
By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer
TL;DR: Chuck Gallagher, AI ethics speaker and author, examines a proposed FTC policy statement warning that quietly steering an AI system away from what users expect — without telling them plainly — can count as deception under federal law.
Picture a woman typing a question into a chatbot. She wants the best answer the machine can give her. Plain advice. A number she can act on. What she doesn’t know is that behind the screen, the system was told to hand her something else. Not her best answer at all, but one that’s been steered. And nobody told her. That gap — between what a user expects and what the machine was built to do — is exactly what a new federal proposal is aimed at.
What Did the FTC Actually Propose?
On July 7, 2026, the Federal Trade Commission published a proposed policy statement applying Section 5 of the FTC Act to companies that market artificial intelligence. Section 5 is old ground. For nearly ninety years it has banned deceptive acts and practices in commerce. The new statement simply points that authority at AI. Its claim is direct: when a company steers an AI system’s output toward goals the user never asked for and wouldn’t expect, and doesn’t say so clearly, that can be deception.
Two things are worth getting straight. First, this is proposed, not final. The comment window closes on Friday, July 31, 2026, and anyone can file. Second, the proposal grew out of a December 2025 executive order, and its examples lean hard into a political argument — companies inserting ideological corrections into answers, or bending outputs to satisfy state laws like Colorado’s. That framing is real, and I won’t pretend it isn’t there. But underneath the politics sits a plainer idea, and that idea is worth your attention no matter where you stand. There’s also no state-law escape hatch here. The statement is clear that complying with a state rule does not excuse deceiving a federal consumer.
Why Doesn’t “We’re Just Optimizing” Hold Up?
Here comes the rationalization. “We’re just optimizing for engagement.” “For safety.” “For the brand.” Every one of those might be true. And none of it was ever the problem. The problem was that nobody said so out loud.
I’ve spent years watching this exact pattern play out in boardrooms, long before anyone ever typed a prompt into a chatbot. Someone makes a quiet change. They tell themselves it serves a good purpose. They just don’t tell the people it affects. The FTC’s deception test doesn’t care about the good purpose. It asks three plain questions. Is there a representation or an omission likely to mislead a reasonable person? Would a reasonable person be misled? And does the thing they’re misled about actually matter to their decision? A company that sells its AI as giving the best possible answer, then quietly trains it to do something else, has walked straight into all three.
What Does “Clear and Conspicuous” Really Mean?
The FTC leaves a door open. A company is allowed to steer its system — if it tells people plainly. But plainly means plainly. The statement is blunt on this point. A disclosure buried in terms of service won’t do it. A one-time line tucked into fine print won’t do it. The disclosure has to be prominent enough to actually change what a reasonable person expects when they sit down to use the thing. The bigger the gap between what you advertise and what your system really does, the louder and more often you have to say so. Trust me — that’s the part most companies will get wrong. They’ll write it to satisfy a lawyer. Informing an actual human being comes second, if it comes at all.
Where’s the Consequence?
Here’s the thing about a rationalization. The longer it runs, the bigger the bill when someone finally reads the fine print. “It’s fine. It’s for their own good.” That sentence has wrecked more good intentions than I can count.
The FTC’s own statement cites a number that should stop you cold: people accept AI answers without checking them more than ninety percent of the time. Think about what that means. That trust is the entire asset. It’s the reason the product is worth anything at all. Spend it quietly, and yes, you’re risking an enforcement action with real teeth. But you’re also spending the one thing that made anyone believe the machine in the first place. Here’s what I’ll tell you: the enforcement risk is the smaller problem. Losing that trust is the one you don’t recover from. It doesn’t come back with a settlement.
So what do you do? Define the objective your system is honestly built to serve. Write down every place it deviates from what a user would expect. Then make the disclosure something a real person would actually see and understand. A signpost. Not a footnote they’ll scroll right past. Tie the whole thing to a governance framework you already answer to, whether that’s ISO/IEC 42001 or the NIST AI Risk Management Framework. Not because a standard is a shield — it isn’t. Do it because writing it down forces you to say out loud what your system is really for. And most of the time, the trouble starts precisely because nobody wanted to say it out loud.
Every choice inside that machine is still a choice. Someone made it. Someone can name it. The only question is whether they’ll name it before the customer does — or before the FTC does.
Frequently Asked Questions
Is the FTC’s AI deception policy statement final?
No. Not yet. As of July 2026 it’s a proposed policy statement, published in the Federal Register on July 7, 2026. The comment period runs through July 31, 2026, and the Commission can still revise it before anything becomes final.
What is “output steering” in an AI system?
It’s when a company quietly aims an AI’s answers at goals the user never asked for — engagement, brand protection, an ideological tilt — instead of the best answer for what the person actually typed. The FTC isn’t worried about steering on its own. It’s worried about the kind nobody tells you about. If a reasonable person wouldn’t know it was happening, the agency says that can cross into deception.
Can a company avoid an AI deception claim just by disclosing?
Maybe. But only if that disclosure is clear and conspicuous. A disclaimer buried in the terms of service doesn’t count. Fine print doesn’t count. It has to be prominent enough to actually change what a reasonable user expects.
Does complying with a state law protect an AI company from the FTC?
No. There’s no state-law safe harbor under Section 5. A company can still catch a federal deception claim even if it altered its outputs to satisfy a state requirement. That’s a real bind, and I’d plan for it now rather than after the letter arrives.
What frameworks help manage AI disclosure risk?
Two names come up a lot: ISO/IEC 42001, an AI management-system standard, and the NIST AI Risk Management Framework. Both lean hard on governance and transparency. Neither one is a legal shield. What they do is push you to document what your system is designed to do and where it departs from user expectations.
The FTC hasn’t finalized anything yet. But the principle underneath its proposal isn’t waiting on a comment deadline — it’s as old as commerce itself. Tell people the truth about what you’re selling them. When the product is a machine that millions trust to think alongside them, that old rule doesn’t get weaker. If anything it gets heavier. If your board or leadership team is wrestling with how to build honesty into the way your AI actually behaves, that’s the conversation I have with organizations every week. You can find me — and book that conversation — at ChuckGallagher.com.
Five Questions for Reflection
1. Where in your own product or operation does the system do something a customer wouldn’t expect — and would they be surprised to learn it?
2. When you’ve told yourself “it’s for their own good,” what were you really avoiding saying out loud?
3. If a regulator read your disclosures the way a rushed customer does, would they come away with an accurate picture?
4. What’s the difference, in your organization, between a disclosure written to satisfy a lawyer and one written to inform a person?
5. Whose job is it to name the objective your AI is really built to serve — and has anyone actually done it?
