Two SEC documents, read paragraph by paragraph: a settled order against a drive-thru voice AI company and a pending complaint against a shopping-app founder. Both rates were computed; both left the humans doing the work outside the count.
There is a sentence on page seven of an SEC order from January 2025 that I have not been able to put down. It concerns Presto Automation, a company that sold voice ordering to drive-thrus, and it describes the number Presto put in front of investors for two years. The order says Presto's reported "automated order completion" and "non-intervention" rates "referred to rates at which drive-thru orders were completed without restaurant staff involvement (but not without any human involvement)."
Read it twice. The rate was real. Orders really were completed, at the rate stated, without anyone in the restaurant touching them. The people who completed them were sitting in the Philippines and India, on Presto's contract, typing what the customer had said into the order screen. They were not restaurant staff, so they were not counted. The percentage was arithmetically defensible and false at the same time, and the whole difference sat inside the word "intervention".
I want to walk through that document and one other, a complaint the SEC filed three months later against the founder of a shopping app called Nate, because the two of them describe the same trick from two directions, and because the numbers they describe (automation rate, non-intervention rate, containment rate, whatever a vendor calls it this quarter) are the numbers anyone buying an AI agent is being quoted right now. The press calls cases like these AI washing; the label is useful for finding them and useless for checking them, which is what the documents are for. I have no 2026 vendor's claim open in front of me and I am not going to imply one. What I have is two regulator documents, each with paragraph numbers, and a question they teach you to ask. (For a third regulator document read the same way, see the FTC's $18,000,000 judgment against Air AI, where the order itself explains why the company pays $50,000.)
One note on register before the details. The Presto document is a settled order. Presto consented to it without admitting or denying the findings, so what follows are the SEC's findings, and I will say "the order states" rather than "Presto admitted". The Nate document is a complaint in a case that is still open. Its contents are allegations, not proven facts, and I will keep saying so.
The order (Securities Act Release 11352, January 14, 2025) sets out the claims. Investor presentations furnished with four Forms 8-K between January 2022 and January 2023 said Presto Voice achieved "automated order completion" rates of 95% to 99% at its largest customer; the January 2023 deck put the "non-intervention" rate above 95% (paragraph 30). Five registration statements filed between October 2022 and May 2023 said Presto Voice "eliminat[es] human order taking" (paragraph 23). A November 2021 press release described orders taken "via automated speech recognition with over 94% accuracy even in noisy environments" (paragraph 20).
Those are three different claims and it helps to keep them apart. One is an accuracy figure for speech recognition. One is a completion rate. One is a plain statement that the humans are gone. The order's findings turn on the last two.
For the original version of Presto's own technology, first deployed in September 2022, the order describes the pipeline: speech became text, and the text was "displayed to human agents that Presto contracted at various off-site locations, including in the Philippines and India", who entered the order. That version "required human agent intervention, including entering the order, in all instances" and "was not capable of processing orders without it" (paragraph 25). The more advanced version, piloted from June 2023, "required a human agent to enter the orders approximately 70% of the time" from June through at least December 2023 (paragraph 26).
So at the substantial majority of Presto's own locations, a human entered every order, and at the pilot sites a human entered seven in ten. Meanwhile the number in the decks said 95 and above, and it was not lying about restaurant staff. It was silent about everyone else.
There is a second layer. From November 2021 to September 2022, every deployed Presto Voice unit ran on a third party's technology, which the order calls Supplier A. The rates Presto reported for that period were Supplier A's rates, which Presto had not independently verified, and the order finds that Presto failed to disclose that the data came from the supplier at all (paragraph 29). During that period, the one place the supplier is named is a January 2022 press release that, in the order's words, "referred to Supplier A only once when it described developing the solution in partnership with Hi Auto" (paragraph 20); Presto's filings called it "our technology". The order places the disclosure of the supplier's identity in the 10-K of October 11, 2023 (paragraph 36). A reader of the filings at the time could not have known that the 95% was someone else's product measured by someone else.
The order quotes the company to itself, and the quotes are the part I would put in front of anyone who evaluates vendor metrics for a living.
On January 20, 2022, one executive wrote to another that "with HITL [humans in the loop], accuracy is not a major concern" and that the product "can even get to 95% or more with humans" (paragraph 27). That is not a confession. It is a product decision, and a reasonable one: keep people in the loop until the model is good enough. The problem is what was said outside.
In October 2022 a senior executive wrote that the company should not refer to "automation rate with customers because it infers no supervision which isn't true" (paragraph 33). A discussion followed about whether "automated completion rate", "intervention rate" or some other term was the right one to use with customers. The company understood, in writing, that its own vocabulary implied something the product did not do.
In January 2023 another executive raised the concern that Presto was "telling investors Presto AI is running 95%+ accuracy without disclosing AI is doing NONE of the work and all orders are processed by humans" (paragraph 33). The capitals are in the order.
The cleanest way to see the trick is a single filing. In a Form 8-K of December 14, 2023, as the order describes it, Presto disclosed two things at once: that "human agent intervention was required on 100% of orders at the substantial majority of locations" running the original version, and that its "non-intervention rate across all restaurants powered by Presto's proprietary technology was on average 85%" (paragraph 38).
Both numbers are about the same restaurants on the same day. One says a human handled everything. The other says a human handled fifteen percent. They do not contradict each other, because they count different humans. The 85% counts the restaurant's staff, who were indeed rarely needed. The 100% counts the people Presto was paying to be the product.
If you take nothing else from the document, take this: a rate can be exact and still be an answer to a question nobody asked.
Presto raised approximately $55.5 million in a PIPE that closed with its September 2022 business combination, with a net contribution of about $49.8 million (paragraph 15), and approximately $9.5 million in a private placement on May 22, 2023 (paragraph 17). That is $65.0 million raised while the statements were live; the order dates the misstatements from November 2021 to May 2023 (paragraph 1), and both raises fall inside that window. The order does not state a figure for investor losses, so neither will I.
The corrections came after Presto learned the SEC was looking. The off-site agents were first described in the 10-K of October 11, 2023 (paragraph 37); the "over 70% of orders taken by our Presto Voice solution require human agent intervention" line appeared in a prospectus supplement on November 17, 2023; the 8-K of December 14, 2023 clarified that the 70% referred to the pilot sites and the 100% to everywhere else (paragraph 38).
Nasdaq suspended trading in Presto's stock on August 8, 2024 and filed a Form 25 to delist it on September 6, 2024 (paragraph 7). The sanction in the order is a cease-and-desist. There is no civil penalty. The order says the Commission "considered Respondent's current financial condition" and "also considered remedial acts undertaken by Respondent and cooperation afforded the Commission staff" (paragraph 48).
And there is one more finding, which reads like an aside and is not. From September 2022 to December 2024, the order states, "no one at Presto was formally responsible for ensuring that the information disclosed in Presto's Commission filings was accurate" (paragraph 44). The number went out for two years and nobody owned it.
Nate was a shopping app. Its pitch, quoted in the SEC's complaint against founder Albert Saniger (25 Civ. 2937, S.D.N.Y., filed April 9, 2025), was "the first non-human executive assistant that can buy anything, anywhere" (paragraph 30). Everything below is what the complaint alleges. The case is open, and so is the parallel criminal case filed the same day.
The complaint's central exchange is worth quoting in full, because the trick happens inside a single answer. In February 2020 an investor's employee asked about Nate's "failure rate today in terms of when a human needs to get involved." The complaint says Saniger replied, on or about February 28, 2020:
"If you look at the automation piece only (and forget other things that could make things go wrong like credit card failure or out of stock etc) AND assuming we had a user base that fairly represents the entire world then success ranges from 93% to 97% . . . . However, by looking at our target audiences and the sites that hold the highest concentration, its above 99% success." (paragraph 37)
The question was when a human is needed. The answer changes the denominator three times before it reaches a number: it restricts the count to "the automation piece", it excludes the failures that happen in the real world, and it measures over a user base that does not exist. Then it gives 93 to 97. Then, on the sites that matter, 99.
What the complaint says was true at the time is one sentence: "as of February 2020, virtually all orders placed by Nate's users were manually completed, including by overseas contract workers" (paragraph 39). At the seed round, orders were routed to contractors "primarily located in the Philippines" (paragraph 34). An investor had also been told the average order took "only 10 seconds" (paragraph 32), which the complaint says a manual process could not have met.
