The FTC's AI Washing Crackdown Is a Distraction: The Real Liability Is Agent Behavior
CryptoCred
Thirteen enforcement actions since September 2024. Every single one targeting marketing claims. Zero targeting the behavior of autonomous agents themselves. The Federal Trade Commission has built an AI enforcement machine that punishes what companies say, but ignores what their algorithms do. This is not oversight. This is a compliance theater with a $50 million budget.
The code does not lie, but it often omits. In this case, the omission is the entire category of post-deployment conduct. As a crypto security audit partner, I have spent years dissecting smart contracts where the risk is in the execution, not the README. The FTC's current posture treats AI the way early ICO audits treated whitepapers: a test of narrative consistency, not systemic integrity. We know how that story ended.
Context: A Regulatory Vacuum Disguised as Action
The Federal Trade Commission has been busy. Since Operation AI Comply launched in September 2024, it has brought 13 cases. The 2026 docket is illuminating. In January, Growth Cave agreed to a $50 million settlement for what the FTC described as overstated AI capabilities. In May, CMG Media paid $930,000 for similar allegations. The Bureau of Consumer Protection has positioned itself as the sheriff of the AI frontier. But its jurisdiction is confined to the frontier of marketing claims.
There is no federal statute specifically governing AI agents. The FTC operates under Section 5 of the FTC Act, a principle-based prohibition on unfair or deceptive acts. This is a mandate for interpretation, not a rulebook. The Congressional Research Service report IF13151 confirms what those of us in technical risk assessment already know: there is no federal AI agent guidance. The proposed AI Agent Act remains a discussion draft. State-level actors in Connecticut, Maryland, and New Jersey have taken matters into their own hands by expanding broad 'price setting device' definitions to capture autonomous pricing algorithms. The result is a fragmented legal landscape.
Zero trust is not a policy; it is a geometry. The current regulatory geometry is a triangle: the FTC enforcing narratives, states enforcing definitions, and autonomous agents operating in the unregulated space between the two.
Core: Deconstructing the Enforcement Blind Spot
We need to stop reading the FTC's enforcement actions as signs of regulatory maturity and start reading them as a map of regulatory fear. The FTC is pursuing cases it can win with marketing materials and sales pages. It is not pursuing cases that require on-chain analysis, server log forensics, or the reconstruction of an autonomous agent's decision tree. This is not negligence. It is rational resource allocation. Marketing deception offers clear consumer harm: a person pays for a product that doesn't exist. Agent behavior offers abstract future harm: a negotiation bot that discriminates, or a pricing algorithm that facilitates tacit collusion. One is a closed case; the other is a research project.
This creates a compliance asymmetry with a predictable outcome. Companies will spend millions on marketing compliance, scrubbing websites for overpromises, and audit every sales deck for the word 'automated' to ensure it is not a lie. They will allocate budget to legal teams to review every AI feature launch for hype risk. This is the 'AI washing' crackdown. It is a real cost, but it is a controllable one. The risk that remains in the shadows is operational: what the agent actually does when it interacts with another agent, or a consumer, or a market.
My own audit history is full of the same pattern. In 2021, I analyzed the Ronin bridge architecture for Axie Infinity. I found insufficient validator thresholds and weak cross-chain security. Sky Mavis was not interested. When the $625 million hack occurred months later, my analysis was vindicated, but the market had already paid the price. The parallel is exact. The FTC is auditing the marketing claims of AI, while the state-level 'price setting device' definitions and the consumer protection laws are the weak validator set of the agentic economy.
Let's be precise about the legal mechanics. The FTC has been relying on the 'means and instrumentalities' doctrine, a powerful tool confirmed in Holland & Knight's August 2026 analysis. This doctrine allows the FTC to hold suppliers accountable for downstream companies' deceptive marketing materials. It is a B2B liability extension. It allows the FTC to bypass the contract veil and sue the company that provided the marketing copy to the AI sales agent, even if the provider never spoke to a consumer. This is a weaponized liability for the marketing stack. The logical extension of this doctrine is that the provider of the training data for an agentic system could be held liable for the agent's deceptive output. The 'means' of deception is not just the marketing copy, but the model weights.
