Gana Misra
By Gana MisraCEO, Finrep
Tue Aug 18 2026

SEC AI Bodies Explained: CETU, FRU and AI Task Force

Share
SEC AI Bodies Explained: CETU, FRU and AI Task Force

The SEC's AI enforcement posture is not a single programme with a single mandate. It is three distinct bodies with different creation dates, different legal authorities, different enforcement targets, and different consequences for the companies they investigate.

Two distinct SEC AI bodies operate in parallel: CETU (the Cyber and Emerging Technologies Unit, created in the Enforcement Division in February 2025) for external enforcement, and an internal AI Task Force (created August 2025) with a Chief AI Officer focused on the SEC's own AI use. Since August 5, 2026, a third body has been added: the Financial Reporting and Accounting Unit, also in the Enforcement Division.

Most CFOs and disclosure counsel treat the SEC's AI enforcement posture as a single programme. When they see a news report about SEC AI enforcement, they assume it is the same team with the same mandate doing the same thing. This conflation produces two specific errors.

The first error is ignoring CETU when the company has made AI capability claims in its investor materials, because the CFO is focused on the Financial Reporting and Accounting Unit's accounting fraud mandate and does not register that a different team is looking at the accuracy of AI descriptions in risk factors and investor presentations.

The second error is treating every SEC inquiry about AI as an AI washing inquiry, when in fact the Financial Reporting and Accounting Unit is reviewing the accounting controls around AI use in the financial close, not the accuracy of AI capability claims in the 10-K risk factors.

This post maps each body, its mandate, its legal authority, its enforcement trigger, and the specific company conduct each one is looking for. The companion blogs in this cluster cover the Financial Reporting and Accounting Unit in depth (the August 13 blog) and the SEC's AI-powered filing review capability (the August 16 blog). This blog covers the institutional landscape that both of those blogs operate within.

Why CFOs Are Confusing the SEC's Three AI Bodies and Why It Matters

The confusion is understandable. All three bodies operate under the SEC's umbrella. Two of them are in the same Division of Enforcement. All three have AI in their mandate in some form. Coverage of all three appears in the same trade press under the same general category of "SEC AI enforcement."

The practical consequence of the confusion: a company that manages its AI disclosure risk as if it were one unified SEC programme will under-prepare for one of the two enforcement units and may over-prepare for the other. A company that believes SEC AI enforcement is entirely about AI washing will spend all its energy ensuring its AI capability claims are accurate and documented, while neglecting the accounting controls over AI tools used in the financial close that the Financial Reporting and Accounting Unit is specifically equipped to examine.

The institutional stakes: the two enforcement units use different legal theories, have different investigative staff (CETU has fraud specialists and attorneys; the Financial Reporting Unit has attorneys and accountants with financial reporting expertise), and reach different departments within the company under investigation (CETU reaches the investor relations and marketing function; the Financial Reporting Unit reaches the controller's office and the disclosure committee).

A company facing an inquiry from CETU is defending the accuracy of public statements about AI. A company facing an inquiry from the Financial Reporting and Accounting Unit is defending the integrity of its financial statements and the effectiveness of its ICFR. Those are different facts, different witnesses, different document productions, and different remediation paths.

Body #1: CETU, What the Cyber and Emerging Technologies Unit Targets and How It Enforces

On February 20, 2025, the Securities and Exchange Commission announced the formation of the Cyber and Emerging Technologies Unit, known as CETU, which replaced the Crypto Assets and Cyber Unit. CETU aims to combat cyber-related misconduct and provide safeguards for retail investors against malpractices emerging in the technologies sector.

CETU is a team of approximately 30 fraud specialists and attorneys spread across SEC offices around the country. Its mandate covers fraud committed using emerging technologies including artificial intelligence and machine learning, use of social media or false websites to perpetrate fraud, misrepresentation by investment advisers or broker-dealers about AI capabilities, and cybersecurity-related misconduct.

CETU's mandate explicitly includes scrutiny of 10-K, 10-Q, and 8-K AI disclosures, policing misleading AI investor communications, and coordinating with the Division of Examinations on advanced analytics.

