The FTC Just Put a Preemption Argument on the Table
General counsel spent the first half of 2026 building compliance programs around a patchwork of state AI laws. On July 1, the ground shifted under them.
The FTC voted 2-0 to propose a policy statement asserting that AI systems which alter or steer their outputs for undisclosed ideological purposes, without disclosure, may violate Section 5 of the FTC Act's ban on deceptive practices. In that statement, the agency suggested that state AI regulations, naming Colorado's AI Act specifically, may be impliedly preempted where they require conduct that conflicts with Section 5 and the FTC's consumer-protection mandate (FTC).
The public comment period closed July 31. On August 3, the pushback arrived: the Electronic Frontier Foundation, the Center for Democracy and Technology, and attorneys general from more than twenty states filed formal opposition, warning the policy could expose routine AI safety engineering, the kind of tuning that prevents a model from producing harmful output, to federal liability unless it's conspicuously disclosed (Tech Times; Reed Smith).
Here's the reversal worth sitting with: this is not a story about whether output steering is good or bad practice. Every AI system that moderates content, ranks recommendations, or filters harmful responses is steering outputs in some sense, and most of that steering is responsible engineering, not deception. The real story is whether your reasoning for doing it is written down anywhere a regulator, state or federal, could find it. Right now, for most companies, the honest answer is no.
That gap is what makes this a board issue rather than a legal footnote. No industry is exempt. Any company running a consumer-facing AI product, a chatbot, a recommendation engine, a content filter, now sits in the middle of an unresolved conflict between the state compliance programs it built this year and a federal agency arguing those programs might not survive.
Waiting for the fight to resolve is not a strategy, because the exposure exists regardless of which layer of law ultimately prevails. A company with no documented rationale for how and why it steers its AI system's outputs is vulnerable either way: to a state regulator if the federal preemption argument fails, and to the FTC's own theory if it succeeds and the company never disclosed its reasoning in the first place.
This sits squarely inside the pattern this newsletter keeps tracking across every industry this year: it is not a technology gap driving governance failures, it is a documentation gap. The companies that get caught flat-footed will not be the ones using AI irresponsibly. They will be the ones who never wrote down why they built it the way they did.
This month's action: have counsel map every AI-facing product or tool your company runs that makes output-steering decisions, content moderation, recommendation weighting, safety filters, anything that shapes what a user sees. Confirm each one has a documented, disclosed rationale on file, not just an engineering assumption sitting in someone's head or a Slack thread. That record is the thing that will matter, whichever way this preemption fight lands.