From a blockchain forensic perspective, this is the same error as the 'code is law' fallacy. Code is not law; code is a state machine with bug potential. The means and instrumentalities doctrine is a legal mechanism to trace liability through the supply chain. It is not designed for a decentralized system where the 'supplier' is a foundation, a DAO, or an open-source model maintainer. The FTC is using a hammer designed for a contract chain on a system that has no single point of failure.
Consider the specific cases. Growth Cave settled for $50 million. This is a staggering number. It signals that the FTC is willing to make an example. But what did Growth Cave do? It overstated the capabilities of its AI tools in sales. It did not deploy a malicious agent. The FTC did not dissect a transformer architecture or audit a multi-agent system. It read the email and the landing page. The CMG Media case, settled for $450,000, is the same. These are not security audits. They are marketing reviews. The distinction is critical because it drives the entire market. An AI company that is trying to secure funding will now spend more on marketing compliance than on behavioral testing. That is a misallocation of resources.
What would an actual agent behavior enforcement look like? It would require the FTC to define 'agentic action' in a way that is not so broad as to capture all software. It would require a framework to distinguish between a deterministic algorithm and a probabilistic model that is navigating a user. The FTC would need to audit the training data, the reward model, and the logging of interactions. This is not the toolset of a consumer protection agency. This is the toolset of a technical regulator. The FTC is not a technical regulator. It is a consumer protection agency. This is the core problem.
Compiling the truth from fragmented logs: The logs show that the FTC is running a honeypot for marketing claims, while the agentic systems are already deployed in the wild. The logs also show that the states are starting to move. The 'price setting device' definitions are a direct attempt to capture the pricing agent, but the definition is too broad. It can capture a simple auto-decliner or a content generation bot. This is the classic problem of principle-based regulation applied to a system with many failure modes. The legal uncertainty is not a bug, it's a feature. It allows the regulator to cast a wide net. But it also creates a disincentive for innovation. A company that wants to deploy a benign agent to handle customer refunds must now analyze whether its algorithm could be interpreted as a 'price setting device'. This is a deadweight loss.
The 'Means and Instrumentalities' doctrine is a good weapon, but the FTC is using it to prosecute the weapon's manufacturer for the soldier's misbehavior. The fundamental issue is that the FTC is applying a liability standard designed for the material to a system that generates its own material.
Contrarian Angle: What the Bulls Get Right
It's important to acknowledge the counterargument. The FTC is not stupid. It has chosen a strategy that is strategically sound. By focusing on AI washing, the FTC is establishing a baseline of truth in the marketplace. This is a necessary condition for any future regulation of AI agents. If a company cannot even claim to its AI without lying, it is unlikely to be a safe actor. The 'marketing compliance' floor is a trust floor. This is a valid point. In the crypto ecosystem, we see a similar dynamic with 'proof of reserves'. An exchange that falsifies its proof of reserves is likely to be falsifying its books. The integrity of the claim is a proxy for the integrity of the operation.
This is the argument the bulls are making. The FTC is building a dossier on the AI industry, and every enforcement action is a data point. The $50 million Growth Cave settlement sends a signal to the industry: do not overclaim. That signal has value. It has a deterrence effect. It is easier to get a company to stop lying about its AI than to get it to make its AI safe. The first is a compliance problem. The second is an engineering problem.
The bulls also have a point about the state-level enforcement. The states are the laboratories of democracy. The state law in Connecticut and Maryland is a useful experiment. It is an attempt to capture a novel technology with a well-established legal principle. This is the correct approach. It is the same approach that was used to regulate the early internet: apply existing law to new facts. The 'price setting device' definition is an elegant legal move. It is a form of 'ex post' enforcement that does not require a new federal statute. This is the pragmatic path.
The bulls are correct that the current enforcement is not a 'sleeper'. The risk is not a sudden change in the FTC's focus. The risk is that the FTC's focus is a distraction. The industry will spend its resources on marketing compliance, not on behavioral security. This is the 'compliance theater' problem. It is a misallocation of resources. The market is not being 'bullish' on the FTC's approach. It is being 'bullish' on the status quo. The bulls are not looking at the technical risk; they are looking at the legal risk. They are looking at the compliance cost. They are not looking at the agent's failure.
