Written and maintained by CASRAI Editorial Board
Last updated
This page is not legal advice. It is a plain-language account of what two US agencies have actually charged over exaggerated AI marketing claims, and what an organisation can take from those pleadings as an internal control. Nothing below establishes a legal standard, and the enforcement record described here is US-specific. If your organisation is deciding whether a particular claim is safe to publish, that is a question for counsel admitted where you operate, not for a reference page. In NIKOLAI, CASRAI’s independent frontier-AI-safety dictionary, the closest concept is the Claim element on track N4 — an assertion that carries its own supporting evidence — and the enforcement record below is essentially what happens when an assertion ships without one.
Last verified: 25 September 2026, against the SEC’s press release of 18 March 2024 and the FTC’s Operation AI Comply announcement of 25 September 2024. Two of the FTC matters described below were proposed consent orders at announcement, subject to a 30-day public comment period; their final posture should be confirmed on the FTC’s own case pages before anyone relies on the terms as settled.
What “AI washing” actually means
“AI washing” is a market term, not a statutory one. It describes selling a product on an AI capability the product does not have, or has not been tested to have — the artificial-intelligence analogue of greenwashing. No US statute uses the phrase, no agency has defined it in a rule, and nobody has been charged with “AI washing” as such.
That is the first thing worth understanding about the enforcement record: every case below was brought under law that long predates the current generation of AI systems. The SEC used the Investment Advisers Act and the Marketing Rule. The FTC used its ordinary consumer-protection authority over deceptive acts and practices. Nothing here required an AI-specific statute to bite, which means the exposure exists today, in every jurisdiction with a general deception regime, regardless of how the pending AI legislation in any particular place turns out.
The second thing worth understanding is who was charged. These were not frontier laboratories, and the theories were not novel. They were ordinary sellers — two registered investment advisers, a consumer legal-services app, a writing tool, and three business-opportunity schemes — charged on the most conventional grounds available: they said the thing did something, and the agency alleged it did not.
The SEC’s March 2024 orders: Delphia and Global Predictions
On 18 March 2024 the SEC announced settled charges against two registered investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of artificial intelligence. Both firms were censured, both were ordered to cease and desist from the violations charged, and both paid civil penalties — $225,000 for Delphia and $175,000 for Global Predictions, $400,000 combined.
The quoted claims are worth reading closely, because they are unremarkable. Delphia said it would “put[] collective data to work to make our artificial intelligence smarter so it can predict which companies and trends are about to make it big.” Global Predictions billed itself as the “first regulated AI financial advisor” and advertised “[e]xpert AI-driven forecasts”; the SEC’s action against it also covered a separate false advertisement about tax-loss harvesting. The agency’s position was that the firms did not have the capabilities they advertised.
Then-SEC Chair Gary Gensler put the theory in one sentence: “Investment advisers should not mislead the public by saying they are using an AI model when they are not.”
The charging provisions matter for anyone in a regulated-marketing environment. This was not a products case or a suitability case. It was an advertising case, brought under the Advisers Act and the Marketing Rule, which governs what an adviser may say in a communication offering its services. In other words: the defect was in the copy, and the copy was the violation.
The FTC’s Operation AI Comply, 25 September 2024
Six months later the FTC announced Operation AI Comply, a coordinated sweep of five matters. Then-Chair Lina M. Khan framed it plainly: “Using AI tools to trick, mislead, or defraud people is illegal.” The five split into two very different groups.
Two cases about what an AI tool was claimed to do
DoNotPay marketed what it called “the world’s first robot lawyer.” The FTC’s complaint alleges that the company did not conduct testing to determine whether its AI chatbot’s output was equal to the level of a human lawyer, and that the company itself did not hire or retain any attorneys. Under the proposed consent order, DoNotPay pays $193,000, must provide notice to consumers who subscribed between 2021 and 2023, and is prohibited from claiming its service can substitute for any professional service without evidence to back it up.
