AI-Washing Compliance in 2026: SEC, FTC, and State Enforcement Against Exaggerated AI Claims
The SEC brought its first AI-washing cases in March 2024, the FTC launched Operation AI Comply in September 2024, and Texas TRAIGA creates new state-level disclosure rules effective January 2026. Here's what in-house counsel must do now.
If your company's marketing materials, SEC filings, or investor communications describe AI capabilities that exceed what your product actually does, you are exposed to enforcement from at least three directions — and most in-house counsel have not yet mapped the full perimeter. The SEC, FTC, and state regulators are each independently scrutinizing exaggerated AI claims, using different legal authorities, targeting different types of statements, and imposing different penalties. The risk surface is no longer theoretical: the SEC brought its first AI-washing cases in March 2024, the FTC launched an enforcement sweep in September 2024, and Texas's TRAIGA creates a new state-level disclosure regime effective January 1, 2026.
This guide walks through each enforcement layer, what the regulators have already done, and the practical compliance framework in-house counsel should build now — before an examiner, investigator, or state AG sends a letter. For related coverage, see our guide to AI vendor contract terms in-house counsel must negotiate and our analysis of EU AI Act compliance for US companies.
What Is "AI Washing" and Why Regulators Care Now
"AI washing" is the practice of making false, misleading, or unsubstantiated statements about a company's use of artificial intelligence. The term draws directly from "greenwashing" — the SEC's own analogy. Then-SEC Chair Gary Gensler stated plainly when announcing the first enforcement actions: "Everyone may be talking about AI, but when it comes to investment advisers, broker dealers, and public companies, they should make sure that what they say to investors is true."
The regulatory concern is straightforward: between 2023 and 2025, companies engaged in an AI marketing arms race, branding products as "AI-powered," "machine-learning driven," or "first regulated AI financial advisor" to attract investors, customers, and talent. Many of those claims outpaced the underlying technology. Regulators are now catching up, and the enforcement perimeter is expanding beyond investment advisers to public companies, consumer-facing brands, and any entity that deploys AI systems in states with AI-specific legislation.
The SEC's AI-Washing Enforcement Actions: Delphia and Global Predictions
On March 18, 2024, the SEC announced its first-ever AI-washing enforcement actions against two registered investment advisers: Delphia (USA) Inc. and Global Predictions Inc. Both settled without admitting or denying the charges.
Delphia: $225,000 Penalty
The SEC found that between 2019 and 2023, Delphia made repeated false and misleading statements about its use of AI and machine learning. The firm claimed in press releases, website content, and Form ADV brochures that it used "proprietary algorithms" to "make predictions across thousands of publicly traded companies up to two years into the future" and that it "put[s] collective data to work to make our artificial intelligence smarter." In reality, Delphia had never developed these capabilities — it collected some client data intermittently but never used AI or machine learning in its investing algorithms. The SEC charged Delphia with violating Section 206(2) of the Investment Advisers Act (an anti-fraud provision) and the Marketing Rule under Section 206(4). The firm paid a $225,000 civil penalty.
Global Predictions: $175,000 Penalty
Global Predictions was charged with similar violations. The firm's website claimed its technology incorporated "expert AI-driven forecasts" — which, according to the SEC, it did not. Global Predictions also described itself as the "first regulated AI financial advisor" but could not produce documents to substantiate that claim. The SEC charged violations of Sections 206(2) and 206(4) of the Advisers Act and the Marketing and Compliance Rules. Global Predictions paid a $175,000 civil penalty.
The critical takeaway for in-house counsel: the SEC did not need new AI-specific rules to bring these cases. It used existing anti-fraud provisions, the Marketing Rule, and fiduciary duty principles that already apply to registered entities. As the Morgan Lewis analysis noted, "the Division of Enforcement doesn't need to wait for the Commission to finalize rules specific to data analytics and AI to bring enforcement actions." For public companies not registered as investment advisers, the SEC can pursue AI-washing claims using the antifraud provisions of the Securities Exchange Act and the Securities Act.
SEC 2025 Exam Priorities and Ongoing Scrutiny
The SEC's 2025 Examination Priorities report, published in October 2024, explicitly identified AI-washing as an examination focus area. The Division of Examinations flagged both the use of AI in investment decision-making and the accuracy of AI-related disclosures in marketing materials and regulatory filings as priority review topics. This means SEC examiners are actively testing whether registrants' AI claims match their actual practices during routine examinations — not just in enforcement-led investigations.
The practical implication for in-house counsel at SEC-registered entities (investment advisers, broker-dealers, and public companies) is that AI-washing scrutiny is now embedded in the examination cycle. Companies should expect examiners to ask: What AI claims appear in your marketing materials? Can you substantiate each claim with evidence? Do your Form ADV disclosures, 10-K risk factors, and public statements about AI use align with your actual technology stack?
FTC Section 5 and False AI Marketing Claims
The FTC's enforcement authority over AI claims flows from Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. The FTC's position is clear: false or unsubstantiated claims about AI capabilities are deceptive under Section 5, just as false claims about any product feature would be.
In September 2024, the FTC launched Operation AI Comply, an enforcement sweep against companies that "relied on artificial intelligence as a way to supercharge deceptive or unfair conduct." The sweep included five enforcement actions:
- DoNotPay, Inc. — Settled for $193,000 after the FTC alleged the company promised its AI chatbot could replace a human lawyer but did not conduct testing to verify that claim. The settlement prohibits DoNotPay from making claims about its ability to substitute for professional services without supporting evidence.
- Rytr LLC — Charged with violating the FTC Act by providing consumers with the means to generate false and deceptive online reviews using AI.
- Ascend Capventures, FBA Machine, and Empire Holdings Group — Federal courts issued orders halting schemes that allegedly used AI hype and false earnings claims to attract investors.
The FTC's guidance, reinforced through these actions, establishes that companies must base AI claims on "competent and reliable evidence (i.e., tests, analyses, research and studies) created according to generally accepted standards in the relevant field." The FTC also recommends vetting third-party AI incorporated into products, implementing testing and risk assessments before deployment, and monitoring for "drift" in AI model behavior.
For in-house counsel, the FTC's framework means that marketing claims like "AI-powered," "machine learning optimized," or "the first AI-driven platform" must be backed by evidence that would withstand FTC scrutiny. A vendor's marketing assertion is not substantiation. A capability you plan to build is not a current capability you can advertise.
State Enforcement Layer: Texas TRAIGA and State AGs
Beyond federal regulators, state attorneys general are building their own AI enforcement frameworks. The most consequential for companies operating in Texas is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), signed into law as House Bill 149 on June 22, 2025, with an effective date of January 1, 2026.
TRAIGA applies to any person who promotes, advertises, or conducts business in Texas, produces a product or service Texas residents use, or develops or deploys an AI system in Texas. The law defines "artificial intelligence system" broadly as "any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments."
TRAIGA Disclosure Requirements
Government agencies must disclose to consumers before or at the time of interaction that they are interacting with AI. The disclosure must be clear, conspicuous, written in plain language, and may not use dark patterns. While this disclosure obligation currently applies to government entities, it establishes a transparency baseline that private deployers should monitor — particularly companies deploying AI chatbots, customer service agents, or automated decision systems that interact with Texas consumers.
TRAIGA Penalties and Enforcement
The Texas Attorney General has exclusive enforcement authority under TRAIGA. There is no private right of action. Before filing an enforcement action, the AG must send a written notice of violation and provide a 60-day cure period. Civil penalties are tiered:
- Curable violations: $10,000–$12,000 per violation
- Uncurable violations: $80,000–$200,000 per violation
- Ongoing violations: $2,000–$40,000 per day
TRAIGA also provides a safe harbor: a person is not liable if they substantially comply with the NIST AI Risk Management Framework or similar recognized standards. This makes NIST AI RMF alignment a business decision, not just a governance preference — it is your safe harbor evidence.
Other states are moving in parallel. California, Colorado, and Utah have each passed AI-related legislation, and multiple state AGs have signaled willingness to use existing consumer protection authority to pursue deceptive AI marketing claims. The state enforcement layer adds geographic complexity: a company's AI claims must satisfy not just federal regulators but the consumer protection standards of every state where it has customers.
