Feature AI Risk
The FTC Just Put AI Pricing on Notice. What the Personalized Pricing Statement Means for Your Fintech.
On August 19, 2026, the FTC proposed an enforcement policy on personalized pricing — using AI and consumer data to set individualized prices. The comment deadline is September 18. Here's what the financial services exception means, where the line blurs with AI, and what your compliance program needs to document.
Table of Contents
TL;DR
- On August 19, 2026, the FTC proposed an enforcement policy stating that undisclosed personalized pricing — using consumer data to price for individual willingness to pay — may violate Section 5 of the FTC Act.
- Insurance and credit have a carve-out because pricing is inherently individualized. But fintech AI pricing that mixes risk signals with behavioral data may not qualify.
- The proposed enforcement framework requires three disclosures: whether the price is personalized, why, and what data was used.
- Comment deadline is September 18, 2026. If you’re in fintech pricing, this is your policy-shaping moment.
AI-driven pricing has been the compliance industry’s “we’ll deal with it when it matters” problem for years. The FTC just decided it matters.
On August 19, 2026, the Federal Trade Commission published a proposed enforcement policy statement on “personalized pricing” — the practice of using consumer data to set prices based on what a company believes an individual is willing to pay. The statement articulates for the first time how existing FTC Act authority applies to this practice, what disclosures businesses must make, and what conduct the agency considers deceptive or unfair.
The statement is out for public comment through September 18, 2026. But compliance teams shouldn’t be waiting for it to finalize. The FTC isn’t creating new authority — it’s describing how it intends to apply authority it already has. And for fintechs using AI to optimize fees, rates, or service pricing, the analysis of where you sit relative to this framework needs to start now.
What the FTC Means by “Personalized Pricing”
The proposed statement defines personalized pricing as the use of personal data — browsing history, location data, demographic information, purchasing patterns, or other individual signals — to set prices based on an individual consumer’s estimated willingness to pay or likelihood of comparison shopping.
The definition distinguishes two things: prices that vary by individual consumer based on their behavioral or attitudinal signals (personalized pricing), and prices that vary because the product itself reflects individual risk characteristics (actuarial or credit pricing). The first is what the FTC is targeting. The second is what financial services relies on.
The statement explicitly acknowledges: “Insurance and credit, for example, necessarily involve individualized characteristics because the price reflects the risk associated with a particular consumer.” That’s the financial services carve-out. But it comes with an unstated assumption: that the individualized price reflects risk, not a model’s estimate of how much the consumer will tolerate before abandoning the transaction.
Where the Carve-Out Gets Complicated
The financial services carve-out sounds clean. Credit pricing reflects credit risk. Insurance pricing reflects actuarial risk. Price variation is therefore inherent, not deceptive.
Here’s where fintech AI is making that boundary messier.
Modern pricing models in fintech — for personal loans, BNPL installment fees, crypto trading spreads, insurance premiums, and savings account APYs — don’t just look at credit risk signals. They look at behavioral signals. How long a user spent on the app before applying. Whether they came through a high-urgency marketing channel. Whether they’ve comparison-shopped before or tend to accept the first offer presented. Whether their browsing history suggests they’re in a time-sensitive financial situation.
When behavioral signals inform a pricing model alongside risk signals, the pricing output may still correlate with creditworthiness — but the model is also pricing for capture probability, not just risk. That is not actuarial pricing. That is personalized pricing dressed in actuarial clothing.
The FTC’s framework doesn’t require intent to deceive. It looks at what the price reflects. If your model weights behavioral willingness-to-pay signals, the financial services carve-out may not protect you.
The Three Disclosures the FTC Expects
The proposed statement identifies three things businesses need to disclose when they use personalized pricing:
1. Whether the price is personalized. A business cannot represent or imply that a price is generally available, static, or based on universal criteria when in fact it varies by individual consumer based on their data profile.
2. Why the price is personalized. Consumers should understand the basis on which their price differs from what another consumer might see.
3. What data was used. The collection or use of personal data for pricing purposes without adequate disclosure of that data use is itself potentially unfair under Section 5.
These disclosure requirements don’t require you to publish your model weights. They require you to give consumers an honest account of the fact that their data was used to set their price and what category of data was involved.
For most fintech pricing disclosures — which say something like “your rate is based on your creditworthiness” — this is likely inadequate if behavioral signals are also in the model. “Creditworthiness” implies credit risk factors. It doesn’t cover session duration, device type, referral channel, or past purchase behavior.
The ECOA Connection: Fair Lending Risk Is Already There
The FTC’s personalized pricing concern and ECOA’s disparate impact prohibition are not the same framework, but they often implicate the same data.
Behavioral signals used to estimate willingness to pay can correlate with protected class status — race, national origin, sex, age, familial status, and receipt of public assistance. When a pricing model uses signals that correlate with those characteristics, it can produce different rates for similarly-situated consumers who differ along protected class lines. That’s ECOA disparate impact exposure, entirely separate from FTC Section 5.
