An AI tool can build your app in a weekend. It won't tell you that the app breaks laws that apply from the first user who signs up. Prompts ask for features, and compliance is never a feature anyone asks for, so it doesn't get built.
Most of these problems are cheap to fix before launch and expensive after. Here are the ten we see most often in AI-built apps, what each law actually says, and what to change. The figures are maximums and real cases, not what every small app will face, but they show why regulators and plaintiffs' lawyers care.
This is general information for builders, not legal advice. Laws differ by country and state and change often. Talk to a lawyer about your specific app before you launch.
1. Your database is open to the internet
The most common problem is also the most serious. Supabase and Firebase apps talk to the database straight from the browser, which is safe only when row-level security or security rules decide who can read what. AI tools often leave those off, write policies that allow everyone, or put secret keys in frontend code.
In 2025, security researchers scanned 1,645 apps from Lovable's public showcase and found 170 of them exposing user data this way, including emails, phone numbers, payment details and API keys. The issue was published as CVE-2025-48757.
A leak isn't only embarrassing. All 50 US states have data breach notification laws, and in Europe GDPR has its own breach rules. If exposed data includes the kinds of information those laws cover, you may have to notify users and regulators, on a deadline.
Fix: turn on row-level security for every table, write policies that check the signed-in user, keep service keys on the server, and test by requesting data as an anonymous user. Our Supabase row-level security guide covers the common mistakes.
2. No privacy policy
California's Online Privacy Protection Act requires a privacy policy from any commercial website or online service that collects personal information from California residents, which in practice means almost every app. The state Attorney General can seek civil penalties of up to $2,500 per violation under California's unfair competition law, and has sued a major airline over a missing app privacy policy.
The platforms enforce it too. Apple's App Store, Google Play and Google's sign-in verification all require a privacy policy link, and will reject or limit your app without one.
Fix: write a policy that matches what your app actually collects, including analytics, error tracking and AI providers. Link it in the footer, at signup and inside the app. A template that lists data you don't collect, or misses data you do, is its own problem.
3. Children on your app
In the US, COPPA applies if your app is directed at children under 13, or if you know a particular user is under 13. Before collecting any personal information from them you need verifiable parental consent, and personal information includes cookies and device identifiers, not just names and emails. Civil penalties are up to $53,088 per violation. An updated COPPA Rule took effect in 2025, with full compliance required since April 2026.
Fix: if your app could attract children, add a neutral age question (one that doesn't hint at the right answer), and have a plan for under-13s: block them, or build a proper consent flow. Keep tracking and advertising tools off anything aimed at kids.
4. Session replay recording everything
Session replay tools record clicks, scrolling and typing so you can watch how people use your app. AI tools add them happily. In California, recording visitors' interactions with a site without consent has led to a wave of lawsuits under the state's Invasion of Privacy Act, which allows $5,000 per violation.
California narrowed one part of that law in 2026, removing private lawsuits for a type of tracking claim known as pen-register claims. Claims under the wiretap section, the ones usually brought against session replay and chat recording, were left untouched.
Fix: load session replay only after consent, mask every input by default, and never record payment, health, password or chat fields.
5. Pixels on health data
Advertising pixels from Meta, Google, TikTok and others send page and event data back to those companies. On a symptom tracker, therapy signup or medical intake form, that can mean sharing health information with advertisers.
The FTC has acted on exactly this. GoodRx paid a $1.5 million civil penalty in 2023 for sharing users' health information with advertising platforms, the first case under the Health Breach Notification Rule. BetterHelp agreed to pay $7.8 million to refund consumers after sharing mental health questionnaire data for advertising.
Fix: keep advertising pixels off any page that touches health, and check what your analytics and tag manager send from forms. If you handle health data for healthcare providers, US HIPAA rules may apply as well.
6. Marketing emails with no unsubscribe or address
Under the US CAN-SPAM Act, every commercial email needs a working unsubscribe link and your valid physical postal address, and opt-outs must be honored within 10 business days. Each email that breaks the rules can cost up to $53,088. There's no exception for business-to-business email.
