When to Tell Your Customers AI Is Involved (and How to Say It) | Cybernomics
governanceFriday, July 24, 2026

When to Tell Your Customers AI Is Involved (and How to Say It)

Executives often treat AI disclosure as a compliance checkbox: tuck a sentence into the terms of service, hope no one reads it, and move on. That was the approach a mid-sized B2C insurer we'll call Northbridge Mutual took at first. T

When to Tell Your Customers AI Is Involved (and How to Say It)

Executives often treat AI disclosure as a compliance checkbox: tuck a sentence into the terms of service, hope no one reads it, and move on. That was the approach a mid-sized B2C insurer we'll call Northbridge Mutual took at first. Their product team shipped an automated triage engine for claims; legal tucked a line into the general terms: "We may use automated systems to assist in claims handling." It satisfied counsel. It didn't satisfy customers or regulators.

Six months later Northbridge tried something different: a short, plain-English "How we use AI" page linked from every claims form, chatbot, quote flow, and email footer. The page explained what AI does (triage, document reading, auto-fill), what data it uses, where humans remain in the loop, and how customers could ask for human review. The company added short, contextual labels in the chat widget and a one-sentence just-in-time notice in the claims portal. The results surprised everyone who expected pushback: conversion for online quotes did not drop; Net Promoter Scores rose modestly; and two state regulators publicly cited Northbridge's disclosures as a practical example of good practice.

That story encapsulates a modern truth: disclosure isn't only about avoiding fines. Done right, it's a trust instrument that can accelerate adoption, simplify complaints handling, and reduce regulatory friction. The trick is to disclose in plain language, in the right places, with an operational plan behind the message.

Below is a practical playbook - legal-aware but business-forward - for deciding when to disclose, where to put the information, how to word it, and how to operationalize across product, marketing, and legal.

Why disclosure matters now - three pressures converging

- Legal: Several laws and local rules already require transparency about automated decision-making or AI-driven interactions. In the US, privacy statutes like the CCPA/CPRA require clear notices about categories of personal data and their uses; state AI laws (for example, the Colorado AI Act) require notice when automated systems make decisions that materially affect consumers; and municipalities such as New York City have bot disclosure rules for automated conversational agents. In the EU, the incoming AI Act contains provisions that aim to ensure users are informed when they interact with AI or receive AI-generated content (see Article 50 and related obligations). These regimes vary in scope and wording, but they create a baseline expectation: tell people when AI is being used and what that means for them.
- Reputational: Public attention to AI failures is high. Customers punished obfuscation harshly - surprise price increases, opaque denials, or synthetic content passed off as human-generated erode long-term trust more quickly than they erode short-term conversion.
- Commercial: Clear disclosures reduce friction in support and compliance channels. Northbridge's clear page cut average handle time for complaints and reduced escalations to regulatory affairs because customers could see how a decision was made and where to request human review.

The business case is simple: transparency can be an enabler, not a cost center, when designed as part of the product experience.

When you must - and when you should - disclose

Not every use of a server-side model requires a banner. Use a risk-and-materiality lens.

Disclose whenever AI:
- Makes or materially assists a decision that affects a person's rights, money, coverage, or access to services (pricing, underwriting, claim denials, fraud holds).
- Generates customer-facing content or recommendations (personalized cover suggestions, policy summaries, generated emails, chat responses).
- Interacts directly with customers through a conversational interface (chatbots, voice agents) - many local laws require notice here.
- Uses sensitive personal data in ways that could cause harm or discrimination (health data, financial history, protected characteristics).

You should also consider disclosure when:
- The AI materially alters the customer experience (e.g., replacing human adjusters with automated triage).
- The company plans to reuse customer-generated content to train models, especially third-party models.
- You want to reduce friction and complaints by making processes visible.

If in doubt, treat the situation as "higher risk" and disclose early.

Where to put disclosures - surfaces that matter

A disclosure strategy is less about a single legal paragraph and more about an orchestration of touchpoints:

- Primary legal texts: Privacy policy and terms of service. These are required and should be accurate, but they're not where customers learn how AI affects them in practice.
- Just-in-time notices: Short, contextual messages shown at the moment of interaction - e.g., "This response was generated with the assistance of an automated system. Ask for a human review." These are highly effective because they answer the customer's immediate question.
- Channel-specific labels: In chat widgets, label the bot clearly ("Bot" or "Virtual Assistant") and open conversations with a disclosure line. In emails or documents that contain AI-generated content, add a brief footer note.
- Dedicated "How we use AI" page: A single, linked resource that explains the company's approach in plain language - purpose, data sources, human oversight, appeal process, model origin (third party vs. in-house), and contact points. Link this page from the FAQ, privacy policy, product pages, and onboarding flows.
- Purchase and quotes flows: If AI affects price or coverage, include a concise notice before the customer commits.
- Customer support scripts and agent prompts: Ensure human agents can explain the role of AI consistently and escalate requests for human review.

The goal: make it easy for customers to find the detailed explanation while answering the immediate question where they experience the AI.

