When (or How) Principles Can Become Law: The FTC’s Proposed Deceptive Steering Policy Scoped Against the AI Life Cycle Core Principles

Introduction

On July 1, 2026, the Federal Trade Commission published a proposed policy statement applying Section 5 of the FTC Act, 15 U.S.C. § 45(a), to AI companies that steer their systems’ outputs “contrary to consumers’ reasonable expectations.” Public comment closes on July 31, 2026. In this post, I process the policy statement through the AI Life Cycle Core Principles (AILCCP) framework to determine which of the framework’s AI-related 37 principles are implicated, how, and what that means for the developers, deployers, and counsel who will eventually need to account for it.

But before we begin, a few words about the AILCCP are in order. In March 2023, I introduced the AI Life Cycle Core Principles, a framework consisting of 37 AI-related life cycle principles built to give developers, deployers, regulators, and legal practitioners a shared, precise vocabulary for evaluating AI systems across their full operational life cycle. The AILCCP’s core ambition was—and remains—to surgically strip away the pervasive definitional ambiguity that keeps AI oversight discussions perpetually aspirational and in the course of this work, the framework grew and gained additional structure. All of these principles are now organized into 10 pillars and mapped across 10 life cycle phases, supported by 48 controls, aligned to 47 international standards from ISO/IEC, IEEE, NIST (and others), and cross-referenced to FTC, SEC, and FDA enforcement. More than 400 explicit cross-references, together with a taxonomy of recognized AI risks, connect these layers. The 10 life cycle phases trace an AI system from scoping and design through decommissioning, and each principle carries life cycle signals marking the phases where its risks, and the oversight they demand, concentrate. (A public-facing version of the framework is found at https://ailccp.replit.app.) 

The AILCCP framework serves a wide range of practical purposes. Practitioners can use it to measure the efficacy of proposed and enacted legislation against a defined principle set, separating statutes that actually drive change in conduct from those that merely aspire to it; to analyze AI vendor agreements, AI corporate policies, and AI oversight documents for the same gaps; to identify which of the framework’s 48 controls a deployment requires, from logging to human-in-the-loop gates; and to address virtually any other AI-related issue, mapping each principle to relevant international standards and enforcement regimes. Every definition in the framework comprises many elements, and any single legal development typically implicates only a subset of them. (The Governance principle, for example, is comprised of 17 distinct elements.) Homing in on the most relevant subset through the AILCCP gives practitioners a more precise vocabulary for gauging both their compliance posture, how well their practices align with the principle, and their exposure, where that alignment fails and enforcement risk begins. 

Queried against the policy statement, the framework yields two findings. The policy statement activates three principles from the AILCCP: Truth, Transparency, and Accountability. It assigns them the force of federal consumer protection law. And in doing so, it generates a collision between federal and state obligations that the Governance principle must absorb.

What the FTC Proposes

The FTC proceeds from the premise that AI companies market their products as systems that distill human knowledge to solve problems in furtherance of consumers’ objectives. Consumers therefore reasonably expect truthful and accurate outputs. A company that steers its system toward other objectives without clearly disclosing the deviation makes a material misrepresentation likely to mislead a reasonable consumer and affect the consumer’s conduct. That is deception under Section 5.

The policy statement treats a company’s motive as irrelevant. Whether the steering serves commercial profit, an effort to shape public opinion, or compliance with a state law that requires embedding particular values, the deception analysis is the same. A company avoids a deception finding, and thus falls within the proposed safe harbor, by “clearly and conspicuously” disclosing that its system prioritizes certain objectives over what users request and otherwise expect. (There is an open question as to whether consumers would bother reading any of these disclosures, let alone understand them, but that is a rabbit hole I want to avoid for now.) Disclosure is the sole lawful path for operating a system whose objectives diverge from the consumer’s default expectation.

Truth: The Default Expectation

In relevant part, the AILCCP framework defines Truth as ensuring “that the outputs, representations, reasoning, and explanations provided by the AI are accurate, honest, and not misleading throughout the system’s life cycle.” The detailed definition extends to grounding responses in verifiable data, minimizing hallucinations, and disclosing areas where the system cannot provide truthful outputs.

The FTC converts this requirement into a legal baseline. The policy statement reads, “[C]onsumers have a reasonable expectation that AI systems aim to give truthful and accurate outputs. Consumers have no basis to believe that AI systems aim to produce outputs that are distorted by undisclosed ideological objectives.” By anchoring the deception analysis to that expectation, the FTC makes Truth the default state against which all AI output is measured. A system that deviates without disclosure is presumptively deceptive.

The AILCCP assigns Truth its primary life cycle signals at Model Development and Training and at Operations and Monitoring (two of the framework’s ten life cycle phases, the first covering how a model is built and trained, the second how it runs in production under ongoing monitoring). Developers who introduce steering during model training, or who let output objectives drift during operations, without a matching disclosure mechanism are now working in territory the FTC has marked.

