Lina Khan, who chaired the FTC, published a short argument on X for the position that the AI policy debate is looking in the wrong place. Her claim is narrow and load-bearing: there is no AI exemption from laws already on the books, and enforcers do not need a new statutory regime to charge companies, or their CEOs, for releasing defective products, mistreating customers’ data, or competing unfairly.

The framing point matters more than any of the five examples under it. In her account, the discussion about what new law to write has become a substitute for whether agencies are willing to enforce the law they already have — and the FTC, she says, made the existing-law case repeatedly during her tenure.

What she says already applies

  • Consumer protection. Releasing unvetted AI models or agents can violate consumer protection law, and shipping a flawed AI tool without measures to detect and stop rogue or defective agents can be an “unfair or deceptive” act or practice under the FTC Act and analogous state laws. She notes some state attorneys general are exploring criminal liability for AI firms and their CEOs when their models participate in criminal activity.
  • Unfair methods of competition. This covers AI firms appropriating competitively sensitive information from customers, including by tracking how they use other tools. Khan also reads it as reaching race-to-the-bottom behavior: a firm pursuing dangerous practices knowing rivals may feel compelled to match them. She quotes the Supreme Court’s older formulation about conduct that casts competitors into the position of either losing business or adopting a practice they are under “a powerful moral compulsion not to adopt.”
  • Ownership structure as an accountability problem. She points to the concentrated, interlocking structure of these markets — the partnerships and cross-investments a January 2025 FTC staff report covered — and to a concrete example: in her telling, OpenAI could face liability over the Hugging Face incident, but with Hugging Face owned by Nvidia, a lawsuit over it is unlikely, given Nvidia’s interest in seeing OpenAI continue unimpeded. That is a structural conflict of interest doing the work that a legal defense would otherwise have to do.
  • Data security. Firms that fail to invest in adequate security or fix known vulnerabilities can already be breaking the law. She cites an analysis that around a third of Fortune 100 companies lack even a channel for reporting security issues, and points to the FTC’s Drizly case, where the agency held both the company and its CEO personally liable.

What she says follows from it

Khan is not arguing against new law. Her fifth point is that new regimes should borrow from prior attempts to govern banking, platforms, and utilities — structural separations, nondiscrimination obligations, supervision — and that there is a usable history of what worked. The sequencing she insists on is that these efforts proceed alongside enforcement of existing law rather than instead of it, because “new legal regimes” is also available as a reason to wait.

Where the argument is strongest, and where it isn’t

  • Strongest: the accountability gap created by ownership. A private actor losing both standing and incentive to sue is precisely the failure mode structural remedies exist for, and it is a claim about corporate control rather than about AI capability, so it does not depend on contested predictions about how the models behave.
  • Least self-executing: every one of the five points requires an enforcer to actually bring a case. The argument is about authority, not about outcomes — “the FTC could have” is compatible with “the FTC did not,” and the political composition of the agencies is the variable her framing leaves untouched.
  • The strongest practical takeaway for builders is the least theoretical: known vulnerabilities left unfixed are not just a risk register item. She is describing them as a liability.

Khan published this on X as a five-point post; the quotations above are hers, and the underlying facts are as she states them — the FTC staff report, the Drizly action, and the Fortune 100 security-reporting analysis are linked from her post and reproduced below.