Car dealership showroom with a general manager and an advisor reviewing a folder in a glass office, illustrating AI legal risks for dealerships
Resources / Blog

AI Legal Risks for Car Dealerships: Privacy, FTC and Liability

By Alexis MerchantOctober 11, 2026 · 17 min read

The biggest AI legal risks for dealerships are customer data pasted into public AI tools, chatbot promises the store is held to, AI calls and texts sent without consent, and credit or hiring decisions nobody can explain. None of it needs a new AI law, because the privacy, advertising, and lending rules you already follow cover all four.

Last updated: October 11, 2026

Erik Nachbahr, our founder, tells a story about speaking to rooms full of accountants and dealers, and I think about it every time a store asks me about AI.

“When I speak at AICPA, everybody there is talking about AI and how it’s gonna make you a million dollars,” he says. “And my thing is, AI is the greatest thing ever, and our AI offering is gonna be ridiculous and awesome, but nobody wants to hear the thing I’m talking about. I’m gonna give you some guardrails and things you need to think about, because this is the stuff that actually matters to your business.” Then he gets to the part that bugs him. “Nobody wants to think about that. They just want to think about all the fun stuff.”

He calls it the Wild West for AI and auto dealerships. From where I sit, he’s right. I’ve spent more than 10 years in this industry, starting in the service department where my dad was the service manager, and later about four years on Tekion’s Learning & Development team teaching dealership staff how to use new software. So I see AI the way the people on the floor see it. It’s a faster way to answer a customer, clean up a repair order note, or get a follow-up text out before lunch. Nobody on the service drive is thinking about federal law when they do that. Why would they?

That’s the gap. It’s why I wrote this. I’m not a lawyer, and nothing here is legal advice, so take the specifics to your attorney. What I can do is show you where AI is already touching the law in your store, department by department, and which guardrails are worth putting in place first. If you want the version where somebody runs that for you, that’s what our managed AI for dealerships program does.

Dealership service advisor with a clipboard talking with a customer on the service drive, where AI legal risks for dealerships start

AI legal risk at a dealership is the chance that an AI tool, or an employee using one, breaks a rule the store already answers to. That covers customer privacy under the FTC Safeguards Rule, deceptive statements under the FTC Act, consent rules for calls and texts, and fair lending and hiring laws. The tool is new. The rules aren’t.

I want to stay on that last point for a second, because it’s the one dealers get wrong the most. A lot of people are waiting for “the AI law” to show up so they know what to do. The Federal Trade Commission answered that back on September 25, 2024, when it announced a sweep it named Operation AI Comply. The chair at the time said the cases “make clear that there is no AI exemption from the laws on the books.” So I’d stop asking whether a law applies to your chatbot. Ask which ones.

And the tools are already in the building. Cox Automotive’s AI in Auto Retail Tracker, published in August 2026, found that 82% of dealers report using AI, and about a third either aren’t measuring what it does or aren’t sure how. Think about that. Most stores are using it, and a good share of them can’t tell you what it’s doing. Not great. AI is here and it is not leaving, so the work now is catching the rules up to the habits.

Where the Risk Shows Up, Department by Department

When I train a store on new software, I never start with the software. I start with who touches it and what they do with it on a normal Tuesday. Same exercise here, with AI.

Where AI shows upWhat happens on the floorRule that already covers itFirst guardrail
Service drive and BDCAn advisor pastes a customer’s name, phone, and repair history into a public chatbot to draft a replyFTC Safeguards Rule, 16 CFR Part 314An approved AI tool, and a short list of what never goes into any other one
Website chatbotThe bot quotes a price, a rebate, or a trade value that isn’t realFTC Act Section 5 and state deceptive practice lawsLimits on what the bot can state, plus a human handoff for pricing
Outbound calls and textsAn AI voice agent calls a list of past service customersTelephone Consumer Protection ActConsent checked before the list is loaded
F&IA scoring tool steers which customers get which termsEqual Credit Opportunity Act and Regulation B, plus new state rulesA person who can explain every decline in plain words
MarketingAI writes the ad and makes the vehicle photoAdvertising rules, OEM co-op terms, copyrightA manager reads every ad before it runs
HRA screening tool ranks technician applicantsFederal and state employment discrimination lawsA human makes the call, and you know what the tool scores on

Six rows. Not one of them is really a technology problem, when you look at it. It’s a person doing their job a little faster with a tool nobody ever set rules for.

