THE CORWINLAW CODEX

Automotive Dealers & AI

Implementing In-House Systems While Guarding Customer Privacy: Best Practices

Codex Entry
010-26
Revision
1.0
Practice Area
Automotive Franchise Law
Last Reviewed
August 2026

Artificial intelligence is already inside many dealerships—even when the dealership has never approved a product labeled “AI.”

AI may be embedded in:

  • Dealer management systems, or DMS;
  • Customer relationship management systems, or CRM;
  • Website chatbots;
  • Digital retailing platforms;
  • Lead scoring and routing;
  • Desking and pricing tools;
  • Trade-in valuation;
  • Inventory acquisition and forecasting;
  • Finance and insurance workflows;
  • Identity verification and fraud detection;
  • Credit application processing;
  • Service scheduling;
  • Technician diagnostics;
  • Warranty administration;
  • Call recording and transcription;
  • Marketing and customer segmentation;
  • Reputation management;
  • Video analytics and facial recognition;
  • Employee recruiting and monitoring;
  • Cybersecurity tools; and
  • Vehicle telematics and connected-car services.

Used well, AI can improve responsiveness, reduce repetitive work, identify missed opportunities, and help employees make better-informed decisions. Used carelessly, it can expose customer financial information, produce discriminatory outcomes, invent facts, make unlawful calls or texts, undermine cybersecurity, and create dependence on vendors the dealer cannot control.

The central dealership challenge is not whether to “use AI.” It is how to control which systems use it, what data they receive, what decisions they influence, who reviews their output, and what happens when they fail.

This Codex explains, in practical terms:

  • What dealer AI systems are;
  • Where AI appears in dealership operations;
  • Advantages and disadvantages;
  • DMS and vendor-integration risk;
  • Customer privacy and financial information;
  • Federal Safeguards, Privacy, Disposal, credit, advertising, and communications requirements;
  • Data minimization and retention;
  • Bias and automated decision-making;
  • Generative-AI errors and hallucinations;
  • Cybersecurity, ransomware, and business interruption;
  • Vendor contracts and service-provider oversight;
  • Real-world enforcement and litigation examples;
  • Human review and AI governance;
  • Incident response;
  • Staff training;
  • A staged implementation plan; and
  • Practical checklists for dealers.

This Codex is state-agnostic and focuses on broadly relevant federal principles. State privacy, biometric, wiretap, recording, breach-notification, consumer-protection, employment, insurance, and motor-vehicle laws vary substantially. A dealer must separately evaluate every state in which it operates or serves customers.

What Is an Automotive Dealer AI System?

An AI system is software that performs tasks commonly associated with human judgment, language, prediction, recognition, or decision support.

Dealer-facing AI may:

  • Predict which lead is likely to buy;
  • Draft an email or text;
  • Carry on a chatbot conversation;
  • Transcribe and summarize a call;
  • Recommend a vehicle;
  • Estimate trade-in value;
  • Detect possible fraud;
  • Flag unusual transactions;
  • Recommend pricing;
  • Prioritize service appointments;
  • Predict parts demand;
  • Summarize repair history;
  • Generate advertising copy;
  • Analyze customer sentiment;
  • Match credit applications with lenders;
  • Recommend F&I products;
  • Screen job applicants; or
  • Monitor network activity.

Some systems generate content. Others score, rank, classify, or recommend. Still others act autonomously through integrations and workflows.

AI can be hidden inside familiar software

A dealership may think it has not adopted AI because it has not bought a stand-alone AI platform. In reality, a vendor may add AI features through an ordinary update, pilot, integration, or “smart automation” module.

The dealership should inventory capabilities, not product names.

DMS: The Operational and Data Hub

The DMS often touches nearly every department:

  • Customer identity and contact information;
  • Driver’s-license information;
  • Deal jackets;
  • Credit and financing data;
  • Vehicle transactions;
  • Service history;
  • Repair orders;
  • Warranty claims;
  • Parts purchases;
  • Payroll and employee data;
  • Accounting;
  • Vendor payments; and
  • Regulatory records.

When AI connects to the DMS, a seemingly narrow function may gain access to a much broader data set than necessary.

For example, an AI appointment assistant may need a customer’s name, contact details, vehicle, and service history. It probably does not need a credit application, Social Security number, income, copy of a driver’s license, or full deal jacket.

The guiding question should be:


What is the minimum data this feature needs to perform its approved purpose?

Typical Dealer AI Uses

Sales and CRM

  • Lead scoring;
  • Automated follow-up;
  • Vehicle recommendations;
  • Lost-lead reactivation;
  • Call coaching;
  • Appointment setting;
  • Customer sentiment analysis; and
  • Sales forecasting.

F&I and credit

  • Fraud and identity checks;
  • Document classification;
  • Lender matching;
  • Deal completeness;
  • Adverse-action workflow;
  • Compliance flags;
  • Product recommendations; and
  • Payment or affordability estimates.

Fixed operations

  • Service scheduling;
  • Predictive maintenance;
  • Technician support;
  • Parts forecasting;
  • Repair-order summarization;
  • Warranty claim review;
  • Customer updates; and
  • Recall outreach.

Marketing

  • Audience segmentation;
  • Personalized offers;
  • Email and text generation;
  • Advertising creative;
  • Search optimization;
  • Review responses;
  • Campaign analysis; and
  • Attribution modeling.

Back office and human resources

  • Invoice processing;
  • Fraud monitoring;
  • Policy drafting;
  • Recruiting;
  • Resume screening;
  • Employee performance analytics;
  • Training; and
  • Cybersecurity monitoring.

Each use creates a different risk. A low-risk tool summarizing an internal meeting is not equivalent to a system recommending credit terms or sending thousands of customer texts.

The Potential Benefits

Faster customer response

AI can respond to leads outside business hours, answer routine questions, schedule appointments, and help employees prioritize time-sensitive inquiries.

More consistent follow-up

A well-configured system can reduce missed calls, forgotten tasks, inconsistent scripts, and stale CRM records.

