AI features and disclosure: what to tell users

What to publish about the AI in your website, product or service: where it is used, what it does with data, and who remains responsible.

4 minread 804words last updated

The short answer

Disclosure about AI serves three different audiences and works best as three different pieces of text. The person in the moment, chatting with an assistant or receiving generated content, needs one sentence: this is automated, here is how to reach a person. The customer reading your policies needs to know what personal data goes to which AI providers, for what purpose, on what basis, where it is processed and how long it is kept, which belongs in the privacy statement built from your record of processing. The business client doing due diligence needs a short AI section in your security summary: which tools, under what terms including training and retention, what data they touch, what human review applies, and who is accountable. Writing one long page for all three serves none of them. What all three share is the substance: what the AI does, what data it uses, whether a person reviews, and how to reach a human or contest an outcome. And all three have to stay current, because a disclosure that no longer matches the product is worse than none.

The three disclosures

AudienceWhereWhat it saysLength
Person interactingFirst chat message, call opening, content labelThis is automated; what it can help with; how to reach a personOne or two sentences
Customer generallyPrivacy statement, and an AI note if you have oneWhich AI processing happens, what data, why, which providers, where, how long, what rightsA paragraph or a short section
Business clientSecurity summary, questionnaire answers, contract termsTools, terms on training and retention, data flows, human review, accountability, incident handlingA page
Regulator, if askedRecord of processing, impact assessment, AI use registerThe full picture with reasoning and datesYour internal documents

Writing them

  1. List your AI uses from the register, marking which are customer-facing.
  2. Write the in-the-moment lines for each customer-facing use, with the route to a person.
  3. Add the AI processing to your record of processing: data, purpose, basis, provider, location, retention.
  4. Update the privacy statement from that record, in plain language.
  5. Write the client-facing AI section for your security summary.
  6. Add an accountability statement saying who remains responsible.
  7. Check the wording against the product whenever features change.
  8. Date each document and review at least annually.

What good disclosure looks like in practice

A chat assistant that opens with a plain sentence about being automated and how to reach a person. A privacy statement with a short AI paragraph naming the categories of processing and the providers. A knowledge base or product page explaining what the AI features do and what they do not. A security summary section a client can forward to their own compliance team. And a consistent story across all of them, which is the part that requires the register to exist rather than being reconstructed for each document.

What this means for you

Write three disclosures for three audiences: a sentence at the point of interaction with the route to a person, a paragraph in the privacy statement describing the AI data flows, and a page for business clients covering tools, terms, review and accountability. Build all three from your register of AI uses so they agree, include who remains responsible, and review them whenever the product changes. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Where should the disclosure live?

In three places. At the point of interaction, in the first message of a chat or at the start of a call. In your privacy statement, describing what personal data goes to which AI providers and why. And in a short AI section of the material you send to business clients, covering tools, data terms, human review and accountability. Each audience needs a different level of detail, and one long page serves none of them well.

How much detail about the technology?

Very little. People need to know that AI is involved, what it does for them, what happens to their data and how to reach a person. Naming the model or the provider matters for business clients and privacy statements, where it is part of the data flow, and is noise at the point of interaction. Explaining architecture in a customer-facing disclosure signals that the wrong question was answered.

What if we use AI internally but customers never meet it?

The interaction disclosure does not apply, and the data disclosure may. If customer personal data goes to an AI provider, that flow belongs in your privacy statement and in your record of processing regardless of whether customers meet the AI. Internal use with no personal data needs no customer-facing disclosure, though business clients may still ask, and having a prepared answer is useful.

Sources

  1. EUR-Lex: Regulation (EU) 2024/1689, Article 50 (accessed 2026-09-14)
  2. EUR-Lex: Regulation (EU) 2016/679, Articles 13 and 14 (accessed 2026-09-14)