2026 Calendar

FTC Chairman Andrew Ferguson Says Enforce Existing Laws on AI. The Question Is: Why Isn't the FTC and State AGs Enforcing Existing Consumer and Child Protection Laws?

FTC Chairman Andrew Ferguson Says Enforce Existing Laws on AI. The Question Is: Why Isn't the FTC and State AGs Enforcing Existing Consumer and Child Protection Laws?

By Rex M. Lee | Security Advisor | Tech Journalist | TechStorm

 

Momentum AI, Reuters Event, AUSTIN, Texas, 09.25.26

I had the opportunity to cover Reuters Momentum AI in Austin, Texas, on Friday, September 25, where I attended A Conversation with Andrew Ferguson, Chairman of the Federal Trade Commission, moderated by Jody Godoy, Reuters Tech Policy and Antitrust Correspondent.

As I watched the interview unfold, I was struck by how closely one of Chairman Ferguson’s central arguments echoed a foundational principle of the Electronic Bill of Rights (EBOR): before government creates another layer of technology-specific legislation, such as the Kids Online Safety Act (KOSA), it should determine whether existing consumer and child-protection, child endangerment, privacy, deceptive trade, competition and other applicable laws can be enforced against the companies and executives responsible for the technology. 

I have researched existing legal frameworks in the United States and multiple countries, including the United Kingdom and Kenya, and have yet to identify a law that categorically exempts a company or its executives from criminal liability associated with harmful products or services simply because those products were developed using new technologies such as AI, algorithms, quantum computing or code.

Consider the implications: negligent companies could produce harmful or even deadly products for public consumption while their CEOs and executives are shielded from potential criminal prosecution simply because those products were developed using new technologies.

That would effectively create a different standard of accountability for the technology industry—similar to what we see today, where negligent tech companies and executives facing allegations of harm and death caused by their addictive products and services are far more commonly confronted with civil litigation and regulatory enforcement than criminal prosecution.

Rather what we see are meaningless congressional hearings, hallow apologies from tech CEOs, plus lawsuits, watered down new laws, plus fines, settlements, and penalties that only benefit the tech industry, government, and lawyers.

This distinction matters. Civil liability and criminal liability are not the same. If corporate executives can profit from products alleged to cause serious harm while facing primarily financial or civil consequences, we must ask whether existing laws provide additional avenues for accountability when the evidence satisfies the elements of a criminal offense—particularly as concerns continue to grow over technology addiction and its effects on children.

These highly addictive technologies are embedded in billions of phones, computers, vehicles, appliances, televisions, wearable technologies and connected products supported by Android, iOS and Windows globally.

Today, internet-connected consumer products and services incorporate AI, apps, platforms and other digital services supported by  Surveillance Capitalism—a business model built around collecting and monetizing user data, through targeted advertising fueled by highly addictive AI-infused apps, platforms, social media and chatbots contributing to the global rise in tech addiction.

The central legal question is whether existing consumer-protection, child-protection, privacy and endangerment laws are being enforced when the evidence supports violations. 

The fact that a product incorporates AI, algorithms, quantum technologies or software does not, by itself, place the company or its executives outside otherwise applicable law.

There is also a fundamental issue of consent.

Consumers, including teens (13+) routinely purchase phones, computers and connected products only to discover that access to essential features and services requires them to click “I Agree” and accept the predatory terms of service. 

These agreements can function as predatory one-way-take-it-or-leave-it contracts of adhesion because they are presented on standardized, non-negotiable terms.

In practice, consumers may be required to forgo their privacy, security, and safety while losing sovereignty over Name, Image, Likeness, and Data (NILD) or what the advertising industry describes as their Digital Twin.

The terms of service require the product owner and user, including children, to give up sovereignty over their data, biology (biometric data), financial data, medical data, and other confidential data.

If the person rejects the agreement, they cannot use the products and services they paid for, this is the definition of consumer oppression and exploitation.

I research shows that the collective terms of service that support all products and services concerned are illegal according to existing consume protection laws governed by the FTC and State AGs consumer protection agencies.

People are forced participate within a highly exploitive business model rooted in Surveillance Capitalism: consumers are presented with the appearance of consent, while meaningful participation in the modern digital economy increasingly depends upon accepting these predatory contracts of adhesion, they no ability to negotiate.