Employee productivity

AI can draft routine communications, summarize long records, extract data from documents, and reduce repetitive entry. Employees can focus on judgment, relationships, and exceptions.

Better inventory decisions

Forecasting tools may help identify likely demand, aging inventory, pricing changes, acquisition opportunities, and parts needs.

Fixed-operations efficiency

AI may improve scheduling, estimate bay demand, identify service opportunities, summarize vehicle history, and help communicate repair status.

Compliance support

AI can flag missing documents, unusual pricing, potential identity issues, incomplete disclosures, or patterns requiring review.

A compliance flag is not a legal conclusion. The system should support—not replace—qualified review.

Fraud and cybersecurity detection

AI may identify anomalous logins, unusual access, suspicious applications, payment fraud, or network activity more quickly than manual review.

Improved training

Call summaries and conversation analytics can help identify coaching needs if used transparently, lawfully, and with appropriate human context.

Accessibility and language support

AI can assist with translation, text simplification, and customer communications. Important terms and legal disclosures should still be validated by qualified humans.

The Costs and Disadvantages

Privacy expansion

AI often works by collecting, combining, and retaining large amounts of data. A tool may infer more than the customer knowingly provided.

Hallucinations and false statements

Generative AI can confidently invent:

  • Vehicle features;
  • Availability;
  • Prices;
  • Warranty coverage;
  • Financing terms;
  • Appointment status;
  • Repair diagnoses;
  • Legal requirements; or
  • Promises that no employee authorized.

Bias and discrimination

Historical data may reflect prior unequal treatment. Automated scoring can reproduce or conceal it.

Loss of explainability

A dealer may be unable to explain why an algorithm ranked a lead, changed an offer, flagged fraud, recommended a product, or affected a credit decision.

Vendor dependence

A vendor outage can halt sales, service, accounting, and communications. Proprietary integrations can make switching difficult.

Cybersecurity attack surface

Each connector, API, user account, chatbot, browser extension, or data export creates another pathway to dealership systems.

Unauthorized “shadow AI”

Employees may paste customer records, credit data, repair orders, HR information, or contracts into public AI tools without approval.

Loss of human judgment

Employees may defer to a machine even when the output conflicts with facts, policy, law, or experience. This is sometimes called automation bias.

Consumer mistrust

Customers may react negatively if they learn that calls, messages, financial information, driving data, or images were analyzed or retained without clear notice.

Contract and audit risk

The dealer may promise privacy, security, or compliance in one document while a vendor’s system behaves differently.

Intellectual-property risk

AI output may reproduce protected material, misuse confidential inputs, or create unclear ownership of advertising, code, training materials, or other content.

Cost opacity

Implementation may require integration fees, data-cleaning, security review, training, monitoring, legal review, insurance, and exit costs—not merely a subscription.

AI Does Not Replace Existing Law

A common mistake is to treat AI as a new field with no settled rules. Existing laws generally apply regardless of technology.

Depending on the use, dealer AI may implicate:

  • Federal Trade Commission Act;
  • Gramm-Leach-Bliley Act rules;
  • Fair Credit Reporting Act;
  • Equal Credit Opportunity Act and Regulation B;
  • Truth in Lending Act;
  • Telephone Consumer Protection Act;
  • CAN-SPAM Act;
  • Electronic communications and recording laws;
  • Copyright and trade-secret law;
  • Employment and anti-discrimination laws;
  • State privacy and biometric laws;
  • State motor-vehicle and advertising rules;
  • Data-breach notification statutes; and
  • Contract law.

There is no “AI exception.”

The FTC Safeguards Rule

Most automobile dealers that finance or lease vehicles are covered financial institutions under the FTC Safeguards Rule.

The Rule requires a written information-security program appropriate to the dealer’s size, complexity, activities, and sensitivity of customer information.

The FTC’s dealer-specific guidance is available at Automobile Dealers and the FTC’s Safeguards Rule FAQs.

Key Safeguards Rule elements

A covered dealer should address:

  • A designated Qualified Individual;
  • A written risk assessment;
  • Access controls;
  • Data inventory and classification;
  • Encryption at rest and in transit;
  • Multi-factor authentication;
  • Secure development and application review;
  • Logging and monitoring;
  • Penetration testing and vulnerability assessment;
  • Employee security training;
  • Service-provider oversight;
  • Data retention and secure disposal;
  • Change management;
  • A written incident-response plan; and
  • Written reporting to the board or senior governing official.

See FTC Safeguards Rule: What Your Business Needs to Know.

AI belongs inside the information-security program

The risk assessment should identify:

  • Every AI system receiving customer information;
  • Data elements shared;
  • Access method;
  • Storage location;
  • Subprocessors;
  • Model-training use;
  • Retention period;
  • Security controls;
  • Authentication;
  • Logging;
  • Output recipients;
  • Failure modes; and
  • Incident-notification obligations.

Purchasing the AI tool through an approved DMS marketplace does not replace the dealer’s own assessment.

Safeguards Rule Security-Event Notification

Covered financial institutions must notify the FTC of qualifying notification events involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.

The FTC’s guidance states that notice is due as soon as possible and no later than 30 days after discovery of the notification event.

This federal notice does not replace applicable state breach notices, contractual notices, law-enforcement coordination, insurer notice, or consumer communications.

The FTC Privacy Rule

Dealers extending credit for personal, family, or household vehicle purchases may have obligations under the FTC Privacy Rule.

The Rule addresses privacy notices and disclosure of nonpublic personal information.

AI concerns include:

  • Using finance customer lists for marketing;
  • Sending customer information to an AI marketing vendor;
  • Combining credit and browsing data;
  • Repurposing data beyond the disclosed use;
  • Sharing data with affiliates or third parties;
  • Using chats to train vendor models; and
  • Honoring opt-out rights.

The FTC’s dealer guidance is available at FTC’s Privacy Rule and Auto Dealers: FAQs.

A vendor’s ability to receive information under a service-provider exception does not give that vendor unlimited rights to use the information for its own advertising, analytics, or model development.

