IOanyT Innovations

Lesson 8 of 10 · 8 min read

AI washing: what regulators have penalised

In one paragraph

AI washing means making false or unsubstantiated claims about how much, or how well, a product or company uses AI. US regulators have acted on it: the SEC settled with two investment advisers in March 2024, and the FTC launched Operation AI Comply in September 2024. The lesson for any business is to hold evidence before making an AI claim.

In this lesson

  • Describe the SEC and FTC actions that defined 'AI washing'
  • Recognise the claim patterns regulators have challenged
  • Apply a simple substantiation routine before publishing an AI claim

The video version of this lesson is in production. The full lesson is below.

Lesson 7 was about what your AI tells customers. This lesson is about what you tell the world about your AI. Regulators have made clear that the usual rules for marketing claims apply in full.

This lesson is a summary for orientation, not legal advice.

The SEC’s first “AI washing” cases

On 18 March 2024, the US Securities and Exchange Commission announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of AI. Delphia paid a $225,000 civil penalty and Global Predictions $175,000.

The SEC’s concern was simple: the firms made claims about using AI in their investment processes that they couldn’t substantiate. Global Predictions, for example, had described itself as the first regulated AI financial adviser.

The FTC’s Operation AI Comply

On 25 September 2024, the US Federal Trade Commission announced Operation AI Comply, five law-enforcement actions against companies using AI hype to deceive consumers or selling AI tools that enabled deception.

One target was DoNotPay, which had marketed “the world’s first robot lawyer”. The FTC alleged the company hadn’t tested whether its output matched a human lawyer’s and hadn’t retained attorneys. DoNotPay agreed to pay $193,000 and to notify past subscribers about the service’s limitations.

Accuracy claims: Workado

In 2025, the FTC reached an order with Workado, whose AI content detector had been promoted as “98 percent” accurate. According to the FTC, independent testing found accuracy of 53 percent on general-purpose content. The order bars accuracy claims unless Workado holds competent and reliable evidence that the product performs as claimed.

The patterns regulators challenge

  • Unsupported numbers, especially accuracy and performance percentages.
  • “First” and “only” claims that can’t be proven.
  • Replacement promises (“replaces a lawyer”, “replaces your team”) without testing.
  • Overstating how much AI is involved, or claiming AI where there is little or none.

Note what’s not on the list: describing what a product does, plainly and accurately.

A substantiation routine

Before any AI claim goes on a website, in a deck or in a filing:

  1. Write the claim exactly as it will appear.
  2. Define the test that would prove or disprove it.
  3. Run it on realistic data, not a hand-picked demo.
  4. Keep the evidence: date, method, result, owner. Keep it for as long as the claim is in use.
  5. Publish wording that matches the result, or soften the claim until it does.

Many teams keep a claims register, one row per public claim with its evidence, test date and owner, and review it before every campaign.

Wording that ages well

RiskySafer
”100% accurate”, “zero errors""Accuracy measured on your data before go-live"
"Guaranteed compliant""Designed to support your compliance work"
"Replaces your team”Describe the specific task and the measured result
”The first AI platform for…”Drop it unless you can prove it

Try it yourself: audit three claims

Find three AI claims your organisation makes publicly. For each, ask: what evidence would we show a regulator tomorrow? If the answer is “none” or “a demo”, soften the claim or run the test.

What comes next

Lesson 9 covers the regulation many AI buyers and builders now plan around: the EU AI Act.

Before you publish an AI claim The discipline regulators now expect: evidence first, claim second. 1: Write the claim — exactly as it, will appear. 2: Define the test — what would prove, or disprove it. 3: Run it — on realistic data,, not a demo. 4: Keep the evidence — date, method,, result, owner. 5: Publish or soften — match the words, to the result. IOANYT ACADEMY / LESSON 8 Before you publish an AI claim The discipline regulators now expect: evidence first, claim second. 01 Write the claim exactly as itwill appear 02 Define the test what would proveor disprove it 03 Run it on realistic data,not a demo 04 Keep the evidence date, method,result, owner 05 Publish or soften match the wordsto the result keep the evidence for as long as the claim is in use

Key takeaways

  • Regulators treat AI claims like any other marketing claim: they need evidence.
  • Accuracy percentages are a common target. One company claimed 98%; testing found 53%.
  • 'Robot lawyer'-style promises without testing invite action.
  • Keep a claims register: every public claim, its evidence, test date and owner.

Check yourself

Pick an answer, then open the card to compare.

  1. 1. What did the SEC's March 2024 cases against Delphia and Global Predictions concern?

    • A.Data breaches
    • B.False and misleading statements about their use of AI
    • C.Late tax filings
    Show the answer

    B. False and misleading statements about their use of AI The SEC alleged both investment advisers made AI claims they couldn't substantiate.

  2. 2. In the FTC's case against Workado, what was claimed versus found?

    • A.Claimed 98% accuracy; independent testing found 53% on general-purpose content
    • B.Claimed 53%; found 98%
    • C.Claimed 100% uptime; found 90%
    Show the answer

    A. Claimed 98% accuracy; independent testing found 53% on general-purpose content The order requires Workado to hold competent and reliable evidence before making accuracy claims.

  3. 3. What is the safest order of work for an AI claim?

    • A.Publish, then test if challenged
    • B.Define the test, run it on realistic data, keep the evidence, then publish wording that matches the result
    • C.Use 'up to' in front of any number
    Show the answer

    B. Define the test, run it on realistic data, keep the evidence, then publish wording that matches the result Evidence first, claim second, and keep the evidence for as long as the claim is in use.

Common questions

Do these rules apply outside the US?

These cases are US actions, but most jurisdictions have consumer-protection and advertising rules that require claims to be truthful and substantiated. Take advice for your own markets.

Are words like 'AI-powered' risky?

The risk is in specific, checkable claims that aren't true or can't be backed up: accuracy figures, 'first', 'replaces a lawyer', or how much AI a product really uses. Describe what the product does and keep evidence for any number.

What about claims a client repeats to its own investors?

That's a reason vendors should be careful. If a client repeats your AI claim in its own filings or pitch, your evidence becomes their evidence.