
The way most e-commerce pricing compliance programs are built, they're designed to solve one legal problem. The FTC proved in 2025 there are two — and collected $2.56 billion across two separate enforcement theories in the same calendar year.
This isn't a nuance. Instacart's $60 million settlement and Amazon's $2.5 billion settlement were pursued on entirely different legal grounds against entirely different kinds of algorithmic behavior. Instacart's algorithm varied prices across users in ways that correlated with protected-class proxies. Amazon's algorithm predicted competitor behavior to extract supra-competitive pricing gains. Your pricing engine — whether you built it, bought it, or licensed it from a third-party vendor — likely has exposure on both tracks.
That's the problem our AI Pricing Compliance & Algorithmic Fairness work is designed to close.
How Input Diversity Becomes Output Discrimination

The Instacart case is the clearest articulation yet of the proxy variable trap. The Eversight pricing tool — which Instacart licensed and deployed — generated up to five different prices for the same item at the same store, with variation reaching 23% across users. The FTC's December 2025 $60 million settlement didn't require evidence of intentional discrimination. It required evidence of discriminatory outcomes. Seventy-five percent of Instacart's catalog was subject to algorithmic price variation. The average basket discrepancy across users ran to 7%. The FTC's theory was outcome-based, not intent-based — which is why the settlement landed.
The technical mechanism behind this matters for every pricing team, not just Instacart's. Your algorithm doesn't see race, income, or protected demographic status. But it sees ZIP code. Device type. App version. Session time. Browsing cadence.
When we run a ZCTA-to-demographic correlation analysis — cross-tabulating pricing-input clusters against Census ACS data for the same geographic units — those individually innocuous variables correlate with racial and income demographics at rates that would fail disparate-impact analysis. A user browsing on an older Android device from a lower-income ZIP code at 11 PM is in a different pricing cohort than an iPhone user in a high-income suburb at 2 PM. The algorithm created that cohort through optimization. Census data reveals who it captured.
The Instacart settlement established that proxy discrimination in pricing doesn't require intent. It requires correlation between your inputs and a protected-class outcome — and most pricing algorithms have never been tested for it.
This is the first compliance gap most teams surface when we run a disparate-impact regression against their pricing log data.
Where the Collusion Risk Actually Lives: Vendor Data Pooling and the RealPage Standard

Amazon's Project Nessie extracted $1.4 billion in excess profits by predicting competitor price-matching behavior. The algorithm identified that most competitors operated on tit-for-tat pricing rules. When Amazon raised prices on items — 8 million items across the catalog — competitors' algorithms followed automatically. No meeting, no agreement, no phone call. Just two algorithms reaching the same supra-competitive equilibrium. The FTC's September 2025 $2.5 billion settlement is a separate proceeding from the ongoing FTC v. Amazon antitrust trial (set for trial October 2026), which will test whether this kind of predictive pricing coordination constitutes a violation of Section 5 of the FTC Act. The trial outcome will define the enforcement standard for an entire generation of AI pricing systems.
The RealPage consent decree, issued by the DOJ in November 2025, did something more consequential than settle a case. It introduced a technical standard for algorithmic pricing systems operating in markets with shared vendor relationships. The decree's prohibitions are written as engineering requirements: no training on active lease data younger than 12 months, no geographic analysis narrower than state level, governor guardrails on pricing recommendations must be symmetric — floors and ceilings equally adjustable by the client. Auto-accept functions require user-set parameters rather than algorithm-defaults.
Most SaaS pricing platforms fail the governor-guardrails requirement by default. The ceiling is typically configurable by the client. The floor adjustment is often algorithm-controlled or locked. That asymmetry is now the subject of an active DOJ consent decree with a 180-day implementation deadline and a seven-year monitoring term.
The vendor-relationship exposure is where the liability surface extends beyond what most legal teams have mapped. California's Cartwright Act amendments — AB 325 and SB 763, effective January 1, 2026 — codify what the FTC has been pursuing on antitrust grounds: a "common algorithm" is one used by two or more market participants that incorporates competitor information to influence prices. If your pricing vendor serves your competitors and pools non-public data across clients, you may have hub-and-spoke conspiracy exposure under California law even if you have never exchanged a word with a competitor.
Gibson v. Cendyn (Ninth Circuit, August 2025) created a three-part safe harbor for pricing vendor relationships. It only applies if you documented the vendor diligence before a Civil Investigative Demand arrived, not after.
The three-part test from Gibson is now the checklist our team uses when evaluating any third-party pricing tool: does the vendor pool competitively sensitive non-public data across clients? Does the vendor market its ability to raise prices industry-wide? Does the tool facilitate exchange of non-anonymized competitor data? The FTC's 2024 6(b) surveillance pricing study — which sent orders to eight firms including Mastercard, Revionics, Bloomreach, PROS, and Accenture — shows that regulators already know which vendors to look at when they're building a case. If your pricing stack touches any of those names, your vendor diligence documentation is what separates a defensible relationship from an unexplained one when CID questions arrive.
The Regulatory Map Your Legal Team Is Actually Navigating