The FTC Disposal Rule

Dealers using consumer reports must dispose of consumer-report information through reasonable measures that prevent unauthorized access or use.

Disposal applies to more than paper shredding. It may include:

  • DMS exports;
  • AI prompt histories;
  • Model logs;
  • Chat transcripts;
  • Scanned applications;
  • Vendor backups;
  • Test environments;
  • Portable drives;
  • Employee devices;
  • Cloud storage; and
  • Decommissioned systems.

See FTC Disposal Rule Guidance.

Deleting a user account does not necessarily delete the data from vendor systems or backups.

Data Mapping: Know What the AI Touches

A dealer cannot protect data it has not identified.

Common data categories

  • Name, address, email, and telephone number;
  • Driver’s-license data;
  • Social Security number;
  • Date of birth;
  • Income and employment;
  • Credit application and report data;
  • Bank and payment information;
  • Insurance information;
  • Vehicle identification number;
  • Purchase and lease history;
  • Service and repair history;
  • Warranty records;
  • Trade-in information;
  • Geolocation and telematics;
  • Call recordings and transcripts;
  • Chat messages;
  • Website behavior;
  • Photos and video;
  • Facial or voice data;
  • Customer complaints;
  • Employee information; and
  • Inferences, scores, and predictions.

Data-flow questions

For each AI system, ask:

  1. Where does the data originate?
  2. Which fields are transferred?
  3. Is transfer continuous or event-based?
  4. Where is the data stored?
  5. Who can access it?
  6. Is it encrypted?
  7. Is it used to train a shared model?
  8. Is it sold, shared, or combined with other data?
  9. Which subprocessors receive it?
  10. How long is it retained?
  11. Can the dealer retrieve and delete it?
  12. What happens at contract termination?
  13. How are customer rights handled?
  14. What logs prove compliance?

Data Minimization

AI vendors often request broad access because broad access is easier to engineer. The dealer should provide only what is necessary.

Examples

A service reminder tool may need:

  • Customer name;
  • Contact preference;
  • Vehicle;
  • Mileage or service due date; and
  • Appointment history.

It generally should not need:

  • Social Security number;
  • Credit score;
  • Income;
  • Driver’s-license image;
  • Full deal jacket; or
  • Payment card data.

A sales chatbot may need inventory and approved FAQs. It should not receive every CRM note, credit application, or private service complaint.

Minimize output too

An AI system should not reveal sensitive data merely because a user asks. Role-based access and output filtering are essential.

Purpose Limitation

Data collected for one purpose should not silently be reused for another incompatible purpose.

Examples of risky repurposing include:

  • Using credit data to target luxury marketing;
  • Using service complaints to score sales leads;
  • Using recorded voices to train biometric systems;
  • Using employee calls for undisclosed performance scoring;
  • Using driving behavior to infer insurance risk without disclosure; or
  • Using chatbot messages to train a vendor’s public model.

The dealer’s notices, consents, contracts, and actual conduct should align.

Vehicle and Telematics Data

Connected vehicles can generate:

  • Precise location;
  • Speed and braking;
  • Acceleration;
  • Trip history;
  • Diagnostics;
  • Infotainment contacts;
  • Voice commands;
  • Mobile-device identifiers;
  • Charging behavior;
  • Driver-assistance data; and
  • Camera or sensor information.

This data can reveal where a person lives, works, worships, seeks medical treatment, or spends time.

In 2025, the FTC announced an action against GM and OnStar concerning alleged collection, use, and sale of precise geolocation and driving-behavior data without adequate notice and affirmative consent. See FTC Action Against General Motors and OnStar.

Dealerships should understand their role in:

  • Enrollment;
  • Consent;
  • Sales explanations;
  • Test drives;
  • Loaner vehicles;
  • Connected-service activation;
  • Trade-in resets;
  • Rental and fleet vehicles;
  • Telematics-based marketing; and
  • Disclosure to OEMs and vendors.

Trade-in privacy

Before resale, a dealer should address personal data in:

  • Navigation history;
  • Paired phones;
  • Contacts;
  • Messages;
  • Garage-door codes;
  • Apps;
  • Account credentials;
  • Home addresses; and
  • Digital keys.

A factory reset procedure should be documented, verified, and adapted to the vehicle.

AI in Credit and F&I

This is one of the highest-risk areas because automated tools may influence legally significant financial decisions.

AI may be used to:

  • Verify identity;
  • Detect fraud;
  • Match applications with lenders;
  • Recommend deal structure;
  • Estimate affordability;
  • Prioritize stipulations;
  • Flag application inconsistencies;
  • Recommend pricing or reserve;
  • Select F&I products; or
  • Generate adverse-action reasons.

Adverse-action notices

A creditor using an algorithm must still provide specific and accurate reasons for adverse action when required by the Equal Credit Opportunity Act and Regulation B.

A vendor cannot excuse compliance by saying the model is proprietary or too complex to explain.

See CFPB Circular 2022-03.

Fair Credit Reporting Act

When a dealer uses consumer reports, fraud scores, identity products, or other covered third-party information, the Fair Credit Reporting Act may govern:

  • Permissible purpose;
  • Authorization or disclosure;
  • Adverse action;
  • Consumer notices;
  • Accuracy and disputes;
  • Red Flags obligations; and
  • Disposal.

The legal status of a data product depends on what it does, not what the vendor calls it.

Fair-lending risk

AI can create unequal outcomes through:

  • Historical pricing patterns;
  • ZIP code or geography;
  • Language preference;
  • Device or browser data;
  • Income proxies;
  • Lead source;
  • Trade-in assumptions;
  • Customer segmentation;
  • Fraud thresholds;
  • Dealer reserve; or
  • Product recommendations.

Protected characteristics should not be used improperly. Proxy variables and correlated data deserve review.

Dealer discretion

Federal auto-finance enforcement has long focused on discretionary pricing and markups. Adding AI does not remove responsibility.

A system that recommends different pricing should be tested for:

  • Inputs;
  • Approved reasons;
  • Overrides;
  • Documentation;
  • Outcome disparities;
  • Human review; and
  • Auditability.

