Services Approach Who We Work With About Insights Connect With Us

Insights  ·  Food Regulation & AI Governance

Generally Recognized as Safe

Food's most embarrassing loophole turns out to be more careful than most companies' entire AI approval process.

From the GreenfieldTable insights desk  ·  Self-approval as unpriced risk.

A franchisee is suing Pizza Hut's parent company for $100M over an AI tool that got approved faster than a new pizza topping. That is not a joke about corporate speed. It is the actual timeline.

Versions of it are running quietly in food and hospitality companies right now, not just in delivery apps.

The Weaker System

There is a phrase in food regulation that sounds more harmless than it actually is. Self-affirmed GRAS. For decades, it has let a company decide, on its own, that a new ingredient is safe. Its own scientists, its own documentation, its own panel. No requirement to notify the FDA. No public record. Just an internal yes.

A March 2026 investigation found more than 100 food chemicals on American shelves that have never been reviewed by anyone outside the company that introduced them. Congress has noticed. Rep. Lawler has a bill in the House. Sen. Marshall has one in the Senate. New York passed its own version in April, banning three ingredients outright and building a public database for every self-affirmed substance sold in the state.

Whether the FDA's own rule survives is genuinely unclear. Legal scholars are already questioning whether the agency has the authority to finalize it. But the direction is set. If any version becomes law, companies get roughly two years to revisit every ingredient they ever cleared themselves and prove it still holds up.

Here is the part nobody in that debate says out loud. Self-affirmed GRAS is a weak process. It is private, slow, and widely considered too thin. But it is a process. A company has to convene a panel of credentialed scientists. It has to produce a documented safety file. Someone has to attest to the decision.

Compare that to how most companies approve AI output today. In most cases there is no panel, no file, and no accountable owner with the authority to say no. AI has become the only system in the enterprise that can go live without a gatekeeper.

AI has become the only system in the enterprise that can go live without a gatekeeper.

The Hard Way

Starbucks Korea found out exactly what that costs. An AI system wrote a tumbler promotion called Tank Day, launched on the anniversary of the Gwangju Uprising, a date every person in the country recognizes instantly. Seven executives signed off without even opening the file. No panel, no credentialed reviewer, no documented process stood between that slogan and 2,000+ stores.

Card payment volumes fell 26% in one week. The company closed more than 2,000 stores early, nationwide, for a single day of mandatory training. The CEO was fired. The chairman apologized on live television. Shinsegae Group called the misstep unintentional. The file did not go unread by accident. Someone decided it was not worth opening. The loophole everyone wants closed for ingredients had more rigor behind it than the process that just cost a CEO his job.

The loophole everyone wants closed for ingredients had more rigor behind it than the process that just cost a CEO his job.

Pizza Hut's parent company learned the same lesson more slowly and at a much higher price. It rolled out an AI dispatch tool called Dragontail, approved inside the same system that built it, with no external operational check on what it would actually incentivize. The tool ended up giving DoorDash drivers visibility into kitchen timing and tip size. Drivers did the rational thing with that information. They batched the high-tip orders and let the rest sit.

Delivery times rose from 30 to 45 minutes, according to the complaint. The franchisee, running more than 100 stores, is now suing for $100M, alleging the tool never delivered the efficiency it was bought to produce. The complaint says the franchisee asked Pizza Hut for support and asked the company to reconsider the rollout. Pizza Hut required them to keep using it anyway. But the lawsuit is not the expensive part. The expensive part is the line hiding inside the complaint. Nobody ever verified whether Dragontail was working before it blew up, not in the calm months, not when the dashboard numbers still looked fine. The franchisee did not discover a broken tool. They discovered a tool nobody had ever reconciled against the business case it was sold on.

The franchisee did not discover a broken tool. They discovered a tool nobody had ever reconciled against the business case it was sold on.

The Real Cost

That pattern does not stay contained to delivery routing, and a CFO does not have to look far to find the same gap sitting somewhere much quieter in the business.

Start with dynamic pricing. A Consumer Reports investigation in late 2025 found that AI pricing tools were letting retailers charge different customers different prices for the same item, in the same store, on the same day. Instacart halted its AI-driven pricing experiments days before 2026 began. The tool was not flagged internally. It was flagged by journalists.

Next, labor scheduling. Fleet management vendor NetworkON estimates automated scheduling can save 10 to 15% on labor cost, and Walmart has reported an actual 15% reduction in labor costs after deploying AI-driven scheduling. Those numbers are what justify the purchase. Almost nobody ever goes back a year later to reconcile delivered results against that range.

Third, delivery and dispatch integrations, the same category that just cost Pizza Hut's franchisee nine figures. Any tool that hands routing, pricing, or timing data to a third-party platform also hands that platform's users a new set of incentives. Nobody has to intend harm for the incentives to shift and for that to go sideways. It only has to go unchecked.

Three different tools, three different functions, yet one identical control gap. A promise gets made at purchase. Nobody ever circles back to test it against reality once the tool is running quietly in the background.

The Exposure Math

Here is a simple way to size it. Take your company's total annual spend across AI tools touching pricing, scheduling, and dispatch. Multiply it by the share of that spend that has never been reconciled against the business case that justified the purchase in the first place. Whatever figure comes out is not hypothetical at all. It is your unmeasured exposure, sitting on the books right now, not stolen and not lost, simply never verified. If you cannot estimate that share with any confidence, that uncertainty is already the finding worth bringing to your board.

To be fair to the comparison, these are not identical failures. GRAS is a missing regulator. Tank Day and Dragontail are a missing internal reviewer. But both come from the same instinct, essentially letting the party with the most incentive to say yes be the only party allowed to decide.

Most CFOs would instantly fire a controller who approved their own expense report. Most of those same CFOs have never bothered to ask who approved the AI tool currently setting their prices.

The Homework

Food already has a quiet version of the discipline this requires. It is called GRAS review, and much of the industry still considers it too thin. That should be the tell. A private, self-graded safety process that at least makes someone attest to the outcome is currently more rigorous than what most companies apply to an AI-generated decision. The AI process is not the frontier problem anymore. It is the more primitive one.

Most AI right now gets approved the exact same way GRAS works, informally, without anyone calling it that. Someone inside the company looked at it and generally recognized it as safe enough to ship. Same casual standard, none of the actual paperwork GRAS requires, a credentialed panel, a documented file, someone willing to attest to the decision.

Pull the three tools in your stack that touch pricing, scheduling, and delivery or dispatch. For each one, ask two questions before anyone renews it. Who actually has the authority to say no to this, separate from whoever built or bought it. And has anyone actually reconciled the delivered result against the business case, not the number assumed.

Ask both questions before the next renewal goes through.

We already accepted that food gets approved this way, no outside review, just an internal yes. Now the same standard is running business decisions with less scrutiny than groceries get. When an AI decision goes live without an independent reviewer or any reconciliation against promised value, the risk does not show up as an incident. It shows up quietly on the balance sheet.

← Back to Insights Connect With Us