Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature AI Risk

SEC AI-Washing Settlements: What Firms Should Prove About AI Claims

A fact-checked guide to the SEC's Delphia and Global Predictions settlements, the $400,000 in penalties, and practical controls for AI claims.

By Rebecca Leung · August 11, 2026 ·
Table of Contents

The Securities and Exchange Commission’s best-known “AI washing” matters are settled administrative orders, not prosecutions and not a new AI statute. On March 18, 2024, the SEC announced separate orders against investment advisers Delphia (USA) Inc. and Global Predictions, Inc. The firms agreed to pay $225,000 and $175,000, respectively.

That distinction matters. A compliance program should respond to what the orders actually establish: existing antifraud, marketing, and compliance obligations apply when a registered adviser describes its use of AI.

August 17, 2026 fact-check update

Earlier versions of this article overstated the matters’ status, used incorrect order numbers, and treated a later SEC unit announcement as if it had brought the 2024 cases. The controlling source record is:

  • Delphia: Investment Advisers Act Release No. 6573, settled March 18, 2024; $225,000 civil penalty.
  • Global Predictions: Investment Advisers Act Release No. 6574, settled March 18, 2024; $175,000 civil penalty.
  • Posture: settled administrative orders with findings accepted without admissions or denials, subject to the jurisdictional exceptions in each order.
  • CETU: announced February 20, 2025. Its stated priorities include fraud using emerging technology, including AI, but the announcement did not create a new rule or designate every AI claim as unlawful.

What the two orders found

Delphia: claims about using client data in an AI-driven process

The SEC’s Delphia order addressed statements in regulatory filings, a press release, and website material about the firm’s purported use of AI and machine learning in its investment process, including claims involving client data. The order found that Delphia did not have the represented AI and machine-learning capabilities during the relevant periods.

The order also addressed Delphia’s compliance program. The useful control lesson is not simply “avoid the word AI.” It is to connect each claim to the system capability, data flow, and approved use that existed when the claim was made.

Global Predictions: claims about an AI financial adviser

The SEC’s separate Global Predictions order addressed false or misleading statements about the firm’s use of AI, including how it described its advisory service. Global Predictions’ order contains its own findings and remedial terms; it should not be collapsed into Delphia’s order as if the facts were identical.

Both matters demonstrate that a polished product narrative does not substitute for evidence. They do not establish that every use of terms such as “AI-powered” is automatically a performance claim or a violation.

The SEC did not need an AI-specific rule for these matters. The orders applied existing Investment Advisers Act requirements, including antifraud, marketing, and compliance provisions, to the facts found for each adviser.

For an SEC-registered investment adviser, the Marketing Rule’s general prohibitions are especially relevant. Among other requirements, an adviser may not include a material statement of fact in an advertisement without a reasonable basis for believing it can substantiate that statement if the Commission demands support.

An AI claim can therefore create ordinary substantiation questions:

  • What capability does the claim describe?
  • Was that capability deployed during the period covered by the claim?
  • What data did it actually use?
  • Did human review or another process materially limit the advertised automation?
  • Do product documentation, regulatory filings, sales material, and customer communications tell the same story?

What CETU changes—and what it does not

The SEC announced the Cyber and Emerging Technologies Unit (CETU) in February 2025. The announcement lists fraud committed using emerging technologies, including artificial intelligence, among the unit’s areas of focus.

That is an enforcement-priority statement, not a rule. It supports monitoring SEC activity involving AI-related fraud, but it does not prove that CETU brought the 2024 Delphia or Global Predictions cases, that “AI washing” is a separately codified violation, or that the SEC adopted a new AI-claims deadline in 2026.

A defensible AI-claims control

A short, repeatable claims-control process is more useful than a one-time scrub.

1. Inventory objective AI statements

Search public and customer-facing material for claims such as “AI-powered,” “machine-learning driven,” “fully automated,” “personalized,” “predictive,” or “real time.” Include websites, pitch decks, app-store descriptions, regulatory filings, due-diligence questionnaires, and sales scripts.

2. Define the claim precisely

For each statement, record what a reasonable reader is expected to understand. Distinguish a system that uses an AI component from a service whose core recommendation or decision is produced by AI.

3. Attach contemporaneous evidence

Link the claim to approved product documentation, model or system descriptions, test records, deployment dates, data-flow records, and the responsible product owner. Evidence should show the capability during the period the claim was live, not only what the roadmap expected later.

4. Reconcile disclosures

Compare marketing language with Form ADV disclosures, policies, contracts, technical documentation, and customer communications. Escalate material differences rather than assuming one document controls the meaning of another.

5. Require review and expiry

Route material AI claims through legal and compliance review. Assign an expiry or revalidation date so a vendor change, model replacement, or product redesign does not leave an old statement live after the supporting facts change.

