AI features and disclosure: what to tell users
What to publish about the AI in your website, product or service: where it is used, what it does with data, and who remains responsible.
The short answer
Disclosure about AI serves three different audiences and works best as three different pieces of text. The person in the moment, chatting with an assistant or receiving generated content, needs one sentence: this is automated, here is how to reach a person. The customer reading your policies needs to know what personal data goes to which AI providers, for what purpose, on what basis, where it is processed and how long it is kept, which belongs in the privacy statement built from your record of processing. The business client doing due diligence needs a short AI section in your security summary: which tools, under what terms including training and retention, what data they touch, what human review applies, and who is accountable. Writing one long page for all three serves none of them. What all three share is the substance: what the AI does, what data it uses, whether a person reviews, and how to reach a human or contest an outcome. And all three have to stay current, because a disclosure that no longer matches the product is worse than none.
The three disclosures
| Audience | Where | What it says | Length |
|---|---|---|---|
| Person interacting | First chat message, call opening, content label | This is automated; what it can help with; how to reach a person | One or two sentences |
| Customer generally | Privacy statement, and an AI note if you have one | Which AI processing happens, what data, why, which providers, where, how long, what rights | A paragraph or a short section |
| Business client | Security summary, questionnaire answers, contract terms | Tools, terms on training and retention, data flows, human review, accountability, incident handling | A page |
| Regulator, if asked | Record of processing, impact assessment, AI use register | The full picture with reasoning and dates | Your internal documents |
Writing them
- List your AI uses from the register, marking which are customer-facing.
- Write the in-the-moment lines for each customer-facing use, with the route to a person.
- Add the AI processing to your record of processing: data, purpose, basis, provider, location, retention.
- Update the privacy statement from that record, in plain language.
- Write the client-facing AI section for your security summary.
- Add an accountability statement saying who remains responsible.
- Check the wording against the product whenever features change.
- Date each document and review at least annually.
What good disclosure looks like in practice
A chat assistant that opens with a plain sentence about being automated and how to reach a person. A privacy statement with a short AI paragraph naming the categories of processing and the providers. A knowledge base or product page explaining what the AI features do and what they do not. A security summary section a client can forward to their own compliance team. And a consistent story across all of them, which is the part that requires the register to exist rather than being reconstructed for each document.
What this means for you
Write three disclosures for three audiences: a sentence at the point of interaction with the route to a person, a paragraph in the privacy statement describing the AI data flows, and a page for business clients covering tools, terms, review and accountability. Build all three from your register of AI uses so they agree, include who remains responsible, and review them whenever the product changes. This is general information rather than legal advice.
Frequently asked questions
Where should the disclosure live?
In three places. At the point of interaction, in the first message of a chat or at the start of a call. In your privacy statement, describing what personal data goes to which AI providers and why. And in a short AI section of the material you send to business clients, covering tools, data terms, human review and accountability. Each audience needs a different level of detail, and one long page serves none of them well.
How much detail about the technology?
Very little. People need to know that AI is involved, what it does for them, what happens to their data and how to reach a person. Naming the model or the provider matters for business clients and privacy statements, where it is part of the data flow, and is noise at the point of interaction. Explaining architecture in a customer-facing disclosure signals that the wrong question was answered.
What if we use AI internally but customers never meet it?
The interaction disclosure does not apply, and the data disclosure may. If customer personal data goes to an AI provider, that flow belongs in your privacy statement and in your record of processing regardless of whether customers meet the AI. Internal use with no personal data needs no customer-facing disclosure, though business clients may still ask, and having a prepared answer is useful.
Sources
- EUR-Lex: Regulation (EU) 2024/1689, Article 50 (accessed 2026-09-14)
- EUR-Lex: Regulation (EU) 2016/679, Articles 13 and 14 (accessed 2026-09-14)