Now live in Texas — California coming soon. Millions of provider records indexed.See state coverage →

Your Practice Website Is Running AI Tools Nobody Disclosed

Argoseer•Oct 5, 2026•11 min read
Your Practice Website Is Running AI Tools Nobody Disclosed

Somewhere in a mid-sized Texas family practice, a patient fills out an intake form before their appointment. The form asks about symptoms, flags severity, maybe suggests an urgency level. It feels like a form. It is not a form. It is an AI diagnostic tool embedded by a third-party vendor, and nowhere on the page does it say so.

The clinician reviewing the output doesn't know it was generated by AI. The patient doesn't know. And the credentialing coordinator who maintains the practice's NCQA audit file has no idea the tool exists, let alone that it produces records with no physician-review statement attached.

This is the problem we kept running into when we scanned Texas practice websites between February 27 and March 6, 2026. We weren't looking for fraud. We were looking for something much quieter: AI tools deployed on practice-facing pages and the disclosure language, or absence of it, that accompanied them.

What we found was harder to explain away than we expected.

What the Scan Actually Found

Of the practice websites where our detectors could positively identify an AI tool on the page, 495 showed an AI diagnostic tool with no practitioner-review statement anywhere on the site. Fourteen more named a chatbot vendor explicitly but attached no AI disclosure label of any kind. Twelve had a disclosure present in the underlying HTML but hidden using CSS, meaning a patient looking at the page would never see it.

That is 521 sites with a detectable AI deployment and a disclosure failure of some kind, as of March 6, 2026 (Argoseer scan, Texas practices, February 27 to March 6, 2026).

A few things worth saying plainly about that number. These are positive detections: the tool was visible to our scanner. We excluded the check that records the absence of keywords, because a practice using no AI at all needs no disclosure. So 521 is a floor on the problem within this scan population, not a ceiling.

AI Disclosure Failures by Type on Texas Practice Websites

Positive detections only. Practices with no AI tool are excluded. Texas practices, scan of Feb 27, Mar 6, 2026.

Source: Argoseer scan, Feb 27–Mar 6, 2026
Argoseer

The breakdown matters because the failure modes are not equivalent. Hiding a disclosure with CSS is a deliberate act. Naming a vendor without a disclosure label looks like an oversight, or an assumption that naming the vendor was enough. But 495 sites with no practitioner-review statement anywhere is a systemic pattern, not an accident scattered across a few bad actors. It is the dominant failure mode by a factor of more than thirty.

The Field Is Celebrating AI While Governance Lags

I want to be honest about what makes this complicated. The healthcare industry is not ignoring AI. It is racing toward it.

The 2025 CAQH Index (CAQH / DataSpring, February 2026) credits automation with $258 billion in avoided administrative costs in 2024. Drawn from 600 or more provider organizations representing 63 percent of insured lives, it frames AI adoption as unambiguous progress. That is a real finding. But the same report does not treat the disclosure gap as a countervailing problem. The field's primary benchmarking body is measuring adoption speed. It is not yet measuring disclosure compliance.

That gap between adoption speed and governance speed is exactly what our scan is measuring, and the 521 instances are evidence that it is wide.

AI Disclosure Compliance Rate Across Detected AI Deployments

Zero sites in this scan population had compliant disclosure across all tested criteria. Texas practices, Mar 6, 2026.

0521 sites
0 sites
Sites with compliant disclosure
Critical gap (0–20%) to 104 sites · Partial compliance (20–50%) to 260 sites · Approaching compliant (50–100%) to 521 sites
Source: Argoseer scan, Feb 27–Mar 6, 2026
Argoseer

The Regulatory Floor Is Not What Anyone Thinks It Is

Here is where the picture gets genuinely complicated, and I think it is worth saying so directly rather than papering over it.