The AI washing enforcement pattern CETU pursues: a company makes claims about its AI capabilities in investor materials, including SEC filings, earnings calls, investor presentations, and Form ADV, that are inaccurate or exaggerated. The company either does not have the AI capabilities it claims, has them in a limited or undeveloped form, or uses third-party AI under a vendor relationship rather than proprietary AI as implied in its communications. Investors rely on those claims when making investment decisions. The inaccurate claims constitute securities fraud.

The SEC has brought AI washing cases totalling more than $44 million in alleged fraud as of April 2026. The Presto Automation case (settled January 2025) and the Nate Inc. case (criminal referral April 2025) are the two landmark CETU-adjacent precedents, though both preceded CETU's formal creation in February 2025.

CETU's leadership has publicly called rooting out AI washing fraud an immediate priority.

The legal theory CETU uses: Section 17(a) of the Securities Act and Section 10(b) of the Exchange Act and Rule 10b-5, the antifraud provisions. The same legal authority the SEC has used to prosecute all varieties of investor fraud since 1934, applied to the specific misrepresentation of AI capabilities.

What CETU does not do: CETU does not investigate accounting fraud in financial statements. It is not looking at whether your revenue recognition is correct, whether your segment operating profit is manipulated, or whether your internal controls over the close process are adequate. Those are the Financial Reporting and Accounting Unit's jurisdiction.

Body #2: The Financial Reporting and Accounting Unit, What It Targets and How It Differs From CETU

The Financial Reporting and Accounting Unit was created August 5, 2026. The companion blog in this cluster covers its mandate in detail. The essential distinction from CETU:

CETU's target: investor-facing claims about AI capabilities. The question is whether what the company said about AI is true. The evidence is in the investor materials, the earnings call transcripts, the investor presentations, and the Form ADV.

The Financial Reporting and Accounting Unit's target: the accuracy of financial statements and the effectiveness of ICFR controls. The question is whether the financial statements fairly present the company's financial results and whether the internal controls over financial reporting are adequate to prevent material misstatements. The evidence is in the general ledger, the accounting workpapers, the internal control documentation, and the SOX 302 certification.

The AI connection for the Financial Reporting and Accounting Unit is different from CETU's. CETU asks: what did you tell investors about your AI? The Financial Reporting and Accounting Unit asks: how are you controlling the AI tools you use in your financial close, and are those AI controls preventing material misstatements?

A company that uses AI in its account reconciliation, tax provision, or disclosure drafting process, without adequate ICFR controls over those AI tools, has a Financial Reporting and Accounting Unit exposure that is entirely separate from any CETU exposure. The CETU exposure exists only if the company made inaccurate public claims about that AI use. The Financial Reporting and Accounting Unit exposure exists if the AI controls are inadequate regardless of what the company said publicly about its AI.

The legal authority the Financial Reporting and Accounting Unit uses: Exchange Act Sections 10(b), 13(a), 13(b)(2)(A), and 13(b)(2)(B). The same provisions involved in the ADM and Key Tronic cases, which are the unit's founding precedents.

Body #3: The SEC's Internal AI Task Force, What It Does and Why It Signals Future Rules

The SEC's internal AI Task Force was created in August 2025. It has a Chief AI Officer and focuses on the SEC's own AI use and AI lifecycle management.

This body is not an enforcement unit. It does not investigate companies, bring enforcement actions, or issue comment letters. Its mandate is internal to the SEC: governing how the SEC itself uses AI in its examination, enforcement, and regulatory functions.

The significance of the internal AI Task Force for companies: it signals the direction of the SEC's future regulatory guidance on AI. The SEC's experience using AI in its own financial filing review (confirmed by the Law.com report covered in the companion August 16 blog) will inform how the SEC thinks about the appropriate governance standards for companies using AI in their financial reporting processes.

The internal AI Task Force has a Chief AI Officer focused on the SEC's own AI use, including the AI tools used by CETU and the Financial Reporting and Accounting Unit in their enforcement work. The AI tools the SEC uses to sift through public company filings (confirmed from the SEC official's statement reported by Law.com) are governed by the internal AI Task Force, not by CETU or the Financial Reporting and Accounting Unit.

The rulemaking signal: the SEC's internal experience with AI in financial regulation will inform any future AI disclosure rules, AI governance guidance, or AI-specific examination priorities. A company monitoring the internal AI Task Force's statements and the Chief AI Officer's public remarks has advance signal of what the SEC is likely to require of regulated entities. The SEC endorsed the COSO GenAI guidance (covered in the companion August 16 COSO blog) as a helpful resource for AI governance, which is consistent with the SEC's own adoption of principles-based AI governance in its internal programme.