Privacy: The Copy and Paste Problem

This is the one I’d fix first, because it’s happening in your store today whether you’ve approved AI or not.

Picture a service advisor with nine cars waiting and an upset customer in her inbox. She copies the whole thread, the name, the cell number, the VIN, the note about the declined brake job, and drops it into a free chatbot on her phone with “write a polite reply.” Ten seconds, tops. She meant well. She did it to take better care of the customer, and that’s exactly what makes it so hard to catch. Customer information just left the dealership and landed with a company you have no contract with.

Dealerships are financial institutions under the FTC Safeguards Rule, and 16 CFR 314.4 expects you to know where customer information goes, train your people on handling it, and oversee the service providers that receive it. A public AI tool an employee signed up for on their own? None of those things. We’ve covered that single issue in more depth in our post on public AI and customer PII, and the full list of duties is in our guide to the FTC Safeguards Rule requirements.

Here’s my trainer’s take, though. Telling people “don’t use AI” doesn’t work. It never has. They’ll nod in the meeting and paste the email anyway, because time is money on a service drive and the tool saves them time. Workarounds need to be left in the past, and you get there the same way every time. Give them a tool that’s allowed, show them how to use it, and make the safe way the easy way.

Repair order paperwork, a pen, and customer keys on a dealership service desk, the kind of customer information AI privacy rules protect

The FTC Side: Your Chatbot’s Promises Are Your Promises

If your website chatbot tells a shopper something that isn’t true, who said it? You did. Not the bot.

That’s the direction every regulator and tribunal has gone so far. In February 2024, a Canadian tribunal ruled against Air Canada after its website chatbot gave a customer wrong information about a bereavement fare. The airline argued the bot was responsible for its own words, and the tribunal held the company to what its chatbot said. That isn’t a U.S. court. It doesn’t bind anybody here. So why bring it up? Because it’s the plainest example of the logic, and the FTC’s own statement about no AI exemption points the same way.

Our industry has its own version. Back in December 2023, somebody talked a Chevrolet store’s chatbot into “agreeing” to sell a new Tahoe for a dollar, and it went around the internet in a day. We wrote about that kind of trick in the scary part of AI in car dealerships. Funny story. It’s a lot less funny if the bot had quoted a believable wrong price, like a rebate the customer didn’t qualify for, and the customer drove an hour to get it.

A quick word on the CARS Rule, since dealers still ask me. A federal appeals court threw out the FTC’s Combating Auto Retail Scams Rule in January 2025, and some people took that to mean the pressure was off. It isn’t. Not even close. The FTC Act’s ban on deceptive practices never went anywhere, and every state has its own version. A misleading price is a misleading price whether a salesperson, a banner ad, or a chatbot put it in front of the customer.

Calls, Texts, and AI Voices

AI voice agents are getting good. Really good. I’ve heard a few that would fool me for the first ten seconds, and stores are starting to use them for service reminders, missed-call follow-up, and equity mining.

On February 8, 2024, the Federal Communications Commission ruled that AI-generated voices count as “artificial” voices under the Telephone Consumer Protection Act. In practice, an AI voice call gets treated like a prerecorded one, and those need the customer’s prior consent. The law lets a consumer sue for $500 per call, and more if a court finds it was willful. So do the math on a list of 2,000 past customers that nobody checked. It adds up fast.

