Regulators spent 2025 and 2026 converting "AI-powered" marketing from a buzzword into a liability trigger. The Federal Trade Commission launched Operation AI Comply in September 2024 and continued enforcement into 2026 with finalized orders, multi-million-dollar judgments, and a proposed policy statement on AI output accuracy. The Securities and Exchange Commission brought AI-washing cases against public companies and startups that allegedly misstated product capabilities or financial projections tied to machine learning. State laws, including Texas TRAIGA disclosure rules effective January 2026, added a third enforcement layer for consumer-facing AI claims.
AI washing enforcement does not require a new statute. Agencies apply existing fraud, securities, and unfair practices frameworks to exaggerated automation claims, fake listening products, and investor decks that promise AI revenues without viable products. Marketing teams, founders, and counsel should treat AI feature descriptions like pharmaceutical efficacy claims: substantiate with competent evidence or narrow the language. Audit your copy against AI chatbot products you actually ship and review AI regulation resources before the next campaign refresh.
What AI Washing Means Legally
AI washing describes marketing or investor communications that overstate artificial intelligence use, often by labeling rules-based software, basic analytics, or manual workflows as advanced AI without substantiation. The FTC applies Section 5 of the FTC Act, which prohibits unfair or deceptive acts in commerce. False claims about AI capabilities are deceptive the same way false claims about battery life or encryption would be. The SEC targets material misstatements in offerings and public filings under Securities Act and Exchange Act antifraud provisions.
AI washing spans several fact patterns:
- Products described as using AI that rely on static scripts or human labor.
- Capabilities attributed to "machine learning" when no trained model performs the advertised task.
- Investor materials projecting AI revenue without products that could generate it.
- Privacy-invasive features marketed as AI listening or sentiment analysis without the underlying technology.
Regulators do not ban AI marketing. They require that claims match reality and that material limitations are disclosed. Startups with genuine models still risk enforcement if they promise accuracy, autonomy, or earnings outcomes they cannot support with tests, pilots, or peer-reviewed methods appropriate to the field.
Recent FTC Enforcement Themes
Operation AI Comply established that the FTC will pursue AI washing through settlements, bans, and monetary relief even when headline fine amounts are modest relative to tech industry revenue. The Cox Media Group case, finalized in August 2026, locked three companies into twenty-year oversight over an "Active Listening" ad product that the FTC alleged collected no voice data and used no AI to analyze conversations. Marketing claimed smartphones and smart TVs could capture casual talk for hyper-targeted ads; the complaint said the service resold email lists from data brokers. The settlement totaled $930,000, small in absolute terms but significant as precedent for voice-surveillance claims.
In March 2026, the FTC announced a settlement with Air AI and its owners banning them from marketing business opportunities after alleging roughly $19 million in customer losses from false earnings claims and refund guarantees tied to AI-assisted sales tools. The action fit a broader pattern targeting opportunistic AI coaching and reseller schemes that surged after ChatGPT popularized generative AI.
The FTC also proposed a policy statement in July 2026 on "Suppression of Accuracy in Artificial Intelligence Systems," arguing Section 5 can be violated when companies steer model outputs toward undisclosed objectives, including hidden adjustments to comply with state AI laws without telling users. Public comment closed July 31, 2026. If adopted, the statement would extend deception theory beyond marketing copy into product behavior and system prompts.
| Case theme | Example (2025-2026) | Regulatory hook |
|---|---|---|
| Fake AI capability | Cox Media Active Listening (no voice AI used) | FTC Act Section 5 deception |
| False earnings from AI tools | Air AI business opportunity scheme | FTC deception + biz-op ban |
| Undisclosed output steering | Proposed FTC accuracy suppression policy (2026) | FTC Act Section 5 unfairness/deception |
| Operation AI Comply sweep | Multiple 2024 actions on deceptive AI claims | Substantiation standards for AI features |
SEC Disclosure Expectations for AI Companies
The SEC brought its first AI-washing cases in March 2024 and continued with startup enforcement in 2026, focusing on material misstatements about product viability and financial forecasts. In August 2026, the commission settled with GenesisAI Corp. and former CEO Archil Cheishvili over allegations that the Miami-based company raised more than $5.3 million from over 4,000 investors while misrepresenting marketplace viability. The SEC said investor decks projected $250 million in 2024 revenue while actual 2024 revenue was about $40,000, mostly from conference hosting, and the marketplace was not commercially viable despite valuation rhetoric above $200 million.
Cheishvili agreed to pay $50,000 disgorgement, prejudgment interest, and a $50,000 civil penalty, with permanent injunctions against Exchange Act violations. Disclaimers that projections were not guaranteed did not shield the company when the SEC alleged no reasonable basis existed for the forecasts.
Public companies face similar scrutiny in MD&A and risk factors. Mentioning "AI transformation" without describing model costs, failure rates, data governance, or customer adoption metrics invites comment letter questions. The SEC's 2025 action against Presto Automation illustrated restaurant-tech AI claims under securities antifraud theories. Private companies preparing IPOs should expect S-1 drafting to excise unverifiable AI superlatives inherited from growth marketing.
