AI Washing Enforcement: Why Unbacked Claims Are Now a Liability
How regulatory bodies are auditing misleading AI claims, and what legal teams must document to prove real model deployment.
The first enforcement cases were not about rogue models. They were about companies describing AI they did not have. Boards should assume their own claims will be read the same way.
On 18 March 2024 the U.S. Securities and Exchange Commission announced settled charges against two investment advisers for false and misleading statements about artificial intelligence. Delphia (USA) Inc. and Global Predictions Inc. agreed to pay $400,000 in total civil penalties. The Commission’s press release is short. The facts are the whole lesson.
Delphia, the order found, had claimed from 2019 into 2023 — in filings, a press release, and on its website — that it used AI and machine learning on client data to predict which companies and trends would “make it big”. It did not have those capabilities. It had even agreed, after an examination, to correct the statements, and further misleading claims continued. Global Predictions had called itself the “first regulated AI financial advisor” and advertised “expert AI-driven forecasts”. Those claims were false. Both firms were also charged under the marketing rule, which prohibits advertisements that include an untrue statement of material fact.
This is not a science-fiction enforcement theory. It is advertising law applied to a fashionable noun. Any company that tells investors, customers, or its own board that AI is doing a job should be able to point at the job.
| Firm | What it told the market | What the order found | Civil penalty |
|---|---|---|---|
| Delphia (USA) Inc. | AI and machine learning on client data would predict which companies and trends “make it big”, in filings, a press release, and on the website, from 2019 into 2023 | It did not have those capabilities. Misleading statements continued after it agreed, following an examination, to correct them | $225,000 |
| Global Predictions Inc. | “First regulated AI financial advisor”; “expert AI-driven forecasts” | The claims were false | $175,000 |
Both were also charged under the marketing rule: an advertisement may not include an untrue statement of material fact. The exhibit was the description, not a model card.
The claim is now part of the control environment
For a decade, “we use AI” was a flourish. It sat in a keynote and a recruiting page. Enforcement has moved it into the same family as performance claims. The Federal Trade Commission warned in February 2023 that it would look at exaggerated AI marketing: claims of a product being AI-powered when the automation is banal, claims that AI is more accurate or fair than a person without evidence, and claims that quietly overstate what the system can do. The vocabulary varies. The test does not. If you would not put the sentence in a footnote with a method attached, do not put it in the headline.
Operating companies sometimes assume this is an asset-manager problem. It is not. A retailer that tells the market its service operation is “AI-run” while humans still handle the exceptions that generate the complaints is making a claim about the business, not about a model. A manufacturer that tells customers its quality system is “AI-assured” while the model only drafts a shift report is doing the same. The SEC cases happened to arise under the Advisers Act. The underlying mismatch — words ahead of the system — is available to every industry that publishes.
| Where the sentence appears | What a reader is entitled to assume | What often turns out to be true | What to write instead |
|---|---|---|---|
| Keynote or recruiting page | A capability is already in production | A pilot, a vendor demo, or a plan | The tense you can defend this week |
| Customer proposal | The control described is the control they will get | “Human in the loop” means a digest the next morning | The actual checkpoint: who sees which words, and when |
| Risk factor or annual report | The exposure is specific enough to govern | A peer’s sentence about hallucinations “may” occur | Which customer process is exposed, and what the human check is |
What a board should inventory before the next letter to shareholders
Read the last annual report, the last customer proposal, and the last all-hands as if you were an examiner. Highlight every sentence in which AI is the subject of a verb that implies a capability: decides, predicts, detects, prevents, personalises, assures, autonomously resolves. For each sentence, name the system, the data it actually sees, the human who can override it, and the metric that would falsify the sentence.
You will find three kinds of claim.
Aspirational, labelled as current. The roadmap has been written in the present tense. This is the Delphia pattern: a future model described as a present process, including after someone inside the firm knew the description was wrong. The corrective is dull and effective. Change the tense. “We intend” is not a confession. “We do” without a system is.
Real, but narrower than the adjective. A model ranks tickets. The website says it “resolves” them. A model drafts a forecast commentary. The earnings script says the outlook is “AI-generated”. Narrow claims survive. Inflated ones become exhibits.
