August 14, 2026|7 min read

The Claim Is Cheap Now. Substantiation Is the Control.

A true "Made in USA" claim can still be illegal without proof. See why substantiation, not honesty, is becoming governance's core control.

Written by Carlos Alvidrez, with AI assistance in research · How we use AI

The Claim Is Cheap Now. Substantiation Is the Control.

Photo by Markus Spiske on Unsplash

Here is a fact that should reframe how you think about compliance: under the Federal Trade Commission's rules, a "Made in USA" label can be completely true and still be illegal. If you cannot produce a substantiation file that existed before you printed the claim, the accuracy of the label does not save you. The proof is the requirement, not the honesty.

That standard is not new for the FTC, but the agency's July round of warning letters, analyzed by Reed Smith attorneys John Feldman and Julia Solomon Ensor, suggests something sharper is taking shape: a triage framework. Risk is not equal across claims or across products. Some companies get a warning; others get a penalty. The sorting logic reveals what regulators now expect proof to look like, and it points to a shift that runs far beyond origin labels. Across data security, artificial intelligence, and the boardroom, the burden of proof is moving upstream. The claim has become cheap. Substantiation is becoming the control.

Proof now comes before the claim

The FTC's logic inverts the intuitive order of compliance. Most teams treat documentation as something you assemble when someone challenges you. The agency treats the absence of that documentation as the violation itself, independent of whether the claim was accurate. The file has to exist first.

The triage angle matters just as much. Regulators are not chasing every imperfect claim with equal force; they are allocating scrutiny by consequence, reserving penalties for the claims and products where a false statement does the most damage. That is a maturity signal, and it is one governance teams should copy. If your documentation effort is spread evenly across every assertion your organization makes, you are both overspending on the trivial and underspending on the claims that can actually sink you.

The same standard is arriving where nobody built for it

The reason this matters now is that generative AI has made claims almost free to produce. Text, images, evidence, marketing copy, and code can all be manufactured in seconds. When production is that cheap, the scarce and valuable thing is provenance: the traceable record of where something came from and how you can prove it. Three stories from this week show that demand landing in domains that never had a substantiation habit.

Start with training data. Twitch is facing backlash after reports that Amazon is training AI on users' livestreams, with executives noting that people can opt out and that this has become common industry practice. Opt-out is a substantiation dodge. You cannot prove informed consent from a default that most people never saw, and when a rights holder or regulator asks you to show that these creators agreed, a silent setting is not a file; it is a hope.

Then consider the labor underneath the models. Bloomberg described blue-collar workers in India with cameras strapped to their foreheads, filming how they use their hands so that humanoid robots can learn to move. The provenance of a model's capability is human work that is rarely documented or credited. When the robot performs the task, whose labor is embedded in it, and can anyone trace it?

Finally, look at forensics, where substantiation is the entire job. Veteran examiner Brett Shavers and Magnet Forensics are pressing an uncomfortable question about where digital investigations break down when people far from casework decide how the work gets done, because those errors land on real defendants and victims. A recent survey of large language models in cybersecurity sharpens the stakes: it catalogs AI-generated malware and dual-use risks, and it keeps returning to explainability. Explainability is substantiation by another name. You cannot defend a decision you cannot reconstruct, and a model that will not show its reasoning is a claim without a file.

You cannot substantiate what you cannot trace

The infrastructure layer has the same problem, and it is older than most of the compliance staff. Microsoft's August Patch Tuesday shipped 398 fixes, including a zero-day in the WinSock Ancillary Function Driver that is already under active exploit. The Register put the count at 421 and noted that North Korean operators had already attacked one of the holes. A separate account of long-lived bugs described vulnerable code roughly 54 years old, with no patch and no expectation of one.

The interesting governance point here is not the patch gap. It is that most organizations cannot substantiate the origin, age, or ownership of the code that runs their business. You are increasingly asked to certify a software bill of materials for a stack whose foundations predate the people maintaining it. When substantiation is demanded at the infrastructure layer, too many teams offer a guess dressed up as a record.

The cadence is being rebalanced, not reduced

It would be easy to read the SEC's proposal to revisit quarterly reporting as evidence that the compliance burden is shrinking. The debate, framed as compliance costs against investor protection, is really about how often companies must substantiate their financial condition to the market. Read next to the FTC crackdown, the picture is not deregulation; it is rebalancing. One regulator questions whether routine quarterly disclosure is too frequent while another raises the depth of proof demanded for a three-word marketing claim. The burden is migrating from scheduled cadence toward on-demand, provenance-grade evidence.

Boards are already being priced on this. Tata Group companies shed about $4.5 billion in combined market value as a chairman's planned exit turned investor attention to succession and strategy. Those investors were not reacting to an operational shock; they were reacting to a continuity claim they could not verify. A succession plan that lives in a few executives' heads is a claim without substantiation, and markets have learned to discount it.

What this means for governance teams

The organizations that handle the next decade well will not be the ones that make the fewest claims, or even the truest ones. They will be the ones that can show, on demand and after the fact, exactly where each claim, output, and artifact came from. A few priorities follow directly:

  • Build the file before the claim. For any public statement about origin, sustainability, AI capability, or security posture, the supporting evidence should exist and be dated before the statement ships.
  • Capture provenance at the source. Consent, training-data lineage, model reasoning, and chain of custody are cheap to record at the moment of creation and nearly impossible to reconstruct later.
  • Triage by consequence. Mirror the FTC's logic and concentrate your heaviest documentation where a wrong claim causes the most harm.
  • Version your foundations. Know the age, origin, and ownership of critical code and dependencies, because "we have always run it" is not substantiation.

Honesty has quietly become table stakes rather than a defense. Provenance is the control now, and the questions are already arriving. The teams that start building the file today are the ones who will still have an answer when "trust us" stops working.

Sources

SubstantiationFileCaptureProvenanceTriageByConsequenceUnverifiableClaimAI-GeneratedClaims mitigates builds prioritizes multiplies traces
Substantiation files and provenance capture, triaged by consequence, control the risk of unverifiable AI-generated claims.

Related governance guides