Company verification
AI-washing: how to verify whether a company really does AI
A practical, source-based guide to telling genuine AI from marketing. Built on the CFA Institute's due-diligence framework, with a checklist, red flags and the filings to read.
“AI-driven.” “Powered by machine learning.” “An AI-first platform.” In 2026 these phrases are on the homepage of almost every software company — and on plenty of companies that sell mattresses, juice and consulting. Some of it is real. A lot of it is marketing.
The gap between the two has a name: AI-washing. It mirrors “greenwashing” — overstating or inventing a capability because the label sells. For a customer it means paying a premium for a feature that may be a few if-statements behind a chatbot skin. For an investor it can mean buying a story instead of a business.
This guide is about closing that gap with evidence. It is not a way to brand any specific company a fraud — that is both unfair and, as we explain at the end, legally risky. It is a way to ask better questions and read the documents that actually answer them.
Why AI-washing is worth taking seriously
Regulators and standards bodies have stopped treating this as a vibe. In June 2025 the CFA Institute — the body behind the Chartered Financial Analyst designation — published a report on AI washing in investment management, defining it as falsely or excessively inflating claims about AI use, and offering a structured due-diligence questionnaire for separating substance from spin. (CFA Institute)
Securities regulators have moved too. The US SEC has brought settled charges against firms for overstating their AI capabilities to investors — making “we use AI” a statement that can carry legal weight, not just a slogan.
The practical takeaway: if a claim about AI is material to your decision, treat it like any other material claim. Verify it.
The same pattern is now spreading to a newer, narrower claim: “agentic.” Our companion analysis of agentic engineering versus agentic washing applies this exact playbook to that specific label.
The two-layer test: technical and organisational
The CFA framework splits due diligence into two layers. It is a useful spine for anyone — investor, buyer, journalist — and it maps cleanly onto documents you can actually read.
Layer 1 — technical substance
- Named models, not adjectives. Genuine AI work usually comes with specifics: which models or techniques, which benchmarks, which datasets. “We use advanced AI” with no nouns is a flag, not proof.
- Training data provenance. Where does the data come from, and does the company have the rights to use it? Vague answers here are both a quality risk and a legal one.
- Measured performance. Is model performance measured and disclosed, or asserted? Real teams have error rates; marketing has superlatives.
- Core vs. veneer. Is AI doing something load-bearing in the product, or is it a wrapper around a third-party API bolted on for the press release?
Layer 2 — organisational substance
- People. Do the leaders and the AI team have verifiable, relevant experience — not just new “Chief AI Officer” titles?
- Spending. How much does the company actually invest in research and development versus sales and marketing? The ratio is in the financial statements.
- Disclosure honesty. Does the annual report describe AI as a genuine dependency in its risk factors, or only as opportunity language in the glossy section? Companies are usually more truthful where the law makes them warn you.
The documents that tell the truth
Marketing lives on the homepage. Substance lives in filings. For a US-listed company, three sources do most of the work — and all are free.
| Source | What it tells you | Where |
|---|---|---|
| Annual report (10-K) | How the business actually makes money; whether “AI” appears in strategy or only in marketing | SEC EDGAR |
| Risk factors (inside the 10-K) | What the company itself admits could go wrong — often the most candid section | SEC EDGAR |
| R&D vs. revenue (financial statements) | Whether real engineering money is being spent, or mostly sales spend | SEC EDGAR (us-gaap) |
Our free AI company verifier links straight to the SEC filings for a set of AI-related companies, alongside the checklist below — so you can go from a claim to the primary document in two clicks. It deliberately shows facts and questions, never a verdict.
For private companies there is no 10-K, and no cheap database will hand you the truth — that is exactly where verification matters most and where the two-layer questions above do the heavy lifting.
Ten red flags of AI-washing
None of these is proof on its own. Several together justify a much harder look.
- AI everywhere on the homepage, absent from the product documentation.
- “AI” with no named model, technique, benchmark or dataset.
- A “Chief AI Officer” hired the same quarter the AI messaging appeared.
- R&D spending tiny relative to marketing spending.
- AI revenue blended into vague “AI-driven” totals, never broken out.
- Demos that are always pre-recorded or human-in-the-loop “for now”.
- The risk factors barely mention AI while the press releases can’t stop.
- Claims of proprietary models that turn out to be a thin wrapper over someone else’s API.
- Accuracy claims with no error rate, test set or methodology.
- The company’s valuation re-rated sharply right after an AI rebrand, with no change in the underlying business.
Tools that help (and what they don’t do)
Two categories of paid tools are genuinely useful here, and we link to them as affiliate partners — which means if you sign up we may earn a commission, at no extra cost to you, and it never changes what we write (see our disclosure).
- Fundamentals & valuation context. For reading a public company’s numbers — R&D, margins, how stretched the valuation is — a research tool such as Simply Wall St turns filings into visual snapshots. It is context, not a verdict.
- Content authenticity. If your question is narrower — “was this ‘AI-written’ report actually generated by a model?” — AI content detectors like Originality.ai or GPTZero address that specific task. We cover those in depth in our detection guides.
No tool verifies a company for you. They surface evidence faster; the judgement stays yours.
A note on fairness and the law
It is tempting, once you spot the flags, to declare a company “an AI-washing fraud”. Don’t — at least not as a statement of fact about a named business. That can expose you to defamation claims, and in regulated markets to allegations of market manipulation. It is also frequently wrong: a weak homepage is not the same as a weak company.
The defensible posture is the one the CFA framework implies: gather verifiable data, attribute it, and frame your conclusion as the questions a reasonable investor should ask. “The 10-K spends two pages on AI opportunity and one line on AI risk; R&D is 4% of revenue; no model is named” is reporting. “This company is a scam” is a lawsuit waiting to happen.
That discipline is also good analysis. The goal was never to dunk on a logo — it was to know what you own.
This article is educational and not investment advice. Figures and frameworks were current as of June 2026; verify primary sources before relying on them.
We report facts with sources and dates. We never label a named company as fraudulent or "AI-washing" as a statement of fact — we present verifiable data and the questions an investor should ask.
Frequently asked questions
What is AI-washing?+
AI-washing is exaggerating or fabricating a company's use of artificial intelligence to attract customers or investors — for example using phrases like 'AI-driven' or 'machine-learning-enabled' without genuine, material AI in the product. The term mirrors 'greenwashing'.
How can I check whether a company really uses AI?+
Read primary sources rather than press releases: the annual report (10-K for US-listed firms), the risk factors section, R&D spending, and how revenue is reported. Ask which specific models are used, where the training data comes from, how performance is measured, and whether the team has verifiable AI experience.
Is calling a company 'AI-washing' legally risky?+
Stating as fact that a named company commits fraud or 'AI-washing' can expose you to defamation and, for regulated markets, market-abuse claims. Safer practice is to present verifiable data with attribution and frame conclusions as questions an investor should ask.
Related reading