A Compliance Framework for In-House Counsel
Given the overlapping enforcement layers, in-house counsel should build a compliance program that addresses all three simultaneously. Here is the framework we recommend:
1. Conduct an AI Claims Audit
Inventory every public statement your company makes about AI — website copy, marketing materials, press releases, investor presentations, SEC filings, Form ADV disclosures, social media posts, product documentation, and customer-facing communications. For each claim, ask three questions:
- Can we substantiate this claim with evidence (test results, documentation, technical specifications)?
- Does the claim describe a current capability or a future aspiration? If future, it must be clearly labeled as such.
- Would the claim survive scrutiny from an SEC examiner, an FTC investigator, or a state AG?
Flag any claim that cannot be substantiated and route it to the relevant business team for correction or removal.
2. Align SEC Filings with Actual AI Use
For SEC-registered entities and public companies, review your 10-K risk factors, MD&A, and any AI-related disclosures against your actual technology stack. The SEC's 2025 exam priorities mean examiners are actively testing this alignment. If your risk factors describe AI capabilities that your product does not yet have, or if your marketing materials tout AI features that your filings do not address, you have created an inconsistency that examiners will flag.
3. Implement an AI Claims Substantiation Process
Following the FTC's framework, establish an internal process requiring that any AI-related marketing claim be backed by "competent and reliable evidence" before publication. This process should include:
- Technical review: engineering or data science confirms the claimed capability exists and functions as described
- Legal review: counsel confirms the claim is accurate, not misleading, and appropriately scoped
- Documentation: retain the evidence supporting each claim in a centralized file that can be produced in response to a regulatory inquiry
4. Assess TRAIGA and State Law Applicability
If your company conducts business in Texas or serves Texas residents, evaluate whether TRAIGA applies to your AI systems. If you deploy AI chatbots, automated decision systems, or any AI that interacts with consumers, assess your disclosure obligations. Consider aligning your AI governance with the NIST AI Risk Management Framework to qualify for TRAIGA's safe harbor. For broader state law compliance, see our TRAIGA compliance guide for Texas AI companies.
5. Build a Cross-Regulator Response Plan
Because the SEC, FTC, and state AGs can each independently investigate AI-washing claims, your response plan should account for parallel inquiries. Designate a primary response lead (typically the GC or Chief Compliance Officer), establish protocols for preserving AI-related documentation, and prepare template responses for common regulatory inquiries. If your company faces simultaneous SEC and FTC interest, coordination is essential — statements to one regulator may create exposure with another.
Actionable Next Steps
- Run an AI claims audit this quarter. Map every public AI claim across all channels — marketing, filings, investor materials, social media. Flag claims that lack substantiation evidence and prioritize correction.
- Review SEC filings for AI-washing risk. If your company is SEC-registered or public, compare your 10-K risk factors, MD&A, and Form ADV disclosures against your actual AI capabilities. Eliminate inconsistencies.
- Establish a substantiation gate. Require that every new AI-related public claim pass through a documented review process — technical verification, legal review, and evidence retention — before publication.
- Assess TRAIGA applicability before January 1, 2026. If you operate in Texas, determine whether your AI systems trigger TRAIGA's disclosure requirements and whether NIST AI RMF alignment is your safe harbor strategy.
- Brief your board on AI-washing exposure. The combination of SEC, FTC, and state enforcement creates a multi-front risk that board members and executive leadership should understand. Quantify the exposure and present the mitigation plan.
- Engage outside counsel for a compliance review. The cost of a proactive AI-washing compliance assessment is a fraction of the cost of a single enforcement action. We help in-house counsel audit claims, align filings, and build cross-regulator response frameworks before an inquiry arrives.
AI-washing enforcement is not a future risk. The SEC has already brought cases. The FTC has already launched enforcement sweeps. Texas TRAIGA takes effect in January 2026. The companies that audit their AI claims now, align their filings with their actual capabilities, and build a substantiation process into their marketing workflow will face these regulators with confidence. The companies that wait will hear from an examiner, investigator, or AG first — and the cost of responding after the fact will dwarf the cost of getting ahead of it.
Facing overlapping SEC, FTC, and state AI-washing enforcement risk? We help in-house counsel audit AI claims, align regulatory filings, and build cross-regulator compliance frameworks before an inquiry arrives.