Sommaire
- 1 Introduction
- 2 I- Why is AI washing a legal risk?
- 3 II- Which legal rules apply to misleading AI claims?
- 4 III- What are the practical risks for companies?
- 5 IV- How can companies distinguish acceptable communication from AI washing?
- 6 V- What roadmap should companies adopt for AI-related communications?
- 7 VI- How does intellectual property law relate to AI washing?
- 8 Conclusion
- 9 Q&A
Introduction
AI washing is becoming a significant legal risk for companies that communicate about artificial intelligence without being able to substantiate the actual role, sophistication or performance of the technology they use. Describing a product as “AI-powered”, “machine-learning driven” or “based on a proprietary model” may enhance commercial appeal, reassure investors or justify a higher valuation. However, these statements become legally sensitive when they influence the decision of a customer, partner or investor.
I- Why is AI washing a legal risk?
AI washing consists of overstating, embellishing or inventing the use of artificial intelligence in a product, service, internal process or investment strategy. The risk arises where communications suggest that a company has more advanced, autonomous or powerful technology than it actually does.
Certain statements are particularly sensitive:
- “our solution is fully AI-driven”;
- “we use a proprietary model”;
- “our algorithm learns automatically from every interaction”;
- “our platform makes decisions without human intervention”;
- “our technology is AI Act compliant” without documented analysis;
- “our tool guarantees reliable results” without technical evidence.
The difficulty is that AI washing is not always intentional. A company may use ambitious commercial language, repeat technical terms that are not fully understood by marketing teams, or describe a basic automated rule, a traditional statistical tool or a third-party feature as “AI”. From a legal perspective, intent is not always decisive: an inaccurate claim may be sufficient if it is likely to mislead the relevant audience.
II- Which legal rules apply to misleading AI claims?
In France, exaggerated communications about artificial intelligence may fall within the rules on misleading commercial practices. Article L.121-2 of the French Consumer Code covers, in particular, practices based on false or misleading claims concerning the essential characteristics of goods or services. A statement about the technology used, expected performance or results may therefore be caught if it influences the customer’s economic decision.
At EU level, Directive 2005/29/EC on unfair commercial practices protects consumers against misleading commercial communications before, during and after a transaction. It applies to practices directly connected with the promotion, sale or supply of a product or service.
The AI Act, Regulation (EU) 2024/1689, adds a further compliance dimension. It does not directly sanction every marketing exaggeration, but it establishes a framework based on transparency, risk management and documentation for certain AI systems. Its purpose is to promote trustworthy AI while ensuring a high level of protection for health, safety and fundamental rights. Transparency obligations for certain AI systems reinforce the need for consistency between the actual technical system and the way it is presented to users.
Where AI involves personal data, CNIL guidance also makes clear that innovation must remain compatible with GDPR principles, including information, security, lawful basis, minimization and the exercise of data subject rights.
III- What are the practical risks for companies?
The first risk is commercial and reputational. A company accused of AI washing may lose the trust of customers, investors and business partners. In sensitive sectors such as healthcare, finance, insurance, human resources or cybersecurity, that loss of trust may immediately affect ongoing contracts.
The second risk is litigation. A competitor may argue that exaggerated AI claims distort competition. If a company falsely suggests that its product is genuinely intelligent while a competitor has invested in real AI capabilities, the communication may raise issues of unfair competition, parasitism or misleading advertising.
The third risk concerns investors. In the United States, the Securities and Exchange Commission has already sanctioned investment advisers for false or misleading statements about their alleged use of artificial intelligence. In the Delphia and Global Predictions matters, the SEC challenged AI-related claims that were not sufficiently substantiated or did not reflect the actual services provided.
The fourth risk is transactional. In a fundraising, acquisition or sale process, AI claims may affect valuation. If due diligence reveals that the technology is mainly human-operated, outsourced or based on third-party components, the buyer may seek a price adjustment, stronger warranties or remedies.
IV- How can companies distinguish acceptable communication from AI washing?
The distinction depends mainly on three criteria: truthfulness, substantiation and audience understanding.
A company may legitimately promote an AI technology if it can explain:
- which feature actually uses AI;
- what part of the service involves human intervention;
- whether the model is proprietary, licensed or provided by a third party;
- which data are used;
- what results can reasonably be expected;
- which limitations must be disclosed to users;
- which technical or legal validations have been carried out.
Companies communicating about artificial intelligence should implement a validation process before publication. This should not be limited to legal documents. It should cover websites, commercial presentations, pitch decks, press releases, product pages, white papers, LinkedIn posts and responses to tenders.
Before publishing any AI-related claim, companies should verify:
- the technical reality of the feature described;
- the available documentation supporting the claim;
- the existence of any third-party provider;
- the rights to use models, datasets and generated outputs;
- GDPR compliance where personal data are processed;
- consistency between marketing claims and customer contracts;
- appropriate disclaimers where performance depends on the use case;
- the absence of absolute or unverifiable promises.
A good practice is to create an internal AI claims policy. This policy may provide for an approval workflow involving product, marketing, legal, compliance, data protection and technical teams.
VI- How does intellectual property law relate to AI washing?
AI washing is not only an advertising issue. It may also reveal weaknesses in intellectual property ownership and control.
Where a company claims to own a “proprietary model”, it must be able to identify the rights it actually holds: source code, databases, technical documentation, structured prompts, software architecture, protected outputs, trade secrets, open-source licenses or development agreements. Vague communications may blur the line between what the company owns, what is provided by a third party and what is merely configured internally.
This verification is particularly important in due diligence. An asset presented as strategic may lose value if the company does not own the necessary rights, if development was carried out by a contractor without a full assignment, or if training data raise legal concerns.
Conclusion
AI washing confirms a simple principle: companies may promote innovation, but they must be able to prove it. Terms such as “AI”, “machine learning”, “intelligent automation” or “proprietary model” are not merely marketing language. They become legally significant when they influence a customer, investor or partner.
Dreyfus law firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property. Dreyfus law firm works in partnership with a global network of attorneys specializing in Intellectual Property.
Nathalie Dreyfus with the support of the entire Dreyfus team
Q&A
Is AI washing illegal?
It can be, if the communication is false, misleading, or insufficiently substantiated. In France, AI washing may be assessed under laws governing misleading commercial practices, unfair competition, or contractual liability.
Can the term “AI” be used in advertising?
Yes, provided that the company can clearly demonstrate what the AI actually does. Businesses should avoid making broad, absolute, or unverifiable claims (see, in particular, our analysis of the use of AI in influencer advertising).
What is the difference between automation and artificial intelligence?
Automation typically relies on predefined rules, whereas AI generally involves capabilities such as analysis, classification, generation, or learning based on computational models. Presenting a simple automated system as advanced AI may create a risk of misleading consumers.
How can a company substantiate its AI-related claims?
Companies should maintain technical documentation showing how the AI system functions, what tasks it performs, the data it relies on (where relevant), and any testing or validation supporting performance claims. Marketing statements should be consistent with this documentation and regularly reviewed.
Can a company be liable for AI claims made by a third-party provider?
Potentially, yes. If a business repeats or relies on misleading claims made by a software vendor or AI service provider, it may still be held responsible for its own communications to customers, investors, or business partners. Companies should therefore verify third-party claims before incorporating them into their marketing or commercial materials.
This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

