AI washing is the use of vague, exaggerated, or misleading artificial-intelligence claims to make a product, service, company, or investment appear more capable or valuable than the evidence supports. The problem is not whether a system uses a fashionable model. It is whether a material claim about its function, performance, autonomy, safety, or business impact is truthful, specific, and substantiated.
Rule-based software is not automatically fraudulent, and an AI system does not have to learn continuously after deployment. Relevant questions are what technique is used, what role it plays, how it was evaluated, and whether the marketed claim matches the product customers receive.
Common warning signs
- “AI-powered” appears without a defined task, model role, or user-visible limitation.
- A demo, anecdote, or single accuracy number is presented as proof of production performance.
- Benchmarks omit the dataset, baseline, sample size, confidence interval, error severity, or evaluation date.
- The vendor combines human work, rules, retrieval, and model output but attributes the entire result to AI.
- Claims of autonomy omit required review, intervention rates, failure handling, and operating boundaries.
- Security, privacy, fairness, or compliance is described as guaranteed by the technology itself.
Turn marketing language into testable claims
| Claim | Evidence to request |
|---|---|
| “Automates the workflow” | Steps automated, human interventions, exception rate, fallback, and measured end-to-end time |
| “95% accurate” | Metric definition, denominator, test set, baseline, class balance, uncertainty, subgroup results, and error costs |
| “Understands documents” | Supported formats, languages, extraction schema, out-of-distribution tests, abstention, and review process |
| “Enterprise secure” | Architecture, tenant isolation, access controls, retention, training-data policy, audit evidence, and incident process |
| “Explainable” | Audience, decision being explained, method validation, known limits, and recourse for affected people |
An explanation graphic or feature attribution does not establish correctness or causality. Review explainable AI examples with the same evidence standard.
A due-diligence workflow
- Define the decision. Document the intended use, users, affected people, prohibited uses, data sensitivity, failure consequences, and non-AI baseline.
- Write claim cards. For every material claim, record the exact wording, audience, product version, measurement, test population, source, limitations, and accountable approver.
- Inspect the system boundary. Identify models, rules, retrieval, third-party services, and human operations. Determine what happens when any component fails.
- Run an independent pilot. Use representative, lawfully obtained data; predefine metrics and thresholds; include hard, ambiguous, missing-data, and adversarial cases.
- Measure the workflow. Include review time, overrides, rework, latency, availability, cost, and severe errors—not merely a model score.
- Contract for change. Require version notice, evidence for renewed claims, security obligations, audit rights, incident notification, exit support, and data deletion.
Connect procurement evidence to AI model management so a model or data change cannot preserve an obsolete claim by default.
Regulatory and enforcement context
In the United States, the Federal Trade Commission has warned companies to substantiate AI claims and has brought matters involving allegedly deceptive AI capabilities or earnings claims. Securities regulators can address material misstatements to investors. Which rule applies depends on the speaker, audience, claim, product, and jurisdiction; this article is not legal advice.
The EU AI Act includes transparency obligations for specified systems and content, but it does not turn every use of the word “AI” into a single disclosure rule. Organizations should obtain current legal advice for their role and implementation timeline rather than copying a generic compliance label.
What buyers should retain
- Approved claim cards and the evidence reviewed.
- Evaluation protocol, dataset provenance, results, limitations, and reviewer sign-off.
- Model, prompt, retrieval source, software, and vendor versions.
- Risk acceptance, human-oversight design, monitoring, incidents, and remediation.
- Contract terms covering data, changes, security, service levels, and exit.
Use AI governance practices to assign ownership and escalation, and evaluate the investment against the outcome framework in machine learning for business.
Conclusion
The best defense against AI washing is not a checklist of buzzwords. Convert each important promise into a measurable claim, test it on the intended workflow, inspect the full human-and-technical system, document limitations, and repeat the review when the product changes.

Historical comments from Datanizant
No public comments on this article
No approved public comments were included in the WordPress export for this article.