Yes, whenever a customer who found out later would feel misled. The law forces the question in only a few places: a chatbot talking to customers in the EU, realistic AI images in advertising, a handful of US state rules. Everywhere else the choice is yours, and one test settles it. If the discovery would change how a customer feels about what they bought, tell them before it matters.
Most owners ask the question the wrong way round. They ask, "Do we have to?" The better question is, "Who would be surprised?" The damage rarely comes from using AI. It comes from a customer finding out.
Is a small business legally required to tell customers it uses AI?
Only in specific situations, and "we used AI somewhere in the business" is not one of them. What follows is the legal floor, not legal advice; if you work in a regulated profession, your regulator's rules come first.
In the EU. If you sell to customers in the EU, the AI Act's transparency rules (Article 50) require that people know when they are dealing with an AI system, such as a chatbot, and that realistic AI-made images, audio or video be disclosed. Our guide to the EU AI Act for small businesses puts these jobs on its Public shelf and explains who the rules reach.
In the UK. There is no blanket legal duty to disclose AI in advertising. The Advertising Standards Authority's guidance (ASA, 29 May 2025) asks two questions instead: is the audience likely to be misled if the use of AI is not disclosed, and if so, does the disclosure clarify the ad's message or contradict it? It adds a warning every marketer should pin above their desk: "disclosure alone is very unlikely to mitigate the harm caused by a fundamentally misleading message."
In the US. No federal rule requires a business to announce that it uses AI, but deception is still deception. When the Federal Trade Commission launched Operation AI Comply, it made plain that existing consumer protection law applies in full to AI (FTC, 25 September 2024). Some states go further. Utah's Artificial Intelligence Policy Act, as amended in 2025, requires a business to disclose generative AI when a consumer clearly and unambiguously asks, and to disclose it up front in "high-risk" interactions in regulated occupations, such as personalized financial, legal or medical advice that draws on sensitive personal information (Davis Polk, 4 April 2025). Check the state you trade in.
In your contracts. Some clients have already decided for you. Read the AI clauses in your larger client contracts before you write a word of your own policy.
Do customers actually want to know when a business uses AI?
Yes, and how much they want to know rises with how close the AI gets to the outcome.
The clearest recent evidence comes from healthcare. Pew Research Center surveyed 3,488 US adults from 22 to 28 June 2026 and found that "about seven-in-ten U.S. adults (72%) say it's extremely or very important that a doctor or other healthcare provider tells them if they're using AI in their healthcare" (Pew Research Center, 25 August 2026). Look at how the answer moves with the task. Eight in ten or more want to be told when AI is used for things that directly affect their care, such as reading scans. That falls to 72% for note-taking during an appointment, 64% for prescription refills and 56% for booking an appointment.
This is American adults talking about their health, so treat it as a pattern rather than a forecast for your customers. But the pattern is the useful part. The closer AI gets to the decision, the more people want to be told, and even for the most routine job on the list a majority still wanted to know. The same survey found that 46% were not sure whether AI had already been used in their care. Uncertainty is its own cost: a customer who suspects you used AI and was never told fills the silence with the worst version.
The Surprise Test
The Surprise Test turns that pattern into a rule a business can apply in a meeting.
The Surprise Test is how I suggest a small business decides when to tell customers it used AI: ask whether a reasonable customer who found out afterwards would be surprised in a way that changes how they feel about what they bought or what they decided. If yes, tell them before it matters, in plain words, at the point where it matters. If no, a short public statement of how you use AI is enough. The law sets the floor; the Surprise Test sets the standard.
It works because it asks about the customer, not the software. "Did AI touch this?" is a useless question in 2026, because nearly every tool a business uses now has some AI inside it, from the spell checker to the accounting package. "Would they be surprised?" separates the AI that drafted an appointment reminder, which nobody cares about, from the AI that wrote most of a "bespoke" strategy a client paid a consultant to think through.
Surprise usually hides in what the customer believes they are paying for. A client buying a professional's judgment expects the professional to have done the judging. A customer reading a handwritten-style thank-you card expects a hand. A visitor looking at "our kitchen" on a restaurant's website expects a camera, not an image generator. None of these needs a law to tell you the answer.
When should you tell customers, and when is a statement enough?
Tell customers up front wherever they meet the AI directly or are paying for a person's judgment, and let a public statement cover the rest. Here is the Surprise Test run on eight common jobs.
| The job | Would a customer be surprised to find out later? | What to do |
|---|---|---|
| A chatbot or AI voice answers customer questions | Yes, if they think it is a person | Say so in its first message and offer a person. EU law requires this for EU customers. |
| Realistic AI-made people, places or products in ads | Yes | Label it. The EU requires it; in the UK, apply the ASA's "likely to be misled" question. |
| AI touch-ups to real photos (tidied background, better light) | No, unless the product itself looks different | Website statement. Label it if what they would receive differs from the picture. |
| Emails and marketing copy drafted with AI and checked by a person | Rarely | Website statement, plus the Receipt Rule on every claim. |
| Client work (reports, advice, designs) where AI drafted part and a professional checked it | Often, if the client is paying for expertise | Say so in the proposal or engagement letter, and name who checks. |
| An AI note-taker on a call with a customer | Yes | Ask at the start of the call, every time. |
| AI that helps decide something about a person (shortlisting applicants, individual pricing, credit) | Yes | Tell them before it happens and how to reach a person. Check the law where you operate. |
| Back-office work (scheduling, invoice drafts, internal summaries) | No | Website statement. |
Notice what decided each row. It was never the tool and rarely the amount of AI involved. It was the gap between what the customer would assume and what actually happened.