What Is "AI Washing" Under CETU and Does Your 10-K Risk Factor Create This Exposure?

AI washing is the SEC's term for misrepresentation of AI capabilities in investor-facing communications. The pattern the SEC has prosecuted: a company tells investors it uses sophisticated proprietary AI for a specific function, when in fact: (a) it uses a vendor-provided AI under a standard licensing arrangement, not proprietary AI, (b) the AI does not work as described because it is in development or is limited in its actual deployment, or (c) the company abandoned the AI programme but continues to represent it as operational.

The Presto Automation settlement (January 2025) involved the SEC charging the company with misleading statements about its AI deployment in its investor materials. Presto had represented to investors that its AI technology was deployed and operating at customer locations, when the actual deployment was far more limited than represented.

The 10-K risk factor AI washing exposure: a risk factor that says the company's AI capabilities may not develop as expected creates a different exposure than a risk factor that implies AI capabilities the company does not actually have. The former is a disclosure of uncertainty about a genuine capability; the latter is a representation of a capability that may not exist.

CETU's scrutiny of 10-K and 10-Q AI disclosures focuses on whether the disclosures accurately describe the company's AI use and capabilities, are consistent with other public statements about AI, and do not create a misleading impression about the company's AI competitive position.

The consistency test is the specific CETU exposure most public companies have not fully assessed. If the CFO made statements about AI capabilities on an earnings call that are more expansive than the 10-K's disclosure of AI use, or if the investor presentation describes AI as a core competitive advantage while the 10-K describes it as experimental, the inconsistency creates the impression that the investor-facing communications are different from the regulatory disclosures, which is the pattern CETU investigates.

The AI washing exposure assessment for your company: pull the five most recent earnings call transcripts, the most recent investor presentation, and the Form ADV (if applicable) alongside the 10-K and 10-Q AI disclosures. Confirm that every AI capability described in the non-SEC materials is consistent with the disclosure in the SEC filings. Any statement in the investor materials that goes beyond what the SEC filing discloses is a potential CETU exposure.

What Is "Accounting and Financial Reporting Fraud" Under the New Unit and How Is It Different From AI Washing?

The Financial Reporting and Accounting Unit pursues financial reporting fraud: misstatements in the financial statements or manipulation of accounting to misrepresent financial results. The AI connection is the use of AI in the financial reporting process without adequate controls.

The specific patterns the unit is equipped to investigate: as described in the companion blogs covering the ADM and Gibson Dunn enforcement pattern blogs, these include segment-level disclosure manipulation (ADM pattern), books and records failures producing inaccurate consolidated statements (Key Tronic pattern), and systematic reserve or non-GAAP manipulation across multiple periods (AI-assisted pattern recognition across filing history).

The AI-specific version of this pattern: a company uses an AI tool in the judgment capability type (credit loss reserve estimation, goodwill impairment modelling, revenue recognition judgments) without adequate human oversight controls. The AI tool produces an output that is convenient for the company's earnings results but is not supportable by the underlying data. The human reviewer does not genuinely scrutinise the AI output (shadow reliance, as described in the FEI framework blog). The resulting financial statement contains a material misstatement that the AI-assisted process produced and the inadequate human oversight failed to detect.

This is not AI washing. The company may not have made any public claims about its AI use. The CETU exposure is zero because no investor was told anything about the AI. The Financial Reporting and Accounting Unit exposure is real because the financial statements are materially wrong and the ICFR controls were inadequate.

The distinction maps directly to the COSO GenAI guidance (covered in the companion August 16 COSO blog): the COSO guidance governs AI use in the financial reporting process, which is the Financial Reporting and Accounting Unit's jurisdiction. CETU's AI washing focus governs the accuracy of claims about AI in investor communications, which is not specifically addressed in the COSO guidance.

The Division of Corporation Finance (Corp Fin) conducts the comment letter review of 10-Q filings. Corp Fin is not CETU and is not the Financial Reporting and Accounting Unit. It is the SEC's disclosure review function, separate from the Division of Enforcement where both CETU and the Financial Reporting and Accounting Unit reside.