Do not let AI invent a credit reason

The stated reason for adverse action must reflect factors actually used. A language model should not guess or generate a plausible explanation after the decision.

AI in Sales and Advertising

Truthful claims

The FTC Act prohibits unfair or deceptive practices. Advertising must remain truthful and substantiated when AI generates or personalizes it.

Risk examples include:

  • Advertising a vehicle that is unavailable;
  • Inventing equipment or trim;
  • Presenting a conditional price as unconditional;
  • Omitting required qualifications;
  • Misstating rebates;
  • Claiming guaranteed approval;
  • Hiding add-ons;
  • Creating fake reviews;
  • Altering vehicle images misleadingly; or
  • Claiming the AI is unbiased or error-free without support.

The FTC’s AI materials emphasize that there is no exemption for automated claims. See FTC Artificial Intelligence.

Personalized pricing and offers

Personalization can become problematic if consumers receive materially different terms based on sensitive or proxy data without a lawful, documented basis.

Dealers should distinguish:

  • Inventory-based pricing;
  • Negotiated pricing;
  • Loyalty offers;
  • Credit-based terms;
  • Geographic offers;
  • Behavioral targeting; and
  • Protected-class or proxy-driven differences.

Review generated content before publication

Approved templates, claims libraries, price feeds, and required disclosures should constrain outputs.

High-risk content should require human approval, including:

  • Price and payment;
  • Financing;
  • Warranty;
  • Safety;
  • Vehicle availability;
  • Trade-in value;
  • Legal disclosures; and
  • Comparative claims.

AI Chatbots and Virtual Sales Assistants

A chatbot may be the first “employee” a customer encounters.

Common risks

  • False promise of price or availability;
  • Unauthorized discount;
  • Misstatement of warranty coverage;
  • Collection of credit or medical information;
  • Failure to disclose automation;
  • Inadequate consent to data collection;
  • Inability to handle opt-outs;
  • Offensive or discriminatory output;
  • Disclosure of another customer’s information;
  • Improper legal or financial advice;
  • Hallucinated appointment or reservation; and
  • Retention of conversations for training.

Best practices

  • Clearly identify the assistant as automated where appropriate;
  • Limit it to approved subject matter;
  • Prohibit collection of unnecessary sensitive data;
  • Escalate finance, complaints, safety, legal, and vulnerable-customer issues;
  • Use approved inventory and pricing feeds;
  • Log conversations securely;
  • Provide a human handoff;
  • Test adversarial prompts;
  • Monitor output quality;
  • Honor opt-outs; and
  • Disclose data practices accurately.

FTC guidance warns AI companies and users to honor privacy and confidentiality commitments. See AI Companies: Uphold Your Privacy and Confidentiality Commitments.

Calls, Texts, and Synthetic Voices

AI may automate lead follow-up, service reminders, collection calls, and appointment outreach.

The Telephone Consumer Protection Act and FCC rules may apply to:

  • Autodialed calls or texts;
  • Artificial or prerecorded voices;
  • Marketing messages;
  • Consent;
  • Revocation;
  • Do-not-call requests;
  • Identification; and
  • Calling-time restrictions.

In 2024, the FCC confirmed that AI-generated voices fall within TCPA restrictions on artificial or prerecorded voice messages. See FCC Declaratory Ruling on AI-Generated Voices.

Practical controls

  • Preserve consent source and language;
  • Distinguish marketing from transactional messages;
  • Process revocation promptly;
  • Synchronize suppression lists across vendors;
  • Prevent the AI from changing approved scripts materially;
  • Identify the dealership;
  • Monitor vendor dialing methods;
  • Audit time zones and frequency; and
  • Retain evidence.

A customer’s prior inquiry does not necessarily authorize every future automated marketing campaign.

Audio, Video, Biometrics, and Recording

Dealers may use AI to analyze:

  • Recorded calls;
  • Voiceprints;
  • Showroom video;
  • License-plate recognition;
  • Facial images;
  • Driver’s licenses;
  • Service-lane video;
  • Employee activity; and
  • Customer emotion or sentiment.

State laws differ significantly concerning:

  • One-party or all-party consent;
  • Notice;
  • Biometric consent;
  • Written policies;
  • Retention and destruction;
  • Private rights of action;
  • Security; and
  • Use of facial recognition.

A state-agnostic national policy should not assume that a single notice is sufficient everywhere.

Sentiment and emotion detection

Systems claiming to infer honesty, emotion, intent, or vulnerability from voice or facial features deserve special skepticism. Accuracy may vary by language, disability, age, race, culture, and environment.

Dealers should not make consequential decisions based solely on such inferences.

AI in Service and Repair

Potential uses include:

  • Appointment scheduling;
  • Repair-order summarization;
  • Diagnostic suggestions;
  • Predictive maintenance;
  • Technician information retrieval;
  • Parts recommendations;
  • Warranty coding; and
  • Customer explanations.

Safety risk

AI should not independently authorize or certify safety-critical diagnosis or repair.

Human technicians should verify:

  • Applicable service information;
  • Vehicle identification and configuration;
  • Diagnostic procedures;
  • Torque and calibration requirements;
  • Recalls and campaigns;
  • Parts compatibility;
  • Completed work; and
  • Road-test or quality-control results.

Customer communication

An AI-generated explanation should not:

  • Overstate certainty;
  • Invent a diagnosis;
  • Promise warranty coverage;
  • Misrepresent urgency;
  • Conceal alternative repairs;
  • Substitute for required authorization; or
  • Create a false safety assurance.

Warranty claims

AI may help identify missing documentation, but should not generate technician facts that were never recorded. Retrospectively invented narratives can create fraud, audit, and credibility risks.

Employee Use and Shadow AI

Employees may use free or personal AI tools to:

  • Draft emails;
  • Summarize contracts;
  • Translate customer records;
  • Analyze credit applications;
  • Create ads;
  • Review repair orders;
  • Prepare HR documents; or
  • Troubleshoot systems.

