Inventory sites, credit-application intake, and service-scheduling tools built with AI can quietly turn a dealership into a regulated "financial institution" under GLBA. Franchised and independent dealers just lived through the CDK Global ransomware outage (~15,000 dealerships idled) and the 700Credit breach (5.8M car buyers' SSNs) - and AI-generated code introduces vulnerabilities in roughly 45% of tasks (Veracode).
Get a Free Security Scan See Our AI App AuditDealers that arrange financing or leasing are legally "financial institutions" under GLBA - a fact many owners of AI-built dealer sites don't know until it's a compliance problem.
AI admin panels built on Supabase or Firebase without row-level security let anyone read or edit listings, pricing, and buyer inquiries - the same CVE-2025-48757 class of bug that exposed 170+ Lovable apps' databases.
Forms that don't capture TCPA prior-express-written consent expose the dealer to – per text. The FCC's revocation rules, effective April 11, 2025, require honoring opt-outs within 10 business days - a step AI-generated "speed-to-lead" texting tools rarely build in.
The moment a form collects SSN, income, and employment to "get you pre-approved," the dealer is handling GLBA customer information and the full FTC Safeguards Rule applies - encryption, MFA, access controls, and a written incident-response plan, none of which AI builders generate by default. The 700Credit breach (discovered October 2025) exposed 5.8 million consumers' names, addresses, DOBs, and SSNs from auto-financing applications through exactly this kind of intake pipeline.
Sequential or guessable booking IDs (IDOR) leak names, phones, addresses, and VINs - and reveal when a customer's car, and house, is unattended. This is the same broken-authorization bug class Veracode found in 45% of AI-generated code tasks.
AI tools frequently embed vendor API keys client-side. A portal wired into a DMS, CRM, or credit bureau inherits - and can leak - that vendor's access. 700Credit's breach came through exactly this pattern: a compromised integration partner and "a failure to validate consumer reference IDs against the original requester," an API authorization bug identical to what AI code generators commonly produce.
Driver's license and vehicle-record data collected for trade-in valuations falls under the Driver's Privacy Protection Act, which carries in liquidated damages per record with no proof of harm required - a private right of action that doesn't care whether a breach ever occurred.
| Regulation | When it's triggered | Penalty |
|---|---|---|
| GLBA / FTC Safeguards Rule | Dealer arranges or facilitates financing/leasing = "financial institution"; full amended rule since 2023-06-09 | Up to /violation (2025); each day of noncompliance a separate violation |
| FTC Safeguards breach-notification | Unauthorized acquisition of unencrypted customer info of 500+ consumers | Notify FTC within 30 days; failure = separate rule violation |
| Driver's Privacy Protection Act | Obtaining/disclosing DMV record data for impermissible purposes | liquidated damages per violation, no proof of harm required |
| PCI DSS 4.0.1 | Site takes card payments (deposits, service, parts); mandatory since 2025-03-31 | – → –; loss of processing |
| CCPA/CPRA + state privacy | Collecting PI above thresholds; connected-vehicle data is an active CPPA target | / intentional; Honda fined (CPPA, 2025) |
| TCPA | Marketing texts/calls to leads without prior express written consent | / willful per text/call |
Not by default. AI-generated code fails security checks in roughly 45% of tasks (Veracode), and any site collecting SSN, income, and employment for financing pre-approval makes the dealer subject to the full GLBA Safeguards Rule - encryption, MFA, and access controls that AI builders don't generate automatically.
Yes, if it arranges or facilitates financing or leasing for customers - which most dealerships do. The FTC's amended Safeguards Rule has applied in full since June 9, 2023, and the FTC published dealer-specific FAQs in June 2025 reiterating the scope.
The June 2024 CDK Global ransomware attack idled roughly 15,000 North American dealership locations for about two weeks, costing an estimated .02 billion in dealer losses. The 700Credit breach, discovered October 2025, exposed 5.8 million consumers' names, addresses, DOBs, and SSNs from auto-financing applications via a compromised integration partner.
Yes. Marketing texts or calls to leads without prior express written consent carry – in per-text penalties, and the FCC's April 11, 2025 rules require honoring opt-outs within 10 business days by any reasonable means.
The DPPA restricts obtaining or disclosing DMV record data for impermissible purposes, and it carries in liquidated damages per violation through a private right of action - no proof of harm required. If your site captures driver's license data for trade-in valuations, it applies.
Rotate every API key and DMS/CRM credential, enable row-level security if it wasn't already on, and if 500 or more consumers' unencrypted customer information was affected, you're required to notify the FTC within 30 days under the amended Safeguards Rule.
We audit AI-built dealership sites for missing RLS, GLBA Safeguards gaps, and exposed financing data - then fix what we find.
Get a Free Security Scan