Transparency: The Mechanism of Compliance

The AILCCP’s Transparency principle requires in relevant part that “every significant aspect of the AI system’s data practices, logic, decision-making, and governance is open, accessible, and understandable to relevant stakeholders.” Because a disclosure that is technically present but practically incomprehensible fails that test, the framework sets the operative benchmark at what it calls “epistemic uptake,” met only when disclosed information is absorbed into stakeholder decision-making.

The FTC’s safe harbor maps onto Transparency and adds a procedural requirement of its own. The requirement demands clarity, conspicuousness, and persistence, which puts it well beyond a single disclosure buried in terms of service. The Commission is describing what the framework calls “multi-level communication,” tailored disclosures for technical, operational, and lay audiences, and “comprehension verification,” the periodic assessment of whether audiences have formed an accurate understanding of system operation. The safe harbor also tracks the framework’s “stratified transparency,” under which disclosure obligations scale with the sophistication gap between developer and affected population. A consumer-facing AI product serves users with limited technical literacy relative to its developer, so the obligation scales up.

Transparency’s life cycle signals sit at two of the framework’s ten life cycle phases: Scoping and Design, and Pre-Deployment Review. A company that builds its disclosure architecture only after a consumer complaint or an enforcement inquiry has already missed the window the safe harbor requires.

Accountability: The Enforcement Dimension

The AILCCP’s Accountability principle requires in relevant part that “AI system design and implementation examines output (decision-making or prediction); identifies gaps between predicted and achieved outcomes; [and] clearly reveals degree of compliance with Data Stewardship.” The principle’s FTC Angle field, which maps each principle to the angles through which the FTC would likely scrutinize, regulate, or take enforcement action, already listed “Transparency, Accountability, Accuracy, Reliability, Advertising, Endorsements” as the relevant enforcement dimensions, an anticipation of precisely this development.

Section 5 has always applied to AI companies, and the policy statement says so expressly. The novelty lies in the articulation of how the deception test reaches output steering, and in the implicit demand that companies maintain oversight structures capable of detecting when their systems operate outside the default expectation and of disclosing it when they do. Accountability’s life cycle signals span three of the framework’s ten life cycle phases: Scoping and Design, Pre-Deployment Review, and Operations and Monitoring. Those oversight structures must therefore be in place from system conception and persist through active monitoring.

The Governance Collision: Preemption and Colorado

The policy statement addresses Colorado’s Artificial Intelligence Act, which provides that AI companies can be held liable for discriminatory outcomes caused by their customers’ use of their products. The FTC foresees that companies might steer their systems toward objectives such as “equity” or correction of “historical injustices” in order to comply with that law or others like it, without telling consumers. Its position is that such steering remains deceptive even when undertaken in good faith, and that “state law is impliedly preempted to the extent it conflicts with a federal regulatory scheme.” The policy statement grounds the preemption argument in Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence” (December 11, 2025), and its stated preference for a single, minimally burdensome national scheme over fifty discordant state frameworks.

The AILCCP Governance principle requires “systems, policies, procedures, processes, roles, and responsibilities for managing AI risks throughout the AI life cycle” and calls for continuous monitoring of the organization’s regulatory obligations. Under the policy statement, a company that steers its outputs to satisfy a state equity mandate can create exposure under the federal prohibition on deceptive conduct. Organizations operating in Colorado, or in any state with similar legislation pending, face that conflict today.

The workable response to that conflict is to treat the policy statement as a disclosure architecture requirement. An organization whose system is steered for any reason, commercial, ideological, or compliance-driven, needs documented policies that make the steering visible to users in a manner satisfying the FTC’s requirement.

What Changes for Practitioners

If adopted, the policy statement would make undisclosed deviation from what the FTC treats as truthful output presumptively deceptive; clear and conspicuous disclosure would become the only safe harbor; federal enforcement would reach output steering regardless of motive; and managing the federal-state conflict would require documented disclosure architecture.

The most substantive change would be the allocation of proof. Today, a company steering its system toward non-default objectives can argue that consumers hold no specific expectation about the system’s internal objectives. The policy statement would articulate that expectation and place the burden of rebutting it on the company through adequate disclosure.

The Comment Period

A comment should engage the three places where the policy statement, measured against the AILCCP, falls short: the deception test’s mechanics, the adequacy of the proposed safe harbor, and the preemption conflict with state mandates. General observations about AI oversight will carry little weight in the record.

Conclusion

The AILCCP framework is designed to give the AI oversight conversation a precise and durable vocabulary. Under the policy statement, principles that lived in internal policy documents and voluntary commitments will be written into enforceable legal obligations.