AI & Privacy · guide
State Attorneys General as AI and Privacy Enforcers: Multistate Actions and How to Monitor Them
Updated
Outside California, almost every US state privacy law is enforced by one office: the state attorney general (AG). AGs also reach AI products through consumer-protection statutes that predate any AI law. Because they act individually and in coalitions, they are the enforcement channel most likely to touch a company that has no EU footprint and no CPPA exposure. This guide explains where their authority comes from, how multistate actions work, and how to keep up with them. Details are current at time of writing (September 2026).
Two sources of authority
UDAP statutes. Every state has a law against unfair or deceptive acts and practices. These are broad, carry per-violation civil penalties, and require no privacy-specific rule. The Texas AG's September 2024 settlement with Pieces Technologies, a company selling generative AI tools that summarize clinical notes, was brought under the Texas Deceptive Trade Practices Act over claims that its error or hallucination rate was below one in 100,000. The settlement imposed marketing and disclosure obligations rather than a payment, according to Orrick's analysis and Healthcare Dive. It is widely described as the first state AG settlement over AI accuracy claims.
Comprehensive privacy laws. Roughly twenty states now have consumer privacy statutes modeled on Virginia's or Colorado's, and nearly all give the AG exclusive enforcement authority with no private right of action. Colorado's AG, for example, states that only the AG and district attorneys can enforce the Colorado Privacy Act. Penalties are typically set per violation; Virginia's statute allows up to 7,500 dollars per violation under Code section 59.1-584.
Cure periods
Many state privacy laws require the AG to send a notice and give the business time to fix the problem before suing. The details vary and change:
| State | Cure period | Status at time of writing |
|---|---|---|
| Virginia | 30 days | Permanent |
| Texas | 30 days, with a written statement and supporting documentation (section 541.154) | Permanent |
| Colorado | 60 days | Expired January 1, 2025 |
| California (CCPA) | 30 days | Expired January 1, 2023 |
A cure notice is still an investigation. The California AG's 2022 Sephora announcement described a sweep of cure notices alongside the settlement, and those notices were the precursor to further action. Treat the cure window as the time to document remediation, not to argue.
How multistate actions work
A multistate action is a coordinated investigation by two or more AGs against the same target. The mechanics are informal but consistent:
- One or more states open an investigation and issue civil investigative demands.
- Other states join, and an executive committee of lead states negotiates on behalf of the group.
- The National Association of Attorneys General (NAAG) provides administrative support such as conference lines and contact lists, but has no authority over who is investigated or how a case is resolved.
- The settlement is signed by each participating state and typically combines a payment split among the states with injunctive terms that apply nationwide.
The largest privacy example remains the Google location-tracking settlement announced November 14, 2022. Forty AGs, with Oregon and Nebraska leading, resolved allegations that Google misled users about whether turning off Location History stopped location tracking, for 391.5 million dollars and required disclosure changes, per the Colorado AG and North Carolina AG announcements.
The Consortium of Privacy Regulators
Privacy enforcement is now organized in a standing coalition. On April 16, 2025 the CPPA and the AGs of California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon announced the Consortium of Privacy Regulators, a bipartisan group operating under a memorandum of understanding to share expertise, coordinate investigations and meet regularly. Minnesota and New Hampshire joined in October 2025, and Vermont joined on August 4, 2026, bringing membership to twelve regulators, per the CPPA announcement. A company receiving an inquiry from one member should assume the others can see it.
How to monitor AG activity
AG offices publish almost everything they do as a press release, but there is no single feed. A workable routine:
- Each AG's press-release page. All 50 offices have one, usually under a news or press section. Some offer RSS or email subscriptions; many do not, so you will need to poll the page or use a change-detection tool.
- NAAG. The multistate settlements database is searchable by topic, year, state and company and is the best single record of concluded multistate matters, though it is not exhaustive.
- Consortium and CPPA news. Consortium announcements are published through the CPPA's news page.
- Court dockets. Filed complaints often precede the press release; state-court dockets are the earliest signal.
- Keyword discipline. Search for the statute name and for terms like artificial intelligence, automated, biometric and geolocation, because AI cases are often filed under consumer-protection rather than privacy labels.
Because most AG sites lack RSS, teams that need timely notice usually end up scraping the pages on a schedule and routing new items into a shared channel; RegPing's AI and privacy bot does this for AG, CPPA and Consortium releases and posts them into Discord.
Where to verify
- NAAG multistate settlements database
- Colorado AG Google settlement release
- Colorado Privacy Act resource page
- Virginia Code 59.1-584 enforcement and penalties
- Consortium of Privacy Regulators announcement
- California AG Sephora settlement release
This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.
Questions people ask
Can consumers sue under state privacy laws?
Generally no. Most comprehensive state privacy laws give the attorney general exclusive enforcement authority, with no private right of action. California's CCPA is the main exception, and only for certain data breaches.
What is a multistate attorney general action?
A coordinated investigation by two or more state AGs against the same company, led by an executive committee of lead states. NAAG provides administrative support but has no decision-making role. The 2022 Google location-tracking settlement involved 40 states and 391.5 million dollars.
Do state attorneys general publish RSS feeds?
Some do, but many AG press-release pages offer no RSS or email alerts, so monitoring usually requires polling the pages directly or using a change-detection service.