"Use AI tools to get ahead of your competition." That line shows up in every vendor deck and every trade show floor pitch. It sounds right. It is not. When a buyer has no way to verify what an AI tool does before signing, the tool does not need to work. It only needs to sound like it works.
In 2023, a Cox Media Group sales rep sat across from a local business owner and asked one question: "Where do you want us to listen?" The product behind that question was a marked-up email list dressed in AI language. The pitch did not land because it was clever. It landed because no one in the room asked for a spec sheet.
What the Product Was
CMG called it "Active Listening." The sales deck said the tool used AI to capture voice data from smart devices. That data would then feed local ad targeting. The company's own site read: "Creepy? Sure. Great for marketing? Definitely." Reps told prospects that voice data made up 40 to 50 percent of the signals in the system.
None of it was real. The FTC filed a complaint in late May 2026, and the settlement tells the whole story. CMG paid $880,000. Two smaller firms, MindSift and 1010 Digital Works, paid $25,000 each, bringing the total to $930,000. The tool had no voice data. It had no listening engine. What it had was email lists bought from data brokers and sold to small businesses at a steep markup.
The Pattern Is a Century Old
The FTC charged these suppliers under a doctrine called "means and instrumentalities" liability. It goes back to 1922, when the FTC charged a company called Winsted Hosiery for labeling garments with false fabric claims. That firm did not sell to end buyers. It sold to retailers. The FTC ruled that giving someone the tools to deceive is itself a violation.
A century later, MindSift and 1010 Digital faced the same charge. They wrote the pitch. They ghostwrote answers for skeptical buyers. They built the script that CMG's reps carried into the room. Even if the listening tool had worked as pitched, the FTC signaled that ambient listening for ad targeting without real consent would still have broken the law. The fraud pattern is over a hundred years old. Only the wrapper changed.
Most people treat this as a trust problem. It is a system problem. CMG runs local TV, radio, and digital ads across the country. Its name carries weight. Small business owners trusted a brand they knew. But trust is not an audit. The vendor built the whole pitch around that gap.
The Markup at Scale
JP Morgan Chase data from late 2025 shows that only 17.7 percent of small businesses have paid for an AI tool. The market is still small. Each bad deal hits harder.
A Builts.ai report from early 2026 found that small business owners spent an average of $2,340 on AI tools in 2025. Roughly 31 percent of those tools went unused within 90 days. Most of the money going into AI tools right now is going in without a spec check. That is not a trust failure. It is a missing step in the buying process.
The Audit
The fix is not to stop buying tools. The fix is to run an audit before you sign. Once that is clear, three moves follow from it.
Move 1: Ask for the data source by name
If a vendor says the tool uses voice data, ask which app, which API, and which consent framework feeds it. If they say "proprietary," ask for a sample output with the source labeled. A tool built on real data can show you where it comes from. A wrapper cannot.
That means sitting with the silence after you ask. Most vendors will not expect the question.
Move 2: Test the geographic claim
If the tool promises local reach, ask for a sample list before you pay. Pull ten names and check whether they are near you or spread across the country. CMG promised local targeting. Buyers got national lists.
Move 3: Run a 30-day hold
Do not sign an annual deal on the first call. Buy the smallest unit the vendor offers. Measure what it sends against what the pitch said it would send. If the vendor will not sell a small trial, that tells you more than the deck ever will.
What the Audit Shows
Running this for one quarter does something the pitch never did. It turns the sales claim into a test you can score. The gap between what the vendor said the tool does and what it produces becomes a number, not a feeling.
The cost per lead shows up next to a source you already use, so you can compare on the same line. Whether the "AI" part adds signal or just adds price stops being a guess and starts being a line item.
Whether the vendor's team can explain the system in plain terms, or only repeat the sales line, becomes obvious the second time you ask.
At the end of 90 days, ask three things.
→ What moved a number I can trace back to this tool?
→ What looked like progress but left no trace in the pipeline?
→ What friction showed up more than once when I asked for proof?
That is the difference between advice that sounds right and a system that proves itself.
Where You Stand
The sales rep asked, "Where do you want us to listen?" The right response was not an answer. It was a question back. That question is the audit, and that is where the markup dies.
