FTC's AI Washing Crackdown Targets US Professional Services
The regulatory ground beneath AI is shifting faster than most professional services firms can track. In the US and Canada, 2025 and 2026 have brought enforcement actions, stalled legislation, sweeping executive orders, and a wave of state-level laws that together create a compliance environment of c
US and Canadian AI Compliance 2025–2026: What Professional Services Firms Need to Know
The regulatory ground beneath AI is shifting faster than most professional services firms can track. In the US and Canada, 2025 and 2026 have brought enforcement actions, stalled legislation, sweeping executive orders, and a wave of state-level laws that together create a compliance environment of considerable complexity. If your firm operates across borders — or works with clients who do — understanding this landscape is no longer optional.
The US Federal Picture: Deregulation at the Top, Pressure Everywhere Else
The Trump administration's position on AI is pro-innovation and explicitly deregulatory at the federal level. One of the first acts of the administration in January 2025 was to revoke the Biden-era AI safety executive order. Subsequent executive orders through 2025 and 2026 have focused on building AI infrastructure, removing what the administration characterises as burdensome oversight, and driving towards a unified national AI policy capable of pre-empting inconsistent state-level rules.
In December 2025, a further executive order directed the Attorney General to establish an AI Litigation Task Force specifically tasked with challenging state AI laws. The message from Washington is clear: the federal government intends to set the pace, and state divergence will be contested.
However, deregulation at the federal level does not mean an absence of enforcement. The Federal Trade Commission has been active throughout this period under its existing authority, and professional services firms should not mistake the administration's pro-innovation rhetoric for a permissive environment when it comes to how they market and deploy AI tools.
The FTC and "AI Washing": A Live Enforcement Risk
The FTC's "Operation AI Comply," launched in September 2024, remains one of the most significant enforcement developments for any business using or promoting AI-powered services. Throughout 2025, the FTC brought at least a dozen cases against companies making unsubstantiated or misleading claims about AI capabilities — a practice it has labelled "AI washing."
Companies sanctioned include DoNotPay, Evolv, IntelliVision, and Rytr. The cases span a range of conduct: overstating the capabilities of AI-powered services, making false claims about earnings potential from AI tools, and misrepresenting what AI products can actually deliver.
The legal basis is Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. In December 2025, the FTC reopened and set aside its 2024 consent order against Rytr, signalling that the new administration is reviewing existing orders for undue burden on innovation. But this should not be read as a weakening of enforcement appetite more broadly — the underlying authority remains intact, and the volume of cases brought in 2025 alone demonstrates that.
Additionally, a rule effective from April 2024 extended impersonation prohibitions to AI-generated voice clones and deepfake images used in commerce. Any firm using AI-generated content in client-facing communications, marketing, or testimonials needs to understand where these rules apply.
The implication for professional services firms globally is direct. If you are marketing AI-enhanced audit tools, AI-assisted legal research, AI-driven HR analytics, or AI-powered campaign management to clients in or connected to the US market, your claims about those tools must be accurate, substantiated, and defensible. Overpromising on AI capability is no longer merely a reputational risk — it is an enforcement risk.
State-Level Complexity: A Patchwork That Demands Attention
While the federal government pursues pre-emption, 145 AI-related bills were enacted at state level across the US in 2025 alone. Colorado, Texas, California, Utah, and Illinois have all introduced broader AI laws addressing high-risk systems, with effective dates ranging from May 2024 through to January 2026.
For businesses operating across multiple US states, or serving US clients from outside the country, this creates a layered compliance obligation that cannot be addressed by reference to federal policy alone. Colorado's SB 24-205, delayed to June 2026, and Texas's TRAIGA, effective January 2026, both impose obligations around high-risk AI systems with accountability and transparency requirements that echo the risk-based frameworks being developed elsewhere in the world.
UK accountancy practices, law firms, HR consultancies, and marketing agencies with US client bases or US-facing operations need to map their AI use against state-level requirements, not just federal guidance.
Canada: A Regulatory Gap With Real Consequences
Canada's position is distinct. The federal Artificial Intelligence and Data Act (AIDA), introduced under Bill C-27, was stalled in January 2025 following Parliament's prorogation. Canada therefore enters this period without a comprehensive federal AI regulatory framework, and reintroduction of legislation — when it comes — is expected to build on AIDA's risk-based, accountability-focused approach.
In the interim, Canada is operating on existing laws supplemented by the Voluntary Code of Conduct for generative AI systems, published in September 2023. That code carries no enforcement mechanisms or penalties, which limits its practical value as a compliance reference point.
What does carry weight is PIPEDA. In May 2026, the Office of the Privacy Commissioner of Canada, alongside provincial counterparts, published findings from a multi-year investigation into OpenAI's ChatGPT practices. The investigation identified contraventions of PIPEDA, centring on the collection and use of personal information for AI model training without adequate safeguards or valid consent.
This matters for any professional services firm whose AI tools process personal data belonging to Canadian individuals — whether that is client data, employee data, or data used to train or fine-tune AI models. Consent, transparency, and accountability are not optional standards. They are existing legal obligations under Canadian privacy law, enforceable now, without waiting for AIDA to be reintroduced.
The Office of the Superintendent of Financial Institutions Canada has also issued Guideline E-23, effective May 2027, imposing AI risk management requirements on federally regulated financial institutions. Firms advising or serving Canadian financial sector clients should factor this into their compliance support offering.
What This Means for Your Firm
The US and Canadian developments of 2025 and 2026 carry clear lessons for professional services firms operating internationally:
Claims about AI must be accurate. Whether you are promoting AI-powered services to clients or advising clients on their own AI deployments, unsubstantiated capability claims create legal exposure under existing consumer protection and competition law frameworks — not just in the US, but as a model for enforcement globally.
Privacy obligations apply to AI regardless of sector-specific AI law. Where comprehensive AI legislation is absent or stalled, data protection and privacy law fills the gap. PIPEDA in Canada, and equivalent frameworks in the EU and UK, impose meaningful obligations on how personal data is handled in AI systems today.
State and provincial variation creates complexity that cannot be ignored. For firms with US operations or US client exposure, federal policy direction does not eliminate state-level compliance obligations. Monitoring, mapping, and managing that variation requires structured oversight.
Risk-based frameworks are converging globally. AIDA's anticipated reintroduction, OSFI's Guideline E-23, the EU AI Act, and state-level US laws all share a common architecture: identify high-risk AI use, implement governance, demonstrate accountability. Building that framework now positions your firm ahead of the curve across multiple jurisdictions.
Talk to Ops Intel
Navigating AI compliance across the US, Canada, UK, and beyond requires more than awareness — it requires structured, jurisdiction-specific guidance tailored to how your firm actually uses AI.
Ops Intel works with professional services businesses to assess AI risk exposure, build compliance frameworks, and keep pace with regulatory change. If you are unsure whether your current AI practices are defensible under existing and emerging law, now is the time to find out.
Get in touch with Ops Intel to discuss your AI compliance obligations and how we can help you stay ahead.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.