From Sanskriti Khandelwal | Product & Market Analysis

AI Disclosure to Customers: What the Law Requires, and What the Trust Data Says

On this page

Disclosing AI use to customers is now a legal duty in the European Union, not a brand choice. Article 50 of the EU AI Act applied from 2 August 2026, and fines reach €15 million or 3% of worldwide turnover. The harder question is what the law leaves open. AI disclosure carries a measured cost, and hiding it carries a larger one.

Key takeaways

  • The EU rule is narrow, not general. Article 50 covers systems that talk to people, synthetic media, deepfakes and emotion recognition. It does not require a company to announce that AI helped write a proposal.
  • Two peer-reviewed experiments say disclosure costs you money. Naming AI in a product description lowered emotional trust and purchase intent, and a separate study of 4,400 people found that disclosed AI users were judged less competent.
  • Concealment is priced higher when it fails. Deloitte Australia refunded A$97,000 on a A$439,000 government contract after fabricated citations were traced to an undisclosed model.
  • Your staff have already decided. In a 47 country study, 57% of employees said they hide their AI use and pass the output off as their own. Your disclosure policy is competing with that.
€15MMaximum Article 50 fine, or 3% of worldwide turnover if higher. Source: European Commission, 2026.
57%Of employees say they hide their AI use and present AI output as their own. Source: KPMG and University of Melbourne, April 2025.
190Organisations signed the EU transparency code before the rules bit. Source: European Commission, 31 July 2026.

The legal floor is lower and narrower than most policies assume

If you sell into the European Union, you must tell customers when they are interacting with an AI system. You must also mark synthetic audio, image, video and text. Outside the EU, disclosure is mandatory only in narrow cases. Everywhere else it is a commercial decision, not a compliance one.

That distinction gets lost fast. Most internal AI policies I have read treat disclosure as one undifferentiated duty. The statutes do not. They target four specific situations, and a company can be fully compliant while saying nothing about how a report was drafted.

What Article 50 actually catches

The European Commission's own guidance splits the duty between providers and deployers. Providers must design systems that interact directly with people so those people know they are talking to an AI system, unless the interaction is obvious to a reasonably observant person. Providers of generative systems must also mark outputs in a machine-readable format.

Deployers carry a shorter list. They must label deepfakes, disclose emotion recognition and biometric categorisation, and label AI-generated text published to inform the public on matters of public interest.

The exemptions matter more than the rules. Marking is not required for short sequences of symbols, source code, machine-to-machine output, closed-loop industrial use, or standard editing assistance. Published text that went through human review or editorial control is outside the labelling duty. That last carve-out is the one most B2B teams will rely on, and it is the reason a designed review step is worth more than a disclaimer. The design question behind it is covered in the piece on building the review loop before you buy the agent.

The United States is disclose-on-request, not label-everything

There is no federal AI disclosure statute. The state rules that exist are aimed at different targets, and two are worth knowing.

California's AI Transparency Act was moved by AB 853, signed in October 2025. The operative date shifted from 1 January 2026 to 2 August 2026, and the scope widened to large online platforms, model hosting platforms and camera manufacturers on later dates. It binds providers of generative systems with more than a million monthly users reachable in California. It does not bind the average software vendor.

Utah took the opposite approach. Under SB 226, effective 7 May 2025, a supplier using generative AI in a consumer transaction must say so only when the customer makes a clear and unambiguous request. Proactive disclosure is required for regulated occupations in high-risk interactions, meaning health, financial and biometric data, or advice on financial, legal and healthcare matters. There is a safe harbour if the system itself says it is not human at the outset and throughout.

The disclosure deadlines that already passed, and the ones still ahead Dates on which each AI disclosure duty becomes enforceable today 7 May 2025 Utah SB 226 on request only 2 Aug 2026 EU Article 50 California SB 942 2 Dec 2026 EU marking grace period ends 1 Jan 2027 California platforms, hosts 1 Jan 2028 California capture devices The 2 August 2026 cluster is the one that changed the default. Everything before it was voluntary for most vendors. Sources: European Commission; Troutman Amin on AB 853; Perkins Coie on Utah SB 226.
Notice the shape. Two of the five dates are still in front of you, and both land on platforms rather than on ordinary software vendors.
What each disclosure rule requires, and of whom
RuleWho it bindsWhat you have to sayIn force
EU AI Act, Article 50(1)Providers of AI that interacts directly with peopleThat the person is dealing with an AI system, unless obvious.2 August 2026
EU AI Act, Article 50(2)Providers of generative AI systemsMachine-readable marking of synthetic audio, image, video and text.2 August 2026, or 2 December 2026 for systems already on the market
EU AI Act, Article 50(4)Deployers publishing deepfakes or public-interest AI textA clear label on the content itself.2 August 2026
California SB 942, as amendedGenerative AI providers above 1 million monthly users in CaliforniaA free public detection tool, an optional visible label, an embedded provenance signal.2 August 2026
Utah SB 226Suppliers using generative AI in consumer transactionsThat the customer is dealing with generative AI, on a clear request.7 May 2025
Utah SB 226, regulated occupationsLicensed occupations in high-risk interactionsProactive disclosure, spoken at the start or written before the exchange.7 May 2025

Spain approved a draft bill in March 2025 proposing fines of up to €35 million or 7% of global turnover for unlabelled AI content, supervised by AESIA. I could not confirm its final enactment status, so it is excluded from the table and should not be planned against yet.

Above the floor, your buyers set the rule

Compliance answers a small question. The commercial question is what a procurement team will ask you, and that has moved faster than the statutes.

Enterprise buyers now route AI questions through the same channel as security questions. The Cloud Security Alliance publishes an AI extension to its consensus assessment questionnaire, mapped to an AI controls matrix. Vendors submit it to the same registry that already holds their security self-assessments. Once a question sits in a standard questionnaire, answering it is not optional in any practical sense.

The contract is where disclosure becomes binding

A marketing page can be vague. A master services agreement cannot. Buyers are asking for named clauses covering model change notice, sub-processor disclosure, training-data warranties and whether prompts and outputs count as customer data. Those clauses convert a soft transparency posture into an enforceable one, which is a different risk profile. The negotiation detail is set out in the breakdown of the clauses a CFO should insist on, and the remedies question in the piece on liability caps for agent errors.

My position is that inconsistency here is the real risk, not disclosure itself. A vendor whose sales deck, questionnaire answer and MSA describe three different levels of AI involvement has created a documented misrepresentation. That is worse than any honest answer would have been.

Your own staff have already answered the question

The KPMG and University of Melbourne study surveyed more than 48,000 people across 47 countries between November 2024 and January 2025. The employment findings are the ones that should worry a founder. 60% of employees said they use AI intentionally at work. 57% said they hide that use and present AI-generated work as their own. 48% admitted using AI against company policy.

Read those three numbers together and the disclosure policy problem inverts. You are not deciding whether to tell customers. You are deciding whether you know enough about your own delivery to make a truthful statement at all. That measurement gap is the same one behind the cost of undisclosed AI inside the organisation. It shows up again in the gap between how much engineers use these tools and how much they trust them.

People use AI more than they trust it, and hide it more than they admit Share of respondents, 48,000+ people across 47 countries, fieldwork Nov 2024 to Jan 2025 Use AI regularly 66% Willing to trust AI 46% Employees using AI at work 60% Employees hiding that use 57% Say AI regulation is needed 70% 0%50%100% Source: KPMG and University of Melbourne, Trust, attitudes and use of artificial intelligence, April 2025.
The red bar is the operational problem. A disclosure promise you cannot verify internally is a promise you will break by accident.

Disclosure has a measured price, and it is not trivial

The advice that transparency always builds trust is comfortable and wrong. Two controlled studies point the other way, and both used decent samples.

Naming AI lowers purchase intent

Researchers at Washington State University and Temple University ran experimental surveys with more than 1,000 US adults across eight product and service categories. The work was published in the Journal of Hospitality Marketing & Management in July 2024. Descriptions were identical apart from the phrase "artificial intelligence". The group that saw it was less likely to buy.

Lead author Mesut Cicek framed the mechanism plainly. Mentioning AI lowers emotional trust, and lower emotional trust reduces purchase intent. The effect was stronger for high-risk categories such as expensive electronics, medical devices and financial services, where failure costs the buyer money or safety. The release did not publish effect sizes, so treat the direction as established and the magnitude as unknown.

The person who used the tool takes a hit too

A 2025 paper in the Proceedings of the National Academy of Sciences ran four experiments with over 4,400 participants. People who disclosed using AI were judged as less competent and less motivated by their evaluators. The authors found the penalty was both anticipated by users and real in how evaluators actually rated them.

That result explains the 57% who hide it far better than any story about laziness. Employees are responding rationally to a penalty that exists. If you want honest internal reporting, you have to remove the penalty first, and a policy memo will not do that on its own.

What silence costs when it fails

Set against that, the case for disclosure rests on asymmetry. The cost of disclosing is a small, continuous discount on trust. The cost of concealment is rare, large and public.

Deloitte Australia produced a report on the welfare compliance system for the Department of Employment and Workplace Relations under a contract worth roughly A$439,000. Academics found citations to studies that did not exist and a misattributed legal quote. The firm republished the report in September 2025 with a disclosure that a large language model had been used. It also agreed to refund the final instalment of A$97,000, confirmed by the department in October 2025.

