Get the latest on creator intelligence and AI workflows.
When an AI tool drafts a review, a synthetic persona "recommends" a product, or a cloned voice reads a testimonial, the old question — did you disclose the connection? — is no longer the only one that matters. The harder question is who pays when something is deceptive and a machine was in the loop: the creator who posted it, the brand that paid for it, the agency that produced it, or the AI vendor that built the tool. That allocation question is where 2026 gets genuinely unsettled, because the FTC spent 2024 asserting an aggressive tool-vendor theory and then, in December 2025, walked a large piece of it back.
TL;DR: When AI is in the endorsement loop, liability still lands primarily on whoever publishes the deceptive content — the advertiser, the creator, or whoever posts it. The FTC's 2024 attempt to hold an AI tool vendor liable (the Rytr "means and instrumentalities" theory) was reopened and set aside on December 22, 2025, so vendors are no longer categorically on the hook. Knowing violations of the Fake Reviews Rule can still draw civil penalties of up to $53,088 per violation, and the FTC expressly reserved the right to "hold accountable actors that use AI to violate the law."
This article is educational information, not legal advice. For your specific situation, consult a qualified attorney.
This is the AI-specific deep dive. For the general disclosure mechanics — what a material connection is, how to place "#ad," what "clear and conspicuous" means under 16 CFR Part 255 — start with our pillar, the FTC influencer disclosure rules guide. Here we stay narrowly on liability: who is exposed, for what, and how much.
How Does AI Change Who's Liable for an Endorsement?
Disclosure law assumes a human in the picture: a real person, with a real opinion, who took something of value from a brand. AI breaks that assumption two ways at once. It can manufacture an endorser who never existed — a generated reviewer, a virtual influencer, a cloned voice — and it can mass-produce endorsement content at a volume no human could, which is exactly how a single bad practice turns into thousands of separate violations.
That changes the liability analysis even when the underlying deception standard does not. The FTC's position, restated by then-Chair Lina Khan during the agency's 2024 sweep, is blunt: "there is no AI exemption from the laws on the books." A fabricated endorsement is deceptive whether a copywriter or a model wrote it. What AI shifts is the apportionment problem — how many parties stand between the fabrication and the consumer, and which of them the law actually reaches. The rest of this article works through that chain.
Who's on the Hook: Creator, Brand, Agency, Platform, or AI Vendor?
There is no single answer, but there is a hierarchy of exposure. Think of it as a chain running from the tool that generated the content to the consumer who saw it.
The advertiser (brand). Primary exposure. The brand procures the endorsement, benefits from it, and under the Endorsement Guides is responsible for what its endorsers say. A brand cannot contract this away or blame "the AI."
The creator or endorser. Primary exposure alongside the brand. Whoever publishes a deceptive endorsement — including one they had an AI draft — owns that publication. "The tool wrote it" is not a defense, the same way "my agency didn't mention it" is not a defense for a missing disclosure.
The agency or marketing intermediary. Real but secondary exposure. An agency that produces or directs fabricated content can be pulled in, but the agency is rarely the only target.
The platform. Generally the most insulated of the group for third-party posts, though platforms have their own obligations around fake engagement and review integrity.
The AI tool vendor. The contested link. In 2024 the FTC tried to put the vendor on the hook under a "means and instrumentalities" theory; by the end of 2025 it had stepped back. That arc gets its own two sections below.
The practical takeaway is to assume the deceptive-publication risk sits with you, not with the vendor that sold you the tool. Anyone planning to lean on "the AI company is liable, not us" is building on ground the FTC itself just walked away from.
Are AI-Generated Reviews Illegal Under the Fake Reviews Rule?
For fabricated reviews and testimonials, the answer is close to a flat yes — and there is now a rule with penalty teeth behind it. The Fake Reviews Rule, 16 CFR Part 465, took effect on October 21, 2024 after a 5-0 Commission vote. Unlike the interpretive Endorsement Guides, Part 465 is an enforceable trade-regulation rule, which lets the FTC seek civil penalties against knowing violators.
The AI hook is explicit. The rule reaches reviews and testimonials that misrepresent that they are by someone who does not exist — and the FTC's own example is "AI-generated fake reviews." That is the cleanest statement in current federal regulation that fabricating a reviewer with software is squarely in scope.
Part 465 covers more than fabrication alone. The provisions most relevant to AI and creator work are:
§465.2 — Fake or false reviews and testimonials, including the central "reviewer exists" prohibition that catches AI-generated fakes. It bars writing, creating, selling, buying, and knowingly disseminating such content.
