2024 left a lesson that no fintech founder should ignore: lying about the use of artificial intelligence is no longer a distant regulatory risk, but a direct cause of criminal proceedings. When Albert Saniger, founder of the shopping app Nate, was charged by the SEC and the Department of Justice with wire fraud, it was not a minor technical error. His company claimed an AI system automated transactions with over 90% effectiveness; in reality, human workers completed every purchase. He had raised more than $42 million on that promise. The question for any startup integrating AI into its product is unavoidable: does your sales pitch match what your code actually does?
This type of fraud has a name in the regulatory world: 'AI-washing.' The SEC defines it as claiming a product or service uses AI when it does not, or materially exaggerating what the AI achieves. The first penalties came in March 2024 against two investment advisers, Delphia and Global Predictions. Delphia stated for three years that it used machine learning to analyze clients' personal data (social media, banking, credit cards) to feed its investment algorithms. It never did. Both firms paid fines of $225,000 and $175,000. But the pattern has escalated.
In January 2025, the SEC sued Presto Automation, a Nasdaq-listed company, for claiming its drive-thru ordering system eliminated the need for human operators. The reality: the vast majority of orders still required manual intervention. Additionally, Presto failed to disclose that the speech recognition technology was third-party, not developed in-house. And then came the Nate case: from civil penalties to criminal charges. Saniger was indicted, not just fined. The direction is unmistakable: regulators no longer limit themselves to financial advisers; they now target operating companies that deceive investors, users, and the market. And fintech is right in the crosshairs, because promises of AI in fraud detection, underwriting, KYC automation, or portfolio management are exactly the kind of statements the SEC compares against actual engineering records.
The recurring pattern in all sanctioned cases boils down to three structural gaps. First: claiming proprietary technology that is actually third-party. Presto sold as its own a system it did not develop. Second: exaggerating the automation rate. Presto said 'no human intervention'; Nate said 'over 90%'; in both cases, the actual number was nearly the opposite. Third: stating the AI does something it never did. Delphia collected data, but its algorithm never used it. Each of these gaps is verifiable. The SEC compares public representations (pitch deck, website, investor communications) with actual system performance data, logs, architecture documentation, and vendor contracts.
Founders should see this as a 'claims-to-code gap.' Closing it is not a one-time legal exercise before a funding round. It is an ongoing discipline built on three pillars. First, a claims register: every public statement about what the AI does (website, deck, App Store, investor updates) must be logged and linked to a specific feature. Second, a capability match: each claim is checked against what the system actually does in production today, not what is on the roadmap. If your deck says 'AI-powered fraud detection' and what you have is a rules engine with a model in shadow mode, that is exactly the gap that got Presto and Nate sanctioned. Third, a provenance flag: is the AI capability built in-house or licensed from a vendor? If licensed, it must be stated. This distinction is the most repeated fact across all cases.
The creation in February 2025 of the SEC's Cyber and Emerging Technologies Unit, with some 30 specialists dedicated to investigating AI-related fraud, confirms this is not a temporary campaign. The agency has been clear that no new rules are needed: existing anti-fraud and disclosure laws already cover misleading AI claims. For founders, this means exposure exists today, under the same securities laws they already comply with. And while changes in administration may shift the volume of SEC actions, private lawsuit data does not lie: AI-related litigation has not slowed down between 2023 and 2025; on the contrary, it keeps rising.
In this context, having a technology partner that understands both the commercial promise and the code reality makes the difference. At Q2BSTUDIO, we develop custom software that integrates AI, cloud, and data analytics without deviations between what is sold and what is delivered. We help startups and established companies design robust architectures on AWS and Azure cloud, implement cybersecurity solutions, build BI dashboards with Power BI, and create AI agents that truly automate processes. It is not just about technology; it is about aligning every public statement with technical evidence. Because when a regulator (or an investor) asks to see logs, architecture documentation, and vendor contracts, the founder who can respond quickly will be the least exposed.
The question every fintech founder should ask today is not 'Am I compliant?' It is 'What is in my claims register right now, and does it match what my system actually executes?' Those who can answer that clearly will have a real competitive advantage. Those who cannot risk being the next headline. This article is a general overview of a developing enforcement area, not legal advice. If you have concerns about your AI-related disclosures, speak with securities counsel. At Q2BSTUDIO, we are passionate about closing the gap between what you promise and what your technology can prove.