I authored the EBOR framework following my work advising Congress on the Facebook-Cambridge Analytica scandal and subsequent technology-policy issues. 

Senator Ted Cruz’s San Antonio office asked me to develop a congressional digital-rights policy proposal from a developer’s perspective that became the Electronic Bill of Rights. eBill of Rights

I am currently working with numerous governments globally through the British Council and Smart Africa who adopting EBOR framework for their digital rights

Many of my readers know that I am a former OTA application and platform developer who later became a government advisor, security and privacy researcher, and technology journalist. 

One issue I have consistently raised is whether existing legal frameworks are being adequately enforced when evidence indicates that technology companies or executives may have violated consumer-protection, privacy, competition, child-protection or other applicable laws through the design, distribution or operation of consumer products.

This issue extends well beyond generative AI. Phones, computers, connected products, operating systems, applications, social-media platforms and AI-powered services have become gateways into an economic model built around collecting data, capturing attention and monetizing engagement through advertising. 

Former Google design ethicist Tristan Harris has argued that major technology services deliberately engineer engagement rather than attracting it accidentally, while Stanford addiction specialist Anna Lembke has described compulsive smartphone use within the broader framework of behavioral addiction. 

Facebook whistleblower Frances Haugen later compared aspects of social-media addiction to cigarettes, testifying that some teenagers reported feeling worse while using Instagram yet being unable to stop. The Washington Post

Generative AI introduces another dimension: the human tendency to attribute understanding, empathy and even human characteristics to machines. That phenomenon dates back to ELIZA, the pioneering chatbot developed at MIT by computer scientist Joseph Weizenbaum and published in 1966. Users sometimes formed surprisingly emotional connections with the program despite its relatively simple pattern-matching architecture—a phenomenon that became known as the ELIZA effect. DOI

When persuasive design, behavioral targeting, continuous engagement and increasingly human-like AI interactions converge, the potential consequences deserve serious scrutiny. The central issue examined in this article is therefore not simply whether technology can addict, manipulate or harm its users. It is whether companies developing and deploying these products are already subject to existing law—and, if they are, why government is debating new laws before fully testing and enforcing the laws already on the books.

The global debate over artificial intelligence, addictive social media, AI-infused apps and companion chatbots is no longer theoretical. 

People, mostly teens and children, have died, families have filed lawsuits, state attorneys general have taken technology companies to court, and thousands of cases now challenge whether the design and operation of digital platforms have harmed consumers and children.

A September 2026 database documenting deaths associated with conversational AI identifies 35 fatalities across 24 incidents in which interaction with conversational AI was alleged to have contributed to the deaths. 

My research on harm and death caused by AI, social media, and chatbots embedded with addictive design, includes the following:

AI Chatbots

  • Global deaths: 35 plus
  • Global lawsuits: 20 plus

Addictive AI Infused Social Media

  • Global deaths: tens of thousands
  • Global lawsuits: 6,500

Combined with harm, more people, mostly teens and children, have been harmed or killed than the number of U.S. servicemen killed in the Vietnam War, so the question is, home come existing consumer and child protection laws, including child endangerment laws, are not being enforced by the Federal Trade Commission and State Attorneys General?

The database does not establish legal causation in those cases, but the number illustrates the growing scope of reported incidents involving AI systems.

Meanwhile, litigation over allegedly addictive social-media design has reached extraordinary scale. 

More than 3,000 lawsuits against Meta, Google, TikTok and Snap have challenged whether platform design contributed to harms suffered by young users.

Against that backdrop, I attended a Reuters NEXT Newsmaker conversation with Federal Trade Commission Chairman Andrew Ferguson at Reuters Momentum AI Austin on September 25.

One of Ferguson's central arguments closely parallels a foundational principle of the Electronic Bill of Rights (EBOR): before government concludes that entirely new AI laws are required, determine whether the laws already on the books can address the conduct.

Ferguson stated the principle directly:

“Whether we need new laws is not a question we should ask until we know that the current laws are insufficient.”

He specifically raised product-liability and consumer-protection laws as existing frameworks that should be examined before government creates an entirely new regulatory structure for AI.

