Skip to main content

New York's FAIR Business Practices Act: What the 2026 'Unfair and Abusive' Standard Means for Small Businesses

9 min readMike ThriftMike Thrift
New York's FAIR Business Practices Act: What the 2026 'Unfair and Abusive' Standard Means for Small Businesses

The Quiet Law Change With a Very Loud Price Tag

On February 17, 2026, New York flipped a switch that most business owners haven't noticed yet. For the first time since the 1970s, the state rewrote the core statute that governs what counts as illegal business conduct toward consumers — and, in a twist that surprises almost everyone who reads the bill, toward small businesses and non-profits too.

The old rule was simple enough to ignore: don't be deceptive. The new rule, created by the FAIR Business Practices Act, adds two entirely new categories — "unfair" and "abusive" — that don't require anyone to prove you lied. A pricing structure, a cancellation flow, or an AI-driven discount algorithm can now violate New York law even if every word of your marketing was completely true.

If you sell anything to a New York consumer — a subscription, a service, a financing plan, a SaaS seat — this changes what "compliant" looks like. And if you are a small business, the same law now gives you new leverage against vendors, lenders, and platforms that treat you unfairly. This is a two-way street, and most small business owners are only prepared for one direction of traffic.

What Actually Changed

New York's consumer protection statute, General Business Law Section 349, has stood mostly untouched for over 40 years. It prohibited "deceptive acts or practices" — conduct likely to mislead a reasonable consumer. Courts required a plaintiff (or the Attorney General) to show something false or misleading actually happened.

The FAIR Act, signed by Governor Hochul and effective February 17, 2026, adds two new standards that don't hinge on deception at all:

  • Unfair practices: conduct causing "substantial injury" to consumers that is "not reasonably avoidable" and "not outweighed by countervailing benefits to consumers or to competition." Nobody has to be tricked — they just have to be harmed, unavoidably, with no offsetting upside.
  • Abusive practices: conduct that "materially interferes" with a person's ability to understand a product's terms, or that "takes unreasonable advantage of" a consumer's lack of understanding, inability to protect their own interests, or reasonable reliance on the business to act in good faith.

If that language sounds familiar, it should. It's modeled almost word-for-word on the federal "UDAAP" standard (Unfair, Deceptive, or Abusive Acts or Practices) that the Consumer Financial Protection Bureau has used against banks and lenders for over a decade. New York just imported it wholesale and applied it to every business operating in or marketing to the state, not just regulated financial institutions.

The Part Almost Nobody Is Talking About: It Protects Small Businesses Too

Here's the detail buried in the legal analysis that deserves top billing for this site's readers: the FAIR Act extends GBL Section 349's protections to "businesses and non-profits," not just individual consumers. The legislature's reasoning was straightforward — a five-person accounting firm signing a SaaS contract or a solo bookkeeper taking out equipment financing is often just as vulnerable to fine-print tricks as an individual consumer is.

Practically, that means a small business victimized by a predatory vendor contract, a payment processor burying fees in unreadable terms, or a B2B lender using dark-pattern renewal tactics may now have a claim under the same statute that protects retail shoppers. If you've ever felt like a "business customer" got zero protection compared to a "consumer," that gap just narrowed — at least in New York.

Who Enforces It, and What It Costs

The FAIR Act splits enforcement cleanly in two:

  • Unfair and abusive claims: only the New York Attorney General can bring these. There's no new private right of action for the expanded categories.
  • Deceptive claims: individuals and businesses retain the existing private right to sue, unchanged.

When the AG does act, the penalties are real: up to $5,000 per violation, or — for willful violations — the greater of $15,000 or three times restitution. Multiply either figure by a customer list, a subscriber base, or a batch of near-identical contracts, and a single sloppy policy can turn into a genuinely large number very quickly.

There is one meaningful safety valve: a compliance defense exists for businesses that are already subject to, and complying with, a relevant federal regulatory regime. If your conduct is squarely governed by an applicable federal rule and you're following it, that can insulate you from a parallel state claim.

Where the Attorney General Is Already Looking

Early guidance and law-firm commentary point to the sectors and practices getting the closest scrutiny first:

  • Auto, student loan, and mortgage lending and servicing
  • Healthcare billing practices
  • Insurance sales and claims handling
  • Subscription and "negative option" services — anything that auto-renews or auto-charges unless the customer actively cancels
  • AI-driven pricing and algorithmic decision-making
  • Marketing materials aimed at non-English speakers
  • Chatbot-driven sales tactics that could be read as manipulating a vulnerable user

Notice how many of these apply to completely ordinary small businesses, not just banks. If you run a subscription box, a SaaS product, a membership-based service, or anything with an auto-renewal clause, you're squarely in the Attorney General's stated enforcement priorities — regardless of your revenue size.

