
My first instinct when we started building pricing compliance tooling was that the legal test would be about intent. Did the algorithm mean to charge different prices to different users based on protected characteristics? That's the intuitive question, and it's wrong.
The Instacart FTC complaint, which led to a $60 million settlement in December 2025, made the correction viscerally clear. The Eversight pricing tool generated up to five different prices for the same item at the same store. Variation reached 23% across users. Seventy-five percent of Instacart's catalog was subject to algorithmic variation — creating an average basket discrepancy of 7% across users. The FTC didn't argue that anyone at Instacart intended to discriminate against protected groups. The settlement hinged on the outcome: consumers in certain profiles paid systematically more. The algorithm never intended anything. The output was discriminatory anyway.
I threw out most of what we'd built for the intent-based framework. Everything we'd designed to catch bias in the algorithm's training data or its objective function — all of that was looking at the wrong place. The FTC looks at the output distribution. The question is whether the users your algorithm put in different pricing cohorts correlate with protected-class demographics. And the answer, for most personalized pricing systems, is yes — because the inputs that make pricing optimization work (ZIP code, device type, session time, browsing cadence) are proxy variables that Census ZCTA data shows track racial and income demographics at correlation rates that would fail disparate-impact analysis.
We built our AI Pricing Compliance & Algorithmic Fairness solution around this correction. The first thing we run on a pricing system now isn't a training-data audit. It's a ZCTA-to-demographic correlation analysis on the system's historical output.
The Vendor Contract That Said Nothing

A few months after we shipped the first version, I was walking a GC through what the Gibson v. Cendyn decision meant for her company's third-party pricing relationship. The Ninth Circuit ruled in August 2025 on the first federal appellate algorithmic pricing antitrust case. The practical outcome was a three-part safe harbor: independently subscribing to the same pricing algorithm as a competitor is not per se anticompetitive, as long as (a) the algorithm doesn't pool competitively sensitive non-public data across clients, (b) the vendor doesn't market its ability to raise prices industry-wide, and (c) the tool doesn't facilitate exchange of non-anonymized competitor data.
She pulled out her vendor contract mid-conversation to check whether any of those three conditions were addressed. The contract said nothing about data pooling. Nothing about whether the pricing tool shared pricing behavior signals across subscribers. When I explained that California's Cartwright Act amendments — AB 325 and SB 763, which took effect January 1, 2026 — codified exactly this as a "common algorithm" liability trigger, and that under those amendments the pleading standard no longer required plaintiffs to exclude independent action at the motion-to-dismiss stage, she called the vendor before I got back to my car.
That conversation is now how I explain the vendor-relationship exposure. The risk isn't that you colluded. The risk is that your pricing vendor did something that creates hub-and-spoke conspiracy exposure, and your contract doesn't document the diligence that would give you a Gibson safe harbor. The FTC's 2024 6(b) surveillance pricing study sent orders to eight firms — Mastercard, Revionics, Bloomreach, JPMorgan Chase, Task Software, PROS, Accenture, McKinsey — which means regulators already have a working map of which vendors to look at when building a case. If your pricing stack touches those names, your vendor diligence documentation is what separates a defensible relationship from an unexplained one.
The Amendment I Kept Rereading

I want to be honest about the finding that concerned me most when I read through the California Cartwright Act amendments. It wasn't the $6 million corporate fine ceiling, though that's serious. It was the sentence about pleading standards.
Before AB 325 and SB 763, algorithmic collusion cases routinely died at the motion-to-dismiss stage because plaintiffs couldn't exclude the possibility of independent action — companies could argue their algorithms arrived at similar prices independently, without coordination. The California amendments explicitly remove that requirement at MTD. A plaintiff now only needs to plead facts plausibly suggesting coordination; the defendant has to disprove independence at summary judgment or trial.
What that means in practice is that discovery becomes the threat. Pricing teams get destroyed in discovery even when they ultimately prevail — producing millions of rows of pricing logs, explaining every algorithm parameter, defending every governor-guardrail setting to opposing experts who are looking for the asymmetry the RealPage consent decree defined. The RealPage consent decree (DOJ, November 2025) is now the technical standard: governor guardrails must be symmetric — floors and ceilings equally adjustable by the client — and no geographic analysis can be narrower than state level. Most SaaS pricing platforms fail the floor-adjustment test by default. The ceiling is configurable; the floor is often locked or algorithm-controlled. That asymmetry is in an active seven-year consent decree.
The individual executive exposure under the California amendments adds a layer I didn't fully appreciate until I mapped it out: up to $1 million per violation for individual officers, not just the company. That's what brings this from a legal department problem to a board-level conversation.
The Thing Amazon's Project Nessie Made Clear

I kept coming back to Amazon's Project Nessie while we were building the collusion detection layer. The FTC's September 2025 $2.5 billion settlement described an algorithm that identified that most competitors ran tit-for-tat pricing rules, then raised prices on 8 million items to induce competitors to follow. No meetings. No agreements. Just predictive modeling of competitor behavior that generated $1.4 billion in excess profits before Amazon turned the system off. The FTC's ongoing antitrust trial — FTC v. Amazon, set for October 2026 — will establish whether this constitutes a Section 5 violation, which will be the definitive precedent for the next generation of pricing AI.
What strikes me about Project Nessie isn't the scale. It's that the collusion was emergent — nobody designed the algorithm to collude. It found a pattern (competitors match our prices when we raise them) and exploited it. Most modern pricing systems are running some version of this analysis, scaled down. The question is whether yours is doing it with competitor data that your vendor relationship makes available to you through data pooling — which takes you from emergent optimization into something that looks a lot like the hub-and-spoke theory the California Cartwright Act amendments now make easier to plead.
What I'm Still Working Through

The part of this problem I'm least confident we've solved is autonomous pricing — and not because we haven't thought about it. It's because nobody has.
Walmart is deploying digital shelf labels to 5,200 stores by end of 2026. Two patents filed in January 2026 describe automated markdown systems and demand forecasting modules that make pricing decisions at the pace of inventory data, not human review. The public positioning is careful — Walmart's messaging says prices are "consistent regardless of demand, time of day, or who is shopping." That phrasing is doing legal work. Forrester projects that one in five sellers will have seller-controlled pricing counter-agents operating against AI buyer agents by 2027. When two AI agents negotiate a price, the compliance frameworks built for human-reviewed pricing decisions don't map cleanly. Who documents the impact assessment for a negotiation two AI agents completed faster than any human could review it?
I don't have a clean answer to that. The compliance architecture we've built at AI Pricing Compliance & Algorithmic Fairness handles the 2025-2026 enforcement surface well — the disparate-impact regression, the vendor diligence checklist, the governor-guardrail audit, the multi-jurisdiction disclosure automation for NY, CA, CO, and the EU. But the agentic pricing layer is going to require a different architecture, and I suspect the compliance standard for it will be defined by the first settlement that involves two AI agents, not by a statute.
The NRF's First Amendment challenge to New York's Algorithmic Pricing Disclosure Act is still working through the courts. The FTC v. Amazon trial will land in late 2026. Those two outcomes will set the practical compliance standard for the next several years. I'm watching both of them very carefully. If you're navigating the same question — particularly if you're running a third-party pricing tool and you're not sure what your vendor contract actually commits them to around data pooling — I'd genuinely welcome a conversation about what we've learned so far.