Ferguson also rejected treating AI agents as independent actors possessing “wills and desires of their own.” Instead, he argued against anthropomorphizing AI tools and focused responsibility on the humans and companies behind their deployment.

But Ferguson went further when discussing the FTC's own existing authority.

He said the FTC Act's anti-unfairness and anti-deception principles apply to data-security issues whether the company involved is a Big Tech company, healthcare company, data broker or AI company.

Ferguson also addressed representations companies make about their products.

If a company makes public “promises, guarantees, representations” concerning the safety of its product that cause people to buy or use it, and those representations are incorrect, Ferguson said that is the type of deception principle the FTC has enforced for decades.

He emphasized that application of those laws to individual cases remains fact-dependent.

Nevertheless, his statements establish an important point:

Artificial intelligence does not automatically exist outside the FTC's existing consumer-protection framework simply because the technology is new.

That raises an important question.

If existing laws apply to AI—and the Chairman of the Federal Trade Commission says existing laws should be examined before government creates new ones—why aren't those laws being used more aggressively when evidence indicates that AI-infused apps, social-media platforms and chatbots may be violating existing consumer-protection laws?

The question becomes more significant when viewed against the FTC's own record.

The Commission has acknowledged that AI can implicate fraud, deception, privacy and other unfair practices covered by existing law. The FTC has also publicly examined what it calls the “Attention Economy,” including technology design and its effects on children.

In September 2025, Ferguson's FTC issued compulsory information requests to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI concerning AI companion chatbots. The Commission sought information about how companies monetize engagement, protect children, test for negative effects, disclose risks, collect and share personal information, and enforce age restrictions.

Yet that Section 6(b) inquiry was a market study rather than a law-enforcement action.

That distinction deserves scrutiny.

If an investigation uncovers evidence that an AI company, social-media platform or app developer violated existing consumer-protection, privacy, children's privacy or competition laws, should government continue studying the problem—or enforce the law?

And where evidence potentially supports criminal violations outside the FTC's own prosecutorial jurisdiction, should those matters be referred to the Department of Justice or appropriate state prosecutors?

THE EXISTING LEGAL FRAMEWORK

The existing framework is substantial.

Section 5 of the Federal Trade Commission Act prohibits unfair or deceptive acts or practices and unfair methods of competition.

The Children's Online Privacy Protection Act (COPPA) regulates the collection and use of personal information from children under 13 and gives the FTC enforcement authority.

The Sherman Antitrust Act prohibits monopolization and anticompetitive conspiracies, with the Department of Justice authorized to criminally prosecute certain antitrust violations.

The Clayton Act addresses anticompetitive mergers, acquisitions and other practices that may substantially lessen competition.

The Robinson-Patman Act, part of the Clayton Act framework, addresses specified forms of discriminatory pricing.

The Restore Online Shoppers' Confidence Act (ROSCA) establishes requirements governing certain online transactions and consumer consent.

Depending upon the conduct and industry involved, additional existing privacy, data-security, advertising, fraud, product-liability and state consumer-protection laws may also apply.

The FTC has already demonstrated that digital design can become an enforcement issue. It has taken action involving deceptive “dark patterns,” unauthorized charges, children's privacy and manipulative consumer interfaces.

In other words, the fundamental question is not whether AI, algorithms or software automatically exist outside existing law.

It is whether applicable laws are being enforced when the facts establish that they have been violated.

FTC ACT APPLIES TO AI

Ferguson was particularly clear when discussing the FTC's longstanding authority over unfair and deceptive practices.

He explained that the FTC has served as a principal federal civil data-security and privacy law enforcer for more than two decades.

Companies making representations concerning the safety or security of their products can face scrutiny when those representations are deceptive.

Ferguson said the disclosure obligations and anti-unfairness and anti-deception provisions the FTC has applied in data security also apply when the company involved is an AI firm.

“How do they apply in specific cases?” Ferguson asked.

His answer was equally important:

“It's heavily fact-dependent.”

Ferguson therefore was not declaring any particular AI developer legally liable. He was explaining that the underlying legal principles remain applicable.

That distinction matters.

