Your Practice Website Already Has an AI Problem. It Just Hasn't Told Anyone.
A practice manager opens a denial letter. The reason code is administrative, something about the provider's listed address not matching the payer directory. She pulls up the practice website to check what patients see. On the homepage there's a symptom checker. Triage questions, branching logic, a recommendation to book. No label. No disclosure. No statement that a licensed clinician reviewed the output.
She wasn't looking for that. But now she can't unsee it.
This is the situation I keep finding myself describing when I talk about what our data actually shows. The credentialing conversation in 2025 and 2026 has been almost entirely about how AI helps with credentialing workflows: automated primary source verifications, AI-assisted roster management, smarter exception queues. What it hasn't been about is the flip side: practices deploying AI directly at patients, with no disclosure that it's happening, no statement that a practitioner reviewed anything, sometimes with the disclosure actively hidden.
What the Scan Found
Between February 27 and March 6, 2026, we scanned Texas practice websites and flagged every site where we could detect an AI tool. The first thing to note: if a practice isn't running AI-facing tools at all, they need no disclosure. We only flag positive detections.
Of the sites where we detected something:
495 practices were running AI diagnostic tools, symptom checkers, triage tools, clinical recommendation engines, with no practitioner-review statement anywhere findable on the page. Another 14 named a chatbot vendor somewhere in the site's code or copy, with zero AI disclosure attached. And 12 had written a disclosure, then hidden it using CSS so no patient could actually see it.
That last category is the one I find hardest to explain charitably. Someone drafted the text. Someone pushed a rule that made it invisible. That's not an oversight, it's a choice.
The controlling observation these figures support: AI deployment on patient-facing practice websites is systematically outrunning the disclosure obligations those deployments trigger. This isn't a fringe finding. 495 sites with no practitioner-review statement is not an edge case. It's the dominant pattern in the data.
The Rules That Were Already on the Books
Here's what makes the timing significant. These sites were scanned in early March 2026, and several disclosure mandates were already in effect by then.
Texas TRAIGA took effect January 1, 2026. It requires AI disclosure to be "clear and conspicuous, written in plain language," and explicitly bars dark patterns, according to Arnall Golden Gregory's analysis of the statute. A CSS-hidden disclosure facially violates that standard. So does silence.
California AB 3030 has been in effect since January 1, 2025, requiring a disclaimer plus clear instructions for patients on how to reach a licensed human provider, per Fenwick & West's statutory analysis. Texas SB 1188, also cited in that analysis, went further: it requires practitioners to personally review all AI-generated recommendations before any clinical decision is made. That's exactly the gap our 495 flagged sites represent.
ONC's HTI-1 Final Rule (89 FR 1192) has mandated disclosure of 31 source attributes for predictive decision support in certified EHRs since March 2024. Live Compliance's synthesis of the rule calls it "the one binding federal AI-transparency rule in force today" for certified health IT. And the FTC's March 11, 2026 policy statement on AI is unambiguous: disclosure must be "clear, conspicuous, and made before or at the point of interaction." Burying it in terms of service, or hiding it with CSS, is explicitly insufficient, per PolicyForge's synthesis of the FTC statement.
So the rules existed. The practices were already in scope. And 521 sites across our Texas scan had some form of gap anyway.
The Complication
I want to be honest about what makes this picture more complicated than it looks.
First, the regulatory floor itself is shifting. A draft ONC rule called HTI-5 would actually remove AI transparency requirements from certified EHRs. The Biden AI executive order was rescinded. The White House is actively pushing to preempt state AI laws, according to Live Compliance's August 2026 review of the federal posture. If HTI-5 finalizes, some of the federal disclosure obligations that make our 521 observations legally actionable at the federal level could shrink, not because practices improved, but because the rule got stripped back.
That's a real tension. State mandates like TRAIGA and AB 3030 don't disappear just because ONC retreats. But the federal enforcement backstop may weaken.
Second, FDA's 2025 labeling guidance requires cleared AI-enabled medical devices to carry explicit disclosure of their AI nature, including inputs, outputs, and known risks, according to the Bipartisan Policy Center's analysis of FDA oversight. Here's the catch: that obligation runs to device manufacturers, not to provider websites deploying those cleared devices. A practice could be running a fully FDA-compliant AI tool, with proper labeling in the manufacturer's submission, and the patient-facing web page could still carry no disclosure at all. Our 495 flagged sites may include some of those cases.
The FDA rule doesn't touch the practice website. The state statutes do.
Third, there's the question of what "compliant" actually means once you get past the website. Compass ITC's January 2026 guidance makes this point directly: "disclosure cannot live only in general website language, it needs to be embedded into the point of care workflow, and you should be able to show evidence that it happened." Under that standard, our 12 CSS-hidden disclosures may not be the only form of cosmetic compliance in the data. Even a visible homepage statement that isn't tied to the actual interaction moment may not satisfy what a regulator or plaintiff's attorney would look for.