Who fixes that? The BDC manager. Not the vendor. Before any AI calling or texting campaign goes out, somebody at the store confirms where the consent came from and that opt-outs are honored. Your vendor’s sales rep saying “we’re compliant” doesn’t count. Sorry.

Dealership BDC manager checking a printed customer call list for consent before an AI voice calling campaign

Liability in the F&I Office and in Hiring

Credit is where I’d slow down the most, and I’ll be upfront that it’s also where you most need your attorney and not a blog post.

If a tool helps decide who gets approved, what rate they see, or which products get offered, fair lending law comes with it. The Consumer Financial Protection Bureau said in Circular 2023-03 that a creditor using AI or a complex model still has to give a customer the specific, accurate reasons for a denial, and can’t hide behind a generic checklist. “The system said no” is not a reason. Not a legal one. If your F&I manager can’t explain a decision in plain words, the store has a problem before any regulator calls. NADA has published fair credit guidance for dealers for years, and it’s a good place to check whether a new tool fits the policy you already have.

The states are moving too. This part changes fast. As I write this in October 2026, here’s where two of them stand.

  • California’s privacy agency finished rules on automated decision-making technology that took effect January 1, 2026, and businesses that use it for significant decisions, lending included, have until January 1, 2027 to comply.
  • Colorado went back and forth. Its 2024 AI law was delayed, then replaced in May 2026 by SB 26-189, which starts January 1, 2027 and is built around telling consumers when an automated tool was used and giving them a way to ask for a human review.

Whether either one reaches your store depends on your size, your state, and what your tools really do. Ask counsel. Please. Hiring gets the same treatment, by the way. A résumé screener that quietly ranks applicants is making the kind of decision employment law has covered for decades, and “the software picked” won’t hold up any better in HR than it does in F&I.

AI Guardrails a Dealership Can Put in Place This Month

I drive an EV. I’ve had it a year now and put 11,000 miles on it, and I’ll admit I’m a fan, even though the paint scratches if you look at it wrong. The driver-assist is the part I don’t fully trust yet. It still has some AI learning to do, so my hands stay on the wheel, and that’s pretty much how I think about AI guardrails in a store. You keep driving. You just don’t let go.

Where I picked up my way of doing this was a DMS conversion. A dealer group with more than 30 stores was moving from one system to another, and we got in the habit of trying every setting on a real deal before we trusted it. The state tax setup, for example, got run on one live deal with the F&I manager before the rest of the group ever saw it. So when a store asks me where to start with AI, I tell them the same thing, which is to start small and write down who’s responsible.

GuardrailWho owns itYou’re done when
Find out what’s in useGM, with every department managerYou have a list of every AI tool tried in the last 30 days, and nobody got in trouble for being on it
A one-page AI ruleDealer principal or GM, reviewed by your attorneyIt names the approved tools, the customer information that stays out of all others, and who to ask
An approved AI toolIT providerStaff have a private workspace where what they type isn’t used to train a model
A human check on customer-facing AISales manager and BDC managerAds, chatbot scripts, and price or payment messages are read before they go out, and consent is confirmed before any call or text list is loaded
Vendor answers in writingController or office managerEach vendor has said what data its AI feature sees, whether it trains a model, and how long it’s kept

Do the top row first. Honestly, if that’s all a store got done this month I’d still call it a win, because nobody can make a rule about an app they’ve never heard of. And the list is going to be long. These things are free, and they’re on every phone in the building.

Something the table can’t show is practice. I went to the Cleveland Auto Show in its last year at the I-X Center, and a couple of the brands had their cars locked, or tagged display only, and I remember thinking what a missed opportunity that was. People don’t go to an auto show to look through a window! They go to open the door and sit down and push the buttons. Training works the same way for me. Nobody on your service drive is going to learn this off a page they initialed, so get each department together for fifteen minutes, let them try it on examples from their own day, and then do that again next quarter. Hands on experience and repetition make a world of difference.