If customer or employee data is entered into an unapproved service, the dealership may lose control of it.

AI acceptable-use policy

The policy should address:

  • Approved tools;
  • Prohibited data;
  • Approved accounts;
  • No personal accounts for dealership work;
  • Human review;
  • Copyright and plagiarism;
  • Confidentiality;
  • Security;
  • Customer communications;
  • Credit and employment decisions;
  • Record retention;
  • Incident reporting; and
  • Discipline.

Prohibited inputs may include

  • Social Security numbers;
  • Credit applications;
  • Consumer reports;
  • Driver’s-license images;
  • Bank or card data;
  • Deal jackets;
  • Passwords or credentials;
  • Medical information;
  • Biometric identifiers;
  • Unredacted employee files;
  • Trade secrets;
  • Privileged legal advice; and
  • Confidential OEM or lender information.

AI in Employment Decisions

Dealers may use AI for recruiting, scheduling, performance scoring, call analysis, or discipline.

Risks include:

  • Disability discrimination;
  • Biased resume screening;
  • Age proxies;
  • Language or accent bias;
  • Penalizing protected leave;
  • Monitoring protected activity;
  • Inaccurate productivity scoring;
  • Hidden biometric analysis; and
  • Automated termination.

Consequential employment decisions should receive documented human review. State and local automated-employment-decision laws may add notice, audit, or consent duties.

Vendor Risk: The Dealer Is Still Responsible

A dealer can outsource a function but not all responsibility.

Under the Safeguards Rule, covered dealers must:

  • Select service providers capable of maintaining safeguards;
  • Require safeguards by contract; and
  • Periodically assess service providers based on risk.

Vendor diligence questions

  • What data does the vendor receive?
  • Is data segregated by customer?
  • Does the vendor train models on dealer data?
  • Are prompts and outputs retained?
  • Which subprocessors are used?
  • Where is data stored?
  • Is data encrypted?
  • Is MFA required?
  • Are access and admin actions logged?
  • What testing is performed?
  • What certifications or reports exist?
  • Has the vendor had incidents?
  • What is the notification timeline?
  • Can the dealer audit?
  • Can the dealer export its data?
  • How is data deleted at termination?
  • Who owns improvements and output?
  • Is the vendor insured?
  • Does the vendor indemnify privacy, security, IP, and regulatory claims?
  • How is business continuity handled?

“We are compliant” is not evidence

Request appropriate support, such as:

  • Security questionnaire;
  • Independent assessment;
  • SOC report where appropriate;
  • Penetration-test summary;
  • Business-continuity plan;
  • Incident-response process;
  • Subprocessor list;
  • Data-flow diagram;
  • AI model card or technical documentation;
  • Bias and performance testing; and
  • Insurance certificate.

The evidence should match the risk.

Contract Terms for AI and DMS Vendors

Scope and data rights

Address:

  • Dealer ownership of data;
  • Limited license to vendor;
  • Permitted purposes;
  • Prohibition on sale or unrelated use;
  • Model-training restrictions;
  • Deidentified data standards;
  • Subprocessors;
  • Cross-customer learning;
  • Data return;
  • Portability; and
  • Deletion.

Security

Require appropriate:

  • Safeguards Rule compliance support;
  • Encryption;
  • MFA;
  • Least privilege;
  • Logging;
  • Testing;
  • Secure development;
  • Vulnerability management;
  • Employee training;
  • Background screening where lawful; and
  • Incident response.

Incident notification

The contract should define:

  • What constitutes an incident;
  • Initial notification time;
  • Required content;
  • Ongoing updates;
  • Preservation of evidence;
  • Cooperation;
  • Forensics;
  • Law-enforcement contact;
  • Consumer and regulator notices;
  • Costs; and
  • Public communications.

A vendor deadline should be shorter than the dealer’s shortest legal or contractual deadline.

AI performance

Address:

  • Approved use cases;
  • Accuracy standards;
  • Testing;
  • Material model changes;
  • Human review;
  • Explainability;
  • Audit logs;
  • Bias monitoring;
  • Prohibited autonomous decisions;
  • Correction process; and
  • Service levels.

Liability and insurance

Review:

  • Liability cap;
  • Exclusions from the cap;
  • Data breach;
  • Confidentiality;
  • IP infringement;
  • Regulatory fines;
  • Gross negligence and willful misconduct;
  • Indemnification;
  • Cyber insurance;
  • Technology errors and omissions; and
  • Business interruption.

A vendor’s standard cap may be a small fraction of the dealership’s real exposure.

Vendor Concentration and Business Continuity

A dealership may depend on one vendor for:

  • DMS;
  • CRM;
  • Desking;
  • Accounting;
  • Inventory;
  • Service scheduling;
  • Repair orders;
  • Parts;
  • Communications; and
  • Payroll integrations.

A failure can become an enterprise-wide outage.

The CDK Global lesson

In June 2024, a cyber incident at CDK Global disrupted systems used by dealerships nationwide. Public dealership-group SEC filings described interruptions to DMS, CRM, sales, service, inventory, accounting, and productivity.

See the AutoNation 2024 SEC filing discussing the CDK incident.

The lesson is broader than one vendor: the dealership’s continuity plan must assume that a critical provider may be unavailable for days or weeks.

Continuity planning

Maintain tested offline or alternative procedures for:

  • Customer intake;
  • Vehicle inventory;
  • Sales worksheets;
  • Credit application handling;
  • Privacy notices;
  • OFAC and identity checks;
  • Contract generation;
  • Repair orders;
  • Parts issuance;
  • Timekeeping;
  • Cash receipts;
  • Accounting;
  • Title and registration work;
  • Customer communications; and
  • Later system reconciliation.

Paper workarounds can create new privacy and accuracy risks. Secure storage, controlled access, numbering, reconciliation, and destruction are essential.

Real-World Example: Dealer Software Data Exposure

In 2019, the FTC alleged that DealerBuilt, operated by LightYear Dealer Technologies, failed to secure dealership consumer data, leading to exposure of personal information associated with approximately 12.5 million consumers.

