AI washing and agent washing

What is AI washing and agent washing?

AI washing is marketing that presents a product or a company as AI-driven when the AI is marginal, absent, or a thin layer over something else. The name borrows from greenwashing: the sticker changes, the thing underneath does not.

Agent washing is the 2025 and 2026 version of the same trick. A chatbot, an RPA bot or a scripted workflow gets relabelled as an "agent" because that is the word buyers are searching for. Gartner put a number on it in a press release of 25 June 2025: of the thousands of vendors selling agentic AI, it estimated that only about 130 offer something genuinely agentic, and it named AI assistants, RPA tools and chatbots as the products most often rebranded. The same release predicted that more than 40 percent of agentic AI projects will be cancelled by the end of 2027.

Neither term is about whether AI is good or bad. Both are about the gap between the claim on the slide and what runs when you press the button. The agentic AI entry already warns that the label hides the architecture; this entry is about the vendor-claim problem and what you check before you sign.

What the label usually hides

Three things sit behind most washed products, and none of them is bad technology. The problem is that they are sold as something else.

A rules engine. The "AI" that categorises tickets or flags invoices is a set of if-then rules written by a developer. It never learns, it never decides, and it handles exactly the cases someone thought of. That can be a fine product. It is not AI in any sense a buyer would recognise.

A single model call. The product takes your input, sends it to a large language model with a fixed prompt, and shows the answer. That is a wrapper. Useful wrappers exist, but a wrapper does not plan, does not retry, and does not choose tools. Calling it an agent is agent washing by definition.

People behind the curtain. The most serious cases involve a human team doing the work that the AI supposedly does, usually offshore, usually under instruction to keep quiet. The customer sees an app; the order is typed in by hand somewhere else. This is the variant that ends up with regulators, because the claim was not exaggerated but false.

A fourth, quieter version is AI that exists but does almost nothing: a model is called for a step a lookup table handled before, so the box can say "powered by AI". Not a lie, just not worth what the label implies.

Cases regulators have acted on

The list below only includes findings by a regulator or charges filed in court, with dates. Where a case is still an allegation, it says so.

Delphia and Global Predictions, United States, 18 March 2024. The SEC settled charges against two investment advisers for false and misleading statements about their use of AI. Delphia had claimed it put client data to work to make its AI smarter; the SEC found it did not have the capability described. Global Predictions had called itself the first regulated AI financial advisor. The firms paid 225,000 and 175,000 dollars respectively, without admitting or denying the findings. SEC chair Gary Gensler used the phrase "AI washing" in the announcement and said it hurts investors.

DoNotPay, United States, 25 September 2024. The Federal Trade Commission opened a sweep called Operation AI Comply and filed a complaint against DoNotPay, which had advertised the "world's first robot lawyer". The FTC found the company had never tested whether the output matched a human lawyer and had no lawyers on staff. DoNotPay settled for 193,000 dollars; the order was finalised in February 2025. FTC chair Lina Khan summed it up: there is no AI exemption from the laws on the books.

Presto Automation, United States, 14 January 2025. The SEC found that Presto, which sold a voice AI for drive-through ordering, had said its product eliminated the need for human order-taking. In fact the speech recognition in every deployed unit was for a period owned and run by a third party, and once Presto switched to its own technology, the vast majority of orders still needed a human. Presto accepted a cease-and-desist order without admitting or denying; the SEC imposed no fine because the company cooperated.

Nate, United States, 9 April 2025. The SEC and the US Attorney for the Southern District of New York filed parallel civil and criminal cases against Albert Saniger, founder of the shopping app Nate. The charges say he raised over 42 million dollars by telling investors that the app completed purchases with AI and no human involvement, while the orders were in fact typed in by contract workers abroad. These are allegations at the time of writing. What made the case stand out is that prosecutors treated AI washing as criminal fraud, not just a disclosure problem.

Builder.ai, United Kingdom, May 2025. The London company behind the "Natasha" app-building assistant entered insolvency on 20 May 2025. The Wall Street Journal had reported in 2019, when the company was still called Engineer.ai, that most of the coding was done by human engineers. In May 2025 the Financial Times and Bloomberg reported that the 2024 revenue figure given to lenders had been cut to roughly a quarter after an internal audit, and that the company had allegedly swapped invoices with an Indian partner to inflate sales. US prosecutors issued subpoenas later that year. As of September 2026 no court or regulator has ruled on the AI claims themselves: the collapse is a fact, the fraud allegations are still allegations.

United Kingdom advertising, October 2023. The Advertising Standards Authority upheld a complaint against an app that advertised AI-improved photos without evidence of the results, and its guidance since then treats "AI" in an ad as a claim like any other: hold the evidence before you run it.

None of these cases involves a European regulator yet, and we found no Belgian decision specifically about AI claims. The legal basis exists, see below; the case law does not.

AI washing versus an honest AI-assisted claim

The dimension that separates the two is what the model actually decides at runtime.

An AI-washed claim says "AI-driven" or "autonomous agent" and, when you look inside, the model decides nothing. Rules pick the category. A script picks the next step. A person in another time zone approves the order. The model, if there is one, formats a sentence at the end.

An honest AI-assisted claim says exactly which step the model does. "The model reads the invoice and proposes supplier, amount and cost centre; a person confirms before booking." The model makes one judgement, the vendor can show you the accuracy on your own invoices, and everything else is ordinary software.

The honest claim sounds smaller. It is also the one you can test, price and explain to your accountant. A vendor that is proud of its product will happily tell you where the model stops.

Questions to ask a vendor before you sign

  1. Which decisions does the model make at runtime? Ask for the list. If the answer is "all of it", ask again for the specific step. If the answer is "none", you are buying a workflow, which may be fine, priced as a workflow.

  2. Show me the run log. A real agent leaves a trail: which tool it called, what came back, what it decided next. Ask to see the log of a real run on your kind of data. A product that cannot produce one has no loop to log.

  3. What happens when the model is switched off? If the product keeps working almost unchanged, the model was decoration. If it stops, the model is load-bearing and the next question matters.

  4. Which model is it, and what was it trained or tuned on? Vendors that build on a public model rarely say so on the homepage. That is not a crime, but you want to know whose model your data goes to, under which terms, and whether "our proprietary AI" means a prompt and an API key.

  5. Where are the humans in the process, and how many? Ask directly whether any step is done or reviewed by people, where they sit and what they see. A vendor with a review team is not doing anything wrong. A vendor that hides one is.

  6. Can we run it on our data before we pay? A pilot on a hundred of your own cases, with the log, answers most of the above in an afternoon. A vendor that refuses a pilot but promises autonomy has told you what you need to know.

Write the answers into the contract as stated characteristics of the product. That turns marketing into a warranty, which is where the law below starts to help you.

What the law says in Europe and Belgium

Europe has no AI-washing rule, and it does not need one. A false claim about what a product does is a misleading commercial practice, and that has been illegal since long before language models.

Unfair Commercial Practices Directive. Directive 2005/29/EC bans misleading actions, which includes false or deceptive information about the main characteristics of a product, and misleading omissions, where a trader leaves out what a consumer needs to decide. Claiming that AI does the work when people do it is a textbook misleading action. National authorities enforce it.

Belgian Code of Economic Law, Book VI. Belgium transposed the directive in Book VI. Article VI.97 defines a misleading practice as one that carries incorrect information or, even when factually correct, deceives the average consumer about, among other things, the main characteristics of the product: its benefits, its performance, its composition, the results to be expected from using it. Since the law of 4 April 2019 there is a separate section on misleading practices between businesses, so a vendor selling to your company is caught too. The Economic Inspectorate of FOD Economie takes complaints through its reporting point, and since the 2022 law that transposed the Omnibus Directive, the fine scales include a percentage of annual turnover, 4 to 6 percent depending on the offence.

AI Act. The AI Act does not police marketing claims. Its transparency obligation in Article 50 works the other way: since 2 August 2026 a chatbot has to tell people it is AI, and generated content has to be marked. So a vendor can be in breach twice over: once for pretending a human is AI, once for pretending an AI is a human. Belgium's advertising self-regulator, the Raad voor Reclame, published twelve guidelines for AI in advertising on 7 August 2025, including that AI content that looks human must be recognisable as such.

For a Belgian buyer the practical point is this: the answers to the questions above are statements about the main characteristics of a product. If they turn out to be false, you have a misleading-practice case under Book VI on top of a contract dispute.

Last Updated: September 3, 2026 Back to Dictionary
Keywords
ai washing agent washing agentic ai ai agent chatbot rpa business rules engine human-in-the-loop ai act shadow ai ai literacy ai