AI-Washing in Fintech: What SEC and DOJ Cases Mean for Founders

The AI behind the Nate shopping app was, for the most part, a call center.

According to the Department of Justice, hundreds of contractors in the Philippines placed orders by hand while investors were told the app ran on proprietary AI. Prosecutors say the real automation rate was effectively zero. The founder raised more than $42 million on the story.

In April 2025, the SEC and the US Attorney’s Office in New York charged him with fraud. These are allegations, and he has pleaded not guilty. Still, the case marked a shift. Describing your AI inaccurately is no longer only a civil problem.

Fintech founders should pay attention. Claims like “AI-powered fraud detection” or “automated KYC” are specific, testable, and made to investors, banks, and customers at the same time. That makes them easy to check.

What AI-washing means, and why there is no new rule to wait for

AI-washing is the term regulators use for claims that a company uses AI when it does not, or that overstate what its AI does.

The first enforcement actions came in March 2024 against two investment advisers. Delphia told clients from 2019 through 2023 that it used AI and machine learning on their data to shape its investment advice. It did not have the capability it described. Global Predictions could not substantiate its own AI claims. Both firms settled, paying $225,000 and $175,000.

Neither case needed a new AI statute. Regulators applied long-standing antifraud, disclosure, and marketing rules to a new kind of claim. The exposure already exists under the laws you are subject to.

Three cases, three different failures

Delphia (2024): a capability that never existed. The data collection happened. The algorithm that was supposed to use it did not.

Presto Automation (January 2025): provenance and automation rate. This was the first AI-washing action against a public company. Presto sold an AI voice product for drive-thru ordering, and the SEC found two problems. For a period, every deployed unit ran on speech recognition technology owned and operated by a third party, while Presto’s disclosures described it as the company’s own. Later, when Presto shipped its own version, it said the product eliminated human order-taking. The SEC found the vast majority of orders still needed a person, and Presto itself later acknowledged that more than 70 percent did. It was also charged with failing to maintain disclosure controls. Presto settled with a cease-and-desist order and no civil penalty, given its financial condition and cooperation.

Nate (April 2025): the criminal case. Investors were told the app could transact “without human intervention”, apart from rare edge cases. Law-firm analyses of the complaint put the claimed success rate at 93 to 97 percent. Prosecutors allege the AI, partly acquired from a third party, never consistently completed purchases, and that humans did the work in secret. They also allege that when volume grew, the founder had engineers build the very “dumb bots” he had told investors Nate did not use. Access to the internal automation dashboard was allegedly restricted, and the data was called a trade secret.

The claims-to-code gap

Line the cases up and the same shape appears. Each one is a gap between what the company said publicly and what its system could prove.

We call it the claims-to-code gap: the distance between what your deck, website, and investor updates say your AI does, and what your codebase and production data can show.

Type of gapCaseWhat was claimedWhat the record showed
CapabilityDelphiaAI used client dataThe capability did not exist as described
Automation ratePresto, NateLittle or no human involvementPeople handled most of the work
ProvenancePresto“Our technology”Third-party owned and operated
ConcealmentNateStrong automation metricsMetrics restricted, data called a trade secret

Regulators measure this gap. In Presto, the SEC compared public statements against system performance data and internal messages. None of the cases turned on a clever legal theory. They turned on whether the marketing matched the build.

We have written before about the same pattern on the vendor side: a pitch that claims more than the architecture can demonstrate under a real question. Regulators are now asking that question of founders too.

Closing the gap: four checks

This is a standing discipline, not a one-off review before a fundraise.

1. A claims register. Log every public statement about what your AI does, taken from your website, deck, app store listing, and investor updates. Each entry gets the exact wording, where it appears, the feature it describes, a named owner, and a date it was last verified.

2. A capability match. Check each claim against what the system does in production today, not what was scoped or what is on the roadmap. The test is simple: what share of transactions does the system complete without a person, measured over the last 30 days? If your deck says “AI-powered fraud detection” and what is live is a rules engine with a machine learning model still in shadow mode, that is the gap.

3. A provenance flag. For every AI capability you claim, record whether it is built in-house or licensed. Using a vendor is normal. Presto’s problem was calling third-party technology its own.

4. A sign-off step. Presto was charged over disclosure controls, not only over wording. Decide who approves a new AI claim before it reaches a deck, a blog post, or an investor update. Engineering should confirm what the system does, and legal or compliance should confirm how it is described.

Human-in-the-loop is not the problem. Hiding it is. Define terms like “automation rate” and “non-intervention rate” once, measure them the same way everywhere, and describe the human role plainly. Some illustrative rewrites:

Instead ofSay (if it is true)
“AI-powered fraud detection”“Rules-based fraud screening, with a machine learning model in testing”
“Fully automated KYC”“Automated document checks, with analyst review of flagged cases”
“Our proprietary AI”“Built on licensed models, with our own orchestration and controls”

Why this is not a passing sweep

In February 2025, the SEC created its Cyber and Emerging Technologies Unit, about 30 fraud specialists and attorneys, and listed fraud involving AI and machine learning first among its priority areas.

Private litigation points the same way. Cornerstone Research and Stanford Law School counted 7 AI-related securities class actions in 2023, 15 in 2024, and 16 in 2025. In the first half of 2026 alone, they counted 15. Two caveats apply. The category also covers cases about AI development, data centers, and infrastructure, so it is not all AI-washing. And 2025 was uneven, with 12 filings in the first half and only four in the second. The direction is still clear.

Where engineering comes in

A claims register lives in a spreadsheet. The evidence lives in your architecture.

If automation rate is a number you can pull on demand, with dates, you can answer a regulator, an investor, or a bank partner in minutes. If it is a number someone estimates before a board meeting, you cannot. Nate is the extreme version, where the dashboard existed and access to it was restricted.

That is why this belongs in the build, not in a pre-raise cleanup. Adding measurement and audit trails after the claims are already public is the same Retrofit Tax we see with compliance: it is paid later, under a deadline someone else sets. The same applies to AI-generated code in regulated systems, where every change needs a named owner and a trail a regulator can follow.

The question to ask this quarter

If a regulator, an investor, or a bank partner compared your public AI claims against your production data tomorrow, what would they find?

If your team cannot answer that quickly, start with the register. It takes days, not months, and it is far cheaper than explaining the gap later.

NeoBank Labs builds compliance-ready fintech infrastructure for teams in the US, EU, and Australia, with architecture and audit trails that can back up what you tell investors and regulators. If you want a technical second opinion before your disclosures are questioned, we are happy to talk it through.

This is a general overview of a developing enforcement area, not legal advice. If your AI-related disclosures are being questioned, talk to securities counsel.

Written by a Solutions Architect at DigiEx Group, where we build production AI systems for enterprise fintech teams and co-developed vCodeX, an AI-native coding agent platform.