Consumer Protection and AI Marketing Claims
10 min read · updated August 4, 2026
“AI washing” is not a new offence. It is the ordinary prohibition on unsubstantiated advertising claims, applied to a category where the claims are unusually hard for a buyer to check. That is exactly why regulators have moved on it, and the actions brought so far follow a single, learnable pattern.
The legal theory, which is not new
In the United States, section 5 of the FTC Act prohibits unfair or deceptive acts or practices. A claim is deceptive if it is a representation likely to mislead a consumer acting reasonably, and it is material. Separately and importantly, an objective claim carries an implied representation that the advertiser had a reasonable basis for it at the time it was made. You cannot substantiate retrospectively.
Everything in this area follows from that second rule. The question a regulator asks is not “is your product good?” but “what did you have in hand when you published the claim?” The absence of a test is itself the violation, independently of whether the product turns out to work.
FTC actions
The FTC announced a coordinated sweep called Operation AI Comply in September 2024, and has brought further actions since. The pattern across them:
| Action | Description |
|---|---|
| DoNotPay (2024) | Marketed as 'the world's first robot lawyer'. The FTC alleged the service could not perform as advertised and that the company had not tested whether its output matched a human lawyer's. The consent order required a payment of just under two hundred thousand dollars, notice to affected subscribers, and a bar on unsupported claims about substituting for professional services. The theory: an efficacy claim with no testing behind it. |
| Rytr (2024) | An AI writing tool with a testimonial generator. The FTC's theory was that providing a means and instrumentality to generate deceptive reviews was itself unfair — a different and broader theory than false advertising, aimed at the tool rather than at the claim about it. |
| Ascend Ecom, Ecommerce Empire Builders, FBA Machine (2024) | Business opportunity schemes using AI claims to sell earnings promises. The AI element was the wrapper; the underlying violation was the earnings claim. Most 'AI enforcement' of this kind is really deceptive earnings enforcement. |
| Evolv Technologies (2024) | AI-based weapons detection screening marketed as able to detect all weapons while ignoring harmless items. Settled with an order prohibiting unsupported claims about detection capability. Notable because the buyers were schools and institutions, and the claim was a safety claim. |
| Workado (2025) | An AI content detector advertised as 98% accurate. The FTC's position was that the company lacked evidence supporting that figure for general use. The order required competent and reliable evidence for accuracy claims and record retention. This is the cleanest example of the rule: a specific number in an advertisement is a claim requiring a test. |
The lesson is not that you cannot make accuracy claims. It is that a number in an advertisement must be traceable to a documented test, on a population resembling the advertised use, retained where you can find it. A benchmark score achieved on a curated evaluation set does not substantiate a general accuracy claim about ordinary customer inputs.
Securities regulators and investor claims
A claim made to investors is regulated separately from a claim made to consumers, and the exposure is larger.
- SEC v. Delphia and SEC v. Global Predictions (March 2024). Two investment advisers charged with making false and misleading statements about their use of AI in their investment process. Both settled, with civil penalties totalling four hundred thousand dollars. The significance is the fact pattern rather than the sums: the firms claimed to use AI and machine learning in ways they did not.
- SEC and DOJ action against the founder of a recruitment technology company (2024). Charges over fabricated metrics and misrepresented AI capability used to raise capital. Where AI claims are used to raise money, the exposure includes securities fraud, which carries criminal liability.
- SEC v. Presto Automation (2025). Charges concerning statements about the autonomy of an AI drive-through ordering product — specifically the extent to which human agents were involved in transactions represented as automated.
The recurring theme across the securities cases is human involvement concealed behind an automation claim. If humans are in the loop, describe the product as assisted rather than autonomous, in every document a regulator might read, including the pitch deck.
When it becomes fraud
In April 2025 the Department of Justice indicted the founder of a shopping app that had been marketed as using AI to complete purchases automatically. The allegation was that transactions were in fact completed by human contractors in an overseas call centre while investors were told the process was AI-driven.
The line between an overstated capability and a criminal misrepresentation is not the technology. It is whether the person making the claim knew it was false and whether somebody parted with money because of it. The practical control is the same one that prevents the civil violation: do not describe a capability you have not demonstrated, and keep the record of the demonstration.
The EU and UK position
EU. The Unfair Commercial Practices Directive 2005/29/EC covers this ground without mentioning AI. Article 6 prohibits misleading actions — false information, or information that deceives the average consumer, about the main characteristics of a product, including its performance, composition and the results to be expected from its use. Article 7 prohibits misleading omissions. Annex I lists practices that are unfair in all circumstances. National consumer authorities enforce it, coordinated through the CPC network. Advertising performance a product does not deliver is squarely within Article 6.
UK. The consumer protection regime in the Digital Markets, Competition and Consumers Act 2024 commenced in April 2025 and changed the enforcement picture materially: the CMA can now decide that a business has breached consumer law and impose penalties directly, rather than having to go to court, with a ceiling expressed as a percentage of global turnover. Separately the Advertising Standards Authority rules on advertising claims under the CAP Code, which requires that objective claims be capable of substantiation before publication. ASA rulings are not fines, but they require the advertising to be withdrawn and they are published.
The substantiation test
Run every AI claim through these six questions before it is published. If a claim fails one, change the claim rather than the answer.
- Is it an objective claim? “Powerful” is puffery. “Reduces processing time by 40%” is a claim. “More accurate than a human” is a claim. If it can be true or false, it needs evidence.
- What evidence do we have, and did it exist before we published? Name the document. If nobody can produce it in five minutes, treat it as absent.
- Was the evidence produced on a population resembling the advertised use? A score on a benchmark, on internal data, or on one customer’s workload does not substantiate a general claim.
- Does the claim describe the product as sold? Including defaults. If the number was achieved with a configuration most customers will not use, the claim is misleading even if the number is real.
- Are humans involved in what we describe as automated? If yes, the description must say so. This single question accounts for a disproportionate share of the enforcement above.
- Would the claim still be true on a bad day? Claims about reliability are read as claims about typical experience, not about the best case.
The specific words that create exposure
| Phrase | Description |
|---|---|
| "autonomous" / "fully automated" / "agentic" | Read as a claim that no human is involved. The most enforced misrepresentation in this area. If a person reviews, corrects or completes any part, say so. |
| "98% accurate" or any bare percentage | A specific quantitative claim requiring a documented test on a representative population. State the task, the dataset and the date alongside the number, or do not state the number. |
| "eliminates" / "prevents" / "detects all" | Absolute claims are almost never substantiable for a probabilistic system. One counterexample falsifies them and counterexamples are cheap to find. |
| "AI-powered" | Fine when true. It becomes a securities problem when used to describe a product whose behaviour is rules-based or human-operated, and it is checkable by anyone with access to the product. |
| "replaces your lawyer / accountant / doctor" | A professional-substitution claim invites both a deception theory and, in regulated professions, an unauthorised practice question. This was the DoNotPay claim. |
| "trained on your data" / "learns from your business" | Creates a privacy representation as well as a capability one. If the model is not actually fine-tuned on customer data, this is a false statement about processing, and it contradicts the assurances in your own data protection documentation. |
The last row is the one that bites companies who thought they were being careful about privacy. A marketing page saying the product learns from your business, alongside a data protection notice saying customer data is never used for training, is an inconsistency a regulator can read in two minutes, and one of the two statements is false.