The FTC just fined a software provider $150 million for overstating what its AI could do — making "AI washing" a board-level enforcement risk enterprises must now govern.
The Federal Trade Commission has levied a historic $150 million civil penalty against a software provider under Section 5 of the FTC Act. The charge wasn't a data breach or a biased algorithm. It was something more mundane and far more widespread: the company said its AI could do things it couldn't prove.
This is the enforcement signal every compliance and risk team has been waiting for — and dreading. "AI washing," the practice of exaggerating an AI system's capabilities, accuracy, or autonomy to win deals or investment, is now demonstrably expensive. And unlike the EU AI Act, this exposure doesn't require you to sell in Europe. It applies to any organization making claims about AI in US commerce.
What AI washing actually looks like
AI washing rarely involves outright lies. It lives in the gap between what a marketing deck promises and what a system was ever validated to do. Common patterns include:
- Claiming a model is "99% accurate" without disclosing the narrow test conditions that produced the number.
- Describing rule-based automation or human-in-the-loop workflows as "autonomous AI" or "agentic."
- Marketing capabilities that exist only in a roadmap, not in the shipped product.
- Repeating a vendor's unverified performance claims to your own customers or regulators.
That last one matters enormously. The FTC's theory of harm under Section 5 targets deceptive claims made to consumers — and those claims travel. When you buy an AI tool and pass its stated capabilities along in your own sales materials, patient communications, or lending disclosures, you inherit the risk. You become the party making the representation.
Why this is a governance problem, not a marketing one
The instinct is to hand this to legal or communications for a copy review. That's necessary but insufficient. The reason AI washing has become endemic is structural: most organizations cannot connect a claim to the evidence that would substantiate it.
Consider the chain of custody required to defend a single performance claim:
- Which AI system are we talking about, and which version?
- What was it actually tested against, and by whom?
- What accuracy, error, or bias metrics came out of that testing?
- Who approved the public-facing language, and against what evidence?
- Can we reproduce that evidence on the day a regulator asks?
If any link in that chain lives in someone's inbox, a stale slide, or a vendor PDF nobody re-verified, the claim is undefendable. The FTC penalty is what happens when that chain breaks and someone notices.

The claim-substantiation gap is widening
Three converging pressures make this the wrong moment to be sloppy about AI claims.
Federal enforcement is now active, not theoretical. A $150 million penalty establishes a precedent and a template. The FTC has repeatedly signaled it views unsubstantiated AI claims as ordinary deceptive-marketing cases dressed in new clothing — a legal theory it already knows how to win. State regulators are piling on. Colorado has narrowed its broad AI law toward transparency and disclosure obligations, and the FTC itself has raised questions about the patchwork of state rules. The common denominator across every version is the same: say what your AI does, and be able to back it up. Sector regulators want proof, not promises. A healthcare union's complaint against Kaiser Permanente over clinical AI triage, and a $15,000 sanction against a lawyer for AI-fabricated citations, both turn on the same failure — deploying AI whose real-world behavior didn't match its claimed reliability, with no human verification to catch the gap.The pattern is unmistakable. The regulatory question is shifting from "do you use AI responsibly?" to "can you prove the AI does what you said it does?"
What to do before the claim ships
Governing against AI washing is fundamentally about linking every external representation to durable internal evidence. Practical steps:
- Inventory the claims, not just the systems. Maintain a record of every capability, accuracy figure, and autonomy statement your organization makes about AI — in marketing, contracts, and regulatory filings — and map each to the system and version it describes.
- Require a substantiation record for each claim. No performance number goes public without a cited test, dataset, date, and owner. If it can't be cited, it can't be claimed.
- Extend the standard to vendors. Treat inherited vendor claims as your own claims. Demand the underlying evidence before you repeat a "best-in-class accuracy" line to your customers or auditors.
- Put claims in the approval workflow. Route AI-related marketing and disclosure language through the same governance gate that reviews the system's risk profile — not a separate, downstream copy check.
- Re-verify on a cadence. Models drift and get retrained. A claim that was true at launch may be false two versions later. Revalidate on the same schedule you review the underlying system.
The uncomfortable truth is that most enterprises can name their AI systems but cannot instantly produce the evidence behind what they say those systems do. That gap is exactly what a $150 million penalty exploits.
This is where a control plane for AI governance earns its keep. When you inventory every AI system, track how it's used and what it costs, and measure the maturity of the controls around it, the substantiation chain stops living in inboxes and starts living in one defensible record. The claim, the system, the evidence, and the owner sit in one place — which is precisely what you need on the day a regulator asks you to prove it.
