# FTC AI-exposure threshold exercise

Entirely synthetic data counts and incidents. No actual breach determination, provider response or FTC notification is represented.

Three fictional variants show why the threshold and reliable-evidence analysis must be documented separately.

| Condition or variant | Invented facts | Decision path |
| --- | --- | --- |
| Scope check | The fictional firm is assumed FTC-covered for this exercise. | A real case must establish institutional and customer-information scope. |
| Variant A: threshold met | 620 distinct consumers; qualifying unauthorised acquisition established in the scenario. | Meets the numerical trigger; assign FTC notice as soon as possible within the 30-day outer limit. |
| Variant B: below this threshold | 420 distinct consumers; same assumed acquisition conditions. | This FTC numerical trigger is not met; investigate and assess other applicable duties. |
| Variant C: access with contrary evidence | 620 consumers; access occurred but reliable technical evidence may establish no acquisition. | Assess that evidence against the rule; do not infer an exception from a lack of known misuse. |
| Encryption check | A separate scenario involves encrypted data and an exposed decryption key. | Treat the key-access condition as part of the unencrypted-information analysis. |
| Discovery and report | Relevant employee, officer or agent discovery is recorded, excluding the person committing the breach; some scope facts remain uncertain. | Assign the owner, report known required facts when applicable and update rather than waiting for perfect certainty. |

## Review steps

- Establish the notification-event facts: Record authorisation, acquisition/access, encryption and key access, with the evidence supporting any exception.
- Count distinct consumers: Reconcile the payload and duplication rather than equating rows with people.
- Assign the FTC notice process: Record discovery, the responsible owner, deadline and updates; check other notification regimes separately.

## Synthetic count reconciliation

File rows: 800
Distinct invented consumers: 620
Duplicate rows: 180
Scenario A acquisition: assumed established for teaching
Scenario A numerical finding: at least 500 consumers

## Case record fields

Record the institution and scope, discovery evidence, data types, distinct consumer count, acquisition/encryption findings, reliable contrary evidence if any, notification owner, known facts submitted and subsequent updates.

No notice is generated or sent by this worksheet.

## Source and scope

Guide: https://aona.ai/resources/guides/ftc-safeguards-ai-exposure-notification/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- FTC: Safeguards Rule, what your business needs to know: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
- 16 CFR 314.2: Definitions: https://www.law.cornell.edu/cfr/text/16/314.2
- 16 CFR 314.4: Information-security programme elements: https://www.law.cornell.edu/cfr/text/16/314.4
