Truth is now a billable input
AI broke the assumption that trusted systems produce trustworthy records. Integrity is now a contract term, not a control.
On 2 August 2026, the California AI Transparency Act becomes operative — the first US mandate requiring providers of large generative AI systems to embed provenance disclosures in AI-generated content and offer a free public detection tool, enforceable by the attorney general at $5,000 per violation. Newsom signed the enabling amendment, AB 853, in October, and its delayed start date was chosen deliberately to align with the EU AI Act's implementation timeline.
The mechanics matter less than what the date confirms. AI has broken the old assumption that trusted systems produce trustworthy records, and integrity is no longer just a control problem. It is a procurement, liability, and governance problem that decides who bears the cost when plausible but wrong outputs enter contracts and operations. The sentence that matters for ELECTE's remit is simple: whoever controls integrity verification in AI workflows controls risk allocation, and whoever shifts that risk onto others captures more of AI's value.
The Integrity Assumption We All Took for Granted
For years, firms treated integrity as the quiet leg of security. Confidentiality got the headlines. Availability got the budget after every outage. Integrity sat in the background as a technical property of systems that, properly configured, would keep data accurate enough to trust.

The assumption held because integrity failures in conventional enterprise systems had a visible cause. A user changed a field. A script overwrote a file. A process imported bad data. Security teams could investigate the event path, identify who or what made the change, and restore a prior state. That made integrity look like a bounded control problem:
- Access controls restricted who could create, edit, or delete records.
- Checksums and hashes detected whether content had changed.
- Version histories preserved earlier states for review or rollback.
- Audit logs recorded actions in a sequence investigators could reconstruct.
These controls were designed for alteration, not authorship. They can show that a record changed, and sometimes who changed it. They cannot establish that a newly generated output is accurate, complete, or grounded in a reliable source. If a procurement team receives a polished summary, a legal team reviews a generated clause, or an operations team acts on a machine-produced recommendation, the technical record can remain perfectly intact while the business meaning is false.
That gap hid an economic premise. Firms never priced verification heavily because the system was assumed to preserve meaning unless a control broke. Integrity was an embedded property of the environment, not a recurring cost centre.
Authorised Systems Now Create Integrity Failures
AI breaks the model at the root. The old problem was keeping unauthorised actors from altering information. The new problem is that authorised systems can generate, modify, and route information that looks legitimate while being wrong, incomplete, or impossible to verify.
The system is approved. The user is authorised. The workflow is legitimate. The record is still wrong.
The break shows up through three recurring mechanisms.
Data poisoning. If manipulated data enters training, fine-tuning, or retrieval pipelines, the model absorbs false patterns and reproduces them at scale. It rarely looks like sabotage. It appears as slightly biased rankings, distorted summaries, or recommendations drifting toward a bad source base — and the firm pays later to audit outputs that earlier systems were presumed to preserve faithfully.
Drift inside approved workflows. Models degrade through changed inputs, altered context windows, prompt reuse across business units, and deployment in settings they were never tested for. Nothing has to be hacked. The system keeps producing polished output while its fit for purpose declines — the kind of failure busy teams miss because the format still looks professional.
Plausible but wrong output. The most expensive category, because it passes human review more often than obvious nonsense. A weak output gets rejected. A plausible output gets accepted, filed, forwarded, quoted, and relied on. Once that happens, the cost shifts from prevention to verification, remediation, and liability. I have written before about why opaque systems create misplaced confidence inside institutions in this analysis of belief and black-box AI. The same dynamic applies here: fluency gets mistaken for evidentiary quality.
Provenance Is Necessary, but It Does Not Settle Truth
Traditional integrity controls still matter for software, records, and transmission. They establish whether something changed after approval. They do not answer the harder question AI introduces: was the output reliable enough to act on in the first place? A generated contract clause can be internally consistent and still misstate obligations. A summary can preserve tone while dropping the fact that controls failed. A synthetic image can pass a casual review while misrepresenting an event. The same evidentiary pressure is already visible in adjacent disputes over synthetic media, which I explored in my piece on deepfakes and the new emergency rewriting the rules of business.
Provenance standards help. If an organisation can trace where an artefact came from, what system handled it, and whether edits were recorded, review becomes auditable instead of speculative. That is exactly the direction regulation is moving: California now demands machine-readable evidence of origin and handling, not vendor assurances after an incident, and the EU AI Act's transparency obligations point the same way.

