RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 2, 2026

AI Washing 2026: When Your Marketing Copy Becomes an FTC Problem

Nearly every software homepage picked up an AI badge in the last two years. Most of those badges are claims about how the product works — and claims about how a product works have always been the kind regulators are willing to test.

It's a claim
'AI-powered' is a factual statement, not positioning
Four accusers
Regulators, competitors, investors, and customers can all raise it
Written first
Substantiation has to exist before the copy ships, not after

Why This Became a Category of Risk

For most of the last decade, "AI" in marketing copy was treated as a mood — a signal that a product was modern. That worked while nobody could check. It stopped working when buyers, procurement teams, and enforcement staff got specific enough to ask which part of the product uses a model, what it was trained on, and what happens when it is wrong.

The legal theory is not new and requires no AI-specific statute. Deceptive advertising law turns on whether a claim is likely to mislead a reasonable consumer about something material to their decision. A buyer choosing your product because it "uses AI to detect anomalies" is making a purchase decision on that description. If the detection is a static threshold someone set in 2023, the description is the problem — not the threshold.

The Four Shapes AI Washing Takes

The capability gap

The product is described as learning, predicting, or generating when it applies fixed rules, templates, or lookup tables. This is the most common form and the easiest to prove, because the codebase settles it.

The human behind the curtain

Output marketed as automated is produced or heavily corrected by staff or contractors. Human-in-the-loop is a legitimate design; describing it as autonomous is the deception. Pricing and SLA promises built on the automated story make the gap material.

The borrowed model

Marketing implies proprietary models trained on proprietary data when the product is a thin wrapper over a third-party API. Wrapping a foundation model is a fine business; claiming 'our model, trained on our data' when neither is true is a factual misstatement — and one your vendor list contradicts.

The unsourced number

Accuracy, time-saved, or ROI figures with no traceable methodology. A percentage on a landing page invites exactly one question, and 'a customer told us' is not an answer that survives it.

The Exposure Isn't Only Regulatory

Founders tend to model this as a low-probability regulator event and discount it accordingly. The more likely first contact comes from somewhere else:

  • A competitor whose honest copy is losing deals to yours, and who has a false-advertising claim available.
  • An enterprise customer whose security review discovers the architecture does not match the sales deck — usually mid-renewal.
  • An investor reading the same claims in a deck, where statements about the technology carry their own liability.
  • A state attorney general acting under a state unfair-and-deceptive-practices statute, which does not require federal attention first.

Rewriting Claims Without Losing the Pitch

The instinct when legal gets involved is to strip the page down to nothing. That is not necessary, and it usually costs conversion. Specific claims outperform vague ones anyway:

RiskyAI-powered ticket triage
DefensibleClassifies incoming tickets into your existing queues using a language model, with a confidence score you can route on
RiskyOur proprietary AI understands your data
DefensibleBuilt on frontier language models, with retrieval over your workspace so answers cite the source document
Risky95% accurate
Defensible94.6% agreement with human reviewers on a 2,000-ticket sample from March 2026 — methodology linked
RiskyFully autonomous agent
DefensibleDrafts and executes routine steps automatically; anything above your approval threshold waits for a human

The Substantiation File

One document, updated when claims change. It takes an afternoon to create and is the difference between a short response and a long discovery process.

Inventory every AI claim on the site, in decks, and in app store listingsStart here
For each claim, name the specific product surface and the model or technique behind itEssential
Record the human involvement in each workflow you describe as automatedEssential
Attach methodology, dataset, and date to every performance number you publishEssential
Note which models are third-party vs. in-house, and keep the copy consistent with thatEssential
Name an approver for AI claims — one person who signs off before copy shipsProcess
Re-review claims whenever the underlying model or vendor changesProcess
Keep fundraising and sales materials aligned with the same fileInvestor risk

Your claims live on pages nobody has audited in months

RatedWithAI scans your web properties for the compliance and accessibility gaps that turn into complaints and legal exposure. Start with a free scan.

Scan Your Site for Free →

Frequently Asked Questions

We wrap a third-party model. Can we still say 'our AI'?

Generally yes, if you are not implying you built or trained the model. 'Our AI assistant' describing a product you built on top of a foundation model reads differently from 'our proprietary model trained on 10 years of industry data'. The first describes your product, the second makes a specific factual claim about provenance that has to be true.

Does a disclaimer in the footer fix a misleading headline?

Rarely. Deception is generally assessed on the net impression a reasonable consumer takes away, and a prominent headline is not typically cured by fine print elsewhere on the page. If the qualification is material to the claim, it belongs next to the claim.

What about aspirational claims for features on the roadmap?

Marketing a capability in the present tense that does not exist yet is the highest-risk version of this, because the gap is total rather than partial. Label future capability as future capability — in the product copy, the sales deck, and the demo.

How does this interact with AI-specific regulation?

Deceptive-advertising exposure sits underneath the newer AI statutes and does not depend on them. A company can be fully outside the scope of an AI-specific law and still have a marketing-claims problem, because the theory is ordinary consumer protection applied to a technical description.

Who should own this internally?

Whoever approves public copy, with a named technical reviewer. The failure mode is a marketing team writing from a positioning doc that nobody on the engineering side ever read — which is how most AI washing happens without anyone intending to mislead.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.