AI washing: how to tell real adoption from communication
The data presented by the Artificial Intelligence Observatory of Politecnico di Milano (2025 research, February 2026) contains a pair of numbers that, read together, describe a phenomenon rarely discussed: 84% of large Italian companies hold Generative AI licences, and only one in five uses AI pe...
The data presented by the Artificial Intelligence Observatory of Politecnico di Milano (2025 research, February 2026) contains a pair of numbers that, read together, describe a phenomenon rarely discussed: 84% of large Italian companies hold Generative AI licences, and only one in five uses AI pervasively across multiple functions. Between those two percentages lives the corporate version of what markets call AI washing, the distance between what a company says it does with artificial intelligence and what actually happens in its processes.
The term was born for the extreme cases, and there at least case law has already moved: in March 2024 the US SEC sanctioned two investment firms for misleading statements about the use of AI in their products, opening a line of enforcement that anyone communicating with investors and clients would do well to know. The version we meet most often in our assessments, though, is less malicious and more insidious: companies telling themselves, in good faith, a story of adoption their internal numbers do not confirm.
The three forms of the phenomenon
The first form faces outward and is the best known: press releases, annual reports and pitches describing AI capabilities oversized relative to reality, to attract capital, clients or talent. Here the risk has stopped being merely reputational, because between financial regulators' enforcement, the AI Act's incoming transparency obligations and increasingly technical due diligence in M&A deals, the distance between declared and verifiable has become a measurable liability.
The second form faces inward, and it is the one that costs most without ever making a newspaper: activity theatre. Task forces, hackathons, licences distributed like confetti, a "head of AI" appointed without mandate or budget, dozens of PoCs celebrated and never taken to production. Each element, taken alone, is legitimate, but the whole produces the illusion of movement, and the illusion is more dangerous than declared immobility because it switches off the urgency to get serious.
The third form is the most recent and comes from suppliers: traditional products rebranded "AI-powered" for one marginal feature, roadmaps promising future capabilities as if they were present. For buyers, recognising it has become a procurement skill.
The tests that do not lie
Telling real adoption from its representation requires questions communication cannot answer on behalf of the systems. The first test is an accounting one: does a P&L line, an operational KPI or a process metric exist that has changed in a way attributable to an AI system? Real adoption leaves traces in the numbers the company already measures, narrated adoption lives only in numbers created to narrate it (people trained, prompts written, workshops held).
The second test concerns production: how many AI systems are integrated into core processes, with users who use them because the workflow runs through them, and not because they were asked to try them? Licences measure spending, integration measures adoption, and the two Observatory figures quoted at the opening show how far apart they can drift.
The third test concerns governance, and it is the fastest to administer: does a systems register exist, a risk classification, an owner with a mandate, a process for deciding what starts and what stops? In the same Politecnico research, only 9% of large companies report structured AI management. An organisation that communicates AI leadership and fails this third test is describing an aspiration, which is legitimate provided it is the first to know.
Why it pays to dismantle it yourself
Internal AI washing has an uncomfortable property: sooner or later somebody dismantles it, and it pays greatly for the company to be the one. If an investor dismantles it in due diligence, the bill is paid in valuation. If an enterprise client dismantles it with a tender demanding governance evidence, it is paid in contracts. If an authority dismantles it, it is paid in sanctions and executive time. If employees dismantle it, and they are always the first to notice the distance between the press releases and their work tools, it is paid in the hardest currency to buy back, the credibility of the next initiatives.
Self-dismantling has a less dramatic name, it is called measurement. A maturity rating run with method, on evidence and multi-level interviews, produces exactly the photograph separating the real from the narrated, and produces it in a context where discovering gaps opens a roadmap instead of a crisis. It is the work we do with the AI Rating, and the most frequent effect on clients is not disappointment, it is relief: knowing where you truly stand frees the energy that maintaining the narrative was consuming.
Communication, to be clear, remains legitimate and even necessary, on one condition: that it chases the facts instead of running too far ahead of them. If you wanted to check today which side your organisation is on, the three tests above can be administered in one meeting, and the full version in four to six weeks: calendly.com/fabiolalli/zerofive, or hello@zerofive.ai. We will suggest the uncomfortable closing question ourselves: if tomorrow you had to prove, evidence in hand, your company's latest public statement about AI, what would you prove it with?