Corp Fin's 10-Q review is a disclosure review, not an enforcement investigation. Its standard is whether the disclosure provides investors with the information required by Regulation S-K and the applicable SEC forms, and whether the disclosure is not materially misleading. Corp Fin's AI-related comment letters ask companies to ensure their AI risk factor language is company-specific, their AI claims are accurate, and their ICFR disclosures address AI tools in material financial reporting processes.

The referral pathway: if Corp Fin's 10-Q review identifies a disclosure that appears materially misleading about AI capabilities, it can refer the matter to CETU for investigation. If it identifies a disclosure that appears to misrepresent the financial results or the effectiveness of ICFR, it can refer to the Financial Reporting and Accounting Unit. The referral converts a disclosure review comment letter into an enforcement investigation.

The AI-powered filing review capability confirmed by Law.com and Global Investigations Review (covered in the August 16 blog) is used by the SEC to surface potential comment letter targets and enforcement referrals from the universe of all public company filings. The AI reader that sifts through vast quantities of filings operates as a triage function that identifies filings for human review by Corp Fin staff and, where appropriate, for referral to CETU or the Financial Reporting and Accounting Unit.

What Is the SEC's Cross-Agency AI Enforcement Coordination With DOJ and FTC?

The Nate Inc. case, where the SEC brought an AI washing enforcement action and the case was subsequently referred to DOJ for criminal prosecution in April 2025, illustrates the cross-agency coordination pattern for AI fraud cases.

CETU coordinates with DOJ's Computer Crime and Intellectual Property Section and with the FBI's Cyber Division when AI fraud cases have criminal dimensions: where the misrepresentation was deliberate, where investor harm is significant, or where the conduct also constitutes wire fraud or other criminal offences.

The timeline of the Nate Inc. case: the SEC brought its AI washing enforcement action, the case was referred to DOJ for criminal prosecution in April 2025, and as of mid-2025 the SEC was still attempting to serve the defendant abroad, illustrating how quickly AI fraud cases can escalate from SEC enforcement to criminal prosecution.

The FTC coordinates with the SEC on AI-related consumer protection matters that also involve securities law violations, such as AI-powered investment product misrepresentation where the same conduct harms both retail investors (SEC jurisdiction) and consumers (FTC jurisdiction). The FTC's Section 5 authority over unfair or deceptive acts or practices can reach AI misrepresentation that the SEC's antifraud provisions also address.

For CFOs, the cross-agency coordination means that an AI-related misrepresentation that reaches the threshold for CETU investigation may be simultaneously investigated by DOJ and FTC. The discovery scope, witness exposure, and remediation obligations are materially larger in a multi-agency AI fraud investigation than in a standard SEC comment letter response.

What Should Your Disclosure Committee Brief Your Board About Both Units?

Four specific board-level disclosures arising from the three-body landscape.

First: confirm which category of AI exposure your company has. A company that has made AI capability claims in earnings calls, investor presentations, or Form ADV has a CETU exposure that requires AI accuracy assessment and consistency review across investor materials. A company that uses AI in its financial close without documented ICFR controls has a Financial Reporting and Accounting Unit exposure that requires control design and documentation.

Most public companies with material AI involvement have both categories of exposure. The board should understand that both units have different mandates, different investigation teams, and different document requests, and should confirm that both are addressed in the company's AI governance programme.

Second: confirm the consistency of AI claims across all investor-facing channels. The disclosure committee's final review before each earnings call, investor presentation, or Form ADV update should specifically confirm that every AI claim is supported by documentary evidence and is consistent with the SEC filings. CETU targets the gap between what investor materials say about AI and what the SEC filings say.

Third: confirm the ICFR controls over AI tools in the financial close are documented and tested. The Financial Reporting and Accounting Unit targets the gap between AI tools used in financial reporting and the controls designed to prevent those tools from producing material misstatements. The board should confirm that the AI inventory (as required by the COSO GenAI guidance covered in the companion blog) is complete and that each AI tool in the financial reporting process is within the ICFR scope.

Fourth: confirm the company has a cross-functional AI governance body that covers both types of exposure. CETU exposure is primarily owned by investor relations, legal, and disclosure counsel. Financial Reporting Unit exposure is primarily owned by the controller, the SOX team, and the external auditor. A cross-functional GenAI Council of the type recommended by the COSO guidance, with CFO, CRO, and technology leadership together, is the governance structure that addresses both.

