The DoorDash AI Photo Problem: TODAY.com Surfaces a Consumer-Trust Risk Just as Merchants Get AI Tools

Smartphone with a food delivery app showing a burger photo and a refund request screen open.

DoorDash launched AI photo tools for merchants on April 9 — and within weeks, X users were posting AI-edited burgers to claim refunds. The vendor case for AI photography is colliding with the consumer-fraud case faster than DoorDash's risk team can deploy detection.

It was a slow Friday afternoon in the office — the kind of mid-April day where the conference calendar finally exhales, Restaurants Leadership Conference wrapped two days ago, and the only thing on my screen should have been the Chipotle Q1 preview I owe my editor by Tuesday. Instead I was watching an X post from a user with the handle King_Sukunaaa, dated April 4, that has now cleared a million views. The video, if you haven’t seen it, is genuinely funny in a bleak way: a perfectly normal-looking burger arrives in a DoorDash bag, the user runs the photo through a consumer AI image editor, adds a small foreign object that I’m not going to describe in print, and submits the doctored photo to the DoorDash refund flow. The refund clears. The caption is, essentially, too easy.

I closed that tab. I opened the next one in the queue. It was a DoorDash press release from April 9 — five days after King_Sukunaaa’s post — announcing a new suite of AI merchant tools, including AI-generated item descriptions and, more pointedly, AI photo generation for menu items. The pitch to operators is clean: better photos lift conversion, AI lowers the cost of getting them, the platform helps you compete.

I’ll be honest. I read the two tabs back to back and the only thought I had was: the trust-and-safety cost of consumer-grade AI imaging is being externalized to platforms, and the cost line is going to show up in DoorDash’s chargeback and refund metrics by the end of Q2.

That’s the Bottom Line take, and the rest of this column is me showing my work.

What the viral exploit actually showed

TODAY.com surfaced the broader pattern this week in a piece by their food desk (today.com), and Cybernews followed with a more technical write-up (cybernews.com) on the deepfake mechanics involved. Both stories converge on the same uncomfortable observation: the tooling needed to fake a “my food arrived wrong” photo has dropped below the friction threshold of the refund flow itself.

Three years ago, doctoring a food-delivery photo convincingly required either Photoshop skills or a willingness to actually ruin your own food for the camera. Today, it requires a phone, a free-tier AI editor, and about ninety seconds. The marginal cost of producing a fraudulent refund claim has collapsed. The marginal benefit — a free meal, or sometimes a full refund credited back to a card — has not.

This is a classic asymmetric-fraud setup. When the cost to commit fraud falls faster than the cost to detect it, you get a volume problem. And in delivery, the detection side has historically leaned on photo evidence as the primary trust signal. Customer says the food arrived wrong, customer uploads a photo, the photo is the evidence, the refund clears. That entire workflow was built in an era when faking the photo was the hard part.

The viral King_Sukunaaa post isn’t notable because it’s clever. It’s notable because it’s demonstrative. A million views on a single video means somewhere on the order of tens of thousands of people now know the trick is trivial. My base case is that DoorDash, Uber Eats, and Grubhub are all about to see a measurable spike in disputed-order claims tied to “item quality” or “foreign object” issues over the next eight to twelve weeks, and the second-derivative problem is that legitimate complaints will be harder to adjudicate because the photo evidence is now structurally suspect.

Why DoorDash launching AI photo tools five days later is the timing problem

Here’s where the M&A brain kicks in. I read a lot of platform companies, and one thing I’ve learned is that product launches and risk-team workloads almost never run on the same clock. Product ships when product is ready. Risk catches up when the damage is visible in a dashboard. The gap between those two is where shareholder pain lives.

DoorDash’s April 9 launch of AI photo generation for merchants is, on its own merits, a reasonable product. Smaller operators undersell themselves with bad phone photos. A generative tool that produces a clean, brand-consistent menu image lowers the barrier and probably does lift conversion at the long tail of the merchant base. I have no quarrel with the vendor case.

The timing case is the problem. DoorDash launched merchant-side AI imaging in the same fortnight that a viral consumer-side AI imaging exploit demonstrated the trust-and-safety blast radius of exactly this technology class. The merchant photos and the fraud photos are produced by structurally similar pipelines. The platform is now, simultaneously, publishing AI-generated food imagery at the top of the funnel and adjudicating AI-generated food imagery at the bottom. Those two activities create competing institutional incentives within the same company.

If you’re the merchant-acquisition team, you want the AI photo tool to look frictionless and trustworthy. If you’re the trust-and-safety team, you want every AI-generated food photo on the platform flagged, hashed, and cross-referenced. Those teams are going to fight, and they’re going to fight in front of a board that has to explain refund-cost-of-revenue trends on the next earnings call.