Rytr sold an AI writing assistant. The FTC’s concern was not the writing tool generally but one feature: a “Testimonial & Review” generator that produced detailed consumer reviews containing specific, often material details bearing no relation to anything the user had input, and which subscribers used to produce hundreds — in some cases tens of thousands — of reviews potentially containing false information. The proposed order bars Rytr from advertising, promoting, marketing or selling any service dedicated to, or promoted as, generating consumer reviews or testimonials.
Both DoNotPay and Rytr were announced as proposed consent orders subject to 30 days of public comment, after which the Commission would decide whether to finalise them. That procedural detail is regularly dropped in secondary coverage, and it is the reason this page says “proposed” rather than stating the orders as final.
Three cases where “AI” was the wrapper on a money scheme
The other three matters — Ascend Ecom, Ecommerce Empire Builders and FBA Machine/Passive Scaling — were business-opportunity cases, each promising guaranteed or near-guaranteed income from AI-powered online storefronts. In each, a federal court issued an order temporarily halting the scheme and placing it under the control of a receiver; all three were left to be decided on the merits by a federal court rather than settled. The FTC alleged Ascend Ecom defrauded consumers of at least $25 million and that FBA Machine cost consumers more than $15.9 million; Ecommerce Empire Builders customers were alleged to have paid as much as $35,000 each.
These three are less useful as a governance lesson than the first two, because the underlying conduct would have been actionable with no AI in it at all. They are included here for an honest reason: they make up three of the five matters in the sweep, and a description of Operation AI Comply that quietly drops them overstates how much of the FTC’s record is really about product-capability claims.
The control that was missing in every one of them
Read the five FTC matters and the two SEC orders side by side and the same gap appears in each: there was no internal step that required a claim in marketing copy to be substantiated against what the system had actually been tested to do. Not a step that failed — a step that did not exist.
The DoNotPay order is the sharpest artefact in the set precisely because it names the missing test. The allegation is not that the chatbot was bad. It is that the company never checked whether the output was equal to the level of a human lawyer, while selling it as a substitute for one. That converts an intuition into an evidentiary bar: if you claim your system replaces a professional, the substantiating evidence is a comparison against that professional’s output, and you are expected to have run it before you said so.
Framed that way, marketing-claim substantiation is an AI governance control like any other — it has an owner, an artefact, a trigger and a documented failure record. It belongs in the same register as your model-evaluation and vendor-diligence controls rather than in the marketing department’s style guide, and it is unusual among AI governance controls in that its enforcement history is already public and specific.
A pre-publication claim-review gate
The checklist below is derived from what the two agencies actually pleaded, not from any published standard. It is deliberately short, because a gate that takes an afternoon will be routed around. Four questions, asked of every external claim that mentions AI, before it ships:
- Who owns this claim? Name a person, not a team. Every matter above involved copy that no identifiable individual was accountable for substantiating. If nobody owns it, nobody checks it.
- What test substantiates it, and where is the result? The claim needs a pointer to a specific evaluation, benchmark run, audit or comparison — with a date — not to a belief about the system. “We know it works” is the state DoNotPay was in.
- Is “AI” describing a capability that ships today? Distinguish what the deployed product does now from what the roadmap says and from what the underlying model can do in principle. Delphia’s claim described an intended capability in the present tense; the SEC charged the tense.
- Is a comparative or substitution claim being made? “Better than,” “replaces,” “first regulated,” “expert” — each of these raises the evidentiary bar sharply, and substitution claims raise it the highest. Under the DoNotPay order, a professional-substitution claim requires evidence, and the evidence has to be a test against the professional.
Two implementation notes. First, the gate should apply to more than advertising: pitch decks, RFP responses, grant and proposal narratives, and sales-engineering answers are all “communications offering services” in substance, and the SEC matters were about exactly that category of document. Second, record the answers. The reason to write them down is not the claim you are about to make; it is the claim someone made eighteen months ago that a regulator, a customer or a litigant now wants explained.
How this differs from frontier-AI litigation exposure
This page is deliberately narrow, and it is worth saying what it is not. It is not a survey of private AI lawsuits against frontier laboratories — negligence, product liability, discrimination and wrongful-death theories brought by private plaintiffs over model behaviour. That is a genuinely different body of exposure, with different defendants, different plaintiffs and a far less settled legal position, and it is covered separately in our general counsel’s guide to frontier-AI litigation exposure.
Nor is it about how prudential and market regulators are positioning themselves toward frontier models as a systemic matter — supervisory expectations, model-risk management, examination priorities. For that, see how federal financial regulators are actually treating frontier AI, which covers the posture rather than the enforcement.
The distinction is worth holding onto because the risk profiles are so different. Frontier-lab litigation exposure is speculative, expensive and concentrated in a handful of companies. Deceptive-claim enforcement is settled law, comparatively cheap to trigger, and available against any seller in the market — including the ordinary enterprise buying an AI feature from a vendor and then describing it to its own customers. If you are running vendor diligence, the claims your vendor makes to you are also the claims you will end up repeating; our guide to assessing third-party AI vendor risk covers the diligence side of that loop.
Why research administration should care
The claim-substantiation problem is not confined to consumer products. University technology-transfer offices, startup spinouts and core facilities all market AI capability — in licensing materials, investor decks and service catalogues — and the same gap applies: the capability described in the marketing copy is frequently the capability hoped for rather than the one demonstrated in a run someone can point to.
The second exposure is narrower but more serious. Capability representations in federally funded proposals sit in a different and less forgiving regime than advertising law, where a knowing misstatement can carry False Claims Act consequences. That is a real analogy and not a loose one, but it should not be stretched: the cases described on this page are consumer-protection and securities matters, and no agency has applied them to grant narratives. The transferable part is the control, not the theory of liability.
Where NIKOLAI fits
NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary. It is unendorsed: no organisation has adopted it as a standard, and every crosswalk row in it is a shadow mapping — CASRAI’s reading of how an organisation uses a term — unless that organisation has filed a Mapping Declaration confirming it. Nothing in NIKOLAI is official, and nothing in it carries regulatory weight.
The element that genuinely bears on this page is Claim, on track N4 (Claims and argument). NIKOLAI proposes to define a Claim as an atomic, identifiable assertion within a safety argument that carries its own supporting evidence, an optional link to a parent claim, and an explicit rule for how it aggregates with its siblings. That is a safety-argument construct, not an advertising one, and the two should not be conflated: a marketing claim is not a sub-claim in a safety case, and NIKOLAI does not purport to govern marketing copy.
What does transfer is the structure. NIKOLAI’s Claim element insists that an assertion is not a free-standing sentence but a unit bound to the evidence that supports it — which is exactly the property the enforcement record shows was missing. An organisation that already maintains claims-with-attached-evidence for its safety argument has most of the machinery it needs to do the same for the sentences it publishes about the product.
Frequently asked questions
Is “AI washing” illegal?
There is no offence by that name. The conduct the term describes has been charged under general law — the Investment Advisers Act and Marketing Rule in the SEC matters, and the FTC’s deception authority in Operation AI Comply. No AI-specific statute was needed in any of the cases on this page.
How much have the penalties been?
Modest, in the matters that settled. The SEC’s two March 2024 orders totalled $400,000 in civil penalties ($225,000 and $175,000), and the DoNotPay proposed consent order carries $193,000. The three FTC business-opportunity cases involve much larger alleged consumer losses — at least $25 million for Ascend Ecom and more than $15.9 million for FBA Machine — but those were halted by federal courts and put under receivership rather than settled for a penalty figure.
Does this only apply to companies selling AI products?
No. The exposure attaches to the claim, not to the business model. Any organisation that describes an AI capability in a communication offering its services — including one describing a capability it bought from a vendor — is making the kind of statement these cases were about.
What is the single strongest lesson from the enforcement record?
That a substitution claim now has a named evidentiary bar. The DoNotPay order treats “we tested it against the professional it replaces” as the substantiation a professional-substitution claim requires. If your copy says the system replaces a specialist, that comparison is the artefact you should be able to produce.
Were the FTC orders final?
The DoNotPay and Rytr orders were announced as proposed consent orders subject to 30 days of public comment, after which the Commission would decide whether to finalise them. The three business-opportunity matters were live federal court cases at announcement. Check the FTC’s case pages for current posture before relying on any of the terms as settled.








