What your AI disclosure tells your customers

Your AI policy could be giving customers the wrong impression of the work you do. If a disclosure suggests that AI produced the expertise they are paying for, when it only helped write the announcement, you have a problem worth addressing.

In recent articles, I have written about the confidence that business leaders need when making technology decisions. Customers need confidence in those decisions too. They need to understand what they are buying, where professional judgement has been applied and who stands behind the result. How you describe your use of AI can influence all three.

That makes disclosure a question for the people running the business. The wording needs to reflect what actually happens, and the organisation needs to be able to support it with evidence. Customer trust is the strongest reason to get this right.

When an AI tag creates the wrong impression

Imagine an engineering consultancy whose engineers inspect a site, assess the evidence and write a report. The report goes through the firm’s normal technical review, and the client agrees that an approved version can be published. So far, the work has been undertaken by the professionals the client appointed.

Someone in marketing then uses AI to draft a short announcement linking to the report. Under the company’s policy, any use of AI means the entire publication is tagged “AI-generated”.

A prospective client could reasonably wonder whether AI undertook the analysis or wrote the recommendations. Neither happened. The company has disclosed that AI was involved, but it has failed to explain where. Its policy has introduced doubt about the expertise it is trying to demonstrate.

This raises a practical question for technology executives and boards:

“How do we govern AI use so that our disclosures are accurate, our obligations are met and our people can make consistent decisions?”

Start by looking at one of your own publications. What would a customer believe AI contributed, based only on what you have told them? Would that understanding match what actually happened?

Be clear about what AI contributed

The engineering example becomes easier to govern when the report and its announcement are considered separately. The engineers produced the report. AI drafted the announcement. Any accompanying image has its own history. A single description of the whole publication can obscure those differences.

Your policy needs language that staff can apply consistently. Correcting spelling or improving readability is different from drafting text for publication. Asking AI to interpret evidence or suggest a recommendation involves a different contribution again. Those distinctions help people decide what needs checking and what the customer needs to understand. They are working definitions for your business, rather than automatic legal exemptions.

“Sense-checking” is particularly easy to misunderstand. Asking a tool to find repeated words is different from asking whether an engineering conclusion is sound. If its suggestion changes a recommendation, AI has contributed to the substance of the work, even if an engineer types every word of the final report. For the customer relying on that recommendation, the distinction matters.

Human review needs equally careful wording. Reviewing an AI draft can improve its quality and establish accountability. It does not make its production history disappear. Equally, using AI to write an announcement does not mean that AI produced the report it links to. Both claims need to be accurate if customers are to trust the explanation.

Give customers an explanation they can use

For our hypothetical consultancy, the explanation could be straightforward: “Our engineers produced the report and its recommendations. AI was used to draft this announcement, which our team checked against the approved report.” If AI had contributed to the analysis, the wording would need to reflect that too.

That level of detail may not fit into a social media post. A public-facing AI policy or statement on your website can explain how you use AI, what review takes place and who remains responsible. A short, specific disclosure can then direct readers to the fuller explanation. The statement needs to help customers understand the contribution to the work they are looking at.

Any mandatory tag, label or platform declaration still needs to appear where required. A website statement can provide context, but it cannot replace a disclosure required alongside the content itself. The same principle applies when a platform adds its own label: check what the customer actually sees and provide clarification where necessary. Preserve the information recording how the content was created, rather than removing it to avoid a label.

Before publishing your statement, ask someone outside the process to read it, ideally a customer. Ask them what they think AI does in your business and what they believe your people remain responsible for. If their answer differs from reality, the wording needs more work.

The rules depend on what you do and where you operate

The legislation matters, but there is no single worldwide requirement that makes every piece of work touched by AI “AI-generated”. The duties depend on the jurisdiction, the content and your role. Building an AI service can create different obligations from using one to prepare a publication.

In the UK, the government’s March 2026 report on copyright and AI describes a position without a general requirement to label AI-generated content. It also records concerns that indiscriminate labelling could misrepresent AI-assisted work. Existing obligations still matter. The ASA’s guidance on AI disclosure makes clear that advertising rules apply regardless of how an advertisement was produced, including whether it misleads customers.

