State enforcers use existing statutes to police business AI use
State attorneys general are applying consumer, privacy and licensing laws to AI systems as comprehensive federal legislation remains absent.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
State attorneys general are increasingly scrutinising corporate use of artificial intelligence under existing consumer protection, privacy, anti-discrimination and professional licensing laws, according to a Reuters legal analysis. More than 250 AI-related bills had been introduced in US states by mid-2025, but companies may face nearer-term enforcement risk from statutes already in force.
The shift matters for businesses using AI in customer service, underwriting, hiring, advertising and data analysis. State enforcement officials can apply long-standing legal tools where AI systems handle sensitive data, influence decisions affecting consumers, generate allegedly misleading representations or carry out work associated with licensed professions.
Congress has not passed a comprehensive national AI law, leaving states to write sector-specific and broader measures. Reuters reported that state bills have covered deepfakes, automated decisions, employment, healthcare and government use of AI.
States split on new AI rules
Some states have moved toward targeted AI statutes. Colorado has enacted rules for automated systems used in “consequential decisions” in areas including education, employment, housing, financial services, insurance, healthcare and public benefits. Under that framework, violations can be pursued by the state attorney general as deceptive trade practices.
California has adopted broad rules covering automated decision-making and algorithmic discrimination. Connecticut recently passed legislation governing employers’ use of AI tools in recruitment, screening and workforce management.
Republican-led states including Texas, Alabama, Arkansas and South Dakota have generally advanced narrower AI measures, Reuters reported, with a focus on subjects such as elections, intellectual property and obscenity. Even so, partisan differences may not prevent coordinated enforcement where state officials identify similar harms.
In December, a bipartisan group of 42 state attorneys general called on large technology companies and AI developers to improve safeguards around potentially harmful AI chatbots, according to Reuters. The move signalled that multistate action remains possible even without a single national AI framework.
Privacy, lending and licensing cases show exposure
Recent enforcement matters identified by Reuters indicate where regulators are testing existing authority. In Texas, the attorney general used the state’s Data Privacy and Security Act in 2025 against an insurer accused of creating software that gathered consumers’ location, movement and speed information through third-party mobile apps.
According to Reuters, AI was alleged to have helped combine that information into a large database on driving behaviour, which was then used to support increases in insurance premiums. A jurisdictional challenge in the Texas matter remains pending.
Massachusetts regulators reached a $2.5 million settlement with a student loan company accused of using AI models that automatically denied applications on the basis of immigration status. The company was also accused of producing higher denial rates and loan costs for Black and Hispanic applicants, according to Reuters.
Professional licensing has become another point of attention. In May, Pennsylvania’s attorney general sued Character.AI, seeking to prevent the company from allegedly presenting AI companion bots as licensed medical professionals able to provide medical advice. Character.AI cited disclaimers stating that its characters were fictional and that their statements should not replace professional advice.
Federal enforcement has moved along similar lines. The Federal Trade Commission previously took action against Rite Aid over allegedly inaccurate facial-recognition technology. The agency has also targeted companies accused of deceptive AI claims or of using AI to support fraudulent reviews and other schemes, according to Reuters.
The emerging compliance question is therefore broader than whether a company has breached an AI-specific statute. For state and federal enforcers, the central issue is often whether the use of AI violates existing rules on privacy, discrimination, advertising, consumer protection, licensed services or consequential decisions.
This story draws on original reporting from PYMNTS.