No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

Substantiate Your AI Claims Before They Become AI-Washing Challenges

With models, datasets and vendor APIs changing constantly, a claim that was accurate in the past may no longer hold up

by Andrew Lustigman and Barry Greenbaum
September 7, 2026
in Compliance
cute robots

Recent regulatory activity illustrates why companies should take AI-washing seriously, Andrew Lustigman and Barry Greenbaum of Olshan explain. Remember: Your vendors’ marketing materials should not become your substantiation record. 

Companies increasingly describe their products and services as AI-related. They promote “AI-powered” personalization, “AI-driven” recommendations, automated customer service, predictive analytics and other features across websites, sales decks, RFP responses, customer contracts, vendor disclosures and executive interviews. 

The claims are everywhere, but in many cases the technology plays only a minor role or none at all. This gap between marketing language and technical reality has become known as “AI washing,” taking a page from overstated sustainability claims and resulting greenwashing, and can result in Federal Trade Commission (FTC) enforcement actions and advertising industry regulator challenges.

Advertising substantiation is not new. Regulators have long required companies to have a reasonable basis for objective claims before those claims are disseminated. What is new is the complexity of AI claims and the difficulty of evaluating the underlying technology. The standard, however, has not changed. Companies still need a reasonable basis for their objective claims. The challenge is that AI can make that basis harder to establish, evaluate and maintain.

Define the claim

The first challenge is often the claim itself. “AI‑powered,” “AI‑driven,” “intelligent” and “automated” can all mean different things depending on context. A customer may reasonably believe “AI‑powered customer service” to mean that an AI system handles interactions with little or no human involvement. The underlying product, however, may use AI only to suggest responses and require human reviews prior to sending. For example, Samsung faced a challenge from the industry’s self-regulatory body, NAD, regarding advertising for its Bespoke refrigerators, resulting in the discontinuance of claims that “smart” connectivity was AI-driven.

Before attempting to substantiate an AI claim, legal and compliance teams should ask: What would a reasonable customer understand this statement to mean? That question forces the organization to articulate what the technology actually does, whether it makes decisions, assists a human decision-maker or performs a narrow function within a larger rules‑based system. Defining the claim is the first step toward identifying the evidence required to support it.

Evidence must match the promise

After defining the claim, the next questions become whether the company has evidence to support it and whether that evidence matches what the claim promises.

If a company says its AI system is “95% accurate,” that should prompt questions about how accuracy was measured, what data was used, what the system was tested against and under what conditions. A claim that the system is “more accurate than human reviewers” involves different considerations. It requires identifying who the reviewers were, what tasks they performed and whether the comparison was statistically meaningful. If a product is described as “fully automated” but employees routinely review or correct its output, the company should consider whether that human involvement changes what customers are likely to understand from the claim.

Regulators have not ignored these types of claims. In the case of FTC v. Workado, LLC, the FTC challenged a company’s AI content detector as being “98% accurate” when independent testing revealed the number was closer to 53%. The company settled with the agency, agreeing to prohibitions on representations about the effectiveness of its AI products unless it had competent and reliable evidence to support the claim. 

More recently, the FTC brought a trio of enforcement actions against Cox Media Group and two small marketing agencies challenging claims that their “Active Listening” branded marketing service deployed a special algorithm to listen in on consumers’ conversations overheard by smart devices. The algorithm would then facilitate the delivery of targeted advertising in the advertisers’ desired locations. The FTC contended that the listening service did not actually listen in on consumers’ conversations or use voice data. Furthermore, the FTC contended that consumers had not opted in for this service. Cox Media Group and the marketing agencies settled the actions, paying nearly $1 million and agreeing to prohibitions on the qualities or features of its advertising or marketing services; the collection and use of voice data and whether consumers have provided their consent to collect, use or disclose their voice data; and the geographic targeting capabilities of its advertising or marketing services.

