The Massachusetts AG Advisory: AI Under Chapter 93A
9 min read · updated August 11, 2026
Massachusetts has no AI statute and has not needed one to bring AI within reach of its Attorney General. On 16 April 2024 the office issued an advisory setting out its position that the Commonwealth’s existing consumer protection, anti-discrimination and data security laws already apply to the development and deployment of AI systems. The interesting part is not the conclusion, which is unsurprising, but the statute it rests on.
What the advisory is and is not
An Attorney General advisory is a statement of enforcement position. It is not legislation, it is not a regulation adopted under notice and comment, and a court is not bound by it. What it does is remove the argument that a defendant did not know the office considered a practice unlawful, which matters a great deal under a statute where knowing and wilful conduct carries multiplied damages.
It is also explicitly not limited to consumer-facing chatbots. The advisory addresses developers, suppliers and users of AI systems — three roles, with the third being any business that deploys somebody else’s model in a Massachusetts-facing product. If you license a model and put it in front of Massachusetts consumers, the advisory is addressed to you as well as to the model’s builder.
Why Chapter 93A is the sharpest tool in the drawer
The core provision is G.L. c. 93A, § 2(a): unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are unlawful. Four features of that statute are what make the advisory consequential, and each of them is worse for a defendant than the equivalent federal position.
- No intent element. A representation can be deceptive without anyone meaning to deceive. A model card that overstates accuracy because the evaluation set was unrepresentative is analysed on what it conveyed, not on what was believed.
- Private enforcement, with multiplied damages. § 9 gives consumers a right of action and § 11 gives it to businesses. Where the violation is a wilful or knowing one, or where a reasonable settlement offer was refused, damages are doubled or trebled, and a successful claimant recovers attorney’s fees. § 9 claims require a written demand letter thirty days before suit, which is why a 93A demand letter is often the first sign that a claim exists.
- Civil penalties per violation for the AG. Under § 4 the Attorney General may seek an injunction and a civil penalty of up to $5,000 for each violation, plus costs and fees. In a software product, “each violation” is a per-consumer arithmetic that scales badly.
- Investigative demands before suit. § 6 lets the office compel documents and testimony on reasonable belief that a person has engaged in conduct declared unlawful, without filing anything. Most 93A matters are resolved at this stage.
The statute is published by the Massachusetts General Court at malegislature.gov.
The conduct the advisory names
The advisory enumerates categories of conduct the office considers potentially unfair or deceptive. Read as a list of what to check before launch, they are:
- Falsely advertising the quality, value or usability of an AI system — the state-level version of the theory the FTC pursues under Section 5, covered in the AI-washing page.
- Supplying an AI system that is defective, unusable or impractical for the purpose advertised.
- Misrepresenting the reliability, manner of performance, safety or condition of an AI system, including representations about testing and about the conditions under which claimed performance holds.
- Offering an AI system that produces performance the supplier knows or should know is deceptive to consumers.
- Failing to disclose reasonably foreseeable risks of an AI system that the supplier knows or has reason to know about.
- Misrepresenting audio or video content of a person for the purpose of deceiving another into a financial transaction — deepfake and voice-cloning fraud, addressed as ordinary deception rather than as a novel harm.
- Using a chatbot or other AI system to deceive consumers, or failing to disclose that a consumer is interacting with a machine rather than a person.
That last one is worth pausing on. Massachusetts has no bot-disclosure statute of the kind California enacted in SB 1001, and the advisory reaches a similar place by a different route: the non-disclosure is treated as capable of being deceptive in itself. That route has no statutory intent element and no commercial-transaction limitation, so it is in one sense wider than the California statute and in another sense weaker, because it depends on a materiality and likely-to-mislead analysis that has to be done case by case.
Two other statutes in the same document
The advisory also applies the Commonwealth’s anti-discrimination statute, G.L. c. 151B, to AI used in employment, housing and credit decisions, on the same reasoning the New Jersey Division on Civil Rights used the following year: liability attaches to outcomes, not to mechanisms, and buying the tool from a vendor does not transfer the exposure.
It applies the state’s data security regulations, 201 CMR 17.00, which require a written information security programme for anyone holding personal information about a Massachusetts resident. Those regulations are prescriptive in a way that most US security rules are not — encryption of personal information transmitted across public networks and stored on portable devices, oversight of service providers by contract, and access controls are all mandated by name. Feeding personal information into a third-party model provider is a service-provider arrangement for those purposes, and 201 CMR 17.03(2)(f) is where the contractual duty to select and oversee that provider sits.
What this changes in practice
The practical shift is about substantiation. Under 93A, a claim about an AI product is a representation like any other, and the question a regulator asks is what evidence existed at the time the claim was made. That is an evidence-retention problem before it is a marketing problem: the evaluation set, its provenance, the version of the model it was run against and the date all have to survive long enough to be produced. The general shape of that record is covered in AI compliance evidence.
The office has begun using these powers rather than merely announcing them. In 2025 it announced a resolution with a student lender over AI-assisted underwriting practices, entered as an assurance of discontinuance with a monetary component and injunctive terms. Because the terms of an assurance are what actually bind, and because summaries of them are frequently wrong, read the office’s own press release and the filed assurance rather than a description of it.
The broader lesson generalises past Massachusetts. Every state has an unfair-and-deceptive-practices statute, most of them modelled on FTC Act Section 5, and most of those have no intent requirement and a private right of action. A company waiting for an AI statute in a given state to arrive before auditing its claims has already been regulated — it just has not been told which statute yet. The snapshot of which states have AI-specific law deliberately keeps that distinction visible.