Feature AI Risk
SEC AI-Washing Settlements: What Firms Should Prove About AI Claims
A fact-checked guide to the SEC's Delphia and Global Predictions settlements, the $400,000 in penalties, and practical controls for AI claims.
Table of Contents
The Securities and Exchange Commission’s best-known “AI washing” matters are settled administrative orders, not prosecutions and not a new AI statute. On March 18, 2024, the SEC announced separate orders against investment advisers Delphia (USA) Inc. and Global Predictions, Inc. The firms agreed to pay $225,000 and $175,000, respectively.
That distinction matters. A compliance program should respond to what the orders actually establish: existing antifraud, marketing, and compliance obligations apply when a registered adviser describes its use of AI.
August 17, 2026 fact-check update
Earlier versions of this article overstated the matters’ status, used incorrect order numbers, and treated a later SEC unit announcement as if it had brought the 2024 cases. The controlling source record is:
- Delphia: Investment Advisers Act Release No. 6573, settled March 18, 2024; $225,000 civil penalty.
- Global Predictions: Investment Advisers Act Release No. 6574, settled March 18, 2024; $175,000 civil penalty.
- Posture: settled administrative orders with findings accepted without admissions or denials, subject to the jurisdictional exceptions in each order.
- CETU: announced February 20, 2025. Its stated priorities include fraud using emerging technology, including AI, but the announcement did not create a new rule or designate every AI claim as unlawful.
What the two orders found
Delphia: claims about using client data in an AI-driven process
The SEC’s Delphia order addressed statements in regulatory filings, a press release, and website material about the firm’s purported use of AI and machine learning in its investment process, including claims involving client data. The order found that Delphia did not have the represented AI and machine-learning capabilities during the relevant periods.
The order also addressed Delphia’s compliance program. The useful control lesson is not simply “avoid the word AI.” It is to connect each claim to the system capability, data flow, and approved use that existed when the claim was made.
Global Predictions: claims about an AI financial adviser
The SEC’s separate Global Predictions order addressed false or misleading statements about the firm’s use of AI, including how it described its advisory service. Global Predictions’ order contains its own findings and remedial terms; it should not be collapsed into Delphia’s order as if the facts were identical.
Both matters demonstrate that a polished product narrative does not substitute for evidence. They do not establish that every use of terms such as “AI-powered” is automatically a performance claim or a violation.
The legal status: existing adviser rules, applied to AI claims
The SEC did not need an AI-specific rule for these matters. The orders applied existing Investment Advisers Act requirements, including antifraud, marketing, and compliance provisions, to the facts found for each adviser.
For an SEC-registered investment adviser, the Marketing Rule’s general prohibitions are especially relevant. Among other requirements, an adviser may not include a material statement of fact in an advertisement without a reasonable basis for believing it can substantiate that statement if the Commission demands support.
An AI claim can therefore create ordinary substantiation questions:
- What capability does the claim describe?
- Was that capability deployed during the period covered by the claim?
- What data did it actually use?
- Did human review or another process materially limit the advertised automation?
- Do product documentation, regulatory filings, sales material, and customer communications tell the same story?
What CETU changes—and what it does not
The SEC announced the Cyber and Emerging Technologies Unit (CETU) in February 2025. The announcement lists fraud committed using emerging technologies, including artificial intelligence, among the unit’s areas of focus.
That is an enforcement-priority statement, not a rule. It supports monitoring SEC activity involving AI-related fraud, but it does not prove that CETU brought the 2024 Delphia or Global Predictions cases, that “AI washing” is a separately codified violation, or that the SEC adopted a new AI-claims deadline in 2026.
A defensible AI-claims control
A short, repeatable claims-control process is more useful than a one-time scrub.
1. Inventory objective AI statements
Search public and customer-facing material for claims such as “AI-powered,” “machine-learning driven,” “fully automated,” “personalized,” “predictive,” or “real time.” Include websites, pitch decks, app-store descriptions, regulatory filings, due-diligence questionnaires, and sales scripts.
2. Define the claim precisely
For each statement, record what a reasonable reader is expected to understand. Distinguish a system that uses an AI component from a service whose core recommendation or decision is produced by AI.
3. Attach contemporaneous evidence
Link the claim to approved product documentation, model or system descriptions, test records, deployment dates, data-flow records, and the responsible product owner. Evidence should show the capability during the period the claim was live, not only what the roadmap expected later.
4. Reconcile disclosures
Compare marketing language with Form ADV disclosures, policies, contracts, technical documentation, and customer communications. Escalate material differences rather than assuming one document controls the meaning of another.
5. Require review and expiry
Route material AI claims through legal and compliance review. Assign an expiry or revalidation date so a vendor change, model replacement, or product redesign does not leave an old statement live after the supporting facts change.
Use a Claim Ledger, Not a Screenshot Folder
Screenshots prove what was published, but they do not prove the statement was true. A claim ledger should connect each material representation to a defined meaning and contemporaneous evidence.
| Ledger field | Question it should answer |
|---|---|
| Exact representation | What words did the audience see, and in which channel? |
| Intended meaning | What capability, outcome, data use, or degree of automation would a reasonable reader understand? |
| Evidence owner | Who can explain and produce support for the claim? |
| System and version | Which deployed model, service, workflow, or vendor release performed the represented function? |
| Evidence period | Was the support current for every date the claim remained live? |
| Limits and human role | What material qualification, override, review, or constraint changes the reader’s understanding? |
| Approval and expiry | Who approved the statement, and what event forces re-review? |
The ledger should cover material factual statements, not merely language containing “AI.” A statement about personalization, automation, forecasting, model accuracy, data sources, or performance can create the same substantiation problem even when the marketing team avoids the AI label.
Use the SEC Marketing Rule deficiency review for the wider advertising-control context. For capability, governance, and evidence ownership beyond advertising, tie the ledger to the role-based AI risk assessment questionnaire.
Treat Vendor Copy as an Input, Not Proof
A firm can publish an unsupported claim even when the words originated in a vendor deck. Before repeating a provider’s representation, determine:
- which component actually performs the claimed function;
- whether the feature is enabled in the firm’s deployed configuration;
- what customer or portfolio data reaches it;
- whether a human or a different rules engine makes the final decision;
- what testing supports any performance statement;
- which limitations, exclusions, or geographic constraints apply; and
- how the firm will learn when the vendor changes the feature.
Contractual warranties and audit rights may support this review, but they do not replace product evidence. Keep the vendor statement, the firm’s validation, identified gaps, approval decision, and monitoring trigger in the same record.
Control Changes After Publication
Claims often become inaccurate through drift rather than through an intentionally false launch. A model is replaced, a feature becomes optional, data access narrows, human review expands, or a vendor changes its architecture while the website remains unchanged.
Create change triggers that route material product events back to the claim owner. At minimum, consider model or vendor replacement, production rollback, data-source change, material test failure, revised human-review workflow, new limitation, and customer complaint suggesting that the description no longer matches experience. The control should be able to correct or withdraw copy quickly and preserve what changed, when, and why.
What to preserve for an examination or inquiry
A useful evidence packet includes:
- the exact claim and every channel where it appeared;
- the approval record and reviewers;
- the technical evidence supporting the claim at publication;
- deployment and change history;
- monitoring or testing results relevant to the stated capability;
- the date the claim was revalidated, corrected, or removed; and
- records showing that regulatory filings and marketing were reconciled.
The point is not to guarantee that the SEC will agree with every characterization. It is to show that the firm had a reasonable, documented basis for the statement it chose to publish.
Bottom line
The verified SEC record is narrower—and more actionable—than a claim that the agency launched a new AI prosecution campaign. Two registered advisers resolved separate administrative proceedings over false or misleading AI statements and related compliance failures. Firms should use those orders as a prompt to substantiate objective claims, align disclosures, and preserve evidence before publication.
Official sources
- SEC press release: SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (March 18, 2024)
- Delphia (USA) Inc., Investment Advisers Act Release No. 6573
- Global Predictions, Inc., Investment Advisers Act Release No. 6574
- SEC announcement establishing the Cyber and Emerging Technologies Unit (February 20, 2025)
- 17 CFR 275.206(4)-1, Investment Adviser Marketing
This article is for general informational purposes and is not legal advice. Review the orders and applicable rules with counsel for your firm’s facts.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is AI washing?
Which SEC matters are the key settled AI-washing cases?
Were Delphia or Global Predictions criminally prosecuted?
Did the SEC's Cyber and Emerging Technologies Unit bring the 2024 cases?
What is the practical control for an AI-related marketing claim?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Keep reading
Related posts.
AI Risk
Model Change Assessment: Revalidate, Reapprove, or Update the Inventory?
Use a model change assessment to route maintenance, material changes, revalidation, reapproval, inventory updates, and model replacement.
Aug 18, 2026
AI Risk
72% of Banks Can't Shut Down a Malfunctioning AI Model. Examiners Are About to Find That Out.
A June 2026 survey found 72% of banks are unprepared to shut down a malfunctioning AI model or report an AI failure to regulators—the two most basic controls in any AI incident-response playbook. OCC and Fed examiners have made AI a permanent standing topic in every routine bank examination. Here's what kill switch documentation, vendor disentanglement testing, and data boundary enforcement look like when an examiner walks in.
Aug 1, 2026
AI Risk
EU AI Act in August 2026: Article 50 Is Live and Annex III Moved to 2027
Article 50 applies from August 2, 2026, while Annex III high-risk rules move to December 2, 2027 under final Regulation (EU) 2026/1744.
Jul 28, 2026