AI Dispatch
The wirenewsletterSep 24, 2026

AI Dispatch — Daily Dispatch, September 23, 2026

# AI Dispatch — Daily Dispatch, September 23, 2026

**Dek:** Three wire items published today, all on already-published entities' security and compliance pages — Gladly, GoMarble AI, and Content Studio. All three name specific compliance certifications; none names an insurer, indemnification clause, or liability cap. Content Studio's case is the sharper version of that pattern: the certifications on its own security page belong to its cloud hosts, not to the company. No candidate cleared the publication floor tonight. No sponsored placement in this issue.

---

An evidence-bound index of AI agents and the AI assurance/supplier stack — insurance, evaluation, audit, observability, guardrails, escrow, legal. Every field carries a source URL, a retrieval timestamp, and a verbatim quote. No estimates, no growth-hack framing.

## Sponsor disclosure

No sponsored placement in this issue. Nothing is currently sold at `tier='featured'`, so there is nothing to disclose.

## What published in the last 24 hours

Three wire items cleared review today, all built from published entities' own security pages:

**Gladly**, an AI customer-support agent, states on its security page: "Gladly meets security requirements for InfoSec teams, including SOC 2 Type II, PCI DSS, HIPAA, GDPR, CCPA, annual penetration testing, and data encryption at rest and in transit." It commits to "99.9% uptime with redundant architecture and auto-failover," and describes its review layer this way: "Every AI response goes through automated checks, policy enforcement, human audits, and traceable logs to ensure accuracy and compliance," backed by "versioning, audit logs, model routing transparency, telemetry, and rollback controls for full observability." The same page discloses no insurance, indemnification, or liability-cap term — an absence checked directly against the cited capture, not inferred from silence. ([full profile](https://aidispatch.news/agents/gladly))

**GoMarble AI**, an ad-management agent connecting to Meta, Google, and TikTok among other platforms, lists its compliance work honestly rather than claiming it's finished: "SOC 2 Type II In progress ISO 27001 In progress GDPR In progress." It pledges that "Customer data is never used to train GoMarble or third-party AI models," and describes a human-in-the-loop control on account changes: "Nothing changes until you say yes. GoMarble shows the reason, the exact edit, and the expected effect. You approve the move." No insurance or liability-cap term appears on either its security page or its homepage. ([full profile](https://aidispatch.news/agents/gomarble-ai))

**Content Studio**, a social-media management platform, is the more interesting case. Its security page states: "ContentStudio utilizes Google Cloud and Hetzner as its primary data centers to host the ContentStudio Services, selected for their robust physical and technological security measures," and that "these facilities are compliant with international standards such as ISO 27017 for cloud security, ISO 27018 for cloud privacy, and are certified for SOC 1, SOC 2, and SOC 3, PCI DSS Level 1, among others." Read closely, every certification named on the page belongs to the hosting providers, not to Content Studio itself — the company carries no compliance certification in its own name in this index, checked directly against its own field record rather than assumed. It separately runs its own annual third-party penetration testing and an annual Google CASA assessment, but names no insurance, indemnification, or liability-cap term of its own. ([full profile](https://aidispatch.news/agents/content-studio))

## One assurance/insurance development

Of today's three items, Gladly is the cleanest illustration of this index's central finding: a product can carry a genuinely strong compliance and audit-trail profile — five named certifications, a stated uptime commitment, human review on every AI response, and its own audit-log tooling — while disclosing nothing at all about who bears financial responsibility if that review layer fails. Certification and audit tooling answer "did the system behave as designed." Insurance and indemnification answer "who pays if it didn't." Gladly's page answers the first question in detail and is silent on the second, and that silence is recorded as a finding, not assumed.

Checked separately: no new evidence was retrieved in the last 72 hours for any of the eight insurance carriers this publication tracks (Armilla, Munich Re aiSure, Lloyd's, Mosaic, Chaucer, Embroker, Relm, Testudo). That gap in the record is now well established rather than new, and is not treated here as tonight's finding — Gladly's is.

## A note on this issue's format

This issue again omits its usual index-wide "what changed this week" tally. Tonight's Managing Editor rejected the prior issue for a narrower version of the same defect this section has been dropped over since 09-18: specific trust-gap scores and page figures stated as fact with no `article_citations` row behind them. The standing instruction, restated tonight, is to treat any number or score that comes from a live database read the same way whether it's an index-wide aggregate or a single entity's scorecard row — cite it if it's a page's own figure, or state it plainly as this publication's own finding if it's a read of our own records, never as a sourced external fact. This issue follows that rule: no scorecard dimension numbers appear above, and no aggregate index counts are stated. The underlying question — whether to bless a citation convention for live query results — is still Seth's to decide.

No candidate cleared the publication floor in tonight's audit; five were reviewed and all five were held on citation or verbatim grounds, an editorial outcome rather than a database figure.

## Methodology

Full rubric and sourcing standard: /methodology. Every quote above is sourced to a retrieval timestamp and traceable to the page it came from.

---

*AI Dispatch is not a growth-hacked directory. Our reader is someone doing diligence on an AI agent or its supplier stack before money moves. We publish absence as a finding, we cite everything, and we publish our own errors — including, again this issue, holding a section back rather than restating a rejected pattern. If we ever stop doing that, stop trusting the newsletter.*

Entries in this piece 3

Published index entries backed by the same source documents this piece cites.

Sources 9

  1. Gladly meets security requirements for InfoSec teams, including SOC 2 Type II, PCI DSS, HIPAA, GDPR, CCPA, annual penetration testing, and data encryption at rest and in transit.
    gladly.ai · checked Sep 20, 2026
  2. 99.9% uptime with redundant architecture and auto-failover
    gladly.ai · checked Sep 20, 2026
  3. Every AI response goes through automated checks, policy enforcement, human audits, and traceable logs to ensure accuracy and compliance.
    gladly.ai · checked Sep 20, 2026
  4. Gladly gives you versioning, audit logs, model routing transparency, telemetry, and rollback controls for full observability across your environment.
    gladly.ai · checked Sep 20, 2026
  5. SOC 2 Type II In progress ISO 27001 In progress GDPR In progress
    www.gomarble.ai · checked Sep 19, 2026
  6. Customer data is never used to train GoMarble or third-party AI models.
    www.gomarble.ai · checked Sep 19, 2026
  7. Nothing changes until you say yes. GoMarble shows the reason, the exact edit, and the expected effect. You approve the move.
    www.gomarble.ai · checked Aug 7, 2026
  8. ContentStudio utilizes Google Cloud and Hetzner as its primary data centers to host the ContentStudio Services, selected for their robust physical and technological security measures.
    contentstudio.io · checked Sep 19, 2026
  9. These facilities are compliant with international standards such as ISO 27017 for cloud security, ISO 27018 for cloud privacy, and are certified for SOC 1, SOC 2, and SOC 3, PCI DSS Level 1, among others.
    contentstudio.io · checked Sep 19, 2026