The FTC does not have to begin with the assumption that artificial intelligence requires an entirely separate universe of consumer-protection law. Existing unfairness, deception and data-security principles can reach AI companies when the facts satisfy the applicable legal standards.

AI AND CONSUMER DISCLOSURE

Ferguson also discussed whether consumers should know when they are interacting with artificial intelligence rather than a human and whether companies should disclose financial incentives influencing AI-generated outputs.

He said existing rules governing disclosures in non-AI contexts do not, on their face, cease applying because artificial intelligence is involved.

Ferguson then discussed the FTC's study of AI chatbots and their interactions with children, including whether children understand that they are communicating with machines and whether that understanding changes during prolonged interactions.

He said the FTC is gathering information about what is actually happening and intends to use that information to inform law-enforcement efforts.

ONLINE SCAMS AND DECEPTIVE ADVERTISING

Ferguson also addressed what he described as an enormous problem involving online scams and deceptive advertising.

He said longstanding FTC principles can impose obligations on advertisers when they have reason to know they are advertising for fraudsters.

The issue, Ferguson explained, is applying those principles to today's online platforms and social-media companies.

He described ongoing FTC investigations and rulemaking involving online scams and deceptive advertising and identified Americans under 25 and over 60 as particularly susceptible to online fraud amplified by advertising algorithms.

Ferguson's message to platforms was direct.

The FTC wants to work with the companies to address the problem.

But he added:

“If we can't fix it together, I will fix it in a courtroom.”

That statement raises a broader historical question about enforcement.

THE WARNING SIGNS DID NOT BEGIN WITH AI

In 2017, former Facebook President Sean Parker publicly described the thinking that went into Facebook's engagement model.

Parker said the objective involved determining how to consume as much of a user's time and conscious attention as possible. He described a “social-validation feedback loop” and said Facebook's creators understood that they were “exploiting a vulnerability in human psychology.”

Four years later, Facebook whistleblower Frances Haugen provided Congress with internal company documents and testified before the Senate Subcommittee on Consumer Protection, Product Safety, and Data Security.

In her written testimony, Haugen said Facebook repeatedly encountered conflicts between its profits and user safety and alleged that the company resolved those conflicts in favor of profit.

She also testified that Facebook's own internal research documented harms affecting vulnerable users, including teenage girls.

Parker's 2017 statements and Haugen's 2021 disclosures are different forms of evidence and should not be conflated.

Parker described the thinking behind Facebook's engagement design.

Haugen subsequently presented internal Facebook research and allegations concerning how the company responded to evidence about the effects of its products.

But both demonstrate that concerns about engagement design, children, privacy, consumer safety and corporate responsibility substantially predate today's generative-AI debate.

Here is a link to a 2 minute video, Sean Parker Admission Validated by Frances Haugen: https://vimeo.com/showcase/9772042?video=1218881089

Sean Parker’s admission coupled with the internal Meta report Frances Haugen gave to the U.S. senate could be used in a court of law to prove criminal negligence through malicious intent leading to the harm and death of adults, teens, and children who used Facebook and Instagram.

That leads to a difficult question: 

How many adults, teenagers and children might have been spared tech addiction, harm, exploitation or loss of privacy if existing consumer-protection laws had been effectively applied when regulators had sufficient evidence to act?

THE SAME LEGAL QUESTION NOW CONFRONTS AI

Artificial intelligence has brought the question back into focus.

During the Reuters interview, Ferguson rejected the assumption that AI automatically requires an entirely new legal regime. Existing product-liability, consumer-protection, anti-deception and data-security principles should first be examined to determine whether they can address the conduct at issue.

He also questioned requests by major AI companies for new regulations and antitrust exemptions.

Ferguson's concern was that dominant companies can sometimes use regulation to protect themselves from competition.

His comments do not establish that any particular AI company has violated the FTC Act.

Nor did Ferguson determine that existing laws will resolve every possible problem created by artificial intelligence. He expressly acknowledged that additional guardrails could eventually prove necessary.

But his position establishes something significant for the debate:

Artificial intelligence does not exist outside the existing consumer-protection framework merely because the technology is new.

WHY THIS QUESTION IS PERSONAL

That question is particularly important to me because my involvement with these issues predates today's generative-AI debate.

From 2017 through 2021, I worked with members of the U.S. Senate and congressional staff on technology, privacy, cybersecurity and consumer-protection issues surrounding major congressional technology hearings.

Those issues included Facebook and Cambridge Analytica and Mark Zuckerberg's testimony; Google's data-collection practices and Sundar Pichai; congressional scrutiny involving Zuckerberg, Pichai and then-Twitter CEO Jack Dorsey; and the Facebook/Instagram whistleblower disclosures brought forward by former Facebook product manager Frances Haugen.

Over those years, my work involved senators and staff on both sides of the aisle, including Richard Blumenthal, Marsha Blackburn, Ted Cruz and John Cornyn.

The history matters because many of the questions confronting policymakers today are not entirely new.

The technology has evolved—from social media and behavioral advertising to generative AI, AI companions and autonomous agents—but fundamental questions concerning consumer protection, privacy, competition, corporate responsibility and accountability remain.

After Ferguson's Reuters interview in Austin, I introduced myself to him and explained my background as a government advisor and whistleblower, my Senate work involving those technology hearings, and my continuing research into these issues.

Chairman Ferguson told me he was interested in learning more. A member of his staff took my card and asked me to follow up.

I intend to do exactly that.

Ferguson's comments at Reuters Momentum AI Austin present an opportunity for an important discussion—not simply about creating another layer of legislation because a product contains artificial intelligence, but about determining exactly what government can already do under laws that exist today.

That is also one of the foundational principles behind the Electronic Bill of Rights.

CONCLUSION: THE ENFORCEMENT QUESTION

Ferguson's comments leave a question extending far beyond artificial intelligence.

If longstanding FTC principles governing deception, unfair practices, data security and consumer protection apply to emerging technologies, then the debate cannot be limited to what new laws Congress should pass.

It must also examine how existing laws have been enforced.

Sean Parker publicly described Facebook's engagement model in 2017.

Frances Haugen brought internal Facebook research to Congress in 2021.

Years later, regulators, lawmakers, researchers, consumers and families continue confronting allegations of harms associated with addictive design, privacy, children and algorithmically driven consumer products.

How many adults, teenagers and children might have been spared addiction, death, harm, exploitation,  or loss of privacy if existing consumer-protection laws had been effectively applied when regulators first had sufficient evidence to act?

The same question applies to deceptive advertising and online scams.

If existing FTC principles impose obligations when companies have reason to know they are facilitating fraudulent advertising, how many consumers might have avoided losing money to deceptive online advertisements and scams if those principles had been effectively enforced against responsible parties?

And now artificial intelligence presents the question again.

AI companies are developing increasingly powerful products while policymakers, researchers and industry leaders debate cybersecurity, consumer safety, catastrophic risks, liability and regulation.

Ferguson's Reuters interview establishes that the FTC does not necessarily begin with a blank sheet of paper simply because the technology is called artificial intelligence.

Existing law remains relevant.

Which leaves perhaps the most important question arising from the Chairman's own remarks:

If the Chairman of the Federal Trade Commission believes the FTC's existing consumer-protection, anti-deception and data-security framework can be enforced against AI companies just as it can against other companies, why isn't that existing framework being enforced wherever the evidence establishes violations—and how many consumers could have been spared harm if it had been effectively enforced sooner?

Technology does not create an exemption from existing law.

The question now is whether government will consistently apply that principle.

For more information on the Electronic Bill of Rights go to Electronic Bill of Rights: www.ElectronicBillofRights.com

You can contact Rex M. Lee at:

Rlee@CyberTalkTV.com

Sources:

Yes. I’d put this at the very end under Sources and Supporting Documentation. I’ve formatted it for a general publication rather than as academic footnotes, and I verified the key sources again.