The matter is a foundational reminder that:

  • Dealer software holds highly sensitive information;
  • Vendor failures can affect multiple dealerships;
  • Publicly accessible backups or databases can be catastrophic;
  • Access controls, encryption, monitoring, and testing matter; and
  • Dealer vendor diligence must be substantive.

See FTC DealerBuilt Settlement.

Real-World Example: DMS Data and Competition

DMS data access can also create competition and control issues.

In re Dealer Management Systems Antitrust Litigation, 680 F. Supp. 3d 919 (N.D. Ill. 2023) involved allegations concerning DMS providers, data integration restrictions, exclusive dealing, and competition.

The litigation illustrates that a dealer’s ability to access and move its own operational data can affect:

  • Vendor choice;
  • Integration cost;
  • Innovation;
  • Switching;
  • Third-party applications;
  • Data control; and
  • Resilience.

Dealers should negotiate data portability and exit rights before dependence deepens.

Real-World Example: Connected-Vehicle Data Litigation

Automotive privacy litigation increasingly concerns vehicle-generated information.

In re Consumer Vehicle Driving Data Tracking Collection, MDL No. 3115 (N.D. Ga. Apr. 22, 2026) addresses claims involving collection and transmission of vehicle driving data and federal and state electronic-communications theories.

The developing litigation demonstrates that telematics data may trigger:

  • Federal privacy claims;
  • State wiretap claims;
  • Consent disputes;
  • Consumer-protection claims;
  • Contract claims; and
  • Multistate class actions.

The dealer’s role may vary, but dealer representations, enrollment practices, and data sharing should be accurate and documented.

Real-World Example: AI and Fair Treatment

The FTC’s 2024 administrative action against Asbury Automotive alleged discriminatory treatment of Black and Latino consumers and unwanted add-ons.

The case was not dependent on AI, but it provides an important AI lesson: automating a pricing, add-on, lead, or F&I process does not cleanse the underlying practice. It may scale it.

See FTC Action Against Asbury Automotive.

Dealers using AI should compare outcomes across relevant customer groups and investigate unexplained differences.

Hallucinations: When the Bot Makes a Deal

Imagine a website chatbot states:


“Yes, that vehicle is available for $31,500, including all dealer-installed accessories, and we will hold it until Saturday with no deposit.”

But the vehicle was sold, the price excluded add-ons, and the dealership has no hold policy.

Potential consequences include:

  • Consumer complaint;
  • Advertising claim;
  • Contract argument;
  • Regulator inquiry;
  • Lost trust;
  • Employee conflict; and
  • Preservation obligations.

Controls

  • Use live, approved inventory feeds;
  • Limit authority to quote and promise;
  • Require confirmation for holds and deposits;
  • Display qualifications clearly;
  • Escalate price disputes;
  • Retain conversation logs securely; and
  • Correct errors promptly without misleading the customer.

Prompt Injection and Data Leakage

A malicious user may instruct a chatbot to ignore prior instructions, reveal system prompts, expose another customer’s data, or produce internal records.

Testing should include attempts to:

  • Extract personal information;
  • Reveal inventory pricing rules;
  • Obtain employee credentials;
  • Bypass identity verification;
  • Generate discriminatory or illegal advice;
  • Access connected systems;
  • Upload malware; and
  • Manipulate actions.

The chatbot should not have broad write access to the DMS or CRM merely for convenience.

AI Governance

AI governance assigns accountability before a problem occurs.

Governance team

Depending on dealer size, participants may include:

  • Dealer principal or executive sponsor;
  • Qualified Individual;
  • Information technology;
  • Privacy or compliance;
  • Legal counsel;
  • Fixed operations;
  • Sales and F&I;
  • Marketing;
  • Human resources;
  • Accounting;
  • Internal audit; and
  • Insurance or risk management.

AI inventory

Maintain a register identifying:

  • Tool and vendor;
  • Business owner;
  • Approved purpose;
  • Data used;
  • Integrations;
  • Decision impact;
  • Risk rating;
  • Human reviewer;
  • Contract term;
  • Subprocessors;
  • Testing date;
  • Incident contact;
  • Retention; and
  • Approval status.

Risk tiers

Lower risk

  • Drafting internal meeting agendas;
  • Summarizing nonsensitive public information;
  • Generating ideas with no customer data.

Moderate risk

  • Drafting marketing content;
  • Summarizing service records;
  • Lead prioritization;
  • Call transcription.

High risk

  • Credit decisions;
  • Pricing and add-ons;
  • Fraud denial;
  • Employment decisions;
  • Biometric identification;
  • Telematics profiling;
  • Autonomous customer promises;
  • Safety-critical repair recommendations; and
  • Tools with broad DMS access.

Higher-risk use requires stronger approval, testing, monitoring, and human review.

NIST AI Risk Management Framework

The NIST AI Risk Management Framework is voluntary but useful for structuring governance.

It emphasizes four functions:

  • Govern: establish policies, roles, accountability, and culture;
  • Map: understand context, users, data, and potential harm;
  • Measure: test performance, reliability, bias, privacy, and security; and
  • Manage: prioritize, mitigate, monitor, and respond to risk.

See NIST AI Risk Management Framework 1.0.

A dealer does not need a research laboratory to use the framework. A disciplined inventory, approval process, documented testing, and monitoring program can implement its core principles.

Human Review

“Human in the loop” is meaningful only when the person:

  • Has authority to disagree;
  • Understands the system’s limits;
  • Receives enough information;
  • Has adequate time;
  • Is not punished for overrides;
  • Documents the decision; and
  • Can escalate uncertainty.

A rubber-stamp review does not reduce risk.

Decisions that should not be fully autonomous

  • Credit approval, denial, or material terms;
  • Adverse-action reason selection;
  • Discrimination-sensitive pricing;
  • Fraud accusations;
  • Employment termination;
  • Safety-critical repair decisions;
  • Legal conclusions;
  • Disclosure of sensitive information;
  • Large refunds or payments; and
  • Binding customer promises outside approved parameters.

Testing Before Deployment

Accuracy

Test against real but appropriately protected dealership scenarios.

Privacy

Confirm the system does not expose data across customers, stores, roles, or vendors.

Security

Perform appropriate vulnerability, access, API, and adversarial testing.

Bias

Evaluate outputs and outcomes across relevant groups and proxies, with legal review.

Explainability

Can the dealer explain a score, recommendation, or decision?

Reliability

Test outages, stale feeds, duplicate records, delayed updates, and unusual transactions.

Compliance

Test required disclosures, consent, opt-outs, adverse-action reasons, retention, and recordkeeping.

Human factors

Observe whether employees overtrust, ignore, or misuse the system.

Monitoring After Launch

AI changes through:

  • Vendor model updates;
  • New training data;
  • Changed prompts;
  • Added integrations;
  • Employee workarounds;
  • New products;
  • New laws; and
  • Shifting customer behavior.

Monitor:

  • Error rates;
  • Complaints;
  • Overrides;
  • Outcome disparities;
  • Unauthorized access;
  • Data exports;
  • Vendor changes;
  • Consent and opt-out failures;
  • Hallucinations;
  • Downtime;
  • Security alerts; and
  • Unexpected use cases.

A tool approved for one purpose should not be used for another without review.

Incident Response for AI Systems

An AI incident may involve:

  • Data breach;
  • Unauthorized model training;
  • Disclosure of customer information;
  • Discriminatory output;
  • False advertising;
  • Unlawful calls or texts;
  • Incorrect credit reasons;
  • Safety-related misinformation;
  • Vendor outage;
  • Prompt injection;
  • Malware;
  • Loss of records; or
  • Material customer promises.

Response steps

  1. Stop or isolate the affected function when appropriate.
  2. Preserve logs, prompts, outputs, records, and communications.
  3. Notify the Qualified Individual, leadership, and CorwinLaw.
  4. Determine affected systems, data, people, and decisions.
  5. Engage the vendor under contractual incident procedures.
  6. Assess federal, state, contractual, insurer, lender, OEM, and consumer notice duties.
  7. Correct affected decisions or communications.
  8. Prevent retaliation against reporters.
  9. Document containment and remediation.
  10. Conduct lessons-learned review.

Do not destroy prompts or retrain the model before preserving evidence.

Insurance

Review whether policies address:

  • Cyber incidents;
  • Privacy liability;
  • Regulatory investigations;
  • Business interruption;
  • Dependent business interruption;
  • Technology errors;
  • Media liability;
  • Social engineering;
  • Ransomware;
  • Contractual liability;
  • Biometric claims; and
  • AI-specific exclusions.

Coverage may depend on timely notice and the accuracy of security representations in the application.

Records and Litigation Holds

AI systems create new records:

  • Prompts;
  • Outputs;
  • Chat transcripts;
  • Scores;
  • Model versions;
  • System instructions;
  • Audit logs;
  • Override reasons;
  • Training records; and
  • Vendor notices.

The dealer should decide which records are business records, how long to retain them, and how to preserve them for litigation or investigations.

A short vendor retention period may destroy evidence needed to defend the dealer. An unlimited retention period creates privacy and security risk. The policy should balance both.

Intellectual Property

Inputs

Employees should not upload:

  • Confidential OEM materials;
  • Lender manuals;
  • Third-party copyrighted databases;
  • Competitor confidential information;
  • Unlicensed photographs;
  • Proprietary code; or
  • Privileged legal advice,

unless approved and legally permitted.

Outputs

Review:

  • Ownership under vendor terms;
  • Whether output can be protected by copyright;
  • Similarity to third-party material;
  • Trademark misuse;
  • Rights of publicity;
  • False endorsement;
  • Accuracy; and
  • Required human authorship.

AI-generated advertising should receive the same legal review as human-created advertising.

Dealer Group Considerations

A dealer group may want centralized AI governance but should account for:

  • Different state laws;
  • Different franchises and OEM rules;
  • Separate legal entities;
  • Shared services;
  • Intercompany data sharing;
  • Customer consent;
  • Cross-store CRM access;
  • Vendor contracts;
  • Local management; and
  • Differing risk profiles.

Centralized control should not result in unauthorized data sharing among rooftops or entities.

Mergers and Acquisitions

When buying a dealership or dealer group, AI and data diligence should include:

  • DMS and CRM contracts;
  • Data ownership;
  • AI inventory;
  • Vendor access;
  • Privacy notices;
  • Safeguards Rule program;
  • Incidents;
  • FTC notifications;
  • State breach notices;
  • Consumer complaints;
  • Biometric systems;
  • Telematics programs;
  • Consent records;
  • Model governance;
  • Data portability;
  • Termination costs; and
  • Post-closing integration.

A stock purchase may inherit historical privacy and security liabilities. An asset purchase does not automatically eliminate statutory, successor, or reputational risk.

A Staged Implementation Plan

Phase 1: Define the problem

  • Identify the business problem;
  • Establish a measurable goal;
  • Identify affected customers and employees;
  • Determine whether AI is actually necessary; and
  • Identify a non-AI alternative.

Phase 2: Classify risk

  • Identify data;
  • Determine legal impact;
  • Rate privacy, security, discrimination, safety, and operational risk;
  • Identify required human review; and
  • Decide whether the use is permissible.

Phase 3: Vet the vendor

  • Conduct security and privacy diligence;
  • Review model use and training;
  • Review subprocessors;
  • Test portability and continuity;
  • Negotiate contract terms; and
  • Confirm insurance.

Phase 4: Pilot safely

  • Use limited data;
  • Limit users;
  • Avoid high-risk autonomous decisions;
  • Test accuracy and bias;
  • Gather complaints and overrides; and
  • Define stop criteria.

Phase 5: Approve and train

  • Document approval;
  • Update policies and notices;
  • Configure access;
  • Train users;
  • Establish escalation; and
  • Prepare incident response.