Marketing Copy Guardrails for Startups
Safe marketing describes specific model functions, human oversight, data inputs, and known limitations; risky marketing uses vague "AI-powered" labels, implies human-level judgment, or guarantees business outcomes. Use this comparison table when reviewing landing pages, sales decks, and App Store listings:
| Risky claim | Safer alternative |
|---|---|
| "Our AI listens to customer conversations in real time." | "We analyze opted-in chat transcripts with a fine-tuned classifier; no audio collection." |
| "Fully autonomous AI replaces your sales team." | "Drafts outreach emails for human review; reply rates vary by industry." |
| "Guaranteed 10x revenue with our AI platform." | "Case study: one customer improved conversion 18% over six months in a pilot." |
| "Military-grade AI encryption." | "AES-256 at rest, TLS 1.3 in transit; SOC 2 Type II audit completed March 2026." |
| "Proprietary AI" (rules engine only) | "Rules-based workflow automation with optional GPT-4o API integration." |
FTC guidance reinforced through Operation AI Comply requires competent and reliable evidence, such as tests and analyses conducted according to generally accepted standards in the relevant field. Document benchmarks, user studies, and third-party model evaluations before publishing performance numbers. Vet AI components sourced from vendors the same way you vet payment processors: contractual representations, monitoring for drift, and incident escalation paths.
Legal and marketing should run a pre-flight checklist on every AI feature launch: name the model or technique, disclose material limitations, avoid implying sentience or universal accuracy, and align public claims with what the product actually ships. Texas TRAIGA and emerging state bills may require additional consumer disclosures for high-risk automated decisions even when federal agencies do not act.
In-house counsel should maintain a claim substantiation file for every AI feature cited in ads or investor updates. Include model cards, evaluation metrics with methodology notes, user consent flows for data used in training or inference, and records of human review steps when products are not fully automated. When marketing refreshes website copy, run a diff against the substantiation file. If sales decks outpace product reality, fix the deck or ship the feature before the next conference season. Regulators increasingly request customer communications and internal Slack threads during investigations, not just public landing pages.
B2B SaaS vendors reselling white-label AI should contractually require upstream providers to warrant accuracy of model capability descriptions and to notify you when models change behavior materially. Pass-through liability clauses rarely satisfy regulators if your brand appears on the deceptive claim. Enterprise buyers are adding AI representation warranties to vendor questionnaires, mirroring SOC 2 and GDPR DPA reviews. Startups that cannot answer those questions lose deals to competitors with clearer documentation even before any agency opens an investigation.
Public relations teams should align crisis communications with legal review when journalists ask whether a product truly uses AI. A confident "yes" that later unravels in discovery becomes exhibit A in enforcement files. Train spokespeople to describe concrete workflows: which models, which data, which human checkpoints. Investor relations at pre-IPO companies must synchronize earnings guidance language with product marketing to avoid SEC comment letters alleging inconsistent material statements across channels.
International startups face overlapping regimes. EU AI Act transparency duties, UK CMA guidance on consumer fairness, and Canada's proposed AI legislation may constrain claims that still pass a narrow U.S. reading of Section 5. Build a global claims matrix mapping each feature description to supporting evidence and jurisdiction-specific qualifiers. A single master landing page with footnoted regional variants scales better than reactive retractions after a foreign regulator cites your U.S. ad copy in an enforcement notice.
Board members and angel investors should ask founders directly: show me the evaluation that supports this headline. That discipline prevents small exaggerations from compounding into S-1 liability years later. Marketing velocity in AI sectors rewards bold claims, but 2026 enforcement shows regulators will chase modest dollar cases when precedent value is high. Treat every AI superlative as a legally binding representation until counsel signs off. Annual marketing audits should include screenshot archives of social posts and webinar slides, not just the corporate website.
Frequently Asked Questions for Startups
What is AI washing?
Exaggerating or falsifying the role of artificial intelligence in a product, service, or investment opportunity, often to attract customers, users, or capital.
Which U.S. agencies enforce AI washing?
The FTC for consumer and business marketing under Section 5, the SEC for securities offerings and public company disclosures, and state attorneys general under consumer protection and new AI disclosure laws.
Do I need clinical trials to claim my AI improves outcomes?
You need evidence appropriate to your industry. Health claims may require clinical validation; B2B productivity claims still need competent testing, not anecdotal testimonials alone.
Can disclaimers fix exaggerated AI decks?
Not if projections lack reasonable basis. The GenesisAI SEC settlement shows disclaimers did not prevent negligence findings when revenue forecasts diverged wildly from operations.
How should we describe third-party models in our product?
Name the provider and model family where accurate, describe your fine-tuning or orchestration layer, and disclose dependency risks such as API outages, pricing changes, and content policy filters.