Securities Counsel for AI Companies:
Disclosure the SEC Is Actively Scrutinizing
Artificial intelligence has become the single most common capability claim in registration statements, private placement memoranda, investor decks, and earnings calls. It has also become one of the fastest-growing sources of SEC enforcement interest. The Commission's stated concern is straightforward: companies describing themselves as AI-driven when the underlying technology is materially less capable, less proprietary, or less deployed than the disclosure implies.
The enforcement theory is not novel. It is the same materiality and misleading-statement analysis the SEC has applied for decades, now pointed at a category of claims that is unusually easy to overstate and unusually hard for investors to verify. Frederick M. Lehrer — a former attorney in the SEC's Division of Enforcement — reviews AI-related disclosure the way the staff reads it, before it is filed or circulated.
What 'AI-Washing' Actually Means in an Enforcement Context
AI-washing is shorthand for a disclosure problem, not a separate statute. When a company states or implies that its products, operations, or competitive advantages depend on artificial intelligence, and the factual reality does not support that characterization, the statement may be materially misleading under Section 10(b) and Rule 10b-5, Section 17(a) of the Securities Act, and — for advisers and funds — the Advisers Act antifraud provisions. There is no AI exception and no safe harbor for enthusiasm.
The claims that draw scrutiny are rarely outright fabrications. They are usually characterizations that were defensible at one point and were never updated, or descriptions that blur the line between what a model does today and what the roadmap contemplates. A company that licenses a third-party model and applies a thin layer of prompt engineering, but describes its 'proprietary AI platform,' has created a gap between the impression and the facts. That gap is exactly where enforcement lives.
The second recurring pattern is quantification without support. Statements that AI 'reduces customer costs by 40 percent' or 'improves accuracy by an order of magnitude' invite the staff to ask for the underlying study, sample size, and methodology. If the number came from a single pilot customer or an internal benchmark that was never validated, the disclosure is exposed. The remedy is not to remove the claim; it is to disclose its basis and its limits with enough specificity that a reader can evaluate it.
Model Provenance, Training Data, and Dependency Disclosure
Investors evaluating an AI company are, in substance, evaluating three things: what the model is, what it was trained on, and what the company controls versus what it rents. Disclosure that leaves any of those three ambiguous invites both comment letters and later fraud claims. Where a company depends on a third-party foundation model, that dependency is a material business risk — pricing changes, terms-of-service changes, rate limits, or deprecation can impair the product with no notice.
Training data raises a distinct set of exposures. Companies that trained on scraped, licensed, or customer-supplied data should be prepared to describe, at a level appropriate to their filings, whether they hold the rights they are relying on, how they handle personal data, and what happens to the product if a data source becomes unavailable or is subject to a claim. The intellectual property questions surrounding generative model outputs remain unsettled, and a risk factor that acknowledges that uncertainty is far safer than silence.
Model performance disclosure should distinguish between benchmark performance and production performance. Hallucination rates, drift, human-in-the-loop requirements, and the volume of manual review actually required to deliver the service are frequently omitted, yet they go directly to whether the described automation exists. Where humans are performing work the disclosure attributes to a model, that is a material fact.
Risk Factors That Withstand Staff Review
Generic AI risk factors — 'the market for artificial intelligence is competitive and evolving' — are worse than useless. They occupy space, signal a lack of company-specific analysis, and provide no protection because they do not warn of the risk that actually materialized. The staff routinely comments on boilerplate, and courts have little patience for cautionary language that does not address the specific risk at issue.
Effective AI risk factors are concrete: named dependency on a specific class of third-party model with described commercial terms; the regulatory regimes the company is subject to and the ones that may extend to it; the litigation exposure arising from training data provenance; the operational cost profile of inference and how it scales with usage; the personnel concentration risk where a small number of researchers hold the capability; and the reputational and contractual consequences of an erroneous output in the company's specific use case.
For companies in regulated verticals — healthcare, lending, insurance, employment, education — the analysis extends further. An AI product that influences a credit decision, a hiring decision, or a clinical recommendation sits inside an existing regulatory framework that predates the technology. Disclosure should reflect that framework rather than treating AI as a category unto itself.
Raising Capital as an AI Company: S-1, Reg D, and Investor Materials
The disclosure discipline that applies to a registration statement applies with equal force to private offering materials. A Regulation D private placement memorandum, an investor deck, and a data room summary are all subject to the antifraud provisions, and in practice the deck is often where the most aggressive AI claims appear. Because decks circulate widely and are rarely versioned carefully, they are frequently the most damaging documents in an enforcement file.
In a Form S-1 context, AI claims produce a predictable comment-letter pattern: the staff asks the company to substantiate performance claims, to clarify what technology the company owns, to reconcile the business description with the risk factors, and to explain the basis of any market-size or adoption projection. Anticipating those comments before filing shortens the review cycle materially and avoids the mid-review restatement of the business description that unsettles investors.
Testing-the-waters communications, Regulation A offering circulars, and crowdfunding materials carry the same substantive standard even though the forms differ. Consistency across every channel — filings, website, press releases, podcast and conference appearances, and social media — is the practical control. Enforcement cases are frequently built by comparing what a company filed against what its executives said elsewhere.
| Area of Scrutiny | What the Staff Looks For |
|---|---|
| Capability claims | Whether the described AI functionality is deployed and in production, or aspirational and on a roadmap |
| Proprietary technology | Whether the model is owned, fine-tuned, or a third-party API with a thin wrapper |
| Quantified benefits | The study, sample, and methodology behind any percentage improvement or cost-savings claim |
| Training data rights | Whether the company holds the licenses and consents it relies on, and the exposure if it does not |
| Human involvement | Work performed by people that the disclosure attributes to automation |
| Revenue attribution | How much revenue is genuinely attributable to AI features versus legacy products |
| Risk factor specificity | Whether risk factors are company-specific or generic industry boilerplate |
| Cross-channel consistency | Whether filings, decks, press releases, and executive statements tell the same story |
- Pre-filing review of AI capability language in registration statements and offering documents
- Risk factor drafting for issuers dependent on third-party foundation models
- Response strategy for SEC staff comments questioning technology and performance claims
- Disclosure counseling for companies transitioning marketing-grade AI language into filed documents
- Nine years in the SEC's Division of Enforcement informing how each claim is likely to be read
Matters are described generally and without client-identifying detail. Prior results do not guarantee a similar outcome. A full list of representative matters is available on the case list.
AI Company Disclosure and Securities Counsel
- AI companies preparing a Form S-1, Reg A, or Reg D offering
- Public companies adding AI capability language to filings or earnings materials
- Founders whose investor deck makes AI claims that have never been legally reviewed
- Boards concerned about the gap between marketing language and technical reality
- The deck says 'proprietary AI' but the stack is a third-party API
- A performance percentage appears in materials with no documented study behind it
- Marketing, filings, and executive interviews describe the technology differently
- SEC staff comments are asking you to substantiate technology claims
- Line-by-line review of AI claims in filings, PPMs, decks, and press releases
- Company-specific AI risk factor drafting
- S-1 preparation and SEC comment letter response
- Disclosure controls so future AI statements stay consistent across channels
- 1. Confidential intake: technology reality, documents, and timeline
- 2. Claim-by-claim gap analysis against the supporting facts
- 3. Written engagement with defined scope and fee
- 4. Revised disclosure, filing support, and staff comment response
Flat-fee AI disclosure reviews are available for a defined document set — typically a deck, a PPM, or a draft registration statement. The next step is a confidential conversation with Frederick M. Lehrer about your facts and timeline — no forms, no intake queue.