# FTC AI-exposure threshold exercise

Three fictional variants show why the threshold and reliable-evidence analysis must be documented separately.

Entirely synthetic data counts and incidents. No actual breach determination, provider response or FTC notification is represented.

Source: https://aona.ai/resources/guides/ftc-safeguards-ai-exposure-notification/
Sources checked: 2026-09-21

## Three decisions, one record

### Scope

Covered institution and customer information

### Event

Acquisition, access presumption and encryption

### Threshold

At least 500 distinct consumers

### Action

FTC notice owner and discovery-based timing

| Condition or variant | Invented facts | Decision path |
| --- | --- | --- |
| Scope check | The fictional firm is assumed FTC-covered for this exercise. | A real case must establish institutional and customer-information scope. |
| Variant A: threshold met | 620 distinct consumers; qualifying unauthorised acquisition established in the scenario. | Meets the numerical trigger; assign FTC notice as soon as possible within the 30-day outer limit. |
| Variant B: below this threshold | 420 distinct consumers; same assumed acquisition conditions. | This FTC numerical trigger is not met; investigate and assess other applicable duties. |
| Variant C: access with contrary evidence | 620 consumers; access occurred but reliable technical evidence may establish no acquisition. | Assess that evidence against the rule; do not infer an exception from a lack of known misuse. |
| Encryption check | A separate scenario involves encrypted data and an exposed decryption key. | Treat the key-access condition as part of the unencrypted-information analysis. |
| Discovery and report | Relevant employee, officer or agent discovery is recorded, excluding the person committing the breach; some scope facts remain uncertain. | Assign the owner, report known required facts when applicable and update rather than waiting for perfect certainty. |

## Review checklist

- [ ] Establish the notification-event facts
  Record authorisation, acquisition/access, encryption and key access, with the evidence supporting any exception.
- [ ] Count distinct consumers
  Reconcile the payload and duplication rather than equating rows with people.
- [ ] Assign the FTC notice process
  Record discovery, the responsible owner, deadline and updates; check other notification regimes separately.

## Included example files

- ftc-ai-notification-exercise.md
- ftc-ai-notification-exercise.csv

## Source references

- FTC: Safeguards Rule, what your business needs to know: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know (2026-09-21)
- 16 CFR 314.2: Definitions: https://www.law.cornell.edu/cfr/text/16/314.2 (2026-09-21)
- 16 CFR 314.4: Information-security programme elements: https://www.law.cornell.edu/cfr/text/16/314.4 (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