Last one. I’ve been hearing about employees who built their own little apps with AI, a lead tracker, a parts lookup, that kind of thing, and I think it’s great that they’re curious. I’d only ask that if one of those apps has customer data in it, it goes on the same list as everything else, and at least one other person at the store knows it’s there.

Dealership manager leading a short hands-on training huddle with service advisors about AI guardrails

Who Should Own This at the Store

My honest answer is that it shouldn’t be IT, at least not by itself, and I say that as somebody who works at an IT company. If you look back at that table, nearly every row is really a choice about how the store treats a customer, which makes it the dealer principal’s or the GM’s call before it’s anybody else’s. Your attorney is the one who tells you what your state requires, and then your IT and security people do their part by getting the approved tool into everyone’s hands, watching what leaves the network, and making AI one more piece of the program you already run for FTC Safeguards compliance.

That last piece is where we come in. Helion Technologies has worked only with dealerships since 1997, and today we support 2,000-plus of them and 35,000 end users, so we’ve seen a lot of stores go through a lot of new technology. We aren’t your lawyers and we’d never pretend to be, but we can make sure that when your lawyer asks which AI tools touch customer data in your store and who approved them, somebody has a real answer.

What Dealers Ask Me About AI and the Law

Is there an actual AI law for car dealers yet?

Not one federal AI law, no, but the FTC Act, the Safeguards Rule, the TCPA, and fair lending rules already apply to anything your AI tools do. The FTC said as much in September 2024 when it announced Operation AI Comply. State rules are being added on top, with California and Colorado both set for January 1, 2027.

Our chatbot quoted a price that was wrong. Are we stuck with it?

That one goes to your attorney the same day it happens, because the answer depends on your state and on what the customer was told. What I’d do in the meantime is save the chat transcript, find out how the bot got that number, and turn off its ability to talk price until someone fixes it. I wouldn’t argue with the customer that the bot isn’t the dealership. That argument has not gone well for anyone who’s tried it.

Can we just ban ChatGPT at the store and be done?

A ban on paper rarely survives a busy Saturday. People use these tools because they save time, and if you take one away without giving them another, they’ll use it on their phones where you can’t see it. A written rule plus an approved tool plus fifteen minutes of practice works much better than a memo.

Does an AI voice calling our service customers need consent?

Since February 8, 2024, the FCC has treated AI-generated voices as artificial voices under the TCPA, so those calls need the same prior consent a prerecorded call does. Check the list before the campaign, not after the first complaint.

We’re a single-point store. Who’s supposed to own all this?

One named person, and at a single-point store that’s usually the GM or the controller, with your attorney and your IT provider behind them. No committee needed. It needs to be somebody who knows which tools are approved, keeps the one-page rule current, and gets asked before a department turns on a new AI feature. If nobody’s name comes to mind, that’s your first guardrail.

Start With What’s Already Happening

My dad ran his service department with one rule I still hear in my head, which was no shortcuts. AI isn’t a shortcut by itself. It turns into one when nobody has told the people on the floor where the lines are. That part’s on us. So this week, ask each department what they’re already using, and write down what you hear. Start there. That list is where your guardrails come from.

And if you’d like a second set of eyes on where customer data is going in your store, AI tools included, our complimentary IT and cybersecurity assessment is a good place to begin. Your team does the hard part. We’ll help you get them set up for success.

About the author

Alexis Merchant

Manager of Dealer Enablement Success, Helion Technologies

Alexis Merchant is Manager of Dealer Enablement Success at Helion Technologies and a Tekion DMS expert with more than 10 years in the automotive industry. She spent four years on Tekion's Learning & Development team and now helps dealership teams get more from the system after go-live.

Alexis Merchant on LinkedIn

Confidence in your current setup and actual protection aren't always the same thing. The only way to know which one you have is to look.

Get Your Complimentary IT & Cybersecurity Assessment →