180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-133
Consumer AI · United States · 2025 · AI-washing

US prosecutors charged the founder of the shopping app Nate with fraud, alleging the AI that was said to complete purchases on its own was mostly people working in a call centre

By Ellie Harris · Filed DOJ and SEC charges announced 9 April 2025; conduct alleged 2019 to 2022

Alleged: Nate, Inc. developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

US prosecutors charged the founder of the shopping app Nate with fraud, alleging the AI that was said to complete purchases on its own was mostly people working in a call centre

What happened

It was reported that Nate, a shopping app founded in 2018, told users and investors that it used advanced AI to complete online purchases on its own, letting a shopper check out with a single tap. On that claim, the company raised more than 40 million dollars from investors between 2019 and 2022.

In April 2025 the US Department of Justice charged Nate’s founder with securities fraud and wire fraud, and the Securities and Exchange Commission filed a parallel civil complaint. Prosecutors allege that the app’s real rate of automation was close to zero, and that the purchases were completed for the most part by hand, by contractors in a call centre in the Philippines, with simpler bots added over time. The indictment alleges the AI claim was central to drawing investors, because automation implied a scale and profit that visible human labour could not. The founder has pleaded not guilty. The allegations remain unproven, and as of mid-2026 the criminal and civil cases had not been decided.

What an auditable version would have shown

A claim that an app runs on AI can be checked, but only if there is a record of what actually ran. An auditable version keeps, for each transaction, whether it was completed by the model or by a person, and turns that into a signed, honest figure for how much of the work the machine really does. With that record, the rate of automation is a number an investor or a regulator can read. Without it, a company can describe its people as artificial intelligence for years, and the first real audit comes from a prosecutor.

Where the gap was

The gap was simple. The central claim, that the app ran on AI, could not be checked from the outside. Investors and customers had the company’s word for how automated it was, and no way to see what actually completed each order. There was nothing kept at the time that an outsider could point to and say this share was done by a machine and this share by a person.

What governance should have looked like

If you raise money by telling people your product runs on AI, you should be able to prove how much of it actually does, from records kept at the time. That is what a conduct record is: a signed log of who or what finished each order, a model or a person at a desk. A metric record turns that log into a single honest number for how automated the thing really is. With both, a claim like almost fully automated is something an investor can check, not something they have to take on faith.

The reference implementation of ConductRecord and MetricRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Nate, Inc. could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →