Trust, Ethics & Regulation · established evidence
Model Disgorgement: What the FTC v. Rite Aid Settlement Actually Requires of AI Vendors
Model disgorgement is a regulatory remedy that forces a company to delete an algorithm along with the data used to build it. Its most consequential appearance to date is the FTC v. Rite Aid settlement of December 2023, the first time the Federal Trade Commission treated an artificial-intelligence system as unlawful on its own terms. The FTC alleged that Rite Aid ran facial-recognition shoplifter detection without validating its accuracy or auditing how often it falsely flagged people by race and gender, and it ordered a five-year ban on that use plus deletion of the models trained on the improperly collected biometric data. What makes the case a landmark is what the FTC did not have to prove: no false advertising claim, no deception. An unvalidated, biased system was found unfair by itself. That reframes the question for any business licensing an AI tool from a marketing claim into a duty of care.
What the FTC v. Rite Aid settlement actually ordered
On December 19, 2023, the Federal Trade Commission announced a settlement with Rite Aid over the pharmacy chain's use of facial-recognition technology for security. The FTC's account is specific. Rite Aid deployed the system across hundreds of stores to identify suspected shoplifters, generated match alerts that led staff to follow, search, and publicly accuse customers, and did so, the complaint alleged, without testing whether the technology was accurate and without tracking whether it produced false matches at different rates across race and gender.
The order that followed was unusually concrete. It imposed a five-year prohibition on Rite Aid using facial recognition for security purposes, required deletion of the images collected to build the system, and required deletion of any algorithms or models that had been trained on that data. That last requirement is the one worth naming precisely: it is model disgorgement, the deletion of the trained artifact itself, not merely the underlying records.
The unfairness prong: a violation with no false claim
Most consumer-protection enforcement against marketing rests on deception: a business said something untrue or misleading, and consumers were harmed by believing it. The Rite Aid action did not run on that theory. It was brought under the separate unfairness prong of Section 5 of the FTC Act, which reaches conduct that causes or is likely to cause substantial consumer injury that consumers cannot reasonably avoid and that is not outweighed by countervailing benefits.
The distinction is the whole point. A company can make no claim at all about an AI system, advertise nothing, promise nothing, and still be found in violation if the system harms people through undisclosed and unaudited failure. In the FTC's framing, the injury was the pattern of false accusations that fell disproportionately on some groups, injury the affected shoppers had no way to anticipate or avoid, produced by a system the operator had never validated. The unlawful act was the deployment, not a description of it.
Read against the FTC's parallel work on deceptive AI claims, the contrast is sharp. The agency's Operation AI Comply, launched in September 2024, polices businesses that overstate what their AI can do, a deception theory. Rite Aid sits in the other lane entirely: the problem was not what anyone said about the system, but that the system was put into consequential use without the diligence its potential for harm demanded.
What model disgorgement is, and why it is a severe remedy
Deleting data is a familiar penalty. Deleting a model is a different order of consequence. A trained model is where the commercial value of a data-driven system accumulates: the collection, labeling, and computation that went into it are, in effect, capitalized in the weights. Ordering its deletion strips that value and forces the work to be redone from a lawful footing, or abandoned.
The logic behind the remedy is that an organization should not be permitted to keep the benefit of an artifact built on a foundation the regulator has deemed improper. If the data underneath a model was collected or used in a way that violates the law, letting the company retain the model would let it keep the fruit of the violation. Disgorgement of the model closes that gap. For a business evaluating an AI vendor, the practical lesson is that the tool you license may itself be contingent: its continued legality can depend on how the data behind it was gathered and whether the system was validated, matters you usually cannot see from the outside.
Why an unvalidated, biased system is the risk, not a dishonest one
The Rite Aid record turns two ordinary engineering practices into legal expectations. The first is validation: measuring whether a system does what it is deployed to do before consequential decisions are made on its output. The second is disparate-impact auditing: measuring whether error rates differ across protected groups, because an aggregate accuracy figure can conceal a system that fails far more often for some people than others.
Neither of these is exotic. They are the baseline of responsible machine-learning deployment and they map directly onto recognized governance frameworks that treat measurement and monitoring as an ongoing obligation rather than a one-time sign-off. The significance of Rite Aid is that it converts what was a best practice into a floor. A system that skips validation and disparate-impact testing is not merely lower quality; in a high-stakes use it can be a legal exposure independent of any claim made about it.
The due-diligence bar this sets for any AI a business licenses
A small business rarely trains its own models. It licenses them: a chat widget on the site, a voice agent that answers the phone, a review-response assistant, a lead-routing automation, a ranking or visibility tool. Rite Aid is about a large retailer and facial recognition, but the principle it establishes travels down to that scale. If you put an AI system into consequential contact with customers, the diligence you performed on it becomes part of your own risk posture, and "the vendor set it up" is not a validation record.
Translating the case into questions a licensee can actually ask produces a compact due-diligence standard. It is not a guarantee of safety and it will not make a vendor honest, but it converts an invisible risk into a set of answerable questions before a system is trusted with real decisions.