§465.5 — Undisclosed insider reviews by officers, employees, agents, and certain relatives. AI authorship is not a loophole here; the disclosure obligation is unchanged.
§465.8 — Misuse of fake indicators of social-media influence, such as bot followers or fake views, where the buyer knew or should have known they were fake. This one bears directly on how virtual personas get launched.
One reason the rule exists at all is AMG Capital Management, LLC v. FTC, a Supreme Court decision that limited the agency's ability to seek monetary relief under §13(b) of the FTC Act. A formal rule restores a penalty pathway — which is why Part 465 changes the liability math, not just the disclosure math.
Why Can't a Virtual Influencer "Love" a Product?
A virtual influencer is a brand asset wearing the costume of a person. That distinction is the whole legal problem. The Endorsement Guides set a standard at 16 CFR §255.2 that an endorsement must reflect the honest opinions of a bona fide user of the product. A synthetic persona, by construction, has no honest opinion and is no one's genuine user.
The Guides illustrate this with a manufacturer-procured fake review reading "I lost 50 pounds with QRS Weight-Loss." The FTC's example states it "is deceptive because it was not written by a bona fide user of the product" and "does not reflect the honest opinions, findings, beliefs, or experience of the endorser." Swap the fictional dieter for an AI-generated influencer and the analysis is identical: a fabricated endorser presenting a fabricated experience fails the honest-opinion standard per se.
That does not make every virtual influencer unlawful. A synthetic character used transparently as a brand mascot is in different territory than one staged to look like an independent customer sharing a real result. The line is misrepresentation: the moment the persona is dressed up as a genuine user with a genuine experience, the endorsement is deceptive — and the brand running it owns that. The disclosure mechanics that apply on top are covered in the pillar linked above.
Is "#ad" Enough When the Endorsement Is AI-Generated?
A correct "#ad" tells the audience there is a paid relationship. It says nothing about whether the person is real or whether the experience happened. Those are separate representations, and AI can make both of them false even when the sponsorship is disclosed perfectly.
Picture a testimonial that carries a clean disclosure but was generated by software to describe a result no customer ever had. The disclosure is fine; the testimonial is still deceptive, because it misrepresents that a real user had that experience. The same is true for a virtual influencer whose "Paid Partnership" label is impeccable but whose entire persona implies a genuine user who does not exist. Disclosing the commercial connection does not cure a misrepresentation about who is speaking or what actually happened. The pillar covers how to place disclosures; the AI-specific point is that placement is necessary but not sufficient when the speaker or the experience is synthetic.
Are Cloned Voices and Deepfake Testimonials Legal?
The most acute version of this is the cloned voice or deepfaked face. The FTC flagged the category early, in its 2023 business-guidance post "Chatbots, deepfakes, and voice clones: AI deception for sale," which warned that synthetic media used to deceive consumers is squarely within the agency's reach.
The liability logic tracks everything above. A cloned celebrity voice reading a testimonial the person never gave is a fabricated endorsement — it misrepresents both who is speaking and that they ever used or endorsed the product. A deepfaked spokesperson is the same problem rendered in video. Neither gets a pass because the technology is impressive; the deception standard does not care how the misrepresentation was produced. And because the harmed party here can also be the impersonated person, not just the consumer, this is the corner of AI endorsement work where exposure is broadest and the appetite for the tactic should be lowest.
What Was Operation AI Comply, and Why Did Rytr Flip?
In Operation AI Comply on September 25, 2024, the FTC announced five law enforcement actions against operations that, in its words, "use AI hype or sell AI technology that can be used in deceptive and unfair ways." The five were Rytr, DoNotPay, Ascend Ecom, Ecommerce Empire Builders, and FBA Machine. Two of them matter most for endorsements: Rytr (an AI review-and-testimonial generator) and DoNotPay (an "AI lawyer" service).
The DoNotPay action is the cleaner of the two, because it still stands. The company marketed an AI subscription as "the world's first robot lawyer" and claimed it could "replace the $200-billion-dollar legal industry with artificial intelligence" — but, per the complaint, it "did not conduct testing to determine whether its AI chatbot's output was equal to the level of a human lawyer" and "did not hire or retain any attorneys." The FTC finalized its order (vote 5-0 on January 16, 2025), requiring $193,000 in monetary relief and barring unsubstantiated "real lawyer" claims.
The DoNotPay lesson for AI endorsements is about capability claims: if a brand or creator says an AI tool "performs like a lawyer" — or, by extension, delivers any specific result — that claim needs competent, reliable substantiation on file before it ships. The deception was not the AI; it was the unsubstantiated promise about the AI.
