Thursday Field Note · Visual operating map
Before Your Business Makes an AI Claim, Build the Receipt
A practical five-part evidence map for connecting what an AI-enabled system actually does to what a business responsibly tells customers.
Current signal: public claims about AI capability are receiving direct scrutiny.
Operating question: what proof should exist before your business describes what an AI-enabled system can do?
An AI claim should never travel farther than the evidence that supports it.
On August 27, the Federal Trade Commission finalized three consent orders resolving allegations that companies misrepresented an “AI-powered” advertising service, its use of voice data, consumer consent, and geographic targeting. The agency reported $930,000 in total payments and restrictions on future misrepresentations.1 The record is specific to those parties and allegations. It still offers every business a useful operating question: who can prove the sentence that marketing is about to publish?
Documentation is also moving closer to the public edge of AI systems. NIST released an initial draft about public-facing model and dataset documentation in July; NIST describes it as a proposal that may change through further input and formal standardization.2 The direction is useful even before any standard is final: a polished claim should remain connected to inspectable facts.
The safest marketing review begins before the copy exists; it begins where the capability is tested.
Build a Five-Part Claim Receipt
A Claim Receipt is a compact evidence bundle attached to one consequential statement. It is not a legal opinion, a certification, or proof that the whole product is trustworthy. Its narrower job is to stop a public sentence from drifting away from the system, conditions, and people that make the sentence true.

A responsible public statement remains traceable to a working capability, current evidence, explicit limits, and the Human owner who accepted it.
Name the Exact Task
Describe what the system does, for whom, with which inputs, and under which operating conditions. “Completed a bounded task” is stronger than “uses advanced AI.”
Preserve the Test Record
Keep the date, system version, evaluated cases, result, failures, and reviewer. One successful demonstration cannot support a universal promise.
State What the Claim Excludes
Record required Human review, unsupported cases, prohibited uses, data assumptions, consent conditions, and any consequence the system cannot own.
Name the Responsible Person
Someone with authority should accept the evidence and the wording. A model, vendor, or agency cannot own your organization's public promise.
Define When the Claim Expires
Price, model, prompt, data, policy, integration, or workflow changes may invalidate yesterday's evidence. Name the change that forces review.
This map is intentionally small. NIST's voluntary AI Risk Management Framework Playbook suggests much broader documentation, including business justification, scope, risks, limitations, testing, dependencies, monitoring, and delegated authority.3 A small business does not need to reproduce an enterprise governance office to learn from that discipline. It can begin by keeping one important sentence attached to one inspectable receipt.
Run the Ten-Minute Claim Check
Before approving AI product copy, ask five questions in the room where product, operations, and marketing can answer together:
- What exact behavior does this sentence promise? Replace broad capability language with the bounded task a customer will experience.
- Which current evidence supports every material word? Open the test record; do not rely on memory, a slide, or a vendor adjective.
- What reasonable impression could a customer take beyond the evidence? Add the boundary before an omitted qualifier becomes the real message.
- Who accepts the claim and its consequences? Record the person, decision date, and unresolved disagreement.
- What change makes this receipt stale? Connect the claim to monitoring and a withdrawal or rewrite trigger.
Prefer a Narrow Truth to a Larger Impression
Consider a synthetic example. A payroll assistant flags anomalies in uploaded reports, but a person reviews the findings and approves payroll. “Eliminates payroll errors” exceeds the described evidence. “Flags defined payroll anomalies for staff review” is narrower, testable, and clearer about who owns the final decision.
The second sentence may feel less dramatic. It gives the product team a better target, the customer a more accurate expectation, and the business a claim it can monitor. Precision is not timid marketing when the precision describes real value.

The difference is not confidence of tone. It is whether the public statement can be traced through capability, evidence, boundaries, and accountable acceptance.
What the Receipt Does Not Prove
A completed Claim Receipt does not establish legal compliance, eliminate privacy or security obligations, prove that evidence represents every user, or guarantee that the system will behave the same tomorrow. Higher-risk work needs proportionately deeper testing, qualified professional review, monitoring, incident response, and recourse. This Field Note is an operating tool, not legal advice.
Its value is practical: when the claim, evidence, boundary, owner, and recheck condition travel together, the organization can correct a statement before customers are asked to trust it. The receipt does not make the claim true; it makes unsupported confidence easier to detect.
Choose Your Most Consequential AI Sentence.
Build its five-part receipt with product, operations, marketing, and the person who owns the consequence. If the evidence cannot support the wording, change the wording or change the system.
Research Record
References and Evidence
Sources were reviewed again on September 3, 2026. The FTC description is attributed as the agency's account of allegations and finalized consent orders. NIST's Zero Draft is labeled as an initial proposal; its AI RMF Playbook is voluntary guidance. The Claim Receipt and payroll example are my operating model and a synthetic illustration, not measured VerShep customer results, legal advice, or an independently validated standard.
- FTC Finalizes Orders with Cox Media Group, Two Other Firms Settling Charges They Deceived Customers About an AI-Powered Marketing ServiceGovernment Enforcement Record · Federal Trade Commission; August 27, 2026
The FTC states that it finalized three consent orders resolving allegations about claims concerning an AI-powered active-listening advertising service, voice data, consent, and geographic targeting. The orders and agency account concern the named parties and claims; they do not establish that every inaccurate AI description produces the same legal result.
- NIST's AI Standards Zero Drafts Pilot ProjectInitial Government Standards Draft · National Institute of Standards and Technology; July 30, 2026
NIST identifies this as an initial public draft about model and dataset documentation for public consumption. The related pilot page says the document is a NIST proposal that may change through input and formal standardization; it is not a binding rule or final consensus standard.
- AI Risk Management Framework Playbook: GovernVoluntary Government Guidance · NIST AI Resource Center; accessed September 3, 2026
The voluntary playbook suggests documenting business justification, scope and use, risks, assumptions, limitations, testing, dependencies, monitoring, and delegated authority. The AI Claim Receipt is my smaller operating interpretation; NIST does not endorse this model or VerShep.