Fix: send marketing through a provider that adds unsubscribe links and handles opt-outs automatically, include a postal address (a registered PO box or mailbox service counts), and keep marketing separate from transactional email such as receipts and password resets.
7. Auto-renewal terms hidden under the Pay button
Subscription apps are a favorite of regulators. California's automatic renewal law, tightened in July 2025, requires renewal terms to be clear and conspicuous and placed right next to where the customer agrees, express consent to the renewal, a confirmation, and a way to cancel online if they signed up online.
The FTC's nationwide click-to-cancel rule was struck down by a federal appeals court in 2025, but the older federal law it built on still applies. In 2025 Amazon agreed to pay $2.5 billion, a $1 billion civil penalty and $1.5 billion in refunds, to settle FTC claims over how it enrolled people in Prime and made cancelling hard.
Fix: show the price, billing period and renewal terms next to the payment button, send a confirmation email with how to cancel, and give users a cancel button in their account settings.
8. Your chatbot never says it's AI
From 2 August 2026, the EU AI Act requires AI systems that interact with people to make it clear they're talking to an AI, unless that's obvious. Breaking the AI Act's transparency rules can mean fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
California adds rules for companion chatbots, the ones built for ongoing personal conversation rather than customer service. Since January 2026 they must disclose they're AI where a person could think otherwise, and people harmed can sue for $1,000 per violation.
Fix: say it's an AI assistant in the first message and near the chat box. It costs one sentence.
9. No alt text, no labels, no keyboard navigation
Accessibility lawsuits are common in the US. 3,117 website accessibility lawsuits were filed in federal courts in 2025, up 27% from 2024, according to Seyfarth Shaw's count, and that excludes state courts. In Europe, the European Accessibility Act now applies to many consumer digital services.
AI-generated interfaces often miss the basics: images without alt text, inputs without labels, buttons made from divs that a keyboard can't reach, and low-contrast text.
Fix: aim for WCAG 2.1 AA. Add alt text and form labels, use real buttons and links, make sure everything works with a keyboard, and check contrast. Automated checkers find a good share of issues in minutes.
10. Users upload content, but there's no DMCA agent
If users can upload files, images or posts, the US DMCA safe harbor protects you from copyright claims over what they upload, but only if you register a designated agent with the Copyright Office and respond to takedown notices. Registration costs $6 and lasts three years; let it lapse and you can lose the protection. Without it, statutory damages for willful infringement can reach $150,000 per work.
Fix: register an agent, publish a copyright or DMCA page explaining how to send a notice, and build a simple way to take content down.
Audit prompt to run before you ship
Paste this into your AI coding tool with the whole codebase in context. Treat the answers as a starting checklist, not a guarantee: the tool can miss things, just as it did when it wrote the code.
Audit this codebase for legal and security gaps and list each one with file and line:
1. RLS enabled on every table, no secrets in client code
2. Privacy policy page that matches what we actually collect, linked in the footer, at signup and in the app
3. Neutral age gate if the app could attract under-13s, and a path to handle them
4. No analytics, session replay or pixels before consent, and never on form, chat, payment or health fields
5. Every marketing email has an unsubscribe link and a postal address, opt-outs honored within 10 business days
6. Subscription terms next to the pay button, a confirmation email, one-click online cancellation
7. Chatbot discloses it's AI in its first message
8. WCAG 2.1 AA basics: alt text, labels, keyboard navigation, contrast
9. DMCA page and registered agent if users can upload content
10. Every third-party script and font listed, self-hosted where possibleAI made building fast. Getting an app safely into production is still a separate job.
Deeraf's Tech Check reviews an AI-built app's security, data handling, tracking scripts, accessibility basics and launch readiness, and gives you a fixed-price fix plan. For the legal side, work with a lawyer; we make the code match what they advise.