Now live in Texas — California coming soon. Millions of provider records indexed.See state coverage →

The Credentialing Gap Nobody's Watching: When AI Moves Faster Than Disclosure

ArgoseerSep 22, 202610 min read
The Credentialing Gap Nobody's Watching: When AI Moves Faster Than Disclosure

A practice manager in Texas opens a new patient's intake form and notices the chatbot on their own website answered a symptom question. She didn't know it could do that. She doesn't know who reviewed the response. She isn't sure whether anyone is supposed to.

This is not a hypothetical. It's the scenario implied by what we found when we scanned practice websites across Texas between February 27 and March 6, 2026.

What the Scan Actually Found

We were looking for AI tools deployed at the point of patient contact: diagnostic widgets, chatbots, symptom checkers, the kind of thing a vendor bundles into a website or an EHR portal. Specifically, we wanted to know whether those tools were disclosed properly, meaning whether a patient visiting the site would have any way of knowing AI was involved in what they were reading.

The short answer: usually not.

Of the detectable AI tool deployments we found, 495 showed an AI diagnostic tool with no practitioner-review statement. Fourteen more showed a named chatbot vendor with no AI disclosure at all. Twelve had a disclosure present on the page but hidden using CSS, meaning the HTML was there and the user couldn't see it (Argoseer scan of Texas practices, March 6, 2026).

I want to be precise about what these numbers mean and what they don't. These are positive detections: the tool was visible on the page, or detectable in the source, and what we measured was the absence of required accompanying language. Practices that use no AI tools need no disclosure; those sites aren't in this count. And when I say "confirmed," I mean our detectors agreed on the finding, not that a payer or a regulator verified it independently.

AI Tool Deployments Without Compliant Disclosure

Texas practice websites, scan of Feb 27, Mar 6, 2026

Source: Argoseer scan, Texas practices, 2026-03-06
Argoseer

The CSS-hidden disclosure is what I keep returning to. The other two failure modes are consistent with negligence: someone added a tool and didn't think about disclosure. But hiding a disclosure requires a different sequence of events. Someone wrote it, then made it invisible. That's not an oversight. That's a choice.

A Regulatory Floor That's Moving

The compliance picture around patient-facing AI is genuinely unsettled, and I think it's worth being honest about that rather than pretending there's a clear bright line that 521 practices crossed.

The FTC said in March 2026 that AI disclosures must be "clear, conspicuous, and made before or at the point of interaction" and that burying one in a terms-of-service page doesn't count (PolicyForge, citing FTC AI Policy Statement, March 2026). Healthcare companies using AI diagnostic or scheduling tools are explicitly named as covered entities under that statement. Those twelve CSS-hidden disclosures fail this standard on its face.

Texas went further. SB 1188, effective September 1, 2025, requires that practitioners personally review AI-generated content before any clinical decision is made, and separately disclose AI use to patients. Both elements must be present (Akerman LLP, January 2026). California enacted similar requirements effective January 1, 2026. NCQA issued a strict AI disclosure policy for the 2025-2026 survey cycle (Integral Healthcare Solutions, citing NCQA).

But here's where the picture complicates. Federal momentum is moving in the opposite direction. A draft ONC rule, HTI-5, would scale back the existing federal AI transparency certification requirement for clinical decision support, the only federal floor against which some of those 495 omissions are measured (The Regulatory Review, Craige, August 2026). The White House has been pushing to preempt state AI laws. Colorado's disclosure law (SB 26-189) is under enforcement suspension following litigation (Live Compliance, August 2026).

What this means, practically: some fraction of those 495 non-disclosing sites may operate in jurisdictions with no currently enforceable disclosure requirement. We can't determine from a website scan which state laws apply to which practice or which federal preemption argument might ultimately prevail. What we can say is that the gap between deployment and disclosure is real, and that state-level mandates are expanding faster than federal deregulation is contracting (Holland & Knight, May 2026). The compliance risk isn't going away; it's migrating.

Share of Detectable AI Deployments Missing Any Compliant Disclosure

95of 100
Sites with no compliant disclosure (495 of 521 detectable deployments)
5 of 100: Sites with disclosure present (even if hidden)
Source: Argoseer scan, Texas practices, 2026-03-06
Argoseer

The Standards Gap Underneath the Disclosure Gap

NAMSS revised its Ideal Credentialing Standards across 13 essential data elements in January 2024. Patient-facing AI tool disclosure isn't on the list (NAMSS via Dr. Lorna Breen Heroes Foundation, January 2024). NCQA's 2025-2026 overhaul tightened primary source verification timelines and monitoring cadence, but the scope is credential verification workflows, not AI tools on practice websites (CertifyOS, citing NCQA, July 2025). CAQH requires re-attestation every 120 days covering licenses, practice locations, and disclosures, but its disclosure framework addresses malpractice, sanctions, and exclusions, not the chatbot the marketing team installed last quarter (SybridMD, citing CAQH, 2026).

This isn't a criticism of those frameworks. They were built for a world where the primary credentialing risk was a lapsed license or an expired DEA certificate. They weren't designed to catch a symptom checker bundled into a website template.

The structural gap is this: the tools that govern what a provider is authorized to do (credentials) are maintained separately from the tools a provider actually deploys to patients (their website). No current credentialing standard systematically connects the two.

One Practice, One Tool, One Long Chain of Assumptions

Walk through what happens when a practice adds an AI diagnostic tool to their website without a disclosure.

A patient in Texas visits the site, enters symptoms into what looks like a contact form, and receives a response that reads like clinical guidance. Under Texas SB 1188, the practitioner was supposed to review that content before it went out. Under the FTC's March 2026 policy statement, the disclosure was supposed to be clear and conspicuous before the patient interacted with the tool. Neither happened.

Six weeks later, a claim comes in. The insurer's audit flags the practice for AI tool use without documented oversight. The credentialing file shows nothing about patient-facing AI. The CAQH attestation covers licenses and sanctions. There's no field for "AI diagnostic widget deployed on website, practitioner review documented."

The practice manager is now explaining, retroactively, what a tool does, who reviewed its outputs, and when they decided it didn't require disclosure. The answers she gives are probably honest. They're also probably inadequate. Not because she's negligent, but because no workflow she was given told her this was her problem to track.

This is the pattern we keep seeing: liability accumulates before anyone realizes the scope of what needs to be monitored. The disclosure problem and the credentialing problem look separate until they collide in a payer audit or an enforcement action.

AI Disclosure Failure Modes by Type

Texas practice website scan, Feb 27, Mar 6, 2026

Failure Mode
Sites Affected
Disclosure Present?
Intentional Concealment?
Regulatory Exposure
AI diagnostic tool, no practitioner-review statement
495
No
No
FTC Act §5; TX SB 1188; state disclosure mandates
Named chatbot vendor, no AI disclosure
14
No
No
FTC Act §5; state chatbot disclosure laws
Disclosure hidden via CSS
12
Yes (invisible)
Likely
FTC Act §5 (conspicuousness); state laws requiring prominence
Source: Argoseer scan, Texas practices, 2026-03-06
Argoseer

The Data Layer Underneath

There's a compounding problem that sits one level below all of this, and I think it's underappreciated.

NPPES, the National Plan and Provider Enumeration System, is self-reported and has no automated validation. CMS found only a 28% match rate between NPPES records and payer directories (Healthmonix, May 2026). That means the provider data layer underpinning AI credentialing tools, the rosters that feed automated workflows and inform coverage decisions, is itself substantially unreliable.

When we look at our own not-listed detection data, the honest version of the headline is more complicated than any single number suggests. As of September 11, 2026, we had roughly 975,000 rows where a single indicative signal suggested a provider might not be listed correctly. But only about 16,900 of those were confirmed by two independent detectors at the higher confidence tier (Argoseer pipeline data, September 11, 2026). The raw count dwarfs the confirmed count. I quote the confirmed figure as our finding, and I mention the raw count only to show the size of the gap between what looks like a problem and what we can actually defend.

That gap matters. If the underlying provider data is unreliable at the NPPES level, and AI tools are being deployed to patients without disclosure or practitioner review, and the credentialing standards that govern what a provider is authorized to do don't address patient-facing tools at all, then three distinct failure modes are running in parallel and reinforcing each other.

Signal Count vs. Confirmed Finding: Not-Listed Provider Detection

Raw indicative signals versus two-detector confirmed findings

Source: Argoseer pipeline data, 2026-09-11
Argoseer

What the FDA Doesn't Settle

The FDA's AI-enabled medical device transparency page lists devices cleared through premarket review. It is, by its own description, "not a comprehensive resource" (FDA, list updated through December 2025). It says nothing about whether deploying practices must disclose AI use to patients on their own websites.

The draft FDA guidance on AI-enabled device software functions, published January 7, 2025, explicitly states that its recommendations are non-binding and do not "establish legally enforceable responsibilities" (FDA Draft Guidance, FDA-2024-D-4488). Manufacturer-level submission requirements exist. Point-of-care disclosure requirements, at least from the FDA, do not.

This leaves a gap that our scan data directly measures. Nobody is requiring the practice that deploys an FDA-cleared AI tool to tell patients it's there. The FDA cleared the manufacturer. The practice's credentialing file tracks licenses and sanctions. Nobody is watching the website.

The Winston & Strawn compliance framework for AI chatbot operators puts it plainly: disclosures must be "prominent, easy to understand, and placed where users are likely to see them, rather than buried in fine print, footnotes, or hyperlinks" (Winston & Strawn LLP, August 2026). Twelve practices in our scan had disclosures that met none of those criteria because they were invisible.

What Practice Managers Are Actually Being Asked to Own

I don't think the practice manager who added a chatbot last year knew she was taking on regulatory exposure. The vendor made it easy. The EHR bundled it in. The marketing team set it up on a Friday.

None of that matters if the FTC comes looking, or if Texas's enforcement machinery turns toward patient-facing AI, or if a payer audit ties an AI-assisted intake to a claim that was processed without documented practitioner review.

Argoseer monitors provider data for credential drift and directory integrity. We are not a CVO, we don't issue licenses, and we don't perform NCQA primary source verification. But what we can see from scanning practice websites is that the boundary of what credentialing teams need to own is expanding, and the standards that define that scope haven't caught up.

We're also seeing, separately, that 293 Texas practices routed their patient-facing email through mail servers resolving outside the United States as of March 6, 2026 (Argoseer scan; Cloudflare Email Routing excluded because its mail hosts are anycast and geolocate inconsistently). Of those, 277 were graded critical. That's a separate data-handling concern, but it lives in the same category: infrastructure decisions made without credentialing oversight that carry compliance exposure.

So the real question isn't whether 495 is a large number or a small one in the context of Texas's total practice count. The question is who, inside a given practice, is responsible for knowing what's running on the website, what those tools are doing at the point of patient contact, and whether the disclosures are there and visible.

Right now, from what we're seeing, the honest answer for most practices is: nobody.

A

Argoseer

Building the future of provider data intelligence.