Rytr is the case that flipped. Marketed since April 2021 as an AI "writing assistant," Rytr included a dedicated "Testimonial & Review" generator that, per the complaint, let paid subscribers "generate an unlimited number of detailed consumer reviews based on very limited and generic input," producing reviews that "contained specific, often material details that had no relation to the user's input" and "almost certainly would be false." Some subscribers generated hundreds, and in some cases tens of thousands, of reviews. The FTC voted 3-2 to file, and on December 18, 2024, approved a final consent order (also 3-2) barring Rytr from selling any service dedicated to generating reviews or testimonials.
Then, on December 22, 2025, the same agency reversed course.
Tool-Vendor Liability After Rytr: the "Means and Instrumentalities" Theory, Narrowed
The Rytr complaint did something new: it charged the tool vendor, not just the end users who posted fake reviews. The "means and instrumentalities" theory charged Rytr with "providing subscribers with the means to generate false and deceptive written content for consumer reviews," plus a separate unfairness count for offering a service "likely to pollute the marketplace with a glut of fake reviews." Had it held, an AI-review-tool vendor could be liable for what its customers did with the output. The two commissioners who dissented from filing in 2024 warned against exactly that reach.
A year later, the dissent's position became the majority's. On December 22, 2025, the FTC reopened and set aside the Rytr final order on a 2-0 vote. Its stated grounds: "the complaint failed to satisfy the legal requirements of the FTC Act" and "the order unduly burdens artificial intelligence (AI) innovation." The Commission concluded that "the facts alleged in the complaint fail to support allegations that Rytr violated Section 5 of the FTC Act," and that setting it aside served the public interest. Rytr consented to vacating the order.
The BCP director put the principle this way: "Condemning a technology or service simply because it potentially could be used in a problematic manner is inconsistent with the law and ordered liberty."
The nuance is the whole point. This does not mean AI-generated fake reviews are legal — they are not, and Part 465 still bans them. It does not mean the FTC has exited AI enforcement; the Commission expressly stated it "will continue to hold accountable actors that use AI to violate the law or deceive consumers about the capabilities of their generative AI." What it does mean is that the aggressive tool-vendor theory — holding the AI maker liable for misuse of its general-purpose tool — has been walked back. As of the end of 2025, the FTC no longer treats AI-review-tool vendors as categorically liable. The deceptive publication still sits where it always did: with the advertiser, the creator, or whoever posts the fake.
What Are the FTC Penalties for AI Endorsements in 2026?
The number to anchor on is $53,088 per violation. That is the FTC Act civil-penalty maximum after the 2025 inflation adjustment, effective January 17, 2025, applying a cost-of-living multiplier of 1.02598. It superseded the 2024 figure of $51,744. Any guide still citing $51,744 as the current cap is out of date.
"Per violation" is the phrase that should set off alarms in any AI-content context. The Rytr facts show why: subscribers generated reviews not by the dozen but by the tens of thousands, and high-volume AI generation is exactly the pattern that multiplies a single bad practice into a catastrophic penalty exposure. The Part 465 penalty authority is what turns "we generated some fake reviews" from a cease-and-desist into a penalty assessed on every single one.
The settlement figures already on the record set the reference points. DoNotPay's order carried $193,000 in monetary relief over unsubstantiated AI-capability claims — a comparatively small number that nonetheless came attached to a binding order and mandatory consumer notices. For endorsement exposure specifically, the combination to internalize is Part 465's fake-review ban plus the $53,088-per-violation multiplier.
A Practical Liability-Allocation Playbook
Translate the above into things you can put in a contract and a workflow:
Treat AI-generated reviews and testimonials as banned content, not a gray area. Part 465 §465.2 makes it a violation to write, create, sell, buy, or knowingly disseminate reviews that misrepresent that the reviewer exists. Prohibit AI-fabricated reviews explicitly in creator contracts and review-collection workflows.
Require that every endorsement reflect a real user's honest opinion. Under §255.2, an endorsement that does not reflect a bona fide user's honest opinion is deceptive. Any virtual persona or AI-fabricated "experience" fails this per se — build the requirement into briefs.
Allocate liability assuming the publisher carries it. The Rytr reversal means you cannot assume the AI tool vendor absorbs the risk. Whoever posts the deceptive content — brand, creator, or agency — holds the primary exposure. Write your indemnities accordingly.
Substantiate AI-capability claims before they ship. DoNotPay's $193,000 order turned on unsubstantiated "AI lawyer" claims and the absence of testing. Any "AI-powered" performance or results claim needs competent, reliable evidence on file.
