Support independent writingAbout the author →
Neil Meyer

When Does Using AI Become Something You Have to Disclose?

Neil Meyer

A plain-English first look at what UK and EU law actually expects when your business uses AI, five everyday situations, a worked example and a short self-check to see where you stand.

Listen to this articleAI-generated narration

I wrote recently on LinkedIn about Clippy, and about the decades we have spent letting software help create our work without feeling any need to say so. This is the practical companion to that piece.

It is written for people running or working in businesses who want an honest first view of where they stand, without reading the legislation. It will not replace legal advice on a specific system, but it should tell you whether you need some.

The short version

  • The EU's AI transparency rules have applied since 2 August 2026. They cover particular situations, not every use of AI.
  • The UK has no general law requiring AI-generated content to be labelled. Existing rules on advertising, consumer protection and data protection still apply to what you do with it.
  • Being a UK business does not automatically put you outside the EU rules. If your AI's output is used by people in the EU, they can reach you.
  • The law looks at what the AI is doing and who it affects. "We use AI" tells you almost nothing.
  • You cannot answer any of this without knowing where AI is already working in your business, including inside software you bought years ago.

Start with one question: what is the AI actually doing?

Most confusion comes from treating all AI use as one thing. It helps to sort it into five kinds, from least to most likely to carry obligations.

  1. Improving your own work. Spelling, grammar, rewording an email, tidying a report before a person signs it off.
  2. Creating something other people will see. Images, video, audio or text that goes on your website, into your marketing or out to the public.
  3. Talking to people directly. A chatbot on your website, an automated phone line, an assistant answering customer emails.
  4. Recommending. Suggesting which candidate to interview, which customer to chase, which claim to look at first, with a person making the final call.
  5. Deciding. Making a decision about a person with no meaningful human involvement: who gets an interview, a loan, an account or a refund.

The further down that list you go, the more the law cares. Most businesses will find they have something in the first three. The fourth and fifth are where the serious obligations sit.

Who built it, and who is using it?

One distinction runs through the EU rules and catches a lot of people out. The organisation that provides an AI system and the organisation that uses it do not have the same responsibilities.

The provider is whoever builds the system and puts it on the market: the company behind the chatbot, the image generator or the writing assistant. You, using it in your business, are what the legislation calls a deployer. Some duties sit firmly with the provider. Making AI-generated content detectable through hidden, machine-readable markers, for example, is the provider's job, not yours. Other duties sit with you, such as telling people when content you publish is a deepfake.

The practical consequence is that buying from a reputable supplier does not hand them all the responsibility. They have to build the system properly. You have to use it properly. Knowing which is which is most of the work.

Five everyday situations

Your website has an AI chatbot

What the rules say. In the EU, people must be told when they are interacting with an AI system, unless it is obvious from the circumstances. That duty sits mainly with the provider, who has to design the system so that people are informed. But if it is on your website, you are the one your customers see.

What to check. Open your own chatbot as a customer would. Does it say clearly, early on, that it is AI? If you bought it from a supplier, ask them how it meets the EU requirement. The precise legal duty depends on your role, but relying on the supplier without checking what your customers actually experience seems an unnecessarily optimistic approach.

Your marketing team makes images and video with AI

What the rules say. Not every AI-generated image needs a label. In the EU, the explicit duty applies where you publish AI-made or AI-altered images, audio or video that could falsely appear authentic: what the Act calls a deepfake. Evidently artistic, creative, satirical or fictional work has lighter requirements.

In the UK there is no AI labelling law, but advertising rules still apply, and they ask a sensible question. The advertising regulators' guidance does not require every advert involving AI to say so. It asks whether your audience would be misled if you did not.

An AI-generated illustration decorating a brochure is very different from a fabricated photograph presented as evidence of how a product performs. And labelling the second one "AI-generated" would not make an otherwise misleading advert acceptable. The law already cares about the impression you create, even when it does not require you to describe the technology used to create it.

What to check. Look at what you publish that shows real-looking people, places or products. Could any of it mislead someone about what is real, or about what your product does?

Your team uses Copilot or ChatGPT to write

What the rules say. This is probably where the most confusion exists, and mostly unnecessarily. The EU rule on AI-written text applies to material published to inform the public on matters of public interest. Even then, there is an exception where the content has been reviewed by a person and somebody holds editorial responsibility for it.

That is quite different from saying every employee who uses AI to improve a document must disclose it. An internal meeting summary, a rewritten email and a public policy article do not fall into the same category. Nor does editing something with AI mean it has been generated by AI in the legally relevant sense.

What to check. Is a named person responsible for everything you publish? If so, ordinary AI-assisted writing is unlikely to need a legal disclosure. Whether you choose to mention it anyway is a separate question, covered below.

AI helps you make decisions about people

What the rules say. Here we move well beyond content labels. In the UK, since February 2026, if a significant decision about someone (a job, credit, a service) is made solely by automated means, you must tell them about it, let them make their case, let them ask for a human to step in, and let them challenge the outcome.

The key question is whether there is meaningful human involvement. A recruiter clicking "approve" at the end of a list the system has already ranked is not, by itself, meaningful involvement.

In the EU, AI used in recruitment and employment is classed as high-risk. Those obligations have been pushed back and now apply from 2 December 2027, but they are substantial, and EU data protection law applies in the meantime.

What to check. If any system screens, scores or ranks people, write down what it decides, who reviews it and whether that review could genuinely change the result. If you cannot answer clearly, this is the area where specialist advice is worth paying for.

AI arrived inside software you already use

What the rules say. Nothing new, which is the problem. This may be the most easily overlooked example. Your organisation might have a careful process for approving new AI products, while the applications you already own quietly acquire AI features through ordinary software updates: the CRM that now summarises calls, the helpdesk that drafts replies, the recruitment system that has started ranking applicants.