Look at what the refund actually priced. It was not the AI use. It was the combination of unverified output and the absence of a disclosure at delivery. Had the methodology note been in the first version, the story is a quality complaint. Without it, the story is a credibility failure that ran in national press for two months.

What an undisclosed model cost on one consulting contract Deloitte Australia, report for the Department of Employment and Workplace Relations, in A$ A$439,000 Contract value A$97,000 Refunded final instalment A$342,000 Retained A$
The refund is 22% of the fee. The reputational line item is not on this chart and was almost certainly larger.

Three postures, and the one most companies drift into

Every company lands in one of three positions. Naming yours is more useful than debating principles.

Disclosure postures compared
PostureWhat it looks likeWhere it genuinely winsWhere it breaks
SilentNo statement anywhere. AI treated as an internal tool, like a spreadsheet.Genuinely incidental use, such as spell-checking or meeting notes, where a disclosure would mislead by implying more.The moment output quality slips, or a buyer's questionnaire asks directly and there is no agreed answer.
On requestAnswer honestly when asked. Nothing volunteered.Legally sufficient in Utah, and cheap to operate.Answers vary by whoever fields the question. Creates inconsistency between sales, security review and contract.
Standing disclosureA published statement of where AI is used, plus in-product labels at the point of interaction.Regulated buyers, public sector, and anywhere an auditor will eventually ask.Costs trust at the top of the funnel, and dates quickly unless someone owns keeping it current.

The on-request model is the worst of the three, and it is the one most companies reach by default. It carries the trust cost of eventual discovery without the operational discipline of a written policy. It also guarantees the inconsistency that turns an awkward answer into a misrepresentation claim.

When disclosure is genuinely a differentiator

Some vendors market their transparency. Most of that is theatre, but there are two situations where it converts.

The first is a regulated buyer. If your customer is a bank, an insurer or a public body, they will be asked how their supply chain uses AI. A vendor who hands over a complete answer removes work from their procurement team. That is a real purchase reason, and it is worth more than any trust messaging aimed at end users.

The second is a formal signal. The EU published a Code of Practice on Transparency of AI-generated Content in June 2026. The Commission and the AI Board confirmed it as an adequate route to demonstrating Article 50 compliance. Around 190 organisations signed before the obligations took effect, roughly half of them small and recent companies. Signatories get a presumption of conformity and a lighter enforcement posture. Non-signatories have to demonstrate compliance some other way.

Treating a general disclosure page as a trust asset is mostly wishful thinking, because almost no buyer reads it. A named signature on a recognised code is different. It is checkable, it is dated, and a procurement team can verify it without asking you.

Where this argument is weakest

Three places, and the first is the one that undercuts most of the section above.

Nobody has measured this in a B2B sale

Both experimental studies I cited test consumer framing. One used product descriptions, the other used evaluations of individuals. Neither tested what happens when a software vendor discloses AI use in a proposal to a procurement committee. I have extended a consumer finding into a business buying context, and that extension is an assumption, not evidence.

There is a decent argument it runs the other way in B2B. Professional buyers have their own AI mandates and may read disclosure as competence rather than as a shortcut. I would not bet either way without data.

The trust penalty may be decaying

The purchase intent study ran before mid-2024. Everyday exposure to these tools has risen sharply since. A penalty grounded in unfamiliarity should shrink as familiarity grows, and a 2024 result may already overstate the 2026 effect. Any post quoting these findings in 2027 without re-checking them, including this one, should be treated with suspicion.

Writing the policy so it survives contact with a buyer

The useful output is not a public statement. It is an internal map of which surfaces carry which duty, agreed once, so that three different people give the same answer.

Disclosure by surface, for a typical B2B software vendor
SurfacePositionReason
Customer-facing chatbot or support agentAlways disclose, at the first turn.Article 50(1) requires it in the EU, and Utah's safe harbour rewards it.
Generated images, audio or video in the productMark them, machine-readable.Article 50(2), with a deadline of 2 December 2026 for existing systems.
Client deliverables and reportsDisclose the method in the document.The Deloitte pattern. Cheap before delivery, expensive after discovery.
Marketing copy and blog postsNo general label.Human editorial control sits outside the EU labelling duty, and volume labelling signals nothing.
Security questionnaire and MSAOne agreed written answer.Inconsistency across documents is the actual legal exposure.
Internal drafting and code assistanceNo customer disclosure, but track it.You cannot make a truthful external statement about usage you do not measure.

