The Bot Desk
Prices checked Sep 2026

Customer Data and AI Agents: US Rules That Apply

No single US law governs running customer data through an AI agent. What applies is a stack: FTC Act Section 5, the state privacy statute that reaches you, any sector rule on top of it, and the privacy promises you already made. Check the vendor's contract terms before you connect a system of record.

The Bot Desk staff · August 25, 2026 · 9 min read

There is no single American law that governs putting customer data through an AI agent. What governs it is a stack: the Federal Trade Commission Act at the bottom, a growing set of state privacy statutes above that, sector-specific rules that override both in health, finance and a few other industries, and — the part most businesses forget — the promises you already made to your own customers, which are enforceable against you.

That stack is the answer to "is this allowed." Nothing in it turns on whether the technology is an AI agent, a script, or a temp with a spreadsheet. The obligations attach to the data and to what you said you would do with it.

Section 5 of the FTC Act is the floor

Section 5 prohibits unfair or deceptive acts or practices in commerce. It has no minimum company size and no industry limit. In practice it means two things for automation: you have to do what you told customers you would do with their data, and you have to keep security promises that are reasonable in light of the sensitivity of what you hold.

Advertisement

The FTC has been unusually direct about the AI version of this. In a 2024 staff post, the agency wrote that it "may be unfair or deceptive for a company to adopt more permissive data practices — for example, to start sharing consumers' data with third parties or using that data for AI training — and to only inform consumers of this change through a surreptitious, retroactive amendment to its terms of service or privacy policy." The same post states that a business "that collects user data based on one set of privacy commitments cannot then unilaterally renege on those commitments after collecting users' data."

The FTC's position on vendors is equally blunt: "There is no AI exemption from the laws on the books." Model providers that fail to honor their privacy commitments "may be liable under the laws enforced by the FTC," including promises "that they won't use customer data for secret purposes, such as to train or update their models."

Read both of those from the source: the terms-of-service post and the model-as-a-service post. They are short.

The practical consequence for a small business: if your privacy policy says customer data is used only to fulfill orders, routing that data through an AI agent to draft marketing copy is a decision with legal weight, not just an operational one.

State privacy laws

A growing number of states have passed comprehensive consumer privacy statutes, and they are not identical. Two of them illustrate the range well: California and Texas.

California. The CCPA, as amended by the CPRA, applies to for-profit businesses doing business in California that meet any one of three thresholds. Per the California Attorney General, those are: gross annual revenue over $25 million; buying, selling or sharing the personal information of 100,000 or more California residents or households; or deriving 50% or more of annual revenue from selling California residents' personal information. Consumers get rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.

California is also the state that has written rules specifically about automated decisions. The California Privacy Protection Agency's regulations covering CCPA updates, cybersecurity audits, risk assessments and automated decisionmaking technology were approved by the Office of Administrative Law in September 2025 and took effect January 1, 2026. On the agency's own timeline, businesses must begin complying with the risk assessment requirements by January 1, 2026, must comply with the ADMT requirements beginning January 1, 2027, and file cybersecurity audit certifications on a staggered schedule — April 1, 2028 for businesses over $100 million in revenue, April 1, 2029 between $50 and $100 million, and April 1, 2030 below $50 million (CPPA, California Finalizes Regulations to Strengthen Consumers' Privacy).

Advertisement

Texas. The Texas Data Privacy and Security Act works differently, and small businesses should notice why. According to the Texas Attorney General, it reaches any entity that conducts business in Texas or produces a product or service consumed by Texas residents and processes personal data. There is no revenue threshold. Small businesses as defined by the U.S. Small Business Administration are generally exempt — except that a small business must obtain consent before selling a consumer's sensitive data.

The threshold question is never "are we big enough to be regulated." It is "which of these statutes reaches us, and on what trigger."

One requirement is close to universal across the state laws and directly relevant to automation: controllers must have a written data processing contract with each processor, containing terms the statute specifies, and processors must impose the same obligations on their subprocessors. If you connect an AI agent to your CRM, that vendor is almost certainly a processor, and the contract is not optional.

Sector rules that sit on top

General privacy law is the baseline. If you are in a covered sector, the sector rule is the operative one.

  • Health. If you are a covered entity or a business associate, HIPAA governs protected health information, and a business associate agreement is required before a vendor touches it.
  • Finance. The FTC's Safeguards Rule, at 16 C.F.R. § 314.4(f), requires financial institutions under FTC jurisdiction to select service providers capable of maintaining appropriate safeguards, to spell out security expectations in the contract, and to periodically reassess those providers. "Financial institution" is defined broadly and catches businesses that do not think of themselves as banks.
  • Consumer reports. If your automation uses data about creditworthiness, tenancy or employment screening, the Fair Credit Reporting Act may apply to how it is used and disclosed.
  • Biometrics and minors. Several states regulate biometric identifiers and children's data separately and more strictly, with their own consent requirements.

Vendor training-data terms

This is where the diligence actually happens, and where the marketing page is least reliable.

Ask for the contract terms, not the FAQ. What you are looking for:

  • Does the default differ by plan? Consumer and free tiers frequently permit training on inputs by default while business and API tiers do not. If some of your staff use the free tier for the same work, you have two policies running at once.
  • Is it "we do not train" or "we do not train unless you opt in"? These are different sentences with different consequences, and only one is stated in the agreement.
  • What is the retention window? Many providers retain inputs for a period for abuse monitoring even when they do not train on them. Ask for the number of days and whether a zero-retention arrangement is available in writing.
  • Who are the subprocessors? Your data processing agreement obligations flow down. Get the current list and the notice terms for changes to it.
  • Can a human review your data? Abuse-monitoring review by staff or contractors is a disclosure. It should be described.
  • What happens on termination? Deletion timelines, and what survives in backups.

Every one of these should appear in the agreement or a data processing addendum you can save as a PDF. A statement on a pricing page is a marketing claim, and the FTC's enforcement interest is precisely in the gap between marketing claims and practice.

Before you connect a system of record

An AI agent reading a document is a bounded risk. An AI agent with credentials to your CRM, billing system or shared inbox is a different thing: it can read everything in there, including data you forgot was in there.

  1. What categories of personal data live in this system, including free-text fields where staff paste things?
  2. Is any of it sensitive under a statute that reaches us — health, precise location, government ID, biometric, financial account?
  3. Does our current published privacy notice cover this use, in plain terms a customer would recognize?
  4. Do we have a signed data processing agreement with this vendor, and does it list subprocessors?
  5. Can we scope the agent's access to a subset of records or fields rather than the whole system?
  6. Is there a log of what the agent read and wrote, and can we produce it if a customer exercises a right to know?
  7. If a customer asks us to delete their data, does that reach the vendor's copies, and in what timeframe?
  8. Who inside the company approved this, and is that written down?

The last one matters more than it sounds. When a regulator or a customer asks how a decision was made, "nobody owned it" is the worst available answer.

None of this requires a compliance department. It requires reading the vendor's agreement once, matching it against your own privacy notice, and narrowing the agent's access to what the job needs.

The Bot Desk publishes information, not legal advice. We are not a law firm and nothing here creates an attorney-client relationship. Which statutes reach your business, and what they require of you, depends on facts we do not know — consult a qualified attorney licensed in your state before making a decision that relies on any of this.