Your Practice Deployed AI. Nobody Told the Patient.
The Tool That Wasn't There
A patient in Texas visits her primary care practice's website in February 2026. She clicks on a symptom checker, types in her concerns, and gets a response. The tool responds quickly, sounds authoritative, and she follows its guidance. Nowhere on the page does it say the output was generated by AI. Nowhere does it say a clinician reviewed it. What she doesn't know, and has no way of knowing, is that the tool is one of 495 we found in a scan of Texas practice websites between February 27 and March 6, 2026, running AI diagnostic tools with no practitioner-review statement. Zero. Not buried in a footer. Not in a terms page three clicks away. Absent.
That's where this piece starts. Not with a policy framework or an industry trend. With a tool on a live website, pointing at a patient, with no label on it.
What the Data Actually Shows
Let me be precise about what we found, because the honest version matters more than the alarming version.
Between February 27 and March 6, 2026, we scanned Texas practice websites and flagged AI-tool deployment against a set of disclosure detectors. Three categories emerged: AI diagnostic tools with no practitioner-review statement (495 sites), named chatbot vendors with no AI disclosure at all (14 sites), and disclosure present but hidden using CSS, meaning invisible to a visitor (12 sites). That's 521 instances total, as of March 6, 2026.
These are positive detections. The tool was found on the page. We're not counting the absence of a disclosure where no AI tool exists; we're counting places where a tool clearly exists and disclosure clearly doesn't. That distinction matters.
Now here's where I want to be honest about our own numbers before citing anyone else's. The 521 figure is a single state, a single week. It's not a national prevalence study. I'd be misleading you if I extrapolated a rate from it without more runs, and we haven't run this scan again since. What I can say is that in one state, in one week, the non-disclosure pattern was so consistent that it stopped looking like an oversight and started looking like a norm.
The external data corroborates that instinct. A 2023 JAMA study (published in JAMA Network Open / PMC in July 2024) examined physician directory data across five large national insurers and found 81% of physicians had inconsistent directory entries. Address discrepancies affected 72%. Specialty inconsistencies hit 32%. If directory data, which is actively maintained by credentialing teams whose entire job is data accuracy, is that degraded, it shouldn't surprise us that website-level AI disclosures, which nobody owns and no checklist covers, are worse.
The Regulatory Ground Shifted Under Everyone's Feet
Here's the part that complicates the picture in a way I think is important to name plainly.
The 521 non-compliant instances we observed on March 6, 2026 weren't technically in a legal gray zone in every state. Some of them were already violations.
Texas SB 1188, effective September 1, 2025, requires practitioners using AI diagnostically to review all AI-generated records and disclose AI use to patients. TRAIGA (HB 149), effective January 1, 2026, requires disclosures that are clear, conspicuous, and written in plain language, expressly covering AI chatbots fielding patient inquiries. Both laws were already in force by our observation date, as detailed by the Texas Medical Liability Trust. The 495 sites with undisclosed AI diagnostic tools and the 14 with unnamed chatbot vendors weren't in a future-risk category. They were in a present-violation category.
California had moved even earlier. AB 3030, effective January 1, 2025, requires health facilities and physician practices to disclaim AI-generated clinical communications and provide clear instructions for reaching a human provider. AB 489, effective January 1, 2026, bars AI from using titles implying a licensed human. Both were in force before our scan date, as documented by the California Legislature / Dickinson Wright Health Law Blog.
And yet: the federal picture is messier. The Biden AI executive order was rescinded. A draft ONC rule would have removed AI transparency requirements. The White House moved to preempt state AI laws. Colorado's SB 24-205, the first comprehensive state AI law, was repealed before it took effect and replaced with a narrower statute (SB 26-189, signed May 14, 2026, effective January 2027), per Live Compliance. The national deregulatory turn in 2025 and 2026 doesn't erase state-level obligations, but it does mean the compliance map is a patchwork, not a single standard.
I want to name one thing the LaunchReady.ai analysis from May 2026 pointed out that I think is genuinely telling: a role coordinating cross-functional AI disclosure compliance is "a still-rare role inside US mid-market companies." That's not a criticism; it's a structural observation. The disclosure gap we measured isn't the result of bad actors. It's the result of nobody having clear ownership of the problem.
The Attestation Gap That Makes This Structural
I've been thinking about why this accumulates the way it does, and I keep coming back to one number: 120 days.
That's CAQH's provider attestation cycle. According to HealthStream's 2026 guide, the CAQH Provider Data Portal, used by 2.5 million providers and over 1,000 health plans, requires providers to attest to their information every 120 days. That's the de facto standard for credentialing data.
NCQA moved in a different direction. Its 2025 standards, effective July 1, 2025 and documented by Verisys and Ethico, now require mandatory monthly monitoring of all enrolled providers, with comprehensive exclusion, sanction, and disciplinary checks every 30 days. Monthly versus quarterly is a meaningful cadence difference, but even monthly monitoring assumes someone is watching what's on the website between checks.
What doesn't fit in any of these cycles is website tooling. CAQH attestation covers the provider's credentials, address, and specialty. NCQA monitoring covers sanctions and exclusions. Neither covers what AI tools are running on the practice's patient-facing website, whether those tools carry required disclosures, or whether the vendor relationship behind the tool is properly documented. That's not a criticism of CAQH or NCQA; it's simply outside their scope. But it means there's a category of compliance exposure that lives in the white space between every existing monitoring framework.
One Practice, One Tool, One Six-Week Chain
Here's how this plays out in practice, at the level of a single site. (The following is a pattern-level reconstruction; no real practice name, NPI, or identifying information is used.)
A mid-size multi-physician clinic in Texas embeds a symptom-checker tool in Q3 2025. The vendor handles the setup. The tool goes live. Nobody on the credentialing team is looped in, because credentialing doesn't own website content. The practice manager knows the tool exists. She assumes the vendor handled compliance language. The vendor assumes the practice handled it.
Texas SB 1188 takes effect September 1, 2025. The tool is still live. No practitioner-review statement. No disclosure. The tool now processes an average of 60 to 80 patient interactions per week.
By late January 2026, TRAIGA is in effect. Still no disclosure. The credentialing coordinator runs the quarterly CAQH attestation. Provider addresses, specialties, hospital affiliations, all confirmed. The attestation covers none of the above.
Our scanner flags the site on March 1, 2026. By March 6, the site appears in our count of 495. The practice still has no idea. Nothing in their existing workflow would have told them.
This is what the JAMA study's 81% inconsistency rate describes at a different level: not malicious omission, but structural invisibility. The 2025 Atlas PRIME Member Experience Monitor, published April 2026, found that 50% of "accepting new patients" statuses were inaccurate, 28% had wrong practitioner contacts, and 26% listed retired or deceased providers. That's provider directory data, maintained by teams whose explicit job is accuracy. Website AI disclosure data has no such team.
The Scale Problem Is Also a Confidence Problem
Let me show you something about our own data that I want to be transparent about.
When we count signals from our pipeline, we have two tiers. The first is what a single detector flags: a raw positive hit. The second is what two independent detectors both agree on, which is what we call a confirmed finding. As of September 11, 2026, our pipeline showed 974,944 single-signal indications and 16,903 confirmed-by-two-detectors findings across our monitored records.
The honest version of our headline is this: 16,903 confirmed findings, and 974,944 raw signals that we're not calling findings because one detector alone isn't enough to stake a claim on. When we publish a number from our data, it's the confirmed row, not the raw row. The gap between those two numbers is a feature, not a bug: it's what happens when you design for accuracy over volume.
I mention this because the broader provider data space has a tendency to cite alarming totals without naming the methodology behind them. The JAMA study's 81% inconsistency rate comes from peer-reviewed research across five national insurers. Our 521 AI disclosure gaps come from a Texas-only scan in one week. Manatt Health's 2026 AI Policy Tracker notes that in Q1 2026 alone, 36 states introduced over 70 bills regulating AI chatbots in healthcare. The regulatory pressure is real and it is moving. What our scan captures is a single moment inside that movement.
What Automated Monitoring Actually Does (and Doesn't Do)
Argoseer monitors provider records for data integrity, credential drift, and state regulation compliance. What I've described in this piece, specifically AI tool disclosure on practice websites, is a different category of signal: it's not credential drift in the traditional sense, it's operational compliance drift on patient-facing infrastructure.
What we can do: detect AI tool presence and check for disclosure language. Flag foreign hosting and email infrastructure that may implicate data residency. Surface signals in the same pipeline that monitors credentialing status, NPPES updates, and directory alignment. What we don't do: issue licenses, perform NCQA primary source verification, or guarantee license validity. The framing I keep returning to is that credentialing systems track what was filed; we check whether it's still true. That applies to credentials, and it applies to what's running on the practice's website.
The NAMSS 2025 Educational Conference coverage by QGenda described the profession's key direction as moving from manual data handling to intelligent process automation. That's right. But NAMSS' own Ideal Credentialing Standards, revised January 2024, contain no specific guidance on AI disclosure obligations for practice websites. The profession is encouraging the right motion without specifying where to step.
Manual audits cannot close a gap at this scale. The FTC issued Section 6(b) orders to seven major consumer-facing AI chatbot providers on September 11, 2025, seeking information on safety testing, disclosures, and data handling, per the FTC's own documentation. That's federal enforcement pressure on AI chatbot operators in consumer contexts, including healthcare. The 14 practice sites in our scan that named a chatbot vendor but included no AI disclosure are exactly the category that kind of scrutiny reaches.
The Question That Stays Open
I started this by describing one patient clicking on one tool and not knowing it was AI. That's the unit of measurement that matters most: not the 521 instances, not the 81% inconsistency rate, not the 36 states with pending legislation. One interaction, no disclosure, no way for the patient to calibrate her trust.
The regulatory environment will keep shifting. California's SB 942 and the EU AI Act's Article 50 both targeted August 2, 2026 as a disclosure deadline, per LaunchReady.ai. The patchwork will get denser. But statutes don't run scanners. They don't flag the vendor that embedded a tool six months ago and forgot the compliance language. They don't catch the CSS that hides a disclosure from the people it's supposed to protect.
The real question isn't whether practice AI disclosure will eventually be regulated into uniformity. It's who is watching the specific tool on the specific website the day the law changes, and whether anyone on the credentialing team will know about it before a patient, a regulator, or a denied claim tells them.
If you're thinking about what continuous monitoring looks like for this kind of exposure, the place to start is argoseer.com/product/monitor.
Argoseer
Building the future of provider data intelligence.