In the self-regulatory context, Horizon Brands faced an NAD challenge regarding advertising claims for its Tiny Traveler “AI-powered Smart Baby Monitor Solution.” While the presence of an AI chip supported claims that the baby monitor did employ AI technology, NAD recommended that AI “emotion detection” and “motion detection” claims note their limitations and discontinue claims that the monitor can ensure infant safety. The challenge demonstrates that companies should be careful to limit claims that a feature is available if it is not yet live and be sure to disclose any limitations on performance and operating conditions.

nist headquarters sign
Cybersecurity

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

by Larry Marks
August 21, 2026

Draft framework TEVV-Athlon is designed for organizational flexibility

Read moreDetails

Substantiating the vendor

Substantiation becomes more complicated when a company relies on third‑party AI technology. Retailers, financial institutions, software companies and other businesses increasingly incorporate AI tools supplied by vendors. A vendor may describe its technology as highly accurate, autonomous, secure or capable of producing a particular business outcome. Those representations often find their way into the customer’s own website, sales materials or RFP responses. But a vendor’s marketing materials should not automatically become the customer’s substantiation record.

Companies should understand what their vendors are providing and what evidence supports material claims about the technology. Vendor claims should be verified before they are incorporated into the company’s own marketing or customer communications. Contracts can help facilitate that process by requiring vendors to provide technical documentation, testing reports and notice of material changes. But contractual protections are not a substitute for understanding the product. If a company tells its customers that its own service provides a particular AI-enabled benefit, pointing to a vendor’s website after the fact is unlikely to establish whether the company’s statement was adequately supported.

Consistency across the organization

AI claims often span multiple departments, which increases the risk of inconsistency. Marketing may approve language for a website. Product developers may describe the same feature differently in a sales presentation. A salesperson may make a broader representation. An executive may characterize the technology in a different way during an interview. Each statement may seem harmless on its own, but together, they can create a picture of the product that is considerably more expansive than what the technology actually does.

A coordinated review process involving legal or compliance, product or engineering and the business or marketing team responsible for communicating with customers can help ensure that everyone is working from the same understanding of the technology; it can also outline the evidence supporting the claim. The goal is not to require every communication to use identical language but to ensure that variations in messaging do not convey materially different impressions of what the technology can do.

Ongoing substantiation

Finally, companies should maintain a record for material AI claims and keep it current. The record should identify:

  • The precise claim.
  • Where it is being used.
  • The product or feature involved.
  • The evidence supporting it.
  • Any material limitations.
  • The designated individual responsible.
  • The date it was last reviewed.

Maintaining a live, periodically updated record ensures ongoing accuracy.

Companies should also have final checks. Before approving an AI claim, companies should thoroughly review what they are saying, what a reasonable customer would understand and what evidence they have today. The companies that can answer these questions each time a claim is made will be the ones that build lasting trust, avoid regulatory risk and maintain credibility across the market. 

Tags: Artificial Intelligence (AI)
Previous Post

Benchmarking Study: Third-Party Risk Management

Next Post

Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor

Andrew Lustigman and Barry Greenbaum

Andrew Lustigman and Barry Greenbaum

Andrew Lustigman is co-managing partner at Olshan in New York and chairs the firm’s advertising, marketing and promotions practice and co-chairs its brand management and protection practice.
Barry Greenbaum is a partner in Olshan’s brand management and protection and intellectual property law practices in New York.

Related Posts

soccer ball near end line

AI Is a Stickler for the Rules, but Rules Don’t See Everything

by Neil Sahota
September 7, 2026

Human inconsistencies and man-made exceptions are often overlooked in AI deployments

news roundup data grungy

Cybersecurity Pros Name Social Engineering as Top Human Risk

by Staff and Wire Reports
September 4, 2026

Plus: 20-point bump for AI in financial predictions; July sees ransomware peak

uk prime minister andy burnham

Risk & Compliance Implications of New UK Government

by Jonathan Armstrong
August 28, 2026

AI policy-making is already undergoing shake-ups

news roundup data grungy

Only 1 in 10 Can See Through Shell Companies for Sanctioned Parties

by Staff and Wire Reports
August 27, 2026

Plus: Small firms have higher chance of reaching SOC 2 goals; AI-enabled cyber risk ranks as top threat

Next Post
cisa website

Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights