NormalNormal

The FTC Safeguards Rule and AI at your dealership: questions before you connect anything

The FTC Safeguards Rule and AI at your dealership: questions before you connect anything

Short answer: the Safeguards Rule treats your customers' information as something you're legally responsible for protecting. AI tools that connect to your DMS and CRM are exactly the kind of vendors the Rule makes you vet. Here's what to ask — and the deployment option where customer data never leaves your building.

Dealers don't need a compliance lecture. You've done the written information security plan, the risk assessment, the access controls. What's new is the wave of AI vendors knocking: agents that answer service calls, tools that mine your data, platforms that "integrate with your DMS." Every one of them wants access to nonpublic personal information — names, addresses, financial details — and the Rule makes their access your problem.

What the Rule expects from you here

The Rule's logic is simple and applies directly: you designate someone accountable, you assess the risk of every vendor that touches customer information, you control access, and you have a plan for when things go wrong. An AI vendor connecting to your DMS is a service provider under that framework. Practically:

  • Vendor risk assessment — you need to know where data goes, who handles it, and what their safeguards are. In writing.
  • Access limitation — the tool should read only what its job requires, not everything.
  • Encryption in transit and at rest — standard for anything touching NPI.
  • An exit plan — what happens to customer data when the relationship ends.

The questions that sort vendors fast

  1. Where is our data stored and processed — which systems, which countries, which subprocessors? In writing, not a sales deck.
  2. Is our data used to train AI models? The only acceptable answer is no, contractually.
  3. Who reviews what it sends to customers? (A tool that messages customers autonomously is both a Safeguards concern and a brand problem.)
  4. Can it run on hardware at our store? This is the question almost nobody asks, because almost nobody offers it. On-premises deployment — your data stored and the AI running on equipment at your dealership — shrinks the vendor-risk problem dramatically, because the vendor stops being in the data's path at all.
  5. What's the offboarding? Data returns to you, deletions are documented, access ends cleanly.

If a vendor's answers live in marketing language instead of specifics, file that under "risk identified."

The failure mode the Rule can't fix

Compliance keeps you legal. It doesn't stop the AI from promising a customer a Friday delivery the shop can't deliver, or texting a loyalty customer like a stranger. That's a supervision question, and the answer is design: the system prepares — lists, drafts, summaries — and your people review, call, and commit. Dealers who keep the human in the loop get the efficiency without the apology calls.

A realistic first step

Add AI vendors to your next risk-assessment cycle. Make every vendor answer the five questions above in writing before a demo, not after a contract. You'll cut the list in half — and the survivors will be the ones worth watching.

We build with the Safeguards mindset from day one: approved access only, your data on systems you control — including equipment at your store if you want it — and humans making every customer commitment. Talk with us — or see how supervised AI works in fixed operations.

More: our approach for dealerships.

Talk with us

Let's see if your business is a good fit.

Book a 30-minute conversation with us. We will ask how your business runs and where your records live, then tell you plainly whether this makes sense and what a first step would look like. If it is not a fit, we will say so.