The row I expect argument about is marketing copy. Volume publishing without disclosure is a live reputational question, and the search side of it is covered in the analysis of what content saturation does to visibility. My view is that a label on every post is noise, and that the accountable version is a named author who checked the facts. The EU drew the same line by exempting text under editorial control.

One more test before you publish anything. If your AI use would embarrass you when a customer discovered it, disclosure is not your real problem. Fix the use, then decide what to say about it.

Frequently asked questions

Do I have to tell customers I am using AI?

Only in specific situations. In the European Union, Article 50 of the AI Act has required since 2 August 2026 that people be told when they interact directly with an AI system. Synthetic media must also be marked. Outside those categories there is no general duty in the EU, the United States has no federal rule, and disclosure becomes a commercial decision rather than a legal one.

What does the EU AI Act require you to disclose to customers?

Four things. That a person is interacting with an AI system, unless that is obvious. Machine-readable marking of AI-generated audio, image, video and text. A clear label on deepfakes and on AI text published to inform the public on matters of public interest. And notice when emotion recognition or biometric categorisation is in use. Fines reach €15 million or 3% of worldwide turnover.

Does disclosing AI use hurt sales?

The available evidence says yes, modestly. A Washington State University and Temple University study of more than 1,000 US adults found that adding the phrase "artificial intelligence" to a product description lowered emotional trust and purchase intent. The effect was stronger for high-risk categories. No published study tests the same question in a business-to-business sale, so the size of the effect for enterprise software is unknown.

How should a chatbot disclose that it is AI?

At the first turn, in plain words, before the customer invests effort. Utah's safe harbour points at the right pattern: the system says it is not human at the outset and remains identifiable throughout the exchange. Burying it in a privacy policy or a footer does not satisfy the EU standard either, which asks whether a reasonably observant person would understand.

Do I need to label blog posts written with AI?

Generally not. The EU exempts text that went through human review or editorial control from the deployer labelling duty. The duty only applies to text published to inform the public on matters of public interest. The stronger practice is a named author who verified the claims, since a label proves nothing about accuracy and adds nothing a reader can act on.

What happens if a customer finds out we used AI without telling them?

The cost depends on whether the work held up. Deloitte Australia refunded A$97,000 on a contract worth about A$439,000 after fabricated citations were found in a government report produced with an undisclosed model. The refund followed the errors, not the AI use. Concealment turns a quality issue into a credibility issue, which is the more expensive category.

Where to start on Monday

Two tasks, both small, both prerequisites to any public statement.

First, find out what your team actually does. Ask each function which AI tools touch customer-facing output, and write the answers in one place. Given that 57% of employees globally say they hide this, run the question as an amnesty rather than an audit, or you will collect a fiction.

Second, write one paragraph and put it in three places: the security questionnaire response, the MSA, and the sales deck. Same words in all three. That single act removes the inconsistency that turns an honest position into a misrepresentation, and it costs an afternoon.

Related on compliance

This post covers the decision. For the operational checklist behind the EU rules, read the Article 50 transparency checklist.

References

  1. European Commission, Transparency obligations under Article 50 of the AI Act, 2026. Used for the scope of the duty, the exemptions, the application date and the penalty ceiling.
  2. European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content, 31 July 2026. Used for the signatory count and the benefit of signing.
  3. KPMG and University of Melbourne, Trust, attitudes and use of artificial intelligence: a global study 2025, April 2025. Used for all employee and trust percentages. 48,000+ respondents, 47 countries, fieldwork November 2024 to January 2025.
  4. Washington State University, Using the term "artificial intelligence" in product descriptions reduces purchase intentions, 30 July 2024. Reports Cicek, Gursoy and Lu, Journal of Hospitality Marketing & Management.
  5. Reif, Larrick and Soll, Evidence of a social evaluation penalty for using AI, PNAS, May 2025. Four experiments, over 4,400 participants.
  6. Troutman Amin, California AI Transparency Act amendments signed into law, October 2025. Used for the AB 853 dates and expanded scope.
  7. Perkins Coie, New Utah AI laws change disclosure requirements and identity protections, 2025. Used for SB 226, the on-request standard and the safe harbour.
  8. CFO Dive, Deloitte AI debacle seen as wake-up call for corporate finance, 2025. Used for the contract value and the refund.

The weakest part of this source base is the leap from consumer experiments to business buying. Both studies on the cost of disclosure tested consumers, and neither tested a procurement decision. The California and Utah entries rest on law firm summaries rather than the statute text, and Spain's draft bill is excluded because its enactment status could not be confirmed. Regulatory dates in this post are current as of 25 August 2026 and the EU high-risk timetable moved in July 2026, so re-check before relying on any date here.

SK
Sanskriti Khandelwal
Founding Member, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading