The Massachusetts Attorney General's advisory on AI, issued April 16, 2024, states that AI developers, suppliers and users must comply with the Consumer Protection Act (G.L. c. 93A, §2), the Anti-Discrimination Law (G.L. c. 151B, §4) and the data security law (G.L. c. 93H, with 201 CMR 17.00). It lists AI practices the office treats as unfair or deceptive, including falsely advertising an AI system, supplying a defective one, and making untested claims that an AI system is 'free from bias' or 'compliant with state and federal law', and it says algorithmic decision-making that relies on discriminatory inputs or produces discriminatory results violates c. 151B. It sets no new rules or deadlines, but it is the legal theory behind the Attorney General's July 2025 Earnest Operations settlement over AI underwriting, so a bank using AI in lending, fraud screening or customer chat should treat its model claims, testing and adverse-action reasons as c. 93A exposure.
OFFICIAL TEXT: mass.gov ↗ · IN FORCE · MASSACHUSETTS AG
| Document | Massachusetts AG AI Advisory (April 2024) — Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Civil Rights, and Data Privacy Laws to Artificial Intelligence |
| Issued by | Massachusetts — Office of the Attorney General (Consumer Protection Division; Consumer Protection Act G.L. c. 93A, Anti-Discrimination Law G.L. c. 151B, data security law G.L. c. 93H) |
| Type | Guidance |
| Status | In force |
| Published | Apr 16, 2024 |
| Applies to | Developers, suppliers and users of AI and algorithmic decision-making systems that deal with Massachusetts consumers, including banks, credit unions, fintech lenders and their AI vendors. The advisory creates no new obligations; it describes how existing Massachusetts statutes (G.L. c. 93A, c. 93H, c. 151B) apply, and it does not address how they apply to federally chartered institutions |
| Official source | mass.gov ↗ |
| Use cases | Credit scoring & underwriting · Fair lending & discrimination · Customer-facing chatbots · Fraud detection · Data & privacy · Third-party & vendor AI · AI governance (general) |
What are the key points of Massachusetts AG AI Advisory (April 2024)?
- Issued April 16, 2024 by Attorney General Andrea Joy Campbell to 'developers, suppliers, and users of artificial intelligence and algorithmic decision-making systems'; it defines AI using the definition in Executive Order 14110, section 3(b), and also covers generative AI.
- Chapter 93A, §2 and 940 CMR 3.00 et seq.: it is unfair or deceptive to falsely advertise the quality, value or usability of an AI system (940 CMR 3.02(2)) and to supply an AI system that is defective, unusable or impractical for the purpose advertised (940 CMR 3.02(4)(d)).
- 940 CMR 3.05(1): misrepresenting an AI system's reliability, performance, safety or condition is unfair or deceptive; the advisory's examples include claiming a system is fully automated when humans perform its functions, and untested claims that it is as accurate as a human, free from bias, not susceptible to malicious use, or compliant with state and federal law.
- 940 CMR 3.08(2): offering an AI system in breach of warranty is unfair or deceptive; the advisory's example is a system not robust enough to perform in a real-world environment as compared with a testing environment.
- 940 CMR 3.05(1) also reaches deepfakes, voice cloning and chatbots used to deceive a person into a business transaction or into giving up personal information; 940 CMR 3.16(3) and (4) make violating protective Massachusetts statutes or federal consumer-protection law, including the FTC Act, a c. 93A violation.
- G.L. c. 151B, §4: the Anti-Discrimination Law bars deploying technology that discriminates on a legally protected characteristic, including algorithmic decision-making that relies on discriminatory inputs and produces discriminatory results; violations of c. 151B may also be charged under c. 93A.
- G.L. c. 93H and 201 CMR 17.03 and 17.04: AI developers, suppliers and users must safeguard personal information used by AI systems and are expected to meet breach-notification requirements; c. 93H violations are enforceable under c. 93A (G.L. c. 93H, §6).
- Federal law: the Attorney General may enforce certain federal laws (12 U.S.C. §§5481, 5552); the advisory says ECOA adverse-action notices must give accurate and specific reasons even when AI models make the decision. The CFPB circular it cites for this point (Circular 2023-03) has since been withdrawn, but the duty is statutory (15 U.S.C. §1691(d)).
What did Massachusetts AG AI Advisory (April 2024) change for banks?
Before April 2024 Massachusetts had issued no AI-specific position, and lenders treated AI as a model-risk question under federal guidance. The advisory told the market that the Attorney General would use c. 93A, c. 151B and c. 93H against AI directly, with no new statute needed, and that marketing claims about an AI system's accuracy, fairness or legal compliance are themselves enforceable representations. Fifteen months later the same office settled with Earnest Operations LLC over AI underwriting, which shows the advisory is an enforcement roadmap rather than commentary.
What does the Massachusetts Attorney General's AI advisory require of banks and lenders?
