← All articles

Practical guide

Should You Tell Customers You Use AI? A Practical Guide to Disclosure

How to decide when to disclose AI use to customers — the contract and platform terms that most often require it, where disclosure matters on trust alone, how to word it, and where the legal questions begin.

Key takeaways

  • Disclosure obligations vary by jurisdiction and industry, and some have moved from proposed to in force during 2026. Treat the rules as a question for qualified professionals; treat the trust decision as yours.
  • Check your contracts and platform terms first. For most small businesses, a client agreement or a marketplace policy is the obligation that actually applies — and reading it costs nothing.
  • The practical test: would this customer feel misled if they found out later? If yes, disclose, regardless of whether any rule requires it.
  • Clearly disclose when a customer is talking to a bot rather than a person, when AI materially informs a decision affecting them, and when they are buying human expertise specifically. Bot-versus-human is the case most likely to be covered by a rule already in force.
  • Genuine human review, with someone accountable for the result, is both the trust answer and a common exception in transparency rules — which makes a review process you can evidence unusually valuable.
  • Disclosure is usually unnecessary for AI-assisted drafting, editing, summarizing, or research where a person reviewed and stands behind the result.
  • Once a customer asks you directly, the decision is already made: answer accurately and say what the human contribution was.
  • Keep the wording plain and non-defensive. Over-explaining suggests there is something to apologize for, and claims you cannot verify turn a routine practice into a misrepresentation.

A customer asks whether their proposal was written by AI. Or you are drafting your website's terms and wondering whether to mention that support replies are AI-assisted.

There are three separate questions here, and mixing them produces bad answers. One is legal: does a law or regulation require you to disclose? One is contractual: does an agreement you have already signed require it? The third is about trust: what happens to this relationship if the customer finds out on their own?

This covers the second and third properly, and marks clearly where the first begins.

Start with the legal boundary

Disclosure requirements for AI use are an active area, and during 2026 several of them stopped being proposals. Depending on where you operate, there may now be binding transparency rules in force rather than pending — so "the law has not caught up yet" is no longer a safe working assumption, and advice written even a year ago may describe a settled question as an open one.

Rules differ by where you operate, what industry you are in, and what the AI is doing. Three patterns recur across the regimes that exist, and they are worth knowing as shapes even though the specifics are not ours to state:

  • Machine-versus-human interactions attract the most consistent obligations. Some regimes require you to say so up front; others only require an honest answer when someone asks.
  • Consequential decisions about people — hiring, credit, insurance, healthcare, lending — attract heavier and more specific duties in nearly every regime.
  • Synthetic or published content is increasingly covered, but human review with a named person accountable for the result is a common carve-out. That is the same distinction this article draws below on trust grounds, which is convenient: doing the operationally sensible thing tends to leave you closer to the rules than not.

This article does not tell you what your obligations are, because that answer depends on facts about your business that a general guide cannot know — including which of these regimes reach you. If you are using AI for anything touching hiring, credit, insurance, healthcare, legal services, or automated decisions that materially affect people, get advice specific to your situation before launch. That is the point where professional guidance is worth its cost.

If you sell into more than one region, ask specifically which rules apply to customers located elsewhere rather than only to where your business sits. That is the question SMEs most often get wrong, because a small team can reach several regimes from one office.

What follows is the contractual question and the trust question. Both are yours to work out, and both matter even where nothing is legally required.

Then check what you have already agreed to

For most small businesses this is where the real obligation lives, and it is the step people skip. You do not need a regulator to create a disclosure duty — you may have signed one already.

Three places to look:

  • Client contracts and master service agreements. Enterprise and public-sector clients increasingly include AI clauses. Some require disclosure or prior approval before AI is used on their work; some prohibit it for certain deliverables; some require that their data never be entered into a third-party AI tool. These clauses are easy to miss because they are often filed under confidentiality or subcontracting rather than under a heading with "AI" in it.
  • Platform and marketplace terms. If you sell or deliver through a marketplace, freelance platform, stock library, app store, or self-publishing service, its rules on AI-assisted work apply to you as a condition of selling there. These change often, and the penalty is usually account-level rather than a warning.
  • Your own published claims. If your website says "written by our team," "hand-crafted," "100% original," or similar, that is a commitment you have made to every customer. Either the practice matches the claim or the claim needs updating.