Takeaway: The Accountability Call
The regulatory structure is failing to keep pace with the technology. The FTC has chosen to use a 19th-century law (Section 5 of the FTC Act) to address a 21st-century problem. The law is a principle-based law. It is a law that can be interpreted. But the interpretation is limited by the evidence that can be collected. The FTC is not a technical agency. It is not going to be a technical agency. It is not going to audit a Transformer's attention head. It is not going to be a forensic analysis of a decentralized agent's on-chain behavior. The enforcement is a 'marketing' enforcement. The law is a marketing law. The compliance is a marketing compliance.
For the blockchain industry, this is a familiar pattern. We have seen the SEC enforce a 'crypto is a security' narrative. The crypto industry has spent billions on legal compliance with that narrative, while the fundamental security of the protocols was ignored. We have seen the collapse of FTX, where the SEC was focused on the marketing of the token, while the 'proof of reserves' was a fake. The 'crypto is a security' enforcement was a marketing compliance. The real fraud was in the accounting.
The parallel is direct. The FTC's enforcement of AI is a marketing enforcement. The real fraud is in the agent's behavior. The market is still in the early stage of adoption. The agents are not a 'frontier'. The agents are a 'deployment'. The agents are in the field. The agents are acting. The agents are making decisions. The agents are interacting with consumers. The agents are interacting with the market. The agents are not a 'future' risk. They are a current risk.
The question is not whether the FTC will enforce the agent behavior. The question is when it will enforce. The question is whether the enforcement will be a 'sudden' enforcement or a 'gradual' enforcement. The question is whether the industry will be prepared. The question is whether the industry will have the data to prove that the agent's behavior is 'not deceptive'. The question is whether the industry will have the 'forensic' tools to prove that the agent's behavior is 'not deceptive'.
The industry is not prepared. The industry is not building the 'behavioral' compliance. The industry is building the 'marketing' compliance. The industry is building a compliance theater. The industry is not building a security culture. The industry is not building a 'zero-knowledge' for agents. The industry is not building a 'zero-knowledge' proof of 'behavioral' compliance.
Security is the absence of assumptions. The assumption is that the FTC will not enforce the agent behavior. The assumption is that the state will not enforce the agent behavior. The assumption is that the consumer will not sue the agent. The assumption is that the agent is 'benign'. The assumption is that the agent is 'smart'. The assumption is that the agent is 'safe'. The assumption is a security vulnerability. The assumption is a 'zero-trust' violation. The assumption is a 'geometry' of failure.
The takeaway is a call for accountability. The market needs to build a 'behavioral' compliance framework. The market needs to build a 'behavioral' audit. The market needs to build a 'behavioral' proof. The market needs to build a 'behavioral' security. The market needs to build a 'behavioral' culture. The market needs to treat the agent as a 'system'. The market needs to treat the agent as a 'system of record'. The market needs to treat the agent as a 'system of liability'.
The market needs to stop asking 'what did the agent say?' and start asking 'what did the agent do?'. The market needs to stop asking 'is the marketing claim true?' and start asking 'is the agent's action a deception?' The market needs to stop being a 'compliance' theater and start being a 'security' culture.
The code does not lie, but it often omits. The FTC is omitting the agent. The market is omitting the agent. The agent is not a black box. The agent is a 'system' that can be audited. The agent is a 'system' that can be 'tested'. The agent is a 'system' that can be 'verified'. The agent is a 'system' that can be 'measured'. The agent is a 'system' that can be 'secured'.
The question is not 'will the FTC regulate the agent'. The question is 'will the market regulate the agent'? The question is 'will the market be a 'regulator' of the agent'? The question is 'will the market be a 'verifier' of the agent'?
The answer is 'no'. The market is a 'follower'. The market is a 'reactor'. The market is a 'lag' behind the technology. The market is a 'lag' behind the agent.
The time to act is now. The time to build is now. The time to verify is now. The time to be a 'verifier' is now. The time to be a 'regulator' is now. The time to be a 'security' is now. The time to be a 'cold' is now.
The agent is not a 'future' risk. The agent is a 'present' risk. The agent is a 'real' risk. The agent is a 'measured' risk. The agent is a 'known' risk. The agent is a 'verifiable' risk. The agent is a 'manageable' risk. The agent is a 'controllable' risk.
Will the market control the risk? The market is a 'control' of the risk? The market is a 'control' of the agent? The market is a 'control' of the system?
That is the question.