Phase 6: Monitor and reassess

  • Review performance;
  • Audit outcomes;
  • Monitor vendor changes;
  • Test continuity;
  • Reassess law and risk; and
  • Retire the system when no longer justified.

Dealer AI Procurement Checklist

Business case

  • Define the problem and expected benefit.
  • Identify an accountable business owner.
  • Determine whether AI is necessary.
  • Establish measurable success and failure criteria.
  • Calculate integration, oversight, and exit costs.

Data and privacy

  • Identify every data element used.
  • Minimize data access.
  • Identify GLBA customer information and consumer-report data.
  • Review notices and consent.
  • Prohibit unauthorized model training.
  • Review deidentification claims.
  • Identify subprocessors and storage locations.
  • Set retention and deletion requirements.
  • Map customer-rights workflow.

Security

  • Include the system in the written risk assessment.
  • Require encryption and MFA.
  • Apply least privilege.
  • Review logging and monitoring.
  • Review secure development and testing.
  • Review incident history.
  • Verify incident response and notification.
  • Test business continuity.
  • Review security evidence.
  • Identify applicable federal and state laws.
  • Determine whether the system makes or affects consequential decisions.
  • Test discrimination and proxy risk.
  • Confirm adverse-action explainability.
  • Review advertising claims.
  • Review calls and texts.
  • Review recording and biometric law.
  • Review IP rights.
  • Establish human review.

Contract

  • Dealer owns and can export data.
  • Vendor use is purpose-limited.
  • Subprocessors are controlled.
  • Security obligations are specific.
  • Incident notice is prompt.
  • Audit rights are meaningful.
  • Material model changes require notice.
  • Service levels and continuity are defined.
  • Liability caps are appropriate.
  • Indemnities address privacy, security, IP, and law.
  • Insurance is adequate.
  • Exit assistance and deletion are required.

Dealer AI Operations Checklist

  • Maintain a current AI inventory.
  • Use only approved tools and accounts.
  • Train employees by role.
  • Prohibit sensitive data in public AI tools.
  • Review high-risk outputs before use.
  • Log overrides and complaints.
  • Test accuracy and bias periodically.
  • Monitor data access and exports.
  • Process opt-outs and consent changes.
  • Review vendor and subprocessor changes.
  • Reassess after material updates.
  • Exercise the incident-response plan.
  • Test manual business-continuity procedures.
  • Report AI risk to leadership.

Department-Specific Checklist

Sales and CRM

  • Validate inventory, price, and incentive feeds.
  • Limit chatbot authority.
  • Provide human handoff.
  • Review lead-scoring outcomes.
  • Audit customer segmentation.
  • Preserve consent for outreach.

F&I

  • Do not allow unexplainable adverse decisions.
  • Validate actual adverse-action reasons.
  • Audit pricing and product recommendations.
  • Limit access to credit data.
  • Review consumer-report use.
  • Document overrides.

Service and parts

  • Require technician validation.
  • Protect repair and telematics data.
  • Do not invent warranty narratives.
  • Validate parts and service information.
  • Control automated customer promises.
  • Preserve authorization records.

Marketing

  • Approve claims and disclosures.
  • Prevent fake reviews and endorsements.
  • Review personalization inputs.
  • Honor suppression and opt-out lists.
  • Control synthetic voice and mass texting.
  • Retain approved creative versions.

Human resources

  • Review recruiting models for bias.
  • Disclose monitoring where required.
  • Avoid emotion or honesty scoring without strong justification.
  • Require human review of discipline.
  • Protect employee data.
  • Preserve accommodation and leave rights.

Questions to Discuss With CorwinLaw

  1. Is the dealership covered by the FTC Safeguards and Privacy Rules?
  2. Which AI systems touch customer information?
  3. Is the system included in the written risk assessment?
  4. Does the dealer’s privacy notice match actual data use?
  5. May the vendor train models on dealer or customer data?
  6. Are subprocessors and data locations known?
  7. Does the contract satisfy service-provider oversight requirements?
  8. Can the dealer explain AI-assisted credit decisions?
  9. Do pricing or lead systems produce unequal outcomes?
  10. Are AI calls, texts, recordings, or synthetic voices lawful?
  11. Do biometric or telematics features require special consent?
  12. What human review is required?
  13. Are advertising and chatbot claims accurate?
  14. Can the dealership operate without the vendor?
  15. Are incident notice and cooperation terms adequate?
  16. Who owns data, prompts, outputs, and improvements?
  17. Can the dealer export and delete its data?
  18. Does insurance cover AI, vendor outage, privacy, and cyber risk?
  19. What state-specific laws apply to each rooftop and customer?
  20. Is the system’s benefit worth its legal and operational risk?

For assistance evaluating, procuring, implementing, or governing dealership AI and DMS-integrated systems, contact CorwinLaw at www.corwinlaw.net.

This Codex is provided by CorwinLaw, www.corwinlaw.net, for general educational and informational purposes only. It is not legal, cybersecurity, privacy, technology, accounting, insurance, or financial advice.

AI, privacy, cybersecurity, consumer-finance, communications, biometric, and motor-vehicle laws change rapidly and vary by jurisdiction. The legal obligations applicable to a dealership depend on its activities, data, systems, vendors, customers, locations, and contracts. Technical controls should be evaluated by qualified security and technology professionals.

Reading this Codex, visiting a website, or contacting CorwinLaw does not create an attorney-client relationship. An attorney-client relationship should arise only through a written engagement agreement accepted by CorwinLaw and the client. Do not send confidential or time-sensitive information unless and until CorwinLaw confirms that it represents you.

Dealers should coordinate legal review with the Qualified Individual, information-security personnel, DMS and technology specialists, compliance personnel, insurers, accountants, and other qualified advisers. CorwinLaw can assist with dealer-franchise issues, privacy, AI governance, vendor contracts, customer communications, incident response, regulatory inquiries, and litigation.

Last reviewed: August 2026.

The CorwinLaw Codex

Explore additional legal guides, practical resources, and practice-area reference materials at:

https://www.corwinlaw.net