The practical move: search your signed agreements for artificial intelligence, machine learning, generative, automated, and subcontractor, and note per client what is required. Do it once, record the result, and re-check when a client sends a contract renewal. A tracked list of vendors and clients makes this ten minutes instead of an afternoon — monthly AI usage review covers where that record lives.

If a clause is ambiguous about whether your use counts, treat that as a question for the client rather than a question you answer for them in your own favor. Asking looks careful; being asked afterward does not.

The test worth applying

Would this customer feel misled if they found out later?

That single question resolves most cases, and it maps onto why disclosure matters at all. The damage from undisclosed AI use is rarely the AI use itself — it is the customer discovering a gap between what they assumed they were getting and what they got.

When to disclose

When a customer thinks they are talking to a person and they are not. A chatbot handling support conversations should be identifiable as one. This is the clearest case, the one most likely to be regulated, and the one where obligations are most likely to already be in force somewhere you operate. It is also simply practical: people ask different questions of a bot.

Note the range here: some regimes require the bot to announce itself before the conversation starts, while others are satisfied by an honest answer when the person asks. Disclosing up front satisfies both shapes, which is why it is the low-effort default even before you know which applies to you.

When AI materially informs a decision about them. An application, a price, a service level, an eligibility outcome. If AI shaped it, the person affected has a reasonable interest in knowing — and, ideally, in reaching a human.

When they are specifically buying human expertise. A client paying professional rates for your analysis assumed they were buying your judgment. AI-assisted drafting of that analysis is fine; presenting it as entirely hand-crafted when it was substantially generated is the kind of gap that damages a relationship on discovery.

When the output is creative work sold as human-made. Illustration, copywriting, photography, music. Buyers in these categories often care specifically about provenance.

When a contract or platform term says so. Covered above, and worth restating: this one is not a judgment call.

When a customer asks you directly

This is the case that actually comes up, and it collapses the whole decision: once you have been asked, the only options are an accurate answer or a misleading one. There is no longer a version where non-disclosure is neutral.

It is worth knowing that this is not only an ethical line. In some regimes, being asked is precisely what triggers the disclosure duty for an ordinary business — the obligation is reactive rather than upfront. Answering a direct question accurately is therefore the single highest-value habit in this entire article, and the cheapest to adopt.

Answer plainly, in one or two sentences, and say what the human contribution was:

Yes — I used an AI tool to produce a first draft, then rewrote and checked it. The analysis and the recommendations are mine.

Three things make this land badly, and all three are avoidable:

  • Hedging. "Not really" or "only a little" about something the customer can often verify reads as a caught-out answer even when it is technically true.
  • Answering for the whole company. If you do not know what other teams do, say so and find out, rather than guaranteeing something you cannot see.
  • Treating the question as an accusation. Usually it is a procurement checkbox, a curiosity, or a quality worry. Matching a neutral question with a defensive answer creates the concern the customer did not have.

If the question keeps arriving, that is signal, not nuisance: it means your market cares about provenance, and a short standing statement on your site will answer it better than five different improvised replies. Make sure your team gives the same answer you would — ChatGPT rules for employees is where that consistency gets written down.

When disclosure is not needed

Disclosing every AI-assisted keystroke is noise, and noise reduces the signal value of disclosure where it matters.

You generally do not need to disclose AI use for:

  • Drafting and editing internal documents
  • Improving the grammar or clarity of something you wrote
  • Summarizing material for your own understanding
  • Research and background reading
  • Formatting, restructuring, or reformatting content
  • Generating first drafts that you substantively review, revise, and stand behind

The common thread: a person reviewed the output and takes responsibility for it. Nobody expects disclosure of which word processor you used, and AI-assisted drafting with genuine human ownership sits closer to that than to a bot impersonating a person.

