When Your AI Lies, You Lie: A Dealer's Responsibility for AI Under the FTC
I have watched dealers buy AI chatbots and AI BDCs the same way they used to buy fax machines. Sign the contract. Plug it in. Forget about it.
That is not going to work in 2026.
The FTC has been clear. There is no AI exemption from the laws on the books. When your chatbot quotes a price, your dealership quoted the price. When your AI BDC promises a customer something, your dealership promised it. When your AI credit pre-qualification denies a buyer, your dealership made that decision. The vendor sold you a tool. The vendor did not sell you a get-out-of-jail-free card.
Most dealers do not understand this yet. The ones who do are about to have a structural advantage over the ones who do not.
What Changed Recently
Two things happened in the last twelve months that dealers should know about.
First, the FTC launched Operation AI Comply in late 2024. Five cases in the first sweep. The agency was clear about its position. The FTC chair at the time said it directly. "There is no AI exemption from the laws on the books."
Second, in December 2025, the President signed Executive Order 14178. Most coverage of it focused on the parts about accelerating AI development. The part dealers should care about is buried in Section 4(b). Every federal agency with consumer-facing enforcement authority had to publish an AI policy statement within 90 days. That deadline was March 11, 2026. The FTC published its guidance on schedule. The position is consistent with what the agency has been saying for two years. Existing law applies. The AI does not change the analysis.
What that means in practice. If a statement would have been deceptive when a salesperson made it, it is still deceptive when the chatbot makes it. If a price would have been illegal under state law when advertised in a newspaper, it is still illegal when the AI quotes it. If a credit decision would have triggered an ECOA adverse action notice when a human underwriter made it, the AI does not get a pass.
The Three Places AI Creates Real Risk for Dealers
I have been around enough dealership AI deployments to know where the trouble actually shows up. Three places, in order.
The chatbot floor
The AI chatbot on the dealership website is the highest-traffic AI tool in the store. It also makes the most statements per day. Pricing. Availability. Financing eligibility. Trade values. Service appointment times. Every one of those statements is a representation by the dealership.
The bot does not know the truth. The bot knows what it was trained on. If the inventory data is stale, the bot quotes prices on vehicles that sold three days ago. If the financing logic was set up by a vendor who does not understand your state's lending laws, the bot makes claims about approval odds that violate ECOA. If the appointment system was not configured for your service hours, the bot books customers into time slots that do not exist.
The FTC does not care that the bot was wrong. It cares that the dealership made the claim.
The AI BDC
The AI BDC sends thousands of messages a month. Every one of those messages is a TCPA exposure point if consent is not properly tracked. Every one is a UDAP exposure point if the message is misleading. Every one is a state consumer protection issue if it makes claims about pricing, financing, or vehicle condition that the dealership cannot back up.
I have read AI BDC transcripts where the bot promised a customer "guaranteed approval" on financing. The dealership had no underwriting authority. The bot was making it up because the model was trained on conversion-friendly language. When the customer showed up to be denied, that was a deceptive practice. The dealership made that promise. The vendor pointed at its terms of service.
AI credit decisions
This is the highest-stakes one. The new wave of AI credit pre-qualification tools that approve shoppers in seconds. If your tool denies a buyer, the dealership owes that buyer an adverse action notice under ECOA. The notice has to explain the reason for the denial. "The AI did not approve you" is not a reason. The dealership has to know what the AI used to make the decision, and the customer has the right to know it too.
Most dealers have not asked their AI credit vendor for the underlying decision logic. Most of those vendors cannot produce it. That is a problem that will land on the dealership, not the vendor, when a regulator asks.
The Vendor Will Not Save You
Read your AI vendor contracts. I have. The pattern is consistent.
The vendor promises the tool works. The vendor disclaims liability for outcomes. The vendor positions the dealership as the operator who is responsible for how the tool is used. When a regulator shows up, the vendor's first call is to its lawyers. The vendor's lawyers point at the contract.
This is not malice on the vendor's part. It is how every SaaS contract is written. The customer is responsible for compliance. The vendor provides the technology. The dealership is the customer. The dealership is responsible.
You can negotiate better contract terms with bigger AI vendors. You probably cannot do it with smaller ones. Either way, the legal position is the same. The FTC's position is the same. The dealership made the statement. The dealership owns the consequence.
What Dealers Are Actually Responsible For
Six things. In order of how much they will matter when something goes wrong.
What your AI says. Every claim your chatbot, your BDC, your credit tool makes is a dealership claim. You are responsible for the truth of those claims. Pricing has to match. Financing claims have to be backed by actual approval authority. Vehicle condition claims have to be accurate. The bot does not get to make claims the dealership cannot make.