Unreconstructable. Nobody can show an example. The team that built the demo has left. The log was not retained. This is the dangerous category, because the company cannot even retreat honestly. NIST’s framework assumes an organisation can map the AI systems it runs. If you cannot map them, you cannot describe them, and you should stop describing them until you can.
| Kind of claim | How you recognise it | What an examiner will do with it | The corrective this week |
|---|---|---|---|
| Aspirational, written as current | Present tense for a system that is still a roadmap | Treat the future as a statement of fact | Change the tense. “We intend” is allowed. “We do” requires a system |
| Real, but narrower than the adjective | The verb is bigger than the workflow (“resolves” when the model ranks) | Compare the verb with one real transcript | Shrink the verb to the step the system actually performs |
| Unreconstructable | No example, no owner, no retained log | You cannot retreat honestly, because you cannot show what was true | Stop describing it until you can map it |
Disclosure is not the same as a press release
Public companies already face a more ordinary version of this test in risk factors and in the management discussion. The question from a sophisticated reader is no longer “do you use AI?” McKinsey’s 2025 survey suggests the answer is yes for nearly nine in ten organisations, at least in one function. The question is whether that use is material to results, to risk, or to the story you are telling about growth. A risk factor that says AI “may” hallucinate, copied from a peer, is less informative than a sentence that says which customer process is exposed and what the human check is.
Regulators outside the United States are building the same expectation into product law. The EU AI Act imposes transparency and, for higher-risk uses, documentation and oversight duties. The OECD AI Principles have said for years that actors should be transparent and accountable. Neither document requires a particular adjective in a Super Bowl spot. Both make it harder to pretend that capability claims are mere puffery once a system affects people.
There is also the internal version, which auditors will care about before any agency does. If the bonus scheme or the investor deck depends on an AI productivity number, the audit committee should ask who measured it and what was held constant. A vendor case study is not a measurement. The SEC’s marketing-rule theory in the adviser cases — you must be able to substantiate — is a sound house rule even when the statute does not reach you.
How claims go wrong in ordinary companies
Three patterns recur.
Inherited adjectives across subsidiaries. A subsidiary buys a tool and the parent’s communications team inherits the adjective. Nobody in the parent has seen the workflow. The sentence is written by someone rewarded for clarity, not for fidelity.
Generalising pilot results. Twenty users liked a drafting aid. The company announces that a function has been “transformed”. The quarterly numbers do not move. The next announcement is quieter, but the first one is still on the website, where a plaintiff’s lawyer or a journalist can find it. Reuters’ report on Alphabet’s February 2023 Bard demo — a factual error in a promotional video, and a market value swing measured in tens of billions of dollars in a single session — is a reminder that public AI claims are priced in real time. Most companies will not move a market. They can still move a customer’s trust or a regulator’s interest.
Implying automatic controls. “Human in the loop” appears in the proposal. On inspection, the human sees a batch the next morning, or sees only the cases the model was unsure about. That is a design. It may even be a good design. It is not the design the words implied. Write the design.
What to do before someone else reads the website for you
Appoint a single owner for outward AI claims. Not a committee that reviews tone. A person who can demand the artefact: a log, a policy, a named process owner. Give that person the right to strike a sentence.
Align the customer-facing bot with the claim. If you say the assistant follows policy, load the policy that is in force and keep the version. The Air Canada tribunal did not fine an adjective. It enforced an answer. Claims and answers are the same risk seen from the board and from the contact centre.
Retire the slide that says “AI-powered” with no noun after it. Powered to do what, for whom, with what stop? If the answer is “summarise internal documents for employees who already have access,” say that. Specificity is not modesty. It is how you stay out of a file named after your own marketing.
A sentence-by-sentence reading of your own site
Take the public pages that mention AI and read them as an examiner with no interest in your roadmap. Highlight every verb: “uses artificial intelligence to,” “powered by,” “predicts,” “ensures,” “the first,” “fully automated,” “bank-grade,” “human-level”. For each verb, write in the margin the artefact that makes it true this week: a log, a policy version, a model you actually call, a person who approves, a metric with a definition. If the margin is empty, the verb comes out. This is not a branding exercise. It is the exercise the SEC applied, in March 2024, to two investment advisers. The amounts are modest next to a franchise. The exhibit is the website.
Do the same for the product, not only the adjective. If the site says the assistant follows your policy, produce a current answer and the policy passage it used. If you cannot, you are one screenshot from a different kind of case, the kind where the words are enforced rather than fined as advertising. Air Canada’s chatbot told a traveller they could claim a bereavement fare after travelling; the tribunal held the airline to that answer. Marketing and the contact centre are the same risk team on the day the sentence is wrong.