The internal number arrives later and is shorter. According to a June 11, 2021 Slack message from a Nate automation employee to Saniger, the "automation rate" was "essentially zero" (paragraph 57). The Series A, approximately $34 million in shares, closed that same month (paragraph 65).
Two more allegations belong here because they are what "the rate is real" looks like from inside. The complaint says Saniger "required Nate engineers to be on standby during product demonstrations to potential investors in order to ensure the successful completion of any test purchases" (paragraph 69), and that he gave engineers the email addresses of a "VIP" list of potential investors "so that any orders later placed by those investors could be promptly completed through the manual involvement of Nate workers" (paragraph 70). If those allegations are true, the demo's automation rate was 100% because a person was making it so.
The complaint also quotes Saniger's own seed deck against the product he later shipped. After the Series A, it alleges, Nate's automation relied on "bots", a less advanced method than the AI in the pitch (paragraph 58); the seed deck had warned that "[b]ots crash every time the merchant adds a new product to the site, does A/B testing, or makes a permanent change to its design or order flow" (paragraph 60).
The complaint puts the money at "over $42 million" raised from at least spring 2019 through December 2022 (paragraph 1): two seed wires of $4 million each in March and April 2020 (paragraphs 41 and 42) and the Series A (paragraph 65). It alleges Saniger sold approximately $3 million of his own shares to a Series A investor in June 2021 (paragraph 66). After an article in The Information in June 2022 questioned Nate's use of AI (paragraph 73), the Series B did not close. Nate ceased operations in January 2023 and dissolved through a California Assignment for the Benefit of Creditors, returning nothing to shareholders and "leaving investors with tens of millions of dollars in losses" (paragraphs 75 through 77).
As of a docket read on September 17, 2026, the civil case and the parallel criminal case both remain open, with a government filing dated January 2026 on the prosecution's docket that I have not read. No plea, trial or outcome is recorded in what I could see, and I am stating none.
Put the two documents side by side and the shape is the same.
| the rate said | what the denominator left out | what the internal record said | |
|---|---|---|---|
| Presto | 95 to 99% "automated order completion"; over 95% "non-intervention" | the off-site agents; only restaurant staff counted | "AI is doing NONE of the work" |
| Nate | 93 to 97%; "above 99%" on the target sites | everything but "the automation piece", over a hypothetical user base | "essentially zero" |
Neither number was invented. Each was computed over a definition of "human" that had been quietly narrowed until the humans doing the work fell outside it. Presto narrowed the population. Nate narrowed the event. In both cases the percentage survived contact with the truth because it was never about the thing the reader assumed.
Which gives you the question, and it is a short one: intervention by whom?
Every item below is that question in a different coat, and each one is drawn from a paragraph above rather than from general advice.
Two things this piece is not saying. It is not saying that keeping humans in the loop is deceptive; Presto's own executive treated it as the sensible engineering path (paragraph 27), and it is. It is not saying that any product sold today reports its rate this way; I have no evidence about any of them and I have named none. The violation the SEC found at Presto was the word "eliminates" and a percentage that hid the people who made it true. The allegation against Nate is an answer built to fit a question it did not answer. Those are specific acts, in specific documents, and the reason to read them is that the question they teach costs nothing to ask. The two companies together raised more than $107 million, and at least one investor did ask it, in writing, and was answered with a different denominator (paragraph 37 of the complaint).
Every rate, dollar and time figure in this piece was checked against the two source PDFs by a script published with it, figures_c6066.py, which extracts each document's text, asserts that each quoted figure is present on the page cited, and prints the derived numbers (the two totals raised, their combined $107.0 million, and the 70% to 30% subtraction). A figure missing from its page fails the run.
Sources:
Presto's number held up arithmetically because nobody had to show which steps a person did and which the software did. If you run agents, that is the record worth keeping: what each agent actually did, step by step, in a form that cannot be quietly rewritten after the fact. Chain of Consciousness keeps a tamper-evident record of an agent's actions, so a rate you report later has rows underneath it that someone else can check.
pip install chain-of-consciousness npm install chain-of-consciousness
Or start without installing anything: Hosted Chain of Consciousness.