In August 2025, researchers at compliance training firm Ethena demonstrated something that should alarm every compliance officer in the country: ChatGPT's agent mode could log into a training platform, navigate lessons, watch videos, answer quiz questions, and generate completion certificates — all without a single human keystroke. By September, advocacy group Training That Matters issued a formal hazard alert, coining the term 'risk-washing' to describe the false sense of security created when organizations rely on training records from platforms that cannot verify authentic participation. The implications are staggering — and they extend far beyond compliance paperwork.
What Is Risk-Washing?
Risk-washing occurs when an organization's training records create the appearance of compliance without the reality of competence. It's the corporate equivalent of a safety inspection sticker on a building that was never actually inspected. The term was coined by Training That Matters in their September 2025 hazard alert, which warned that 'AI agents can now log into a training platform and complete all assigned courses on behalf of an employee — navigating lessons, answering all question formats, and generating completion certificates without any human involvement.' The result: every training record, compliance report, and competency metric generated by unverified platforms is effectively worthless.
Why This Is Different From Traditional Cheating
Employees have always found ways to cut corners on training — sharing answers, having coworkers take tests for them, or running courses in the background. But as compliance journalist Matt Kelly noted in Radical Compliance, 'AI now gives everyone the ability to cheat on training with nothing more than a few keystrokes. You don't need to be an engineer who knows how to code up a script. You don't need to find co-conspirators willing to share answers.' The democratization of cheating is what makes risk-washing an enterprise-scale problem rather than an isolated integrity issue. When any employee can delegate mandatory safety training to an AI agent in seconds, the entire training verification model breaks down.
The Legal and Safety Consequences
Risk-washing doesn't just create paperwork problems — it creates real danger. Consider an aircraft manufacturer whose maintenance technicians use AI agents to complete safety protocol training. Or a healthcare system where nurses bypass HIPAA training through automated completion. Or a construction company where workers hold safety certifications they never actually earned. When workplace incidents occur, these hollow training records won't just fail to protect the organization in court — they may actually increase liability by demonstrating a pattern of negligence. As Training That Matters warned: 'If a training platform cannot verify the learner, no defensible claim of training, related competency, or due diligence can be made.'
Why Detection Alone Won't Solve It
Some training vendors claim their systems can detect AI-generated responses or flag suspicious completion patterns. While pattern detection — such as identifying groups of employees completing training in suspiciously similar times or achieving identical scores — has value, it's fundamentally a losing strategy. Ethena CTO Anne Solmssen put it bluntly: 'HR and compliance teams shouldn't focus their time on technology-based prevention methods. AI agents will adapt faster than controls can be built and workarounds will prevail.' The arms race between AI capabilities and detection tools will always favor the AI. The sustainable solution isn't detection — it's verification at the source.
Source-of-Training Verification: The Only Real Solution
The core insight behind risk-washing is that the problem isn't with employees — it's with training systems that were never designed to verify who is actually learning. As Rob Day, a leading expert on training integrity, stated: 'Training systems haven't kept pace. If a platform can't verify authentic participation, no defensible claim of training or due diligence can be made, putting lives at risk.' Source-of-training verification addresses this by confirming the identity and engagement of the learner during the training process itself — not after the fact. This means biometric identity checks before and during training sessions, real-time engagement monitoring that confirms active human participation, and tamper-proof documentation that creates an unbreakable chain of evidence from learner identity to certificate issuance.
What Organizations Should Do Right Now
The Training That Matters hazard alert recommended several immediate actions that every organization should take: First, assess all online training platforms to determine whether they can confirm that a human — not an AI agent — actually completed each course. Second, implement safeguards that go beyond password-based authentication to include biometric verification and behavioral engagement monitoring. Third, begin documenting whether each training completion was 'verified' or 'unverified,' creating transparency about the reliability of your records. Finally, benchmark all training systems against current regulatory standards, particularly in safety-critical industries where OSHA, FAA, NRC, or DOT requirements apply. Organizations that act now will be positioned to demonstrate genuine due diligence. Those that wait may find their entire training compliance history called into question.
The Path Forward
Risk-washing represents a fundamental challenge to how organizations think about training compliance. For decades, the question was 'Did the employee complete the training?' In the age of AI agents, that question is meaningless unless you can also answer: 'Can you prove it was actually them?' The organizations that will thrive in this new reality are those that move beyond completion tracking to genuine identity verification — ensuring that every certificate they issue represents real learning by a real person. Everything else is just risk-washing.
Authoritative Sources & Further Reading
- Training That Matters Hazard Alert— Formal hazard alert on AI agents undermining safety training
- Radical Compliance— Analysis of ChatGPT agent mode completing compliance training
- OSHA Training Requirements— Official OSHA guidelines for workplace safety training
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial