
The CETU — the SEC's Cybersecurity and Emerging Technologies Unit, created in February 2025 specifically to investigate AI-related misconduct — is not looking for your AI governance policy. It's looking for the document that connects every AI claim in your 10-K to the specific model, data pipeline, and decision point that delivers on it. Most public companies don't have one.
The common failure across every AI washing enforcement action isn't bad AI. It's the gap between what you said and what you can prove.
The Delphia and Global Predictions settlements in March 2024 — combined penalties of $400K — established that unsubstantiated AI claims in adviser marketing materials violate the SEC Marketing Rule. Presto Automation's cease-and-desist in January 2025 moved the target: the SEC charged a public company for claiming its AI system eliminated human involvement in drive-thru ordering when, by the SEC's findings, 70% of orders required human intervention, and 100% at some locations. The gap between the marketing and the operation was the charge. Four months later, the SEC and DOJ filed parallel criminal actions against the founder of Nate Inc., which had raised $42M+ claiming an AI-powered shopping automation rate that was, by the government's findings, essentially zero — hundreds of contractors manually completing purchases. DOJ charges carry up to 20 years.
The enforcement logic is identical across every case. Examiners compare what you said against what your AI actually does.
What the CETU Examination Actually Asks For

Examination request patterns across CETU inquiries are consistent in their first document request. Before auditors ask anything technical, they ask for a claim-to-system map.
Every public AI claim — in your 10-K, on your website, in earnings calls, in press releases — linked to the specific system component that delivers on it. Model version, data pipeline, decision point, and the evidence that it works at the level claimed. The SEC's 2026 examination priorities state explicitly that examiners will "review for accuracy registrant representations regarding their AI capabilities." Registrants who cannot produce this map within the first ten days signal a substantiation problem before any technical review begins.
Operational validation is the harder requirement — and the one Presto failed. The system existed. But there was no documentation showing it actually influenced the decisions their disclosures claimed it influenced. The AI ran; humans ran alongside it at rates the company hadn't disclosed. That distinction is what converts a governance gap into an enforcement event.
What an AIBOM delivers is the machine-readable record that anchors both of the above: a complete inventory of every component in the AI system. Training data lineage. Model versions. Third-party dependencies. Infrastructure specifications. Not a policy document. Not a one-time snapshot. A living record that stays current through model retraining cycles. If the model was documented at launch and has since gone through two retraining cycles and three version updates, the substantiation package describes a system that no longer exists. The AIBOM at the time of filing is not the AIBOM at the time of examination.
Where the Governance Platforms Stop

The AI governance market is well-stocked. Credo AI, named a Forrester Wave leader, brings policy packs and audit-ready reporting. IBM watsonx.governance is the IDC MarketScape leader in generative AI model evaluation and covers both IBM and third-party models. OneTrust brings its privacy governance heritage to AI inventory management. Fiddler AI covers explainability, drift detection, and bias monitoring. Holistic AI anchors fairness assessments for employment and lending.
All useful. None of them produce what an SEC examiner asks for.
The standards exist: SPDX 3.0 AI profile (released October 2024) covers models and datasets. CycloneDX 1.6 has ML-BOM support. OWASP's formal AIBOM project is building tooling. The gap isn't the standards — it's that generating an AIBOM from a live ML pipeline using cdxgen or custom tooling produces hybrid outputs that require legal review before they can be submitted as compliance evidence. The OWASP AIBOM Generator is open-source; the legal sign-off that converts a generated inventory into a submittable evidence artifact is not.
The SPDX 3.0 AI profile exists. CycloneDX 1.6 ML-BOM support exists. The OWASP AIBOM working group is writing tooling. What doesn't exist yet is a machine-readable AIBOM that an SEC examiner will accept without legal sign-off on the provenance fields.
ISO 42001 and NIST AI RMF give boards and procurement teams something to point to. They don't produce the claim-to-system map, the operational validation record, or the AIBOM that a CETU document request will ask for. We built AI Verification & Anti-AI-Washing Compliance for this specific gap: not governance frameworks, but the evidence chain itself.
The Content Claim Problem

The substantiation obligation doesn't stop at capability claims in filings. It extends to what your AI produces.
EU AI Act Article 50 takes effect in August 2026. Machine-readable labeling of AI-generated content becomes a mandatory transparency obligation for operators serving EU users — and the Code of Practice on AI-Generated Content Labeling, with its final version expected June 2026, is where the technical standards are being written now. C2PA — the Coalition for Content Provenance and Authenticity — is the current implementation standard: a market of $1.63B in 2025 growing to $2.06B projected in 2026, already supported natively at the hardware layer by Samsung Galaxy S25 and Google Pixel 10, and at the platform layer by LinkedIn, TikTok, and Cloudflare.
The FTC's liability chain, established through Operation AI Comply launched in September 2024, extends the substantiation obligation from provider to enterprise customer. Workado's AI detection tool was marketed at 98% accuracy; FTC real-world testing found 53%. DoNotPay's "world's first robot lawyer" claim was unsubstantiated. Both resulted in consent decrees. The accuracy figure you repeat from a vendor's marketing sheet is, in the FTC's enforcement theory, your accuracy claim.
The operational cost of not tracking AI content provenance runs to $67.4B in global losses attributed to AI hallucinations in 2024, with enterprises reporting an average of 2.3 significant AI-driven errors per quarter at costs between $50K and $2.1M per incident. The $14,200 per employee per year that organizations report spending on hallucination mitigation — roughly 4.3 hours per week of fact-checking — is the hidden carrying cost of deploying AI without provenance tracking built in from the start.
The Multi-Jurisdiction Clock

AI washing enforcement is not a single-administration, single-agency story. The 36-state bipartisan coalition of attorneys general that formed in November 2025 to oppose federal preemption of state AI laws spans both parties. States are enforcing now, under UDAP statutes, while federal preemption questions work through courts.
The specific exposure is multi-front. Colorado's SB 205 takes effect June 30, 2026: high-risk AI systems require impact assessments, annual reviews, and consumer notification, at $20,000 per violation. New York's AI enforcement framework carries $15,000 per day per violation. Texas RAIGA, in effect since January 1, 2026, gives the AG civil investigative demand authority based on a single complaint — a document request that can arrive before your GC knows the inquiry exists.
Stanford Law School's Securities Class Action Clearinghouse counted 53 AI-related securities class actions through H1 2025. Median settlement: $11.5M. Average, excluding a $189M outlier: $38.4M. The SEC has named AI washing examination an explicit priority for 2026. The DOJ's Justice AI Initiative runs parallel to SEC enforcement — as the Nate case demonstrated.
Where to Start

The claim inventory doesn't exist at most enterprises. Marketing, investor relations, and engineering operate in silos. Nobody maintains a master list of what the company has publicly claimed about its AI — what percentage automation, what accuracy rate, what decision influence. Before any technical substantiation work begins, legal and compliance need to build that inventory.
The practical order from there: identify which claims carry the highest regulatory exposure (public filings, investor materials, claims about accuracy rates or automation percentages), run the operational validation against those claims first, work backward to the AIBOM and continuous monitoring from there. The claim-to-system map is both the starting point and the most likely first document request if a CETU examination begins. The architecture we built for this — documentation, AIBOM generation, operational validation, and continuous monitoring against public claims — is at https://veriprajna.com/solutions/ai-verification-anti-ai-washing.
If you're a GC or CCO working through this for the first time, the question that frames the whole effort: if an examiner sent a document request this afternoon, how long would it take your team to produce a claim-to-system map for your three most prominent public AI claims?