The advisory, issued April 16, 2024, adds no new obligations; it says that Massachusetts's existing consumer-protection, anti-discrimination and data-security laws apply to artificial intelligence exactly as they apply to any other product. For a bank or lender that means five things in practice: do not overstate what an AI system can do (including claims that it is unbiased or legally compliant) without testing; make sure an AI system performs as advertised in the real world, not only in a test environment; do not deploy algorithms that rely on discriminatory inputs or produce discriminatory results under G.L. c. 151B, §4; protect the personal information AI systems use under G.L. c. 93H and 201 CMR 17.00; and give accurate, specific reasons for credit denials even when a model made the decision. The Attorney General enforces these through G.L. c. 93A, and the July 2025 Earnest Operations settlement shows the office will bring AI underwriting cases.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| G.L. c. 93A, §2 and 940 CMR 3.02(2) — False advertising of AI | Massachusetts AG | Do not falsely advertise the quality, value or usability of an AI system, for example by claiming functionality it does not have. | In force; advisory issued April 16, 2024 |
| 940 CMR 3.02(4)(d) — Defective or impractical AI | Massachusetts AG | Do not supply an AI system that is defective, unusable or impractical for the purpose advertised; suppliers must ensure the system performs as intended. | In force; advisory issued April 16, 2024 |
| 940 CMR 3.05(1) — Misrepresenting AI reliability | Massachusetts AG | Do not misrepresent an AI system's reliability, performance or safety, including untested claims that it is bias-free, as accurate as a human, or compliant with state and federal law. | In force; advisory issued April 16, 2024 |
| 940 CMR 3.08(2) — Breach of warranty | Massachusetts AG | Do not offer an AI system that is not fit for its ordinary or known purpose, such as one not robust enough to perform in a real-world environment as compared with testing. | In force; advisory issued April 16, 2024 |
| G.L. c. 151B, §4 — Anti-discrimination | Massachusetts AG | Do not deploy AI or algorithmic decision-making that relies on discriminatory inputs or produces discriminatory results against residents on a protected characteristic. | In force; advisory issued April 16, 2024 |
| G.L. c. 93H and 201 CMR 17.03–17.04 — Data security | Massachusetts AG | Safeguard personal information used by AI systems and meet breach-notification requirements; violations are enforceable under c. 93A (c. 93H, §6). | In force; advisory issued April 16, 2024 |
| ECOA adverse-action notices (15 U.S.C. §1691(d); 12 U.S.C. §§5481, 5552) | Massachusetts AG | Give consumers accurate and specific reasons for credit denials, including when an AI model made the decision; the Attorney General may enforce this federal requirement. | In force; advisory issued April 16, 2024 |
The advisory is deliberately framed as an application of settled law. It reminds the market that the Attorney General's consumer-protection regulations (940 CMR 3.00 and 5.00) already define product and service broadly, so an AI system sold to or used on consumers is within them, and that the 'novelty, complexity and claimed inscrutability' of AI does not take it outside c. 93A. Its list of unfair or deceptive practices is expressly non-exhaustive, and the office says it expects to amend or expand the advisory as the technology and the governing laws evolve.
For banks the most consequential passages are the ones on representations and on discrimination. A lender that tells customers, regulators or counterparties that a model is fair, accurate or compliant must be able to substantiate the claim, because an untested assertion is itself treated as a misrepresentation. And because c. 151B reaches practices that are 'fair in form, but discriminatory in operation', disparate-impact exposure does not depend on intent. The July 2025 Earnest settlement applied both ideas, alleging that the lender failed to test its models for disparate impact and sent inaccurate adverse-action notices, and it is covered in the Earnest Operations document.
The advisory sits alongside federal expectations rather than replacing them. A national bank or federal savings association answers first to its prudential regulator, and the advisory does not analyse preemption; state-chartered banks, licensed lenders and non-bank fintechs have the most direct exposure. Banks that buy AI from vendors should note that the advisory addresses suppliers as well as users, so contractual allocation of responsibility does not remove the bank's own c. 93A exposure as the user.
WHAT THIS MEANS IN PRACTICE
- Inventory every marketing, disclosure and vendor-contract statement about an AI system's accuracy, fairness, automation or legal compliance, and keep substantiation for each.
- Test models in conditions that resemble production before launch and monitor them afterwards, since the advisory treats real-world underperformance as a potential warranty and c. 93A problem.
- Run disparate-impact testing on credit models and the variables that drive them, and document the search for less discriminatory alternatives.
- Check that adverse-action notices name the actual principal reasons a model produced, not the nearest item on a drop-down list.
- Confirm AI systems that touch Massachusetts residents' personal information are covered by the written information security program required by 201 CMR 17.00.
Does the Massachusetts AG's AI advisory apply to banks?
It applies to any developer, supplier or user of AI that deals with Massachusetts consumers, which includes banks, credit unions and fintech lenders. It does not discuss how Massachusetts law applies to federally chartered institutions, so preemption questions are separate. Non-bank lenders such as the one in the 2025 Earnest settlement are squarely within reach.
Is the Massachusetts AG's AI advisory binding?
The advisory itself creates no new legal duties; it states the Attorney General's view of how existing law applies. The statutes it relies on (G.L. c. 93A, c. 93H, c. 151B) and the Attorney General's regulations in 940 CMR are binding, and the Attorney General has said her office intends to enforce them against AI.
What are the penalties under the Massachusetts AI advisory?
The advisory does not set penalties. It says violations of c. 93H and c. 151B can give rise to liability under c. 93A, and c. 93A remedies are enforced by the Attorney General. In July 2025 the office reached a $2.5 million settlement with Earnest Operations LLC on this theory.
How does the Massachusetts AI advisory compare with the Colorado AI Act?
Colorado's statute imposes AI-specific duties such as impact assessments and consumer notices; Massachusetts imposes none. The Massachusetts advisory instead says existing consumer-protection, anti-discrimination and data-security law applies to AI and will be enforced case by case.
| Date | Document | Status |
|---|---|---|
| Jul 10, 2025 | Massachusetts AG Earnest Operations settlement (July 2025) — Assurance of Discontinuance: In the matter of Earnest Operations LLC (Massachusetts Attorney General, announced July 10, 2025) | In force |
| Aug 11, 2026 | Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) | Comment period open |
| Jul 24, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | In force |
| Jun 24, 2026 | RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) | Proposed |
| May 19, 2026 | Draft Commission guidelines on high-risk classification — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act | Proposed |
| May 14, 2026 | SB 26-189 — Automated Decision-Making Technology Act (repeal and reenactment of the Colorado AI Act) | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning