a regulator's attention.
Watch the EU AI Act too if any client or partner relationship touches the European market. Its extraterritorial reach means a US based MSP can fall under its scope through a client's EU operations even without a physical EU presence, and its compliance deadlines have already shifted once in 2026. That is a separate front from the FTC fight, but the underlying discipline is the same: know exactly what your AI tools do before you promise it in writing.
If you are not sure which of your current AI powered offerings would hold up under this kind of scrutiny, Actiforge's stack builder is a fast way to map what you are actually selling against what each tool actually delivers. Review the rest of the Actiforge product catalog for the tools built to help your team sell AI capability you can stand behind.
Sources: Federal Trade Commission Operation AI Comply case record | DLA Piper AI washing enforcement analysis | General Services Administration proposed AI contract clause | Holland and Knight EU AI Act compliance guidance.