The fact that a supplier provides the technology does not mean every responsibility stays with the supplier. Knowing what they have delivered is only part of the question. You also need to know what your organisation is doing with it.

What to check. Ask your main software suppliers which AI features are now switched on in your account, and what they do with your data.

Does EU law apply to a UK business?

It can. The EU AI Act reaches businesses established outside the EU when the output of their AI system is used in the EU. A Brighton company whose chatbot serves customers in Dublin, or whose marketing is aimed at buyers in France, should assume the EU rules may apply to those activities and check, rather than assuming its registered address settles the question.

The governance problem underneath

I suspect many organisations already have an AI policy. Some will have approved-tool lists, acceptable-use guidelines, governance committees and risk assessments. What I am less certain about is how many have an accurate picture of where AI is actually participating in their operations.

That is not necessarily evidence of negligence. AI capabilities increasingly arrive inside software businesses already own, and individual employees adopt useful features long before anybody thinks to update a central list. But it creates a predictable gap between the policies an organisation believes it operates under and what happens when people get on with their jobs. I have spent much of my career working in that gap, and AI governance is proving to be no exception.

The starting point does not need to be a complicated governance programme. It can be a straightforward exercise:

  • Establish where AI is being used. Include existing software and suppliers, not just dedicated AI products.
  • Understand what it does. Is it correcting, generating, talking to people, recommending or deciding?
  • Identify who is affected. Employees, customers, applicants and the public, including where they are located.
  • Establish responsibility. What the provider must do, what you must do, and who in your organisation is accountable for the outcome.

Those questions will not settle every legal interpretation, and some deployments will need specialist advice. They will tell you whether you understand enough about your own use of AI to start assessing what applies.

A ten-minute self-check

Answer these honestly. You do not need to be technical to do it.

  1. Could you list every place AI is used in your business, including features inside software you already pay for?
  2. Does any AI talk directly to customers or the public? If so, does it say that it is AI?
  3. Do you publish images, video or audio made with AI that could pass as real?
  4. Do any of your customers, users or audiences live in the EU?
  5. Does AI influence decisions about people, such as hiring, credit, access or pricing? Is there a person who genuinely reviews those decisions?
  6. For each use you listed in question 1, is a named person accountable for it?
  7. Have you asked your software suppliers which AI features they have switched on for you?

How to read your answers. If you answered "no" to question 1, start there: everything else depends on it. If you answered "yes" to questions 3, 4 or 5, look at those uses properly, and consider taking advice. If your use of AI is mostly the first kind on the list earlier (improving your own work, with a person responsible for the result), you are probably in a better position than you feared.

A worked example

To make that concrete, imagine a 25-person digital agency in Brighton. It is an illustration, not a real company, but it will feel familiar to a lot of businesses on the south coast.

The team uses ChatGPT and Copilot to draft copy, which an account director reviews before anything reaches a client. It generates images for client campaigns, including some realistic lifestyle shots for a fashion retailer that sells across Europe. It has a chatbot on its website, bought from a supplier last year. Its CRM started summarising sales calls after an update in the spring. And it recently noticed that its recruitment software now ranks applicants before anyone reads a CV.

Run it through the self-check and the picture sorts itself out fairly quickly.

  • The copywriting is the first kind of use, with a named person responsible. No legal disclosure is needed, although the agency may choose to say something to clients.
  • The campaign images need a closer look. They are aimed at EU buyers, and realistic lifestyle shots of people who do not exist could fall within the deepfake rules depending on how they are presented. In the UK, the question is whether any image misleads customers about the product.
  • The chatbot needs one check: does it tell visitors it is AI? If not, the agency should raise it with the supplier now.
  • The CRM summaries are internal. They need a named owner and a quick look at what the supplier does with the call data, but they are not a disclosure problem.
  • The recruitment ranking is the one that deserves real attention. If nobody meaningfully reviews the ranking before candidates are rejected, the agency is close to making solely automated decisions about people, with the UK safeguards that brings.

Five uses of AI, and only two need real work. That is a typical result, and a much more useful one than either "we're fine" or "we need to label everything".

Three things that get confused

It helps to keep three questions separate: what the law expressly requires, what sound governance practice suggests, and what an organisation voluntarily chooses to disclose.

Some businesses will tell customers more than the law requires because their customers value it. That is a perfectly reasonable choice, but it is a choice. I would be cautious about presenting all three as though they were legal obligations, because that creates needless anxiety. Equally, meeting the minimum disclosure requirement should not be mistaken for having dealt with every governance risk around your use of AI.

Back to the paperclip

Clippy offered to help write a letter. Today's systems can write it, research the recipient, generate the accompanying presentation and potentially send the whole thing.

It would be odd to insist that every one of those activities creates the same disclosure obligation. The legislation does not do that, and businesses should not build their understanding around the assumption that it does. The more useful question is what the AI is actually doing, who encounters the results, and what they need to understand about its involvement.

Some of those questions now have explicit legal answers. Others come down to judgement. The difficulty is that you cannot answer any of them until you know where AI is already being used.

At least Clippy made that part easy. He was almost impossible to miss.

AI helped with the research and editing of this article. The argument, and any mistakes, are mine.

This article reflects the UK and EU position as at 1 October 2026. It is a general overview for businesses, not legal advice on a particular system.

Sources and further reading

The EU rules are summarised from the Act and the European Commission's guidance; the UK points from government, regulator and legal-practice sources.

I work with organisations navigating this shift, fractionally, as an adviser, or as a trusted collaborator. See how I work →

Governance
← Back to all articles