State attorneys general are increasingly using decades-old consumer protection and professional licensing laws to police AI business practices, sidestepping the slow pace of AI-specific legislation. Recent enforcement actions and multistate letters show that existing statutes - particularly Unfair and Deceptive Acts and Practices (UDAP) laws - are being applied to everything from AI chatbots posing as therapists to algorithmic pricing tools.
Targeting AI as a substitute for licensed professionals
Regulators are focusing on AI products that claim to replace human professionals in fields that require state licenses. A first-of-its-kind enforcement action came from Pennsylvania's Department of State against Character.AI, alleging its companion chatbots held themselves out as licensed psychiatrists and offered treatment recommendations without actual licensure.
The complaint cites chatbots that claimed to hold Pennsylvania medical licenses and provided assessments to users. Pennsylvania is seeking injunctive relief, and Character.AI is set to respond by September 1, 2026. The case is notable because it leans on professional licensing board authority rather than any new AI law.
In December 2025, a bipartisan coalition of more than 40 state attorneys general sent a letter to major AI companies expressing concern about "sycophantic and delusional outputs" from generative AI, particularly involving children. The letter called for age-tailored conversations, mandatory referrals to mental health professionals when conversations involve self-harm, and mitigation of AI outputs designed to tell users only what they want to hear. The companies have not responded publicly.
AI-fueled deception and illegal content
State AGs are also targeting social media platforms for enabling AI-driven scams. Investment frauds using deepfake impersonations, fake cryptocurrency schemes, and misleading weight-loss ads for GLP-1 drugs have drawn warnings from the New Hampshire AG and a bipartisan group of 35 AGs. The coalition demanded that platforms better enforce their own policies, review high-risk ads, and curb AI-generated content that evades automated controls.
In January 2026, the same coalition sent a letter to xAI over its chatbot Grok, which the AGs said could generate nonconsensual intimate images and child sexual abuse material. The letter argued that existing safeguards are insufficient and asked the company to explain how it will permanently block such content and remove existing harmful material. xAI has not issued a public statement.
Surveillance pricing and data transparency
California's privacy and consumer protection regulators launched an investigative sweep into how retailers, grocers, and hotels use personal data to set individualized prices. The state warned that undisclosed use of such data may violate the California Consumer Privacy Act. New York complemented this approach with the Algorithmic Pricing Disclosure Act, which requires businesses using personalized pricing to display a clear notice: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." Noncompliance carries civil penalties.
Why this matters for legal professionals
Companies developing or deploying AI tools need to demonstrate that their governance, disclosures, testing, and oversight are sufficient to prevent consumer harm under existing laws. For legal professionals advising clients, staying current on these enforcement trends is critical. AI for Legal training can help practitioners understand how traditional legal frameworks apply to emerging AI risks. In practice, this means substantiating AI performance claims, disclosing personal data use, reviewing AI-generated content for deception, and documenting safeguards against foreseeable misuse - especially where minors or regulated professional advice are involved.
Your membership also unlocks: