
A startup raised $42M+ on an "AI-powered" shopping app. The real automation rate? Essentially zero.
The purchases were being completed by hand — hundreds of contractors in the Philippines. In April 2025 the SEC and DOJ filed parallel charges against the founder. The criminal counts carry up to 20 years.
This is "AI washing," and the enforcement playbook is now bipartisan and multi-agency. The SEC stood up a dedicated unit for it. The FTC is running sweeps. State AGs have new statutory tools.
Here's the part most teams miss: every action follows the same logic. The agency compares what you said about your AI against what your AI actually does.
Delphia claimed ML-powered investing but never integrated the data. Presto claimed AI eliminated human order-taking — 70%+ of orders still needed a human. The failure was never bad AI. It was the gap between the marketing and the technical reality, and the absence of documentation that could close it.
One trap worth saving for your next disclosure review: if you repeat a vendor's accuracy number in your 10-K — say a detection tool sold as "98% accurate" — the SEC treats that as your claim. (Workado advertised 98%; the FTC tested it near 53%.) Do you have independent validation, or are you inheriting someone else's risk?
A governance policy says you should document your AI. Substantiation is the actual evidence: a claim-to-system map, an AI Bill of Materials, and operational proof that the model influences the decisions your filings describe. That's what an examiner asks for — and what most firms can't produce on demand.
Worth asking before your next 10-K goes out: could you prove every AI claim in it, in writing, today?
Save this for the next time legal and engineering are in the same room. 🔎
#AIWashing #AICompliance #SECEnforcement #AIGovernance #AIBOM