One Site, Traced Forward
Let me walk through what the 495-category gap actually looks like at the practice level. Not a real site, a pattern we see repeatedly.
A Texas multi-specialty group is running a symptom checker on their appointment-booking page. The tool asks about onset, severity, associated symptoms, and outputs a triage recommendation: "Based on your responses, we recommend scheduling within 48 hours" or "Please proceed to an urgent care setting." The tool is FDA-cleared. The manufacturer's documentation is clean.
The practice website has no statement that a licensed clinician reviewed the triage output. No disclosure that AI is involved in generating the recommendation. No instruction for how a patient could reach a human instead.
Texas SB 1188 was already in effect. TRAIGA was already in effect. Our scanner flagged the site in late February 2026 as a positive detection: AI diagnostic tool, no practitioner-review statement.
Now a patient follows the 48-hour recommendation instead of going to urgent care. Six weeks later, there's a claim. The denial letter comes back with a reason code about the patient's escalation pathway. The practice's legal team is reviewing the website. They find the symptom checker. They pull the terms of service. There's no disclosure there either.
The disclosure gap wasn't the only thing that went wrong. But it became the thing that made everything else worse.
NCQA's FAQ, updated December 2025, is explicit: AI cannot make medical necessity denial or appeal decisions; those must be made by qualified clinical professionals, per NCQA's official FAQ. The practitioner-review requirement isn't novel. It's a principle the field already accepts. The practice just didn't apply it to their patient-facing tool.
What the Field Is and Isn't Doing About It
NAMSS held its annual conference in October 2025. The Qgenda summary of that conference captures the tenor: sessions on "automated primary source verifications," "AI-assisted tools," and "embracing AI" as a professional opportunity, per Qgenda's seven takeaways. That's exactly the right conversation for a credentialing professional body to be having. But the same summary documents no specific disclosure or practitioner-review standards for patient-facing AI tools. The field's professional body hasn't produced a framework that would address what our data shows.
NCQA is further along. Their October 2025 memo on proposed AI standards for Health Plan Accreditation 2027 acknowledges the "increasing complexity, scale, and autonomy of AI systems" and the need for "updated oversight," per NCQA's overview memo. But those standards are aimed at health plan accreditation, not practice-level website deployment. The gap our data documents sits in a space the major professional bodies haven't fully mapped yet.
The Regulatory Review's August 2026 governance analysis puts the systemic picture clearly: two-thirds of clinicians now use AI, fewer than 2% of cleared AI devices are backed by randomized controlled trials, and federal oversight is weakening rather than strengthening. The compliance gap our figures document may face diminishing federal enforcement pressure even as state mandates accumulate. Which means the gap between what state law requires and what practices are actually doing may quietly grow.
Note on the heatmap: the FDA column scores low for the first two gap types and zero for CSS-hidden disclosure because the FDA labeling obligation runs to device manufacturers, not practice websites. The state statutes and FTC statement are the most directly applicable frameworks for the patterns we're seeing.
What Argoseer Does Here, and What It Doesn't
To be precise about scope: Argoseer's website scanner detects the presence of AI tools on practice websites and checks for associated disclosure signals. It does not verify that a disclosure is legally sufficient under any particular statute, that analysis is for legal counsel. It does not perform NCQA primary source verification, issue licenses, or make a determination about whether a practice is compliant. What it does is surface the detection pattern so someone can act on it: "this site has an AI diagnostic tool and no practitioner-review language we can find."
The distinction matters because a visible disclosure that isn't embedded in the point-of-care workflow may still fail TRAIGA or AB 3030 standards. Our scanner can tell you the disclosure exists and whether it's findable. Whether it satisfies the workflow-embedding requirement that Compass ITC flags is a question for someone with both the law and the workflow in front of them.
Think of it the way you'd think about a smoke detector. It tells you something is burning. It doesn't put the fire out.
The Honest Version of the Headline
521 sites. Three gap types. Rules already in force at the time of the scan.
What I'm genuinely uncertain about is how much of this is knowing non-compliance versus practices that simply don't know what their website is running. The CSS-hidden disclosure case suggests at least some deliberate action. The 495 no-practitioner-review cases are harder to read. Some of those practices may have installed an off-the-shelf symptom checker without understanding what disclosure obligations it triggered. Some may have reviewed the FDA clearance documentation and assumed that covered the website. Some may not have looked at all.
The Regulatory Review's governance analysis frames the systemic version: the governance gap is a structural feature of how AI deployment and regulation have evolved at different speeds, not a story about bad actors. I think that's right, and also that it doesn't change the legal exposure.
The real question isn't whether practices meant to comply. It's who is watching the website the day the AI tool gets added, and whether anyone checks what disclosure obligations that addition triggers.
For practices curious about what their own site is running, Argoseer's monitoring dashboard is a starting point. But the heavier question sits further upstream: does your credentialing and compliance workflow include a step for reviewing patient-facing AI before it goes live?
Most of what I see in the data suggests it doesn't. Not yet.
Argoseer
Building the future of provider data intelligence.