Language that works - concrete, jurisdiction-aware, and non-defensive

People respond to clarity. Legalese and techno-jargon backfire. Use three principles:

1. Be concrete about function, not about algorithms.
- Say what the AI does and why: "We use automated tools to read uploaded documents and extract policy numbers to speed up claim filing."
- Avoid hyper-technical detail: customers don't need model architecture names - they need to know impact and recourse.

2. Be jurisdiction-aware.
- Tailor disclosures where law demands it: if you operate in the EU, mention relevant rights under the AI Act and GDPR. In Colorado or California, include the specific notices or opt-out pathways required by state law.
- Use local-language templates for large markets.

3. Be non-defensive and actionable.
- Don't lead with denials ("We will never...") or defensive legalese. Lead with how the company protects customers and what customers can do: "A human reviews final claims over $10,000" or "You can request a human review within 14 days."
- Provide a clear contact and escalation path (email, phone, form).

Sample snippets (adapt to your legal counsel's review):

- Chatbot label (short): "Hi - I'm AssistBot, an automated helper. Ask me anything or type 'agent' to speak with a person."
- Just-in-time purchase notice (one line): "This quote was calculated using automated systems that analyze the information you provided. Request human review before purchase."
- "How we use AI" page intro (short): "We use AI tools to speed up claims and make pricing more accurate. Here's what that means for you: what we use, what data is involved, where people stay involved, and how to get a human review."

Coordinating marketing, legal, and product - an operational blueprint

Disclosure is a cross-functional exercise. Create a small, empowered working group with representatives from legal/compliance, product, UX, marketing, customer support, and security. Give them a simple mandate: minimize legal and reputational risk while preserving conversion and user experience.

A practical cadence:
- Week 0: Discovery sprint - map all AI touchpoints (where models are used, who sees the output, data inputs, effect on customers).
- Week 1: Risk triage - classify uses as low/medium/high risk based on materiality, personal data use, and regulatory exposure.
- Week 2: Draft messages - produce short and long-form templates for every surface (labels, just-in-time notices, page copy).
- Week 3: Legal review and localization - counsel clears language and flags jurisdictional requirements.
- Week 4-6: Implementation - product and UX add labels and links; marketing updates pages and emails; support gets scripted responses and training.
- Ongoing: Monitor customer metrics (conversion, NPS, complaints), legal/regulatory developments, and escalate any issues.

Operational details that matter:
- Style and consistency: Use approved templates so disclosures are consistent across channels.
- Version control: Track changes in a compliance register with owners and effective dates.
- Training: Give support teams a one-pager and role-play scripts so they can explain AI decisions confidently.
- Logging & audit: Record disclosures in logs to show regulators you followed your published policies.
- Measurement: A/B test disclosure placements for conversion and track complaint/escalation rates.

This cross-functional playbook turns disclosure from a legal afterthought into a product feature.

Disclosure as governance - a competitive advantage

Regulators increasingly look favorably on firms that meet both the letter and spirit of transparency obligations. The Northbridge example shows that disclosure, when done as part of experience design rather than as legal obfuscation, can reduce friction and even draw praise from regulators.

Good governance here is not a compliance tax. It's an economic enabler:
- It reduces customer uncertainty and lowers support costs.
- It reduces regulatory escalations and the associated remediation costs.
- It strengthens brand trust - helpful in markets where trust drives price sensitivity.

Link disclosure to your broader AI governance program: model inventories, risk assessments, incident response, and human-review policies. Frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 provide structure for these programs - use them to align disclosure with broader controls and audits.

A simple readiness move to start today

If you only do one thing this quarter: run a 6-week "AI Disclosure Sprint." Checklist:

- Inventory: Map every customer-facing AI use.
- Risk score: Classify the customer impact and data sensitivity.
- Draft: Create short labels and a single comprehensive "How we use AI" page.
- Implement: Add just-in-time notices to the highest-risk flows (chat, underwriting, claims).
- Train: Give support and sales teams a one-page FAQ and escalation path.
- Monitor: Track conversion, complaints, escalations, and regulator queries.

Make the sprint visible to the board: transparency is now a board-level risk and strategy item. Present the sprint findings, the proposed language, and the monitoring plan. Turn disclosure from a legal sentence into a business practice that reduces risk and builds customer confidence.

Conclusion - transparency as readiness

The regulatory landscape will keep shifting, but the business logic is stable: customers respond better to clarity than to secrecy. Disclosure is not a binary legal checkbox but a design and governance problem that, when solved, enhances product adoption and reduces regulatory heat. Northbridge's experience is a useful lesson: a buried line in the terms of service satisfies nobody; a plain, linked explanation with contextual notices wins trust and regulators' nods without hurting conversion.

Make disclosure part of your AI economy readiness program - map the surfaces, craft plain-language explanations, and operationalize across product, legal, and customer teams. The concrete first move is the 6-week sprint: inventory, prioritize, disclose, monitor. That single program converts legal exposure into commercial advantage.

(If you want, I can draft a one-page "How we use AI" template and three short in-product disclosure lines tailored to your product flows for review by counsel.)

AI GovernanceTransparencyDisclosureCustomer Trust

Original Article by Cybernomics

Expert operational AI insights for business leaders

Learn About Operational AI