The EU AI Act’s Article 50 distinguishes between providers’ duties to make synthetic outputs machine-readable and detectable, and disclosure duties for organisations using AI. It includes an exception for standard editing assistance under the provider obligation. Separately, disclosure is required for deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. For that text, human review or editorial control, together with editorial responsibility, can provide an exception. This is not a general exemption for anything a person approves.

Article 50 applies from 2nd August 2026. The Commission’s guidance describes a limited transition to 2nd December 2026 for the provider marking and detection obligation for systems placed on the market before August. It should not be treated as a general delay to disclosure duties.

The California AI Transparency Act, as amended by AB 853, focuses on covered AI providers, including detection and provenance requirements for image, audio and video content, with further platform duties following in 2027. It is not a blanket instruction for every company to tag every document involving AI. China’s labelling measures, effective from 1st September 2025, take a broader approach across text and other media in covered services, including duties for users publishing generated content to declare it and use the available labelling functions.

For an SME, the practical step is to seek appropriate legal advice about your activities and markets, taking account of client contracts, professional requirements and platform rules. Then decide where your business will go further to support customer trust. Staff should be able to distinguish a legal requirement from a choice you have made in your own policy.

Make the policy part of everyday work

A policy can only produce consistent disclosures if the organisation can establish what happened. The CIO, CTO or person responsible for technology should work with the people doing the work to identify where AI contributes. Include suppliers and AI features within everyday software. A list of approved tools will only take you so far when the same tool can proofread a sentence, draft a page or suggest a conclusion.

Build the record into your existing review or publication process. For the consultancy, that could mean recording the AI task, the item it affected, who reviewed it and why the disclosure was chosen. Substantive analysis needs enough evidence to show what was accepted and how it was checked. Routine editing can follow a simpler process, with records proportionate to the work and its confidentiality.

Give the review a clear purpose. Someone checking the announcement should compare it with the approved report and look for exaggerated findings, missing qualifications or unsupported claims. They should also consider whether the disclosure gives customers an accurate understanding of how the work was produced. A tick beside “human reviewed” provides little confidence unless that review means something.

Apply the same discipline to suppliers. An agency’s assurance that work was human reviewed does not explain what AI generated or changed. Ask for enough detail to support the claims you will make under your own name. Your customer needs to be able to rely on your explanation, regardless of who supplied the work.

Give the board evidence of customer trust

The board should agree the principles, appoint an accountable executive and expect evidence that the policy works. The technology lead should make the process practical. Those responsible for customer communications should make the language understandable, supported by appropriate legal and compliance advice. The business owner remains accountable for the published work. In an SME, several responsibilities may sit with one person, but they still need to be clear.

Start with three recent publications. Ask your team where AI contributed, what review took place and why the disclosure was appropriate. Then test what a customer would understand from each one. Any gap between those accounts gives you something concrete to improve, whether that is the wording, the review process or the evidence you retain.

Board reporting should include customer questions and complaints, unsupported claims and the action taken to correct them. Counting AI tags tells you little about whether people understand or trust what they are reading. Review the approach regularly and when your tools, suppliers, publishing channels or obligations change.

Your customers should be able to understand how you use AI and why they can still rely on your work. That confidence comes from an explanation which matches reality, backed by people willing and able to take responsibility for it.

If your policy currently stops at “AI used: yes or no”, take one real piece of work and follow it through the process this week. Can you explain the contribution accurately, and would your customer understand it in the same way?

At DigitalTeddy, we help leadership teams assess how technology is used and put practical governance in place. If you need help reviewing your AI policy, defining responsibilities or turning it into a process your team can follow, get in touch. We can start with how AI is being used in your business today and what your customers need to have confidence in it.

After writing this article, we reviewed our own approach and strengthened DigitalTeddy’s published AI statement. The principles were already there, but working through the examples prompted us to explain our use of AI and our editorial responsibility more precisely. It was a useful reminder that disclosure needs to evolve as the way we work with AI changes, and as we learn what customers need to understand. Applying that scrutiny to our own wording is part of the same governance we encourage others to practise.