The word doing the work there is "substantively." If the review was a glance, the output is effectively unreviewed, and you are relying on the customer never noticing — see how to review AI-generated content before it goes out for what review has to include to earn that claim.

This distinction is also the one most likely to matter beyond trust. Where transparency rules carve out an exception for reviewed content, they generally expect real review with somebody accountable for the published result — not a formality. So the review process you can actually evidence is doing double duty, and "we reviewed it" is worth being able to demonstrate rather than merely assert.

How to word it

Plain, brief, and not apologetic. Over-explanation signals guilt about something that mostly does not warrant it.

For an automated support interaction:

You are chatting with our automated assistant. Ask for a person at any time and we will connect you.

For AI-assisted service delivery:

We use AI tools to help prepare drafts and analysis. Everything we send you is reviewed by a member of our team, who is accountable for it.

For a website or terms page:

We use AI tools in parts of our work, including drafting and research. Our team reviews AI-assisted output before it reaches you. We do not enter your personal information into AI tools without a business reason and appropriate safeguards.

Only make the last claim if it is true. A disclosure statement that overstates your controls is worse than no statement, because it converts a routine practice into a misrepresentation. If you are not sure whether it is true, the data-input rules in prompt safety tips are the place to start.

What not to say

Most disclosure statements fail in the same few ways:

  • "AI-powered" as a claim about quality. It describes your tooling, not your result, and it invites the question of what your people contribute.
  • Promises you cannot verify. "Fully compliant," "bias-free," "always accurate," "never wrong." Each of these is a commitment that a single bad output disproves.
  • Guarantees about the vendor's side. "Your data is never stored" or "never used for training" is a statement about someone else's system. Only say it if the vendor's terms say it for the plan you are actually on — see what to check in an AI vendor's data terms.
  • Blanket denials that outlive their accuracy. "We do not use AI" is true until one person tries a tool. If you say it, you need a rule behind it and a way to know it is holding.
  • Legalistic length. A paragraph of qualifications reads as concealment. If the disclosure needs that much protection, the underlying practice is probably the thing to revisit.
  • Disclosure as an apology. "Unfortunately we sometimes have to use AI" tells customers that you consider your own process a defect.

Where to put it

Match placement to consequence. An automated chat needs disclosure in the interaction itself, at the start. AI-assisted service delivery is usually appropriate in your terms or an FAQ. A decision informed by AI should be disclosed at the point the decision is communicated, not buried in a policy page.

Then keep it consistent. Disclosure in your terms and a support agent denying AI use is worse than either alone.

Decide it once, in writing

Disclosure handled case by case produces inconsistency, and inconsistency is what customers notice. Decide which of your uses warrant disclosure, write the wording, and put it where your team can find it.

A one-page record is enough: the uses you disclose, the uses you deliberately do not, the approved wording for each, any client or platform that requires something different, and who answers if a customer asks. Date it, and revisit it when you add a tool or sign a client.

Date it for a second reason too: this is an area where the rules are moving, and a decision recorded on a known date can be re-checked against what applies now. A dated page you revisit annually is worth more than a better-reasoned one nobody can place in time.

That decision belongs alongside your other AI rules — how to write an AI usage policy covers the document it lives in. The small business AI governance checklist tracks whether the surrounding controls are in place.

Assess a specific customer-facing use

The AI Risk Checklist scores a planned use across five dimensions — including whether output reaches customers and whether a human reviews it first — and returns a Low / Medium / High rating with tailored safeguards. Free, no account, entirely in your browser.

The Starter Pack includes an editable Customer-Facing AI Disclosure template with wording you can adapt, alongside the policy and review checklists that back it up.

This article provides practical operational guidance for AI usage management. It is not legal advice and does not guarantee regulatory compliance. AI disclosure requirements vary by jurisdiction and industry, are actively developing, and some took effect during 2026 — nothing here states what any particular rule requires of you. Consult qualified professionals about the obligations that apply to your business before relying on any approach described here.

Put it into practice

Turn the guidance into a working rule.

The free tools on this site generate a tailored AI policy, risk assessment, or prompt safety check in under two minutes — no account required.