Does This Apply If You're Not Based in New York?

Yes — and this is the detail that trips up out-of-state founders every time a state passes a new consumer-protection law. GBL Section 349 has always applied based on where the consumer is, not where the business is incorporated or headquartered. If you sell a subscription, a course, a financing product, or a SaaS seat to someone in New York, New York law reaches that transaction regardless of your company's home state.

For a business with customers spread across the country, that means a single unfair-terms audit shouldn't stop at "we're not a New York company, so we're fine." If any meaningful share of your customer base is in New York — or if your marketing specifically targets New York consumers — the FAIR Act's unfair and abusive standards apply to those transactions today.

A Concrete Example: The Subscription Renewal Trap

Picture a small software company offering a monthly plan with a "50% off your first three months" promotion. The signup flow is a single click. But canceling requires finding a hidden settings menu, then confirming through a multi-step "are you sure" sequence designed to induce fatigue, before finally reaching a support email that takes two business days to respond.

Under the old deceptive-practices standard, this company was probably safe — nothing in the marketing was false, and the discount was real. Under the FAIR Act, that exact same flow is a textbook example of an "abusive" practice: it takes unreasonable advantage of the friction between an easy sign-up and a deliberately hard cancellation, and it materially interferes with a customer's ability to act on their own understanding that the discount period was ending. No lie was ever told, and the company can still be on the wrong side of the law.

This is exactly why the compliance checklist below starts with mapping the entire customer journey rather than just checking your marketing copy for accuracy. Accuracy was the old bar. Friction, asymmetry, and hidden difficulty are the new one.

A Practical Compliance Checklist

Legal commentary on the FAIR Act converges on a few concrete steps that any business selling into New York should walk through:

  1. Map the full customer journey. Discovery, sign-up, ongoing use, billing, and cancellation each need a fresh look — "unfair" and "abusive" conduct can show up at any stage, not just at the sale.
  2. Audit clarity, not just accuracy. A term can be 100% true and still be "abusive" if it's buried, jargon-heavy, or structured to be missed. Ask whether a non-lawyer would actually understand the terms without help.
  3. Verify explicit consent, not constructive notice. "It was in the terms of service" is a weaker defense than it used to be. Where it matters — price changes, renewal terms, fee structures — get an active, documented yes.
  4. Make cancellation as easy as sign-up. Negative-option and subscription services are named explicitly as an enforcement priority. If sign-up is one click and cancellation is a phone call during business hours, that asymmetry is exactly the kind of "unreasonable advantage" the statute targets.
  5. Check non-English materials for consistency. If your Spanish-, Chinese-, or Korean-language marketing says something materially different from your English terms, that's now a named enforcement priority, not a hypothetical risk.
  6. Document your AI and algorithm logic. If pricing, credit decisions, or recommendations are automated, keep a written rationale and add human review — "we don't know why the algorithm did that" is not a defense anyone wants to test in front of the AG's office.
  7. Tighten vendor and platform oversight. If a third-party processor or affiliate handles part of your customer relationship, their unfair or abusive conduct can become your legal exposure.

A law about "unfair and abusive" business conduct might look like a pure legal-compliance issue, but it lands squarely on your financial records too. Auto-renewal terms, subscription pricing tiers, and fee disclosures aren't just legal language — they're the exact line items that show up in your revenue recognition, deferred revenue, and refund reserves. If an auditor, a regulator, or your own accountant can't quickly reconstruct what you charged whom, when, and under what terms, you can't demonstrate the transparency this law now demands.

This is where clean, auditable bookkeeping stops being a nice-to-have. A ledger where every subscription charge, renewal, refund, and fee is recorded as a discrete, timestamped transaction — rather than buried in a payment processor's monthly net deposit — gives you a paper trail that matches the "explicit, documented consent" standard regulators are now asking for. It also makes the compliance audit in the checklist above dramatically faster, because you're not reconstructing history from bank statements after the fact.

Keep Your Records as Transparent as the Law Now Requires

As New York (and likely other states watching this bill closely) raises the bar on what counts as fair dealing with customers, the businesses best positioned to prove compliance are the ones whose financial records were already clear, complete, and easy to audit. Beancount.io provides plain-text, version-controlled accounting that gives you a transparent, auditable history of every transaction — no black box, no vendor lock-in, and no scrambling to reconstruct what a customer was actually charged. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article