As we’ve written before on AI bias testing for fair lending, the compliance test for AI pricing models isn’t just “are we using a protected class variable?” It’s “do our outputs produce statistically significant differences across protected class groups?” If your AI pricing model produces that result — even without intent — you have both ECOA exposure and, depending on model design, potential FTC exposure.
The FTC statement reinforces the need for the same governance work that ECOA compliance requires: model documentation, input variable audits, output testing, and disclosure review. For fintech AI governance programs, the personalized pricing policy adds another pillar to the same analytical framework.
What “Personalized Pricing” Looks Like in Fintech, Specifically
Let’s make this concrete. Here are fintech pricing practices that may fall in or near the enforcement zone:
Loan pricing that weights session urgency signals. If a model assigns higher rates to users who came through a “need cash fast” landing page or who have a short session before applying, the rate reflects urgency signaling, not credit risk. That’s a behavioral willingness-to-pay signal.
BNPL fee structures that vary by merchant channel. If a BNPL product charges higher installment fees on luxury retail channels vs. pharmacy channels — because luxury shoppers are estimated to have higher price tolerance — that’s not a credit risk differential. That’s personalized pricing by consumer segment.
Insurance premium models that include behavioral data. Telematics and usage-based insurance are generally within the actuarial carve-out because driving behavior is the risk being priced. But if the model also uses data about how a consumer shops for insurance — urgency, comparison behavior, prior acceptance rates — the carve-out application becomes less clear.
Savings rate offers optimized for stickiness, not risk. If a fintech’s savings product offers lower APYs to consumers the model predicts are less likely to comparison-shop, that’s not pricing for risk. That’s pricing for capture probability. The FTC’s framework would likely treat this as personalized pricing.
The Comment Window: Should You File?
The FTC is accepting public comments through September 18, 2026. For fintech companies whose pricing models touch any of these issues, filing a comment is worth considering for two reasons.
First, the financial services carve-out is underspecified. The proposed statement says credit and insurance pricing is inherently individualized, but doesn’t define where the line is between actuarial pricing and behavioral personalization. The comment period is the opportunity to argue for a more precise carve-out that protects risk-based pricing without exposing legitimate credit models to enforcement risk.
Second, the disclosure requirements as currently framed are ambiguous in their application to complex multi-variable models. Comments can push for clearer guidance on what disclosures satisfy the framework — rather than letting the ambiguity become enforcement fodder later.
So What? What Fintech AI Teams Need to Do Now
Inventory your pricing models. List every model that produces a consumer-facing price, rate, or fee. For each, identify the input variables and categorize them: risk signals, behavioral signals, or both.
Determine whether the financial services carve-out applies. For each model, ask honestly: are the behavioral signals in this model pricing for risk, or pricing for willingness to pay? If it’s the latter, the carve-out may not apply and you need disclosure remediation and potentially model redesign.
Audit your pricing disclosures. For every consumer-facing disclosure of how prices are set, verify that the disclosure accurately describes what the model actually does. “Based on your creditworthiness” is not accurate if behavioral signals are material to the output.
Run a disparate impact analysis. Across all pricing outputs, test for statistically significant rate or fee differences along protected class lines. This is ECOA compliance work that also addresses the FTC exposure.
Document the governance record. For each pricing model, create a documentation file that records input variables, model purpose, output testing results, and disclosure accuracy review. This is the paper trail that distinguishes a compliant program from a target.
The AI Risk Assessment Template is built for exactly this kind of AI governance documentation — model inventory, pre-deployment scorecard, and vendor questionnaire for third-party AI pricing tools. The 44-question scorecard covers model purpose, bias testing, explainability, and regulatory touchpoint — the same questions you’d need to answer in an FTC examination.
The Comment Deadline Is September 18
If you want to influence how this policy develops — including the scope of the financial services carve-out and the specificity of required disclosures — September 18, 2026 is the window. The FTC has signaled it intends to enforce regardless of whether the policy finalizes. The comment period is your input into how enforcement gets applied.
Sources
- FTC press release: Seeks comment on enforcement policy statement regarding personalized pricing
- FTC proposed policy statement (PDF)
- Consumer Finance Monitor: FTC proposes enforcement policy on personalized pricing
- Holland & Knight: FTC proposes enforcement policy statement on personalized pricing
- King & Spalding: FTC proposes enforcement framework for personalized pricing
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the FTC's personalized pricing statement apply to insurance and credit pricing?
Does the ECOA bar personalized pricing in credit?
What disclosures does the FTC expect?
What is the comment deadline?
Does this apply to dynamic pricing that changes by time of day or location rather than consumer data?
What should a fintech AI pricing team document?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026
AI Risk
The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.
The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.
Sep 5, 2026