There is no single comprehensive federal AI disclosure statute in healthcare. The federal posture through 2025 and into 2026 turned sharply deregulatory. The Biden administration's AI executive order was rescinded. The ONC actually floated a draft rule, RIN 0955-AA09, that would remove existing AI transparency requirements from certified EHRs, per Live Compliance's August 2026 analysis citing ONC's HTI-5 fact sheet. The White House has been pushing to preempt state AI laws. So the disclosure standards that our 521 instances are measured against were themselves unsettled on the day of the scan.

This matters. It means the compliance gap is real, but what counts as "proper disclosure" varied by jurisdiction as of March 6, 2026. Our data does not resolve that question. It surfaces practices where something detectable was absent.

What we can say more precisely: the FTC published an AI policy statement on March 11, 2026, requiring disclosure to be clear, conspicuous, and made before or at the point of interaction, with penalties up to $53,088 per violation under FTC Act Section 5 authority, per PolicyForge's March 2026 analysis. Both CSS-hidden disclosures and chatbots named without a disclosure label fail that test. The FTC standard applies to healthcare companies using AI diagnostic or scheduling tools. That is a live enforcement ceiling for at least part of our 521.

Texas is further. Texas SB 1188, effective January 1, 2026, requires a practitioner to both disclose AI use AND review all AI-generated records under Texas Medical Board standards. Two distinct obligations, both statutory. The 495 practices with no practitioner-review statement are not falling short of a best practice in Texas. They are out of compliance with state law.

Texas HB 149 (TRAIGA), codified at Texas Business & Commerce Code Section 552.051, goes further still: disclosure must be clear and conspicuous, in plain language, and providers cannot use dark patterns to obscure it. CSS-hiding a disclosure is, by definition, a dark pattern.

A May 2026 Holland & Knight legal analysis documents that in 2026, states continued efforts to regulate healthcare AI, including requiring patient disclosure and in some cases informed consent, but the patchwork is state-by-state. Dickinson Wright's August 2026 health law analysis notes 177 pending bills in 31 states. The exposure is not uniform. But for Texas practices in our scan population, the statutory requirements were clear and in effect.

One Clinic, One Tool, One Paper Trail That Doesn't Exist

Let me walk through what this looks like in practice, because the abstract numbers are easier to dismiss than a single arc.

A family practice clinic in a Texas suburb deploys an AI-powered symptom checker in late 2025. A vendor sells it as a "patient engagement" product. The implementation takes an afternoon. The vendor's contract is signed by the office manager; nobody on the credentialing team is looped in. The tool goes live.

The tool generates an urgency classification for every patient who uses it. That classification influences which appointment slot the patient receives. The physician sees the patient, reviews the notes, and signs off, but the notes do not say the initial triage was AI-generated. There is no practitioner-review statement on the website, no vendor disclosure in the patient portal.

Six months later, the practice is up for NCQA survey renewal. NCQA's July 1, 2025 standards update, described by CertifyOS as "the most significant revision to credentialing standards in a long time", explicitly requires audit trails showing who changed provider data, what was changed, when, and why. An AI tool with no practitioner-review statement and no vendor disclosure produces no such audit trail. The practice is asked to document its AI tools during survey. Nobody can locate the vendor contract. The office manager who signed it left six months ago.

This is not a hypothetical designed to alarm. It is the operational consequence of the pattern our data shows. The disclosure failure and the audit-trail failure are the same failure.

NAMSS's Ideal Credentialing Standards (revised 2023, updated February 2025) require primary-source verification of all practitioner credentials. An AI diagnostic tool operating without a practitioner-review statement cannot satisfy the ICS requirement that credential elements be traceable to a primary source. And Atlas Systems' August 2026 summary of NCQA's 2025 standards makes the same point from the accreditation side: annual training on data integrity, audit trails for every change. Tools that leave no trail fail both standards simultaneously.

What Our Own Data Tells Us About Confidence

There is one more thing worth saying about how we count. We publish two numbers for some findings: a raw signal count and a confirmed count, where two independent detectors agreed at a higher confidence tier.

For our not-listed detector specifically, as of September 11, 2026 (Argoseer internal pipeline), the raw single-signal count was 974,944. The confirmed count, where two detectors agreed, was 16,903.

Raw Signal Count vs. Confirmed Count: Not-Listed Detector

The gap is not error, it is the honest cost of requiring two detectors to agree. Confirmed means our detectors agreed at the higher confidence tier, not that a payer or practice verified it.

SINGLE INDICATIVE SIGNALCONFIRMED BY TWO DETECTORSNot-listed signal 974,94416,903
Source: Argoseer pipeline, as of Sep 11, 2026
Argoseer

I'm including this because I think it is the right thing to do. The raw count is real. The confirmed count is what we would stake a finding on. Both belong in the same sentence. That discipline applies to the AI disclosure scan too: 521 positive detections, Texas practices only, one week's worth of data. The pattern is real. The precise national figure is something we don't have yet.

The Infrastructure Picture Alongside It

The AI disclosure finding sits alongside two other signals from the same Texas scan worth naming, because they point at the same underlying problem: practices deploying tools and infrastructure that nobody inside the practice is tracking.

As of March 6, 2026, 293 Texas practices were routing their email through mail servers resolving to addresses outside the United States. Cloudflare Email Routing was excluded from this count because its mail hosts are anycast and geolocate to Toronto for everyone; what remains is real foreign mail infrastructure, including Hostinger, Zoho India, Proton, and Tucows (Argoseer scan, February 27 to March 6, 2026). 277 of those 293 are graded critical.

Separately, 274 practice websites were hosted on IP addresses outside the United States. Anycast networks were excluded because their edge locations are not where the site is actually hosted; that removed 262 of the 536 initial detections. What remains resolves to real foreign hosts, mostly in Canada, the UK, Germany, Lithuania, and India (Argoseer scan, February 27 to March 6, 2026).

These are not the same as the AI disclosure finding. But they share a common shape: infrastructure decisions made without a compliance lens, invisible until someone runs a scan.

Texas Practice Website Infrastructure Signals, Feb–Mar 2026

'Excluded' reflects anycast/CDN removals or lower-severity grades. AI disclosure column reflects positive detections only. Texas practices, Feb 27, Mar 6, 2026.

Source: Argoseer scan, Feb 27–Mar 6, 2026
Argoseer

The Credentialing Team's Blind Spot

Here is what I keep coming back to. The credentialing team's job, as defined by NCQA and NAMSS, is to verify that the providers in a practice are who they say they are, credentialed to do what they're doing, practicing where they say they're practicing. The credentialing file is about practitioners.

But the AI tool embedded in the patient-facing website? That is nobody's explicit job to track. The vendor relationship lives in the office manager's email. The disclosure language, or lack of it, lives on a page the credentialing coordinator has probably never audited. The practitioner-review statement that Texas law requires? Nobody assigned that to anyone.

This is not a criticism of credentialing teams. It is a description of a scope problem that nobody has formally resolved. As AI tools proliferate in clinical and administrative workflows, the credentialing function is being asked, implicitly, to extend its verification reach into territory it was never resourced to cover.

Argoseer's scans are not a substitute for that structural decision. We surface what's detectable: the tool is on the page, the disclosure isn't. What happens next, who is responsible, what the remediation looks like, that requires a human decision inside the practice. We don't credential providers, we don't perform NCQA primary source verification, and we don't issue licenses. What we can do is make the invisible visible, quickly enough that someone can act on it before a survey cycle or an FTC inquiry.

The real question this data opens is not how to fix 521 disclosure failures. It is who inside a practice is positioned to even know the question exists. Right now, from what we're seeing, the answer is often nobody.

And given that 177 AI bills are pending across 31 states as of August 2026, the window to figure that out is getting shorter.

A

Argoseer

Building the future of provider data intelligence.