My base case is that the trust-and-safety team wins the internal fight, but slowly, and the cost shows up in the meantime. Specifically: I’d expect DoorDash to add some form of provenance signaling or AI-detection layer to the refund-photo workflow within the next two quarters, probably announced quietly as a “trust update” rather than a feature launch. In a later piece on operator-side guest trust we’ll get into the broader frame, but the short version is that the platforms are about to discover the hospitality industry’s oldest lesson: trust infrastructure is expensive to build and cheap to lose.

Where the cost line will appear in the financials

I’m not going to invent a refund-loss number for DoorDash. I don’t have one, and the numbers floating around social media right now are guesses dressed up as reporting. What I can do is point to the line items where a sophisticated reader should be watching.

The first line is cost of revenue. Delivery platforms typically absorb refund costs in one of two places — either the merchant eats it (which damages merchant retention) or the platform eats it (which compresses contribution margin per order). DoorDash has historically tried to split the difference, but the split tilts toward the platform when fraud is suspected on the customer side. If consumer-AI fraud volumes rise, expect either margin pressure on cost of revenue or a quiet shift in policy that pushes more chargebacks back onto restaurants. Either outcome is observable.

The second line is the dispute and chargeback ratio reported to card networks. This one’s less visible but more telling. Card networks track dispute rates by merchant of record, and when they cross thresholds, the merchant pays higher interchange and faces remediation programs. Delivery platforms are unusually exposed here because they’re the merchant of record for a high-volume, low-ticket transaction stream with weak post-delivery verification. A modest uptick in AI-driven refund claims can move the network-level dispute ratio meaningfully.

The third line — and this is the one I’ll be watching on the May earnings cycle — is contribution profit per order. DoorDash reports this metric, and it’s sensitive to exactly the kind of one-off claim costs that fraudulent refund pushes generate. I’d be surprised if April-quarter contribution profit moves visibly on this issue (the timing is too tight), but the back half of Q2 is where I’d expect to see the first echo.

As our later DoorDash/SevenRooms coverage frames it, the deal logic on the platform side is increasingly about end-to-end guest data, and end-to-end guest data only works if the trust layer underneath holds. AI-generated refund photos are an attack on that trust layer.

What an operator should do about menu photography this week

This column normally writes for the public-market analyst reader, but I get enough notes from restaurant operators that I want to land a practical section here too.

If you’re running a multi-unit restaurant on DoorDash, three things change for you in the next ninety days.

One — your refund-dispute workload is going up, and the photo evidence you used to rely on is going to get noisier. Make sure your store-level managers are documenting outbound order quality more aggressively. A clean photo of the bagged order at handoff, tied to the order ID, is the single best counter-evidence you can produce when a refund claim looks suspicious. This is operationally annoying but it’s the cheapest insurance available.

Two — if you’ve been considering the platform’s AI-generated menu photos, my honest read is not this quarter. Not because the tool is bad, but because the brand-association risk of having AI-generated imagery on your listing during a news cycle about AI imagery fraud is asymmetric. Use real photography for the next two quarters. The lift you’d get from AI photos isn’t worth the headline risk.

Three — push your platform account manager on what DoorDash’s chargeback-protection policy looks like for the next two quarters. If the platform is going to externalize fraud costs to merchants, you want that conversation in writing now, not after the policy ships. Multi-unit operators have leverage on this; independents don’t, which is its own structural problem.

The bigger picture is that consumer-grade AI tooling has crossed a threshold where the trust assumptions baked into every consumer platform built between 2010 and 2023 need to be re-examined. Food delivery is the visible edge case this month. It won’t be the last.

— Marcus writes The Bottom Line. Tips: [email protected].

Featured More

The Voice Agent Maturity Curve

mise

·

12 min read

The Four Margins of a Restaurant

mise

·

14 min read

The AI Premium in Hospitality M&A: Broker Story or Real Number?

the bottom line

·

9 min read

What the DoorDash/SevenRooms Deal Actually Buys

the bottom line

·

11 min read

Browse all 494 posts

Related posts

Darden trades like a tech company. It shouldn't.

the bottom line

·

11 min read

Darden trades like a tech company. It shouldn't.

Applebee's just became its own franchisee. The territory math is the trade.

the bottom line

·

12 min read

Applebee's just became its own franchisee. The territory math is the trade.

FAT Brands has to sell. Here's what the AI premium does (and doesn't) buy a multi-brand QSR.

the bottom line

·

12 min read

FAT Brands has to sell. Here's what the AI premium does (and doesn't) buy a multi-brand QSR.