The regulatory landscape in 2026 doesn't reduce to a single compliance framework because there isn't one. There are concurrent state, federal, and international regimes with different requirements, different enforcement timelines, and different penalty structures.
New York's Algorithmic Pricing Disclosure Act (effective November 10, 2025) requires clear and conspicuous disclosure when prices use personal consumer data, with civil penalties of up to $1,000 per violation. The NRF challenged the law on First Amendment grounds in July 2025; enforcement is currently paused pending a preliminary injunction ruling. The pause creates false comfort for teams that aren't building the disclosure infrastructure anyway — the NRF case is about whether the disclosure requirement is constitutional, not about whether personalized pricing creates legal risk.
California's Cartwright Act amendments create more acute exposure. The lowered pleading standard means plaintiffs no longer need to exclude independent action at the motion-to-dismiss stage — which is where most algorithmic collusion cases historically died. Corporate fines cap at the greater of $6 million or 2x pecuniary gain or loss. Individual executives face up to $1 million per violation. Treble damages and attorney's fees apply in private litigation.
Colorado's AI Act (SB 24-205, effective June 30, 2026) requires impact assessments for high-risk AI systems making consequential decisions, explicitly including pricing decisions that affect consumers. The assessment must document purpose, algorithmic discrimination risks, data categories used, and mitigation steps. Fifty-one proposed bills across 24 states in 2025 means this legislative surface will expand, not contract, over the next 18 months. Tennessee and New Mexico both introduced bills in 2026 sessions. The EU AI Act's high-risk provisions become applicable August 2, 2026, with penalties reaching €35 million or 7% of global turnover for prohibited practices.
What's notable across all of these regimes is that the documentation requirement is the compliance requirement. Colorado's impact assessment, California's common-algorithm evidence standard, New York's disclosure obligation, and the RealPage consent decree's audit-logging mandate all share the same underlying ask: prove what your algorithm does, with records, before a regulator asks.
What the Architecture Actually Requires

The gap our AI Pricing Compliance & Algorithmic Fairness work addresses is structural: no existing vendor category delivers an integrated compliance layer across both enforcement tracks. Pricing platforms like Pricefx, PROS, Zilliant, and Competera optimize prices — and several appeared in the FTC's 6(b) study orders alongside Revionics, Dynamic Yield, Accenture, and McKinsey. None include disparate-impact testing, disclosure automation, or collusion risk monitoring. That's not a product gap they're racing to close; it's a scope boundary. Compliance is the client's responsibility. Law firms publish the best design guidelines available — Wilson Sonsini's antitrust advisories and Duane Morris' Cartwright Act guidance are the practitioner standard — and economic consultants like FTI Consulting provide expert witness analysis for active litigation. None of that infrastructure provides automated monitoring for the pricing decisions your engine makes every hour.
The technical architecture that closes both tracks starts with the gap that produced the Instacart settlement shape: demographic impact analysis on historical pricing outputs, cross-tabulated against Census ZCTA data. Without that analysis, you don't know whether your pricing cohorts correlate with protected-class proxies — and you can't document that they don't. The second gap is the vendor-relationship one the RealPage decree defines: governor-guardrail symmetry audits against the DOJ consent decree standard, and data-pooling documentation for each third-party tool your pricing stack touches. Disclosure automation handles the multi-jurisdiction requirement across NY, CA, CO, and the EU — built as an extensible framework, because 51 bills in 24 states means custom-engineered jurisdiction-by-jurisdiction solutions are already obsolete. The audit-trail layer is what FTC CID readiness actually requires: not just that the compliance analysis ran, but production-standard documentation of when it ran, what it covered, and what it found.
The first-year cost of implementing a compliance program of this scope runs $100,000 to $505,000 depending on the complexity of the pricing stack. The math is straightforward: the Instacart settlement was $60 million and the Amazon settlement was $2.5 billion.
The Next Problem: Autonomous Pricing That No Current Framework Covers

The compliance frameworks above were designed for pricing systems that have a human review step somewhere in the loop. The next compliance frontier doesn't.
Walmart is deploying digital shelf labels to 5,200 stores by end of 2026. Two patents filed in January 2026 — an automated markdown system and a demand forecasting module — describe pricing decisions made at the pace of inventory data, not human review. Walmart's public positioning carefully frames this as "algorithmic merchandising" with prices "consistent regardless of demand, time of day, or who is shopping." That framing is deliberate, and the regulatory exposure is visible in it.
Forrester projects that one in five sellers will respond to AI buyer agents with seller-controlled pricing counter-agents by 2027. When a buyer's AI agent negotiates with a seller's pricing agent, no regulatory framework currently addresses who is liable if the agreed price is discriminatory or collusive. The compliance obligation that applies to that transaction will be defined by litigation before it's defined by statute.
Companies building pricing compliance architecture now — under the 2025-2026 enforcement precedents — will have documentation that maps to whatever framework emerges for autonomous pricing. Companies that wait will be building documentation after CIDs arrive.
We're still watching how the NRF v. NY AG injunction resolves and what FTC v. Amazon establishes at trial in October 2026. Those two outcomes will set the enforcement precedents that the next five years of algorithmic pricing litigation will follow. If your team is navigating the compliance architecture questions for the first time or rebuilding after the California Cartwright Act amendments changed your exposure picture, we'd genuinely welcome a conversation — the problems here cross company lines, and the compliance architectures that actually work tend to travel fast once a reference design exists.