But provenance is not accuracy. Metadata can show origin without showing correctness. It can document that a model generated a result and a person approved it, while leaving open whether either party had a basis to rely on it. A useful verification set therefore asks:
- What source material supported the output
- Which system generated, transformed, or summarised it
- Whether human review occurred before operational use
- What evidence exists that the reviewer checked substance, not just format
- Which parts of the chain are verifiable and which remain opaque
The deeper change is procedural. If a system rewrites analyst notes, classifies invoices, or prepares disclosure text, the integrity question attaches to the chain of production and approval, not to any single object. I explored a related reporting risk in my analysis of when AI becomes an informant. Process integrity now matters more than object integrity — and someone has to fund the review, preserve the decision records, and absorb the loss if a plausible output turns out to be false.
The Contract Is the New Firewall

That someone gets named in contracts, which is why procurement is now a risk-allocation exercise.
Corporate disclosure already reflects the shift. Per Fortune's analysis of 2025 filings, 72% of S&P 500 companies disclosed AI as a material risk in their 10-Ks, and a Harvard Law School Forum on Corporate Governance review found reputational risk — biased outcomes, unsafe outputs, brand misuse — the most frequently cited AI concern, disclosed by 38% of S&P 500 firms. JPMorgan's 2026 10-K names the failure mode outright: inaccurate or biased output from rapid deployment and insufficient testing. When companies write the risk into the most cautious document they produce, the exposure is real — and it lands wherever the contract puts it.
Traditional software contracts were built around uptime, access control, service levels, and breach notice. AI introduces a different exposure: a system that produces incorrect summaries, altered clauses, or flawed classifications without any intrusion event. So integrity now sits inside indemnities, warranties, audit rights, evidentiary requirements, and limitations of liability. The supplier gets paid for speed. The customer often pays to verify. If a vendor automates drafting, review routing, or record creation, but leaves the buyer responsible for substantive checking of every material output, the buyer has not purchased integrity.
The buyer has not purchased integrity. The buyer has purchased a new verification workload.
The party that controls the logs, the provenance trail, and the contractual definitions of acceptable error has structural advantage. It can narrow its own exposure while pushing verification work onto the buyer. That is how integrity risk gets repriced in AI markets — and it is why technical evidence only affects risk when the contract gives the customer access to it and ties failure to a remedy.
A Working Checklist for Procurement Teams
Most SME buyers don't need another lecture on the CIA triad. They need what to ask, what to sign, and what to watch.

Ask before signing:
- Show the provenance chain. Where does training and operational data come from, what gets modified, and what evidence exists for those changes?
- Show the decision record. If the system affects pricing, vendor selection, contract language, or reporting, can it produce logs linking outputs to prompts, source material, and review actions?
- Show review boundaries. Which outputs require human approval — and is that approval substantive or a box-ticking step?
- Show the failure mode. How does the system surface uncertainty or low-confidence output instead of presenting every answer as equally usable?
Sign for evidence, not just functionality:
- Integrity warranty. The supplier warrants traceability of AI-generated or AI-modified content used in material workflows, preservation of source context, and logging of transformations.
- Audit and evidence rights, with retention. Access to process records, review logs, version history, and model-change documentation — retained long enough to support audit, dispute resolution, and regulatory review.
- Notification duty. Prompt notice and a documented remediation path when the supplier discovers integrity degradation, provenance failure, or material model, data-source, or workflow changes that could affect output quality.
- Reliance boundaries. Which outputs the customer may rely on, what level of human review is assumed, and whether the supplier disclaims plausible but incorrect content.
- Allocation of loss. If synthetic or corrupted outputs create contractual, financial, or reporting harm, the agreement says who bears it. Generic liability caps can shift nearly all downside to the customer even when the supplier controls the model, the logging, and the output pipeline.
Watch after go-live:
- Spot-check against ground truth: sample AI outputs against original documents, approved terms, or validated records.
- Separate drafting from approval: never let the same automated chain generate, classify, and approve a material output.
- Track silent changes to logs, metrics, and records made during transfer or summarisation.
- Escalate provenance gaps: if teams can't prove where a key output came from, treat it as a control failure, not an inconvenience.
A usable AI system is not necessarily a trustworthy one. A strong buyer doesn't ask whether the supplier "uses AI safely" in the abstract. A strong buyer asks whether the supplier can prove authenticity, reconstruct process history, and carry liability where its system creates risk.
Who Pays for Truth?
This does not get solved by telling firms to "adopt responsibly". The pressure lands elsewhere: in procurement questionnaires, control documentation, audit rights, provenance requirements, insurance exclusions, and liability clauses — and now, starting 2 August, in statute.
The market consequence is straightforward. Providers that can disclaim responsibility while customers pay to verify outputs will capture disproportionate value. Buyers that fail to negotiate for evidence and recourse will absorb the operational cost of truth. That is why information security integrity now belongs in commercial strategy, not just cyber policy.
In AI markets, truth has become a billable input.
If this is the kind of analysis you want more of, subscribe to ELECTE's Newsletter. Every week, I write about AI as power, contract, regulation, and market structure, without recycling vendor talking points.
Sources
- Destcert on the CIA triad and ISO/IEC 27000:2018's definition of integrity
- AB 853, chaptered text — California AI Transparency Act operative 2 August 2026
- Mayer Brown on AB 853's obligations, enforcement, and $5,000-per-violation penalty
- Fortune on 72% of S&P 500 companies disclosing AI as a material 10-K risk
- Harvard Law School Forum on Corporate Governance on AI risk disclosures in the S&P 500
- NIST SP 1800-26 on data integrity and detecting integrity events
- NIST SP 800-53 system and information integrity guidance
Fabio Lauria
CEO & Founder, ELECTE
Every week, we explore AI without the hype — using data, analysis and an independent perspective.

Comments ()