Frequently Asked Questions

What is the SEC's CETU and what does it target?

CETU, the Cyber and Emerging Technologies Unit, was created on February 20, 2025 to combat cyber-related misconduct and protect retail investors from bad actors in the emerging technologies sector. It is led by Laura D'Allaird and comprises approximately 30 fraud specialists and attorneys. CETU targets AI washing: misrepresentation of AI capabilities in investor-facing materials including SEC filings, earnings calls, investor presentations, and Form ADV.

What is the SEC's Financial Reporting and Accounting Unit?

The Financial Reporting and Accounting Unit was created August 5, 2026. It is led by Timothy Zimmerman and is staffed by attorneys and accountants with specialised financial reporting expertise. Its mandate covers financial reporting fraud, accounting fraud, and auditor misconduct. It investigates misstatements in financial statements and inadequate ICFR controls, not misrepresentation of AI capabilities in investor materials.

What is AI washing and how does CETU enforce against it?

AI washing is misrepresentation of AI capabilities in investor-facing communications. The SEC has brought AI washing enforcement cases totalling more than $44 million in alleged fraud. The legal theory is Section 10(b) and Rule 10b-5, the antifraud provisions. CETU investigates when what a company says about its AI capabilities in investor materials is inaccurate, exaggerated, or inconsistent with the actual state of its AI deployment.

Which SEC unit reviews my 10-Q for accounting fraud vs AI disclosure inaccuracies?

The Division of Corporation Finance conducts comment letter review and can refer matters to either unit. CETU receives referrals for AI disclosure inaccuracies: risk factor language that misrepresents AI capabilities or investor-facing AI claims that are inconsistent with SEC filings. The Financial Reporting and Accounting Unit receives referrals for accounting fraud: financial statement misstatements, books and records failures, and ICFR inadequacies. Both units may separately receive referrals arising from the same filing if the filing contains both types of issues.

What is the SEC's internal AI Task Force?

The SEC's internal AI Task Force was created in August 2025 with a Chief AI Officer. It governs the SEC's own use of AI in its examination and enforcement functions. It is not an enforcement unit and does not investigate companies. It signals future rulemaking direction as the SEC's internal AI governance experience informs what it expects from regulated entities.

Key Takeaways

  • The SEC now has three distinct AI bodies: CETU (created February 20, 2025, targets AI washing in investor materials), the Financial Reporting and Accounting Unit (created August 5, 2026, targets accounting fraud in financial statements), and the internal AI Task Force (created August 2025, governs the SEC's own AI use, not an enforcement body).
  • CETU is approximately 30 fraud specialists and attorneys. Its AI mandate covers AI washing: misrepresentation of AI capabilities to investors. The legal theory is Section 10(b) antifraud.
  • The Financial Reporting and Accounting Unit is staffed by attorneys and accountants with financial reporting expertise. Its AI mandate covers inadequate ICFR controls over AI tools used in financial reporting. The legal theory is Exchange Act Sections 13(a) and 13(b).
  • A company can have a CETU exposure without a Financial Reporting Unit exposure (if it made inaccurate AI claims in investor materials but uses no AI in its financial close), and vice versa (if it uses AI in its close without adequate ICFR controls but made no public claims about that AI use). Most companies with material AI involvement have both.
  • The consistency test for CETU exposure: confirm every AI capability described in earnings calls, investor presentations, and Form ADV is consistent with the 10-K and 10-Q AI disclosures. Any gap between non-SEC investor materials and SEC filings is a potential CETU exposure.
  • The ICFR test for Financial Reporting Unit exposure: confirm every AI tool in the financial close is within the ICFR scope under the COSO GenAI guidance taxonomy, with documented controls and human review protocols. Any AI tool in the financial reporting process without documented ICFR controls is a potential Financial Reporting Unit exposure.
  • The cross-agency dimension: CETU coordinates with DOJ for criminal referrals when AI washing fraud is sufficiently deliberate and harmful. The Nate Inc. criminal referral in April 2025 illustrates the escalation pathway from SEC enforcement to criminal prosecution.

Run your financial reporting on Finrep