Use a Claim Ledger, Not a Screenshot Folder

Screenshots prove what was published, but they do not prove the statement was true. A claim ledger should connect each material representation to a defined meaning and contemporaneous evidence.

Ledger fieldQuestion it should answer
Exact representationWhat words did the audience see, and in which channel?
Intended meaningWhat capability, outcome, data use, or degree of automation would a reasonable reader understand?
Evidence ownerWho can explain and produce support for the claim?
System and versionWhich deployed model, service, workflow, or vendor release performed the represented function?
Evidence periodWas the support current for every date the claim remained live?
Limits and human roleWhat material qualification, override, review, or constraint changes the reader’s understanding?
Approval and expiryWho approved the statement, and what event forces re-review?

The ledger should cover material factual statements, not merely language containing “AI.” A statement about personalization, automation, forecasting, model accuracy, data sources, or performance can create the same substantiation problem even when the marketing team avoids the AI label.

Use the SEC Marketing Rule deficiency review for the wider advertising-control context. For capability, governance, and evidence ownership beyond advertising, tie the ledger to the role-based AI risk assessment questionnaire.

Treat Vendor Copy as an Input, Not Proof

A firm can publish an unsupported claim even when the words originated in a vendor deck. Before repeating a provider’s representation, determine:

  • which component actually performs the claimed function;
  • whether the feature is enabled in the firm’s deployed configuration;
  • what customer or portfolio data reaches it;
  • whether a human or a different rules engine makes the final decision;
  • what testing supports any performance statement;
  • which limitations, exclusions, or geographic constraints apply; and
  • how the firm will learn when the vendor changes the feature.

Contractual warranties and audit rights may support this review, but they do not replace product evidence. Keep the vendor statement, the firm’s validation, identified gaps, approval decision, and monitoring trigger in the same record.

Control Changes After Publication

Claims often become inaccurate through drift rather than through an intentionally false launch. A model is replaced, a feature becomes optional, data access narrows, human review expands, or a vendor changes its architecture while the website remains unchanged.

Create change triggers that route material product events back to the claim owner. At minimum, consider model or vendor replacement, production rollback, data-source change, material test failure, revised human-review workflow, new limitation, and customer complaint suggesting that the description no longer matches experience. The control should be able to correct or withdraw copy quickly and preserve what changed, when, and why.

What to preserve for an examination or inquiry

A useful evidence packet includes:

  • the exact claim and every channel where it appeared;
  • the approval record and reviewers;
  • the technical evidence supporting the claim at publication;
  • deployment and change history;
  • monitoring or testing results relevant to the stated capability;
  • the date the claim was revalidated, corrected, or removed; and
  • records showing that regulatory filings and marketing were reconciled.

The point is not to guarantee that the SEC will agree with every characterization. It is to show that the firm had a reasonable, documented basis for the statement it chose to publish.

Bottom line

The verified SEC record is narrower—and more actionable—than a claim that the agency launched a new AI prosecution campaign. Two registered advisers resolved separate administrative proceedings over false or misleading AI statements and related compliance failures. Firms should use those orders as a prompt to substantiate objective claims, align disclosures, and preserve evidence before publication.

Official sources

This article is for general informational purposes and is not legal advice. Review the orders and applicable rules with counsel for your firm’s facts.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is AI washing?
AI washing is a shorthand description for false, misleading, or unsubstantiated statements about how a product or service uses artificial intelligence. The SEC's March 2024 Delphia and Global Predictions matters applied existing Investment Advisers Act provisions to adviser marketing and disclosures; they did not create a new AI-specific offense.
Which SEC matters are the key settled AI-washing cases?
On March 18, 2024, the SEC announced settled administrative orders against Delphia (USA) Inc. and Global Predictions, Inc. Delphia agreed to a $225,000 civil penalty and Global Predictions agreed to a $175,000 civil penalty. Each matter must be read separately because the findings and remedial provisions are entity-specific.
Were Delphia or Global Predictions criminally prosecuted?
No. These were settled SEC administrative proceedings, not criminal prosecutions. Each respondent consented to an order without admitting or denying the SEC's findings, except as to the Commission's jurisdiction and the subject matter of the proceeding.
Did the SEC's Cyber and Emerging Technologies Unit bring the 2024 cases?
No. The SEC announced the Delphia and Global Predictions settlements in March 2024. The Commission announced the Cyber and Emerging Technologies Unit in February 2025. Its stated focus includes fraud involving emerging technologies such as artificial intelligence, but that later announcement should not be retroactively attributed to the 2024 orders or described as a binding 2026 compliance mandate.
What is the practical control for an AI-related marketing claim?
Treat each objective AI claim as a representation that needs an identified owner, evidence showing what the system actually does, legal and compliance review before publication, version control, and periodic revalidation. For SEC-registered advisers, the Marketing Rule also requires a reasonable basis for believing material factual statements can be substantiated on Commission demand.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.