The questions the Rite Aid standard implies
Each question below maps to something the FTC treated as missing or required in the Rite Aid matter, applied to the far smaller AI systems a local business typically runs.
- Validation: has the system been measured against real cases for whether it does what it claims, and can the vendor show that record, or is "it looked fine on day one" the only evidence?
- Disparate impact: for any system that screens, scores, prioritizes, or accuses, are error rates checked across the groups it could affect unequally, or only reported in aggregate?
- Data provenance: where did the training and reference data come from, and was it collected and used lawfully, given that an improper foundation can make the model itself a liability?
- Human firewall: when the system is wrong, what consequential action can it trigger on its own, and where must a person review before anything happens to a customer?
- Ongoing monitoring: is accuracy re-checked on a schedule and after each model change, or was it a single check at launch that says nothing about next month?
The enforcement context around the case
Rite Aid is one action inside a broader and still-forming posture. In September 2024 the FTC opened Operation AI Comply against deceptive AI claims, a deception lane distinct from the unfairness theory in Rite Aid. Named actions included a consent order against DoNotPay over its "robot lawyer" claims, finalized in February 2025, and a complaint against Evolv Technologies over claims that its AI weapons detection was near infallible, filed in November 2024.
The same record carries a caution about durability. In December 2025 the FTC reopened and set aside its own 2024 consent order against the writing tool Rytr, citing the administration's AI executive order. The facts of these actions are established; the stability of the doctrine across administrations is not. For a business, the practical takeaway is not that enforcement is guaranteed, but that the underlying standard Rite Aid articulated, validate and audit before you deploy, is sound engineering regardless of who chairs the Commission, and it is the part you control.
The generation-side risk a licensee also inherits
Rite Aid concerns a system a business runs. There is a second, structurally different AI risk a business does not run at all: the answer engines that now describe it to buyers. These systems can state confident, fluent, and false things about a business, and this is not an occasional defect. The canonical survey of the field categorizes hallucination as an intrinsic property of how generative models are trained and decoded, present across every language-generation task studied, not a bug that more data removes.
The consequence for due diligence is that vetting extends past the tools you license to the answers that represent you. The reference case for why unverified generative output cannot be treated as fact is Mata v. Avianca, in which a lawyer submitted a brief citing six fabricated precedents produced by a chatbot and was sanctioned when no court could locate them. The marketing translation is direct: an AI answer about your prices, services, or credentials can be wrong in ways that damage you, and the only defense is to measure what the engines actually say rather than assume they say something true.
What this reading does and does not establish
The core of this article is established. The Rite Aid settlement, its December 2023 date, the five-year ban, the model-disgorgement order, and its basis in the unfairness prong of Section 5 are drawn from the FTC's own announcement and independent legal analysis of the order.
Two things are deliberately not overstated. First, Rite Aid is a settlement, not a litigated appellate ruling, so it establishes the FTC's enforcement position rather than binding precedent, and the wider enforcement posture around it is politically contingent, as the Rytr reversal shows. Second, the due-diligence questions above are a framing derived from the case, not a legal safe harbor; performing them does not immunize a business, and no vendor answer should be read as a promise of safety. The value of the case is that it names a duty of care that was previously optional, and that duty is worth adopting on its own merits.
The evidence
Key findings, with their sources
-
In December 2023 the FTC ordered a five-year ban on Rite Aid's use of facial recognition for security plus model disgorgement (deletion of algorithms trained on the improperly collected biometric data), establishing that an unvalidated, biased AI system can violate Section 5 with no false claim required.
established FTC press release, "Rite Aid Banned from Using AI Facial Recognition After FTC Says Retailer Deployed Technology Without Reasonable Safeguards," Dec 19, 2023; Arnold & Porter case advisory, Jan 2024.
-
The action was brought under the unfairness prong of Section 5 of the FTC Act (15 U.S.C. §45), not a truth-in-advertising (deception) theory.
established FTC v. Rite Aid Corp., FTC Matter No. 2023190 (settled Dec 2023).
-
The FTC's Operation AI Comply, launched September 2024, opened a separate lane against deceptive AI claims (AI-washing), including a DoNotPay consent order finalized Feb 2025 and an Evolv Technologies complaint filed Nov 2024; the FTC set aside its own 2024 Rytr order in Dec 2025.
contested FTC case dockets via Benesch Law, "One Year In, FTC's Operation AI Comply Continues Under New Administration"; Lexology, "FTC retreats on Rytr."
-
Large language models hallucinate (generate fluent, confident, false content) as a structural property of how they are trained and decoded, present across summarization, dialogue, QA, data-to-text, and translation, not a bug removable with more data.
established Ji, Z., Lee, N., Frieske, R., et al., "Survey of Hallucination in Natural Language Generation," ACM Computing Surveys, 55(12), Article 248, 2023 (preprint arXiv:2202.03629).
-
A lawyer who submitted a brief citing six fabricated precedents produced by a chatbot was sanctioned when no court could locate the cases, the reference case for why unverified AI output cannot be presented as fact.
established Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y. 2023).
-
The EU AI Act's Article 50 transparency obligations become enforceable August 2, 2026, with fines up to €15M or 3% of global annual turnover, part of a wider 2026 wave of AI-disclosure law relevant to any AI system a business deploys.
established European Commission AI Act Service Desk, Article 50; Regulation (EU) 2024/1689.
Calibration
What is proven, what is promising, what is unproven
| Evidence tier | Tactics | What the evidence says |
|---|---|---|
| Established | The Rite Aid settlement facts: Dec 2023 date, five-year facial-recognition ban, model-disgorgement order, unfairness-prong basis; the structural nature of hallucination; the Mata v. Avianca sanctions. | FTC press release (Dec 19, 2023); FTC Matter No. 2023190; Arnold & Porter advisory; Ji et al. 2023; Mata v. Avianca (S.D.N.Y. 2023). |
| Emerging | The wider AI-enforcement posture (Operation AI Comply actions and the 2026 disclosure-law wave) as a direction of travel that shapes how any licensed AI system will be scrutinized. | FTC Operation AI Comply dockets, 2024-2025; EU AI Act Art. 50 (enforceable Aug 2026); analysis via Benesch Law and Lexology. |
| Contested | The durability of AI-enforcement doctrine across administrations, and whether a single settlement generalizes into a stable standard. | The Dec 2025 Rytr consent-order reversal, cited as evidence enforcement posture is politically contingent rather than a fixed floor. |
Reference
Glossary
- Model disgorgement
- A regulatory remedy requiring an organization to delete a trained algorithm or model, together with the data used to build it, so it cannot retain the benefit of a system built on an improper foundation.
- Unfairness prong (Section 5)
- The part of the FTC Act reaching conduct that causes substantial consumer injury consumers cannot reasonably avoid and that is not outweighed by benefits, independent of whether any deceptive claim was made.
- AI-washing
- Making deceptive or overstated claims about an AI system's capability or benefit. Policed as deception, a distinct theory from the unfairness basis of the Rite Aid action.
- Disparate-impact audit
- Measuring whether a system's error rates differ across protected groups, since an aggregate accuracy figure can conceal a system that fails far more often for some people than others.
- Hallucination
- A generative model producing fluent, confident content that is false or unverifiable against its source, categorized as a structural property of the technology rather than an occasional bug.
Straight answers
Frequently asked questions
What is model disgorgement?
It is a remedy that forces a company to delete a trained algorithm and the data used to build it. The FTC applied it in its December 2023 Rite Aid settlement, ordering deletion of the facial-recognition models trained on improperly collected biometric data, so the company could not keep the benefit of a system built on an improper foundation.
Why was FTC v. Rite Aid significant if there was no false advertising?
Because it was brought under the unfairness prong of Section 5 rather than the deception prong. That established that an AI system deployed without validation or bias auditing can be unlawful on its own, through the harm it causes, with no false claim required. It shifts the question from what a vendor says about a tool to whether the tool was responsibly deployed.
How does the Rite Aid case affect a small business that only licenses AI tools?
It sets a standard of care. A local business rarely trains models, but it does put licensed systems, chat widgets, voice agents, review bots, ranking tools, into consequential contact with customers. The diligence performed before trusting those systems, whether they were validated, whether error rates were checked, becomes part of the business's own risk posture, not just the vendor's.
What should I ask a vendor before trusting an AI system?
Ask for a validation record (has it been measured against real cases), a disparate-impact check for anything that screens or scores people, the provenance of the training and reference data, what consequential action the system can take without a human reviewing, and whether accuracy is re-checked on a schedule rather than only at launch. These convert an invisible risk into answerable questions.
Is this article legal advice?
No. It is an evidence-based reading of a public FTC settlement and the due-diligence framing it implies. The Rite Aid matter is a settlement rather than binding appellate precedent, enforcement posture can shift, and performing the diligence described here does not immunize any business. For decisions with legal consequence, consult qualified counsel.
Provenance
Sources
- FTC, press release, "Rite Aid Banned from Using AI Facial Recognition After FTC Says Retailer Deployed Technology Without Reasonable Safeguards," Dec 19, 2023 (established)
- FTC v. Rite Aid Corp., FTC Matter No. 2023190 (settled Dec 2023) (established)
- Arnold & Porter, case advisory on the FTC Rite Aid order, Jan 2024 (established)
- FTC Act, Section 5, 15 U.S.C. §45 (unfairness and deception prongs) (established)
- Ji, Z., Lee, N., Frieske, R., et al., "Survey of Hallucination in Natural Language Generation," ACM Computing Surveys, 55(12), Article 248, 2023, preprint arXiv:2202.03629 (established)arxiv.org
- Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y. 2023) (established)courtlistener.com
- FTC, Operation AI Comply case dockets and press materials, 2024-2025, via Benesch Law, "One Year In, FTC's Operation AI Comply Continues Under New Administration" (established facts / emerging doctrine)
- Lexology, "FTC retreats on Rytr," 2025 (contested, cited as evidence of politically contingent enforcement)
- European Commission AI Act Service Desk, Article 50; Regulation (EU) 2024/1689 (transparency obligations enforceable Aug 2, 2026) (established)
Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.