Don't buy fake engagement to launch synthetic personas. §465.8 bars buying fake followers or views used to misrepresent influence for a commercial purpose — a direct hit on virtual-influencer launch tactics.
Vet the humans before you get to the AI question. The cleanest defense is upstream: partner with real creators whose audiences and engagement are genuine, so you are not relying on fabricated personas or inflated reach in the first place. Vetting creators across Instagram, TikTok, X, and YouTube — authenticity and fake-follower signals, audience analysis — is exactly what Celavii is built to help brands do. To be clear about scope: Celavii is a creator-intelligence platform, not a compliance, disclosure-monitoring, or legal tool, and it does not detect AI-generated reviews. Use it to choose compliant partners upstream, and pair it with proper legal guidance and clear creator briefs.
Liability runs in a hierarchy. The advertiser (brand) and the creator who posts the endorsement carry primary exposure; an agency that produces or directs the content has real but secondary exposure; the platform is generally the most insulated for third-party posts; and the AI tool vendor's liability is now uncertain after the Rytr reversal. The practical rule: assume the deceptive publication sits with whoever posted it, not with the company that sold the tool.
Fabricated AI-generated reviews are prohibited. The Fake Reviews Rule (16 CFR Part 465), effective October 21, 2024, bans reviews that misrepresent that the reviewer exists, and the FTC's express example is "AI-generated fake reviews." Knowing violations can draw civil penalties of up to $53,088 per violation.
No. When it set aside the Rytr order on December 22, 2025, the FTC stated it "will continue to hold accountable actors that use AI to violate the law or deceive consumers about the capabilities of their generative AI." What changed is the tool-vendor theory — holding the AI maker liable for misuse of a general-purpose tool — not the underlying ban on deceptive endorsements.
It was the FTC's theory that an AI tool vendor could be liable for "providing subscribers with the means to generate false and deceptive" reviews, rather than only the end users who posted them. The FTC charged Rytr on that basis in 2024 and finalized an order, but reopened and set it aside in December 2025, finding the complaint "failed to satisfy the legal requirements of the FTC Act" and unduly burdened AI innovation.
Yes, when they misrepresent a real user's experience. Under 16 CFR §255.2, an endorsement must reflect a bona fide user's honest opinion. A synthetic persona staged as an independent customer with a genuine experience fails that standard per se, and the brand running the persona carries the exposure.
No. A disclosure addresses the commercial connection, not whether the speaker is real or the experience happened. An AI-generated testimonial or a synthetic persona can carry a perfect disclosure and still be deceptive because it misrepresents who is speaking or what actually occurred. Those are separate representations that both have to match reality.
They carry the broadest exposure. A cloned voice or deepfaked spokesperson reading an endorsement the person never gave misrepresents both who is speaking and that they used or endorsed the product. The FTC flagged this category in its 2023 "Chatbots, deepfakes, and voice clones" guidance, and the harmed party can include the impersonated person, not just the consumer.
The maximum is $53,088 per violation, reflecting the 2025 inflation adjustment effective January 17, 2025, which superseded the 2024 figure of $51,744. Because penalties are assessed per violation, high-volume AI generation multiplies exposure fast — Rytr subscribers generated up to tens of thousands of reviews each.
The FTC alleged DoNotPay made unsubstantiated claims that its AI "robot lawyer" could perform like a human attorney, without testing its output or retaining any attorneys. The finalized order, announced February 11, 2025 (vote 5-0 on January 16, 2025), required $193,000 in monetary relief and barred unsubstantiated "performs like a real lawyer" claims. The lesson: AI-capability claims need competent, reliable substantiation before they ship.
Yes. The Endorsement Guides are interpretive, but 16 CFR Part 465 is an enforceable rule, which restores a civil-penalty pathway partly lost after the Supreme Court's AMG Capital Management v. FTC decision limited monetary relief under §13(b). That restored penalty power is what gives the fake-review ban real teeth.
The Bottom Line
AI creates neither a new exemption nor new immunity. The deception standard is the one it always was: an endorsement has to reflect a real user's honest opinion, and a review cannot misrepresent that its author exists. What AI changes is the allocation question — and on its hardest piece, tool-vendor liability, the FTC moved decisively in 2025. After the Rytr reversal, do not plan around the AI company absorbing your risk. The deceptive publication belongs to whoever posts it, the Fake Reviews Rule still backs that with penalties up to $53,088 per violation, and the FTC has reserved the right to come after anyone who uses AI to break the law.
This article is educational information, not legal advice. For your specific situation, consult a qualified attorney.