Move Fast & Fabricate Things: What the Delve Scandal Should Teach Us About Regulating Silicon Valley’s Optimization Problem

Adithi Kadle

Delve had all the trappings of a bona fide Silicon Valley success story. It is also, it turns out, a revealing one: Iits rise and apparent unraveling offer a case study in how the industry’s pursuit of speed and scale incentivize corner-cutting behaviors. 

Its founders, Karun Kaushik (CEO) and Selin Kocalar (COO), started the company while freshmen at MIT before dropping out in their sophomore year to launch a YC-backed “AI-native compliance platform” that promised to automate the slow, tedious process of regulatory paperwork. The startup repeatedly made headlines, first raising a $3 million seed round and then, led by global venture capital firm Insight Partners, closing a $32 million Series A at a $300 million valuation in July 2025. Within a year, Kocalar reported that Delve had acquired over 1,000 customers in 50 countries and had helped clients land nine-figure deals.

Yet, this premise seemed to fall apart following a viral 10,000-word bombshell report published March 18, 2026 on Substack alleging Delve had fabricated evidence of board meetings and security audits, generated auditor conclusions before any review had taken place, and issued unenforced compliance certifications to clients. The anonymous whistleblower behind the post wrote that Delve generated Trust Pages (public-facing webpages showcasing a company’s compliance certifications), claiming that companies were compliant with standards that could not be verified through the company’s platform.  

This is, in a nutshell, the Delve scandal. Delve responded to the allegations in a blog post clarifying that they simply provide “draft templates,” not pre-filled evidence, and that third-party mills like the ones they were accused of using are “used broadly across the industry, including by other compliance platforms.” In early April, the startup was removed from Y Combinator. High-profile clients, including the $6.6 billion vibe coding startup Lovable and $700 million dictation app Wispr Flow, have since released statements distancing themselves. Insight Partners, the startup’s lead investor, scrubbed an article touting their collaboration with Delve before quietly restoring it. A LinkedIn post detailing the investment remains inactive. 

It is tempting to treat the Delve case as a story about one company’s alleged fraud. But, that interpretation fails to address a systemic issue at the heart of Silicon Valley’s AI startup ecosystem: Delve is a product of the move-fast-break-things ethos that has long dictated how tech startups approach their business. 

The phrase is reminiscent of a bygone era of technological optimism, an operational and aesthetic slogan that promised to democratize the information economy, undermine authoritarian leaders, and discard outdated systems to usher in something greater. In practice, it has come to mean an ecosystem where entrepreneurs are incentivized to compress timelines, eliminate friction, and optimize at all costs. In that context, compliance and corporate governance, the process by which companies detail adherence to industry standards like HIPAA, GDPR, and SOC 2, appears as a hindrance rather than a safeguard. Compliance is a requirement for any startup hoping to handle consumer data or land major contracts, and it is also, as Delve correctly identified, genuinely slow. Traditional processes involve months of evidence compilation, security audits, and multi-stage authentication before attestation is issued. Delve’s promise of compressing this timeline from months to days, while appealing, is a fundamental misunderstanding of compliance. 

Regulatory compliance is time-consuming and litigious. While obstacles like patchwork regulatory standards exist, compliance is burdensome by design. The GDPR was adopted to protect consumers from growing technological overreach and data abuse. HIPAA was created to combat unauthorized access and misuse of sensitive patient information in healthcare. SOC 2 standards were developed in response to major information security breaches. The friction embedded into these frameworks is also the mechanism by which accountability is assigned. Each checkpoint distributes responsibility across actors, from startups to auditors to accounting firms, so that when failures occur, liability can be clearly identified. Delve’s automation enabled the company to collapse this process into one streamlined structure, establishing itself as “both implementer and examiner.”

Moreover, while Delve’s alleged misconduct may be chalked up to a particularly well-funded drop in the bucket, the pattern is undeniable. During the first half of 2025 alone, AI startups accounted for 65 percent of VC capital, and Y Combinator itself has backed more than 5000 startups.  In an environment that optimizes for rapid customer acquisition, oversimplification, and increasingly, (ineffective) AI integration without oversight, we lose the methodological rigor that complex legal processes like compliance require. 

This is not an argument against AI, nor against automation. It is a cautionary tale about what happens when the appearance of innovation becomes the only metric that matters. This optimization problem has massive consequences for both clients and consumers. We must ask: Is simplifying and fragmenting complex processes the best way to understand them? 

The question of liability that the Delve incident raises is still unfolding. When an AI platform generates a fraudulent report, who do we blame? The platform that generated the report? The certification mill that rubber-stamped it? The client who accepted the template without scrutiny, or the venture capitalist who helped legitimize the platform? 

There is a tendency, in moments like this, to call for more stringent regulation. Lawmakers and policy activists alike have highlighted the need to replace parochial standards with clear regulatory guidance on AI growth, across party lines. The EU’s AI Act, the first of its kind, is set to apply starting August 2, 2026 and aims to outline a more comprehensive compliance framework for high-risk AI systems. The future of regulation is unclear, but when the burden is ultimately placed on Delve’s clients who are potentially at risk of criminal liability, it will not be enough. 

What is more difficult to legislate is the internal disposition that made Delve possible. There is a conviction within Silicon Valley, deeply embedded and richly rewarded, that speed is a virtue. The slow parts of a system are, uncritically, the ones to eliminate. Some systems, however, are meant to resist that impulse, and unless we recognize this broader pattern, the Delve story risks being the first in a long list of sequels.

Next
Next

Solving the Youth Voting Gap: Adopting School-Based Voter Education in the Hawai’i Department of Education