Somewhere in the last two years, "the AI flagged it" quietly became a stand-in for "we checked." It shows up in incident reports, vendor risk reviews, hiring decisions, and customer refund logs. It sounds like due diligence. In an actual audit, it's closer to a shrug, and regulators have started treating it that way. The Phrase That Doesn't Hold Up "AI approved it" answers a different question than the one auditors, regulators, and courts actually ask. They don't want to know what the system did. They want to know who was accountable for letting it do that, and whether a qualified person reviewed the outcome before it affected a customer, an employee, or a filing. A model output is not a control. A person checking that output, on a defined cadence, with the authority to override it, is a control. Those two things get conflated constantly, and the gap between them is where compliance programs are quietly failing. The Federal Trade Commissi...