What your AI knows about your customers. Any AI tool that touches customer credit data is in scope of the FTC Safeguards Rule. That means MFA. Encryption. Access controls. Vendor oversight. The AI tool is treated the same way the DMS is treated. If the AI vendor cannot produce a SOC 2 report and demonstrate Safeguards-equivalent controls, that is a problem you need to surface now.
The decisions your AI makes. If your AI makes or influences a credit decision, ECOA applies. Adverse action notices have to go out. Reasons have to be documented. Disparate impact has to be monitored. You cannot outsource these obligations to a vendor.
How your AI identifies itself. Some states require disclosure that a chatbot is a bot, not a human. California has had this on the books since 2019. Other states are adding versions of the same rule. If your bot is having conversations that imply it is a person, you may already be in violation in some states.
How your AI handles consent. Every automated message your AI BDC sends is subject to TCPA. Consent has to be tracked. Opt-outs have to be honored in real time. Quiet hours have to be respected. If your AI vendor is not enforcing this at the platform level, the dealership is exposed every time the bot sends a message.
What your AI does when it gets it wrong. You need a process for what happens when the bot makes a mistake. Customer-facing correction. Internal review. Updates to the training or the rules. Documentation. The FTC is now asking dealers to prove the AI is monitored, not just deployed.
How to Stay Out of Trouble
Practical action list. The order matters.
One. Audit what your AI is actually saying.
Pull a sample of chatbot transcripts and AI BDC messages from the last thirty days. Read them. Not the executive summary the vendor sent. The actual transcripts. Look for three things. Claims about pricing that do not match current inventory. Claims about financing or approval odds. Claims about vehicle condition or features that may not be accurate. If you find any of these, fix the source.
Two. Make the vendor produce the playbook.
For every AI tool you run, ask the vendor for the rules the AI follows when it makes claims. What pricing source it uses. What financing logic it applies. How it handles edge cases. If the vendor cannot produce this in writing, you have no way to defend yourself when a regulator asks why your bot said what it said. Vendors who cannot produce documentation are vendors you should not be using.
Three. Wire AI tools into your Safeguards program.
Every AI vendor that touches customer credit data gets added to your Safeguards Rule vendor list. SOC 2 or equivalent attestation. Documented access controls. Documented data flows. If the AI is sending data to a third party for processing, that is another link in the chain you are responsible for.
Four. Set the bot's authority limits in writing.
The bot is not allowed to promise things the dealership cannot deliver. Get this in writing with the vendor. No guaranteed approvals. No claims about specific lender decisions. No pricing claims outside a documented source. No vehicle condition claims that have not been verified. If the bot crosses these lines, the vendor has to fix it.
Five. Track adverse action notices.
If you use AI for credit pre-qualification, every denial generates an ECOA adverse action notice obligation. Document the process. Make sure the notice actually goes out. Make sure the reason on the notice is something the customer could act on. "Insufficient credit history" is fine. "Our AI declined you" is not.
Six. Disclose the bot.
Add the disclosure to your chatbot. "You are chatting with an AI assistant." It costs you nothing. It satisfies California's law and the rules other states are adding. Customers who want a human can ask. The customers who do not care will not stop using the bot because it told them what it is.
Seven. Document the monitoring.
Keep records of who reviews the bot's output, how often, and what was flagged. The FTC in 2026 is asking dealers to prove the AI is monitored, not just deployed. If a regulator asks how you make sure your bot is not lying, the answer needs to be more than "the vendor handles it."
The Mindset That Keeps You Safe
The dealer mindset that gets in trouble with AI is the one that treats the AI as separate from the dealership. The bot is a vendor product. The BDC is outsourced. The credit tool is a black box. None of that matters to the regulator.
Treat the AI the same way you treat a new salesperson. You train it. You supervise it. You correct it when it gets something wrong. You are responsible for what it says to customers. You are responsible for the decisions it makes on your behalf.
The dealers who get this right in 2026 will be the ones who built AI into their compliance program from day one. The dealers who get hit will be the ones who treated AI like a magic black box that was somebody else's problem. The bot is not somebody else's problem. The bot is your salesperson, your BDC rep, your underwriter, and your phone agent all at the same time. The standards have to match.
Structure before tools. Strategy before speed. Systems before scale.
The AI Operator Framework is the methodology for designing, governing, and scaling AI operations inside a business, including the AI governance work that keeps dealerships out of regulatory trouble. Explore the full framework at JamilAshkar.com/framework. Start with the free course at JamilAshkar.com/course.