Disclosure is the governance question small businesses find hardest, because it sits between two instincts: the wish to use AI without drawing attention to it, and the fear of inviting a conversation nobody wants to have. In practice, a short, specific disclosure position removes both problems, and it is far easier than improvising an answer when a client asks.

This guide covers when disclosure is expected, what to say to clients and staff, and how to write the position into a policy. It is part of the Governance, Risk & Data pillar.

Clients rarely object to AI assistance. They object to discovering it later.


The distinction that resolves most of the question

Two very different situations are often conflated.

  • Direct interaction. A customer or user is interacting with an AI system rather than a person. This is where transparency expectations are strongest, and where a route to a human should always exist.
  • Assisted production. A person uses AI to draft their work, then reviews it and stands behind it. Here the human is the author, and the tool is a drafting aid.

The first situation normally requires disclosure. The second usually does not require disclosure of the tool, and does require that a named person verified the output — which is the more useful thing to communicate.

Most small-business disclosure anxiety comes from applying the first situation’s rules to the second.


What to tell clients

Four lines cover most professional relationships.

  • State the control rather than the tool. “AI assisted with drafting; all figures, claims and citations were verified by [name] before delivery.” This is specific, honest and reassuring, and it describes something that actually happened.
  • Disclose where material. Where AI use is material to how the work was produced — a significant analytical component, for instance — say so.
  • Follow the contract. Where an agreement requires disclosure or prohibits AI use, that governs. Check the engagement terms before assuming either.
  • Answer when asked. A client asking whether AI was used should receive a straight, unhesitating answer. Hesitation creates more concern than the fact.

The practical test: would you be comfortable if the client read your disclosure in a year’s time alongside the work? If not, the position needs changing rather than wording.


What to tell staff

Staff need more detail, and they need it in the policy.

  • What is permitted — approved tools, permitted uses, the data rule.
  • What is prohibited — the data categories, and the tools that are not approved.
  • What is expected — that output is a draft, that a named person verifies it, that the check is recorded.
  • How to ask — a named person, and a route for requesting a new tool.
  • What happens if something goes wrong — the incident path, framed so that raising a problem is safe.

The last point matters more than it appears. Where staff fear the consequence of reporting a mistake, mistakes are concealed, and a concealed mistake is the most expensive kind.


Writing it into the policy

A disclosure section in an AI policy needs three sentences.

  • When disclosure is required — direct customer interaction, material use, and wherever a contract or rule requires it.
  • What is communicated — that AI assisted, and that a named person verified the output.
  • Who decides — the person who owns the policy, for cases not covered by the above.

Three sentences reduce a contentious topic to a rule that can be applied without a meeting.


Where disclosure is most likely to be required

Even where no rule applies, four contexts call for a deliberate position.

  • Regulated professional services, where a professional body’s guidance shapes expectations.
  • Direct customer interaction with an AI system, where transparency is the norm.
  • Work delivered under a contract that addresses subcontracting, confidentiality or processing.
  • Public-facing content with factual claims, where a claim’s provenance matters.

In each case, the answer is not necessarily to disclose the tool; it is to decide the position in advance rather than in the moment.


A worked position

A consultancy adopts a single disclosure position for its client work.

  • Client deliverable, human-reviewed. The engagement terms state that the firm may use AI-assisted drafting and that all deliverables are reviewed and verified by a named professional before issue. No per-document disclosure is required.
  • Direct AI interaction. Where the firm pilots a client-facing assistant, the interface states that the user is interacting with an AI assistant, and offers a route to a person.
  • Staff. The policy states what is permitted, what is prohibited, who to ask, and what happens if something goes wrong — and it is walked through once, with the data rule.
  • The line for a direct question. When a client asks whether AI was used, the answer is a plain yes, with the verification step named. No hedging.

Four decisions, written once into the engagement terms and the policy, remove the question from every future project.

When the honest answer is uncomfortable

Occasionally the disclosure question surfaces something bigger. A contract prohibits AI use and the team has been using it; a client’s compliance position depends on knowing where their data sits; a deliverable was issued with unverified content.

Those cases are not solved by a better disclosure line. They are solved by changing the practice and then disclosing the change:

  • Fix the practice first, so the disclosure describes something true rather than something intended.
  • Disclose proactively where the client’s position has been affected, rather than waiting for the question.
  • Record the change and the date, so the position is evidenced.
  • Take advice where the contract, a regulation or professional guidance is engaged.

The general principle is the same one that governs errors in reports: a controlled correction strengthens the relationship, and a discovery weakens it.

Common mistakes

  • Saying nothing and hoping. The question eventually arrives, and an improvised answer is worse than a prepared one.
  • Disclosing the tool instead of the control. The verification is the reassuring part.
  • Inconsistent answers. Two clients receiving different answers creates a problem where none existed.
  • No staff position. People invent their own disclosure rules, differently.
  • Ignoring the contract. Engagement terms come first.
  • Hesitating when asked. Uncertainty reads as concealment.

Frequently asked questions

Do we need to tell clients we use AI?

Where the work involves direct AI interaction, where AI use is material, or where a contract or rule requires it, yes. In all cases, stating that a named person verified the output is the more useful disclosure.

What should an AI disclosure say?

That AI assisted with production, and that all figures, claims and citations were verified by a named person before delivery — a short, specific statement of the control.

Should we disclose AI use in every deliverable?

Not necessarily. A standing position, stated once in the engagement terms or on request, is usually more practical than a line in every document.

What if a client prohibits AI use?

Then follow the contract. Where a prohibition is impractical, raise it with the client rather than working around it, because discovery is worse than the conversation.

What do we tell staff about disclosure?

What is permitted, what is prohibited, what is expected of them, who to ask, and what happens if something goes wrong — written into the policy and walked through once.

Does disclosing AI use reduce trust?

Handled well, it increases it. What reduces trust is discovering later that AI was used and nobody said so, particularly where the client’s own compliance position depends on knowing.

Should the disclosure be in every document or in the terms?

In the terms, as a standing position, wherever the agreement allows — that is more practical than a line in every deliverable, and it sets the expectation once. Confirm the wording with your clients rather than assuming it is acceptable.


Next step

Write the three-sentence disclosure position, decide the client line, and walk staff through it alongside the data rule. See Writing an AI Acceptable-Use Policy and the AI Policy Template, or book an AI adoption call to draft the position with you.


Sources

  • ABA Formal Opinion 512 (American Bar Association) and the ICMCI Code of Ethical Conduct (International Council of Management Consulting Institutes) are examples of professional guidance that shapes disclosure expectations in regulated and advisory contexts.

No statistic in this article is invented. This article is general information, not legal advice; confirm your specific obligations with qualified counsel.