The FTC’s instruction to keep AI claims in check is practical. Do not claim a capability you cannot demonstrate. Do not claim a control the product does not apply. Do not imply that a general-purpose model is a regulated fiduciary, a safety system, or a guarantee. Specificity is the defence. “Drafts a reply from the current return policy, which a person sends” is a claim you can live with. “AI-powered customer care” is a claim that will be filled in by the worst transcript.
Extend the reading to recruiting, lending, pricing, and fraud pages, and to the sales deck the field actually uses. Decks drift ahead of the product because they are edited locally. A local deck is still the company’s speech when a customer relies on it. Put the same owner on the deck and the site, with the right to strike a sentence without a steering committee. Committees protect tone. Owners protect verbs.
Then decide what you will not say while the programme is still a pilot. Most organisations are using the technology somewhere and have not scaled it. “We are piloting drafting on a defined class of tickets” is an accurate sentence and a dull one. Dull sentences do not attract the file. They also leave you room to promote the pilot later without having to walk back a superlative. The companies that get this right will sound, for a while, less ambitious than the companies that do not. That is the point.
Use the margin test before the next page ships. An empty cell is a verb that comes out, including on the field deck.
| Verb on the page | Artefact that makes it true this week | If the cell is empty |
|---|---|---|
| Predicts, detects, assures | The system, the data it sees, and the metric that would falsify the sentence | Delete or change to “we intend” |
| Ensures, fully automated, bank-grade, human-level | The control as it actually runs, not as the proposal described it | Strike the adjective. Write the design |
| AI-powered, the first | The noun: powered to do what, for whom, with what stop | Replace with the specific job |
| Follows our policy | A current answer and the policy passage it used, with the version kept | You are one screenshot from a case about the words, not the adjective |
| Human in the loop | Who sees the outbound sentence, and whether they see it before it is sent | If they see a digest the next morning, say that |
Strike the verb you cannot open
Read the public pages as an examiner. Every “predicts,” “ensures,” “fully automated,” and “AI-powered” needs an artefact in the margin this week: a log, a policy version, a person who approves. An empty margin means the verb comes out, including on the field deck. The settlements were about descriptions. The description you can live with is specific and dull. Dull is the defence.
A call to chief executives and general counsel
The first AI cases that stuck were about honesty. That should be a relief. You do not have to settle a philosophical argument about machine agency to comply. You have to describe what you run.
Go through the claims. Keep the ones you can demonstrate this week. Rewrite the ones that describe next year. Delete the ones nobody can explain. The companies that treat “AI” as a fact to be evidenced, rather than a mood to be signalled, will find the regulatory conversation boring. Boring is the point.
References
- U.S. SEC, false and misleading AI statements, 18 March 2024
- U.S. FTC, Keep your AI claims in check, 27 February 2023
- McKinsey, The State of AI: Global Survey 2025
- NIST AI Risk Management Framework
- Regulation (EU) 2024/1689
- OECD AI Principles
- Reuters, Alphabet shares dive after Bard error in a public demo
- Moffatt v. Air Canada, 2024 BCCRT 149
About Nimbus
Nimbus is a Collaborative AI Operating System built around four core pillars that bring human teams and autonomous AI together into a single, unified workspace.
Communication: Keep context tied to the job. Unify emails, meeting recordings, transcripts, and operational files directly within active projects—ending knowledge silos buried in private inboxes, scattered Slack threads, or unrecorded calls.
Collaboration: Work alongside AI in real time. Bring people and AI agents onto the exact same brief, visual canvas, or initiative. Query company-wide data, invite agents into live calls, and co-create in one shared space—eliminating the split between human group chats and isolated AI sidebars.
Automation: Put routine workflows on autopilot. Connect more than 2,000 enterprise tools and standardize repetitive operations. Background loops run on schedules or data triggers with full execution logs, ensuring operational knowledge is shared across the team rather than trapped in one person’s head.
Governance: Deploy AI with absolute control. Enforce strict role-based access controls across workspaces. AI agents can analyze, summarize, and draft—but no live system changes or external communications occur without explicit, verified human sign-off.
Claims, not model failures
What is AI washing?
Describing AI the company does not actually have. The first enforcement cases were about the claim, not about a rogue model.
What will a regulator ask?
What the system does, what data it uses, who is accountable, and whether the public description matches the product. Boards should assume their own claims will be read the same way.
Is a slide that says AI-powered enough to worry about?
Yes, if the feature is a rules engine, a human, or a vendor you do not control. The mismatch between the sentence and the system is the exposure.
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.