Massachusetts AG Says Consumer Laws Apply to AI | TLY

AI Regulation Tracker  /  United States, enforcement

Massachusetts AG: Existing Consumer Laws Already Apply to AI

Massachusetts Attorney General Andrea Joy Campbell issued an advisory declaring that the state's existing consumer protection, anti-discrimination, and data security laws already govern how AI is developed, supplied, and used. No new AI statute is needed for the AG to act. The advisory is dated April 16, 2024 and remains the office's operative position, which is why it belongs on your compliance map now: it is the enforcement theory a firm using AI in Massachusetts can be measured against today.

The Leveraged Years AI Regulation News

There is a comfortable myth in AI adoption that says the law has not caught up yet, so anything goes until a legislature passes a dedicated AI statute. Massachusetts closed that argument two years ago and the closure still stands. The Attorney General's office issued a formal advisory telling anyone who builds, sells, or uses AI in the Commonwealth that the laws already on the books apply to them right now.

Let me keep the framing honest. This advisory is dated April 16, 2024, so it is not breaking news. What makes it worth a working professional's attention today is that it is durable. It is the standing, published position of the office that would actually bring an enforcement action, the office has said it will expand it rather than retire it, and no new Massachusetts AI statute has displaced it. If you operate AI in Massachusetts and you have never read it, that is the gap to close, because it is the theory a regulator uses when something goes wrong.

The core move: no AI exemption from existing law

The heart of the advisory is a single idea, and the office states it plainly. Existing state laws and regulations, it writes, "apply to this emerging technology to the same extent as they apply to any other product or application within the meaning of the Attorney General's Consumer Protection regulations in the stream of commerce."

The advisory then heads off the most common defense directly. "The novelty, complexity and claimed inscrutability of AI systems do not take their marketing, sale and use beyond the reach of Chapter 93A." In other words, calling your model a black box is not a shield. If you cannot fully explain how your system generates its results, that is your problem to manage, not a reason the consumer protection statute stops applying.

What counts as unfair or deceptive under Chapter 93A

The advisory lists specific acts it considers unfair and deceptive within the meaning of Chapter 93A, section 2. The list is not exhaustive, and it maps cleanly onto how AI is actually marketed. Among the practices it names:

Read that third bullet twice. The advisory treats an untested claim that your AI is free from bias, or is compliant with the law, as itself a potential deceptive act. Marketing copy is now a liability surface.

Data security and anti-discrimination carry through too

Consumer protection is only one of the three regimes. On data security, the advisory states that AI developers, suppliers, and users must take the necessary and appropriate steps to safeguard personal information used by those systems under the Commonwealth's Standards for the Protection of Personal Information, meaning 201 CMR 17.00, and are expected to comply with the state breach notification requirements. Critically, it notes that violations of Chapter 93H are expressly subject to enforcement under Chapter 93A. The data security duty and the consumer protection remedy are wired together.

On civil rights, the advisory invokes the Anti-Discrimination Law, G.L. c. 151B, section 4, which it says prohibits developers, suppliers, and users of AI systems from deploying technology that discriminates against residents on the basis of a legally protected characteristic. That expressly reaches algorithmic decision-making that relies on discriminatory inputs and produces discriminatory results. The office adds that a c. 151B violation may itself be an unfair and deceptive act, giving rise to liability under Chapter 93A. So a biased hiring or lending model is not only a civil rights exposure, it is a consumer protection exposure.

Why the Chapter 93A hook is the one to respect

The reason this advisory has bite is the statute it runs through. Chapter 93A is not a gentle regulatory framework. For willful or knowing violations it authorizes courts to award up to double or treble the actual damages, and it awards attorneys fees to a prevailing claimant. It supports both private lawsuits and enforcement by the Attorney General. When the AG says AI marketing and AI performance fall inside 93A, the office is not gesturing at a theoretical duty. It is pointing at a remedy that multiplies damages and shifts fees, available to private plaintiffs and to the state alike.

The advisory also reminds AI suppliers that selling or using AI in a way that violates federal consumer protection statutes, including the FTC Act, may itself be a Chapter 93A violation, and that state attorneys general are empowered to enforce certain federal laws applicable to AI. The exposure is layered, not narrow.

What this means for firms using AI in Massachusetts

Treat this as a checklist you can be measured against, because a regulator with the doubled-damages statute in hand already has.

Start with your claims. Every representation you make about an AI system, that it is accurate, unbiased, fully automated, more capable than a person, or compliant with law, needs to be something you can actually substantiate. Under this advisory an untested superiority or bias-free claim is a candidate deceptive act. Pull the unsupported adjectives out of your marketing and your sales decks.

Then look at performance and security as legal duties, not aspirations. If you supply an AI tool, you owe an obligation that it performs as advertised for its stated purpose. If your system touches the personal information of Massachusetts residents, 201 CMR 17.00 safeguards and the breach notification rules apply, and a lapse is enforceable through 93A. If you use algorithmic decision-making in hiring, lending, housing, or any context touching a protected characteristic, a discriminatory result is exposure under both c. 151B and 93A.

Finally, remember the reach. The advisory binds users of AI, not just the developers who built it. Buying a vendor's model does not outsource the compliance answer. If you deploy AI against Massachusetts residents, you are one of the parties the Attorney General named.

Questions professionals are asking

Does Massachusetts have an AI law I have to follow?

Not a dedicated AI statute in this advisory. The point of the advisory is that you do not need one. The AG says existing laws, the Chapter 93A Consumer Protection Act, the c. 151B Anti-Discrimination Law, and the c. 93H Data Security Law with 201 CMR 17.00, already apply to AI to the same extent they apply to any other product.

Is this advisory binding, or just an opinion?

The advisory is interpretive enforcement guidance, so it is the AG's stated position rather than a new rule. But the laws it invokes are binding and in force, and the office can enforce them. Treating it as non-binding because it is an advisory misreads the risk: it tells you exactly how the enforcer intends to apply statutes that already carry penalties.

What AI conduct does it flag as unfair or deceptive?

Among others: falsely advertising an AI system's quality or usability, supplying a defective or impractical AI tool, and misrepresenting reliability, such as untested claims that a system is free from bias, more capable than a human, or compliant with the law. The list is explicitly not exhaustive.

Why does Chapter 93A matter so much here?

Because of the remedy. Chapter 93A permits courts to award up to double or treble the actual damages for willful or knowing violations, plus attorneys fees, and it allows both private suits and Attorney General enforcement. Routing AI conduct through 93A turns a marketing or performance problem into a multiplied-damages exposure.

Does this reach my firm if we only use a vendor's AI?

Yes. The advisory names developers, suppliers, and users of AI. Deploying a third-party model against Massachusetts residents makes you a user within its scope, and the data security and anti-discrimination duties attach to how you use the system, not only to who built it.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how the Massachusetts AG advisory and the underlying statutes apply to your specific use of AI with qualified counsel.