Sources and Supporting Documentation

Reuters — Andrew Ferguson / AI Liability and Existing Law
Jody Godoy, “FTC chair suggests AI developers should be liable for conduct of agents,” Reuters, September 25, 2026. Reporting from Reuters Momentum AI Austin covering FTC Chairman Andrew Ferguson’s comments concerning AI agents, developer responsibility, product liability, consumer-protection law and the application of existing legal principles to artificial intelligence. Reuters
Read the Reuters report

Reuters — AI Antitrust Exemptions
Jody Godoy, “FTC chair suspicious of calls for AI antitrust exemptions,” Reuters, September 15, 2026. Ferguson discusses requests by AI companies for antitrust exemptions and new regulation and warns about the potential for regulation to protect established companies from competition. Reuters
Read the Reuters report

Federal Trade Commission — AI Companion Chatbot Inquiry
Federal Trade Commission, “FTC Launches Inquiry into AI Chatbots Acting as Companions,” September 11, 2025. The FTC issued Section 6(b) orders to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI seeking information about AI companion products, including monetization of engagement, potential negative effects on children and teens, safety testing, disclosures, advertising, age restrictions, data collection and use of personal information. The FTC states that Section 6(b) authorizes studies that “do not have a specific law enforcement purpose.” FTC Search
FTC AI Companion Chatbot Inquiry

Reuters — Social-Media Addiction Litigation
“US court rules Meta, other tech firms must face thousands of lawsuits over social media addiction,” Reuters, August 10, 2026. Reuters reported that more than 3,000 lawsuits involving Meta, Google, TikTok and Snap could proceed. The cases include allegations that social-media platforms were designed to be addictive to young users and contributed to harms. The companies have disputed various allegations in the litigation. Reuters
Read the Reuters report

Reuters/Ipsos — Public Concern About AI Risks
Reuters, “Three out of four Americans say AI firms not doing enough to prevent disaster, Reuters/Ipsos poll finds,” September 22, 2026. The Reuters/Ipsos survey of 1,277 U.S. adults found 73% concerned that AI companies were not doing enough to prevent potentially catastrophic consequences from AI; the online poll reported a margin of error of approximately three percentage points. Reuters
Read the Reuters/Ipsos report

U.S. Senate — Frances Haugen Testimony
U.S. Senate Committee on Commerce, Science, and Transportation, Subcommittee on Consumer Protection, Product Safety, and Data Security, “Protecting Kids Online: 

Testimony from a Facebook Whistleblower,” October 5, 2021. Former Facebook product manager Frances Haugen testified concerning internal Facebook research, children's safety, Instagram's effects on teenagers and other consumer-protection issues. Senate Commerce Committee
Senate hearing and testimony

Frances Haugen — Written Testimony to Congress
Statement of Frances Haugen, October 4, 2021, submitted for the October 5 Senate hearing. Haugen alleged that Facebook repeatedly encountered conflicts between profit and safety and said internal company research documented harms, including effects involving vulnerable teenagers. These statements represent Haugen's testimony and allegations concerning Facebook's internal practices and research. Senate Commerce Committee
Read Haugen's written testimony

Axios — Sean Parker on Facebook's Engagement Design
Erica Pandey, “Sean Parker: Facebook was designed to exploit human ‘vulnerability,’” Axios, November 9, 2017. Former Facebook President Sean Parker described Facebook's early engagement strategy as seeking to capture users' time and attention through a “social validation feedback loop” and discussed exploiting vulnerabilities in human psychology. Axios
Read the Axios report

Primary Source — Reuters Momentum AI Austin
Andrew Ferguson, Chairman, Federal Trade Commission, Reuters NEXT Newsmaker interview at Reuters Momentum AI, Austin, Texas, September 25, 2026. Article quotations attributed directly to Chairman Ferguson were drawn from the session and transcript of the interview.

Author's Reporting and Research
Rex M. Lee attended Reuters Momentum AI Austin on September 25, 2026, attended Chairman Ferguson's Reuters Newsmaker session and subsequently spoke with Ferguson in person. Analysis concerning the Electronic Bill of Rights (EBOR), enforcement of existing law and the author's prior government advisory work reflects the author's research, professional experience and reporting.

Electronic Bill of Rights (EBOR)
Research and policy framework concerning consumer protection, privacy, data ownership, child protection, corporate accountability and enforcement of existing laws.
Electronic Bill of Rights

Editorial note: I would still add the source for the 35 fatalities across 24 conversational-AI incidents to this section before publication. That's a prominent statistic in your opening, so the underlying database should be named, dated, and directly accessible to readers.