What should an AI disclosure actually say?
Say what the AI does, who checks it, and what you will never use it for, in words a customer would use. The four templates below are starting points to adapt, not legal wording; fill the brackets with what is true for your business and delete anything that is not.
1. A "How we use AI" statement for your website
How we use AI. We use AI tools to help with [drafting emails and marketing, summarizing documents, scheduling]. A member of our team checks anything AI helps produce before it reaches you. We never use AI to [make final decisions about your account / give advice that a qualified person has not reviewed]. We only put your information into [approved business tools that do not use it to train AI models]. If you would like to know whether AI was used in work we did for you, ask us and we will tell you. Last reviewed: [month and year].
2. A clause for proposals and engagement letters
We use AI tools to speed up research and first drafts. Every recommendation in this work is reviewed and signed off by [name, role], who is accountable for it. Your confidential information is used only in [approved tools]. If you would prefer that we do not use AI on your work, tell us and we will agree how we proceed.
3. A chatbot's first message
Hi, I'm [name], [business]'s AI assistant. I can help with [orders, bookings, opening hours]. If you would rather talk to a person, type "person" at any time and I will pass you to the team.
4. A line for an AI note-taker
Before we start, I'd like to use an AI note-taker so I can listen rather than write. I'll check the summary and send it to you. Are you happy with that?
Two cautions. Promise only what is true today: a statement that says "a person checks everything" becomes a liability the first week nobody does. And keep the chatbot honest about what it may say; the Promise Rule covers that.
The Question to Ask Your Team
The most useful question I can give a team on disclosure is this: "Which of our customers would be surprised, and by what?"
Ask it with the whole team in the room, because the people who know the answer are rarely the ones writing the policy. In the business teams I train, the jobs that worry people most are often the ones that matter least. Staff fret about an AI-polished social post that no customer would think twice about, and say nothing about the review reply signed with a colleague's name or the note-taker that joined a client call. The front line knows where the surprises live, because the front line is where customers ask, "Did a person actually do this?"
Businesses earn trust in very different ways. Organizations as different as those I have worked with, from Kahoot! and Findel to Premier League Education, could not share one disclosure rule, and neither could a law firm and a coffee roaster. That is why the answer belongs to your business and not to a template alone. The templates above give you the words. The question gives you the list.
What does the Surprise Test look like in a real business?
Take a hypothetical 15-person landscape design firm that has started using AI in four places.
Garden visualizations. Designers turn a client's photo and the planting plan into an AI-generated image of the finished garden. Clients know a visualization is not a photograph, so the image itself is no surprise. What would surprise them is mature borders that will take five years to fill. The firm labels every image "AI visualization, planting shown at maturity" and says so out loud at the design meeting.
Quotes. AI drafts the first version of each quote from the site survey notes, and the lead designer checks every line and price. A client would shrug at this. The website statement covers it.
The booking chatbot. It books site visits and answers questions about areas covered. Its first message now says it is an AI assistant and offers a person.
Replies to reviews. AI drafts replies to online reviews, and they go out signed by the founder. This is the one that fails the test, and not because of the AI. A customer who learned the founder had never read the reply would feel misled by the signature. The fix costs nothing: the founder reads and edits every reply before it goes out, or the reply is signed by "the team."
Four jobs, one label, one changed signature, one first message and one paragraph on the website. That is what proportionate disclosure looks like.
Will telling customers you use AI make them trust you less?
Rarely, if you say it plainly and say who checks. The research on younger US consumers that we covered in our guide to AI for sales and marketing found most said knowing an ad used AI would not put them off. What puts customers off is careless work and the feeling of being deceived.
The real risk sits on the other side. As our guide to AI policies puts it: "Disclosure you choose reads as honesty. Disclosure a client discovers reads as a secret."
Disclosure can still go wrong in two ways. The first is labeling everything: stamp "AI-assisted" on every email and customers learn to ignore the label, including on the one job where it matters. The second is treating a label as a cure. The ASA's warning holds everywhere: if the message is misleading, saying AI made it does not make it honest.
What should you do this week?
- Make the list. In thirty minutes with your team, write down every place a customer meets AI or AI's work, using the table above as prompts.
- Run the Surprise Test on each line. Mark it "tell before" or "statement is enough."
- Fix the first message of any chatbot or AI phone line so it says what it is and offers a person.
- Publish your statement. Adapt template 1, put it on your website and link it from the footer.
- Update your proposal template with the clause in template 2 if you sell expertise.
- Answer "What do we tell clients?" in your one-page AI policy. It is the fourth of the One-Page Five, and this list is your answer.
- Put a review date in the diary for six months from now. Your uses of AI will have changed by then, and your statement should change with them.
Where to go next
If you want your leadership team to agree, once, what you tell customers and who decides when a new use of AI comes along, that is the kind of question my AI strategy and governance work with businesses is built to settle. If you would rather see where your business stands first, take the free Business AI Readiness Scorecard.
Sources and further reading
- Pew Research Center, "Americans want transparency when AI is used in their healthcare", 25 August 2026. Survey of 3,488 US adults, 22 to 28 June 2026. pewresearch.org
- Advertising Standards Authority, "Disclosure of AI in advertising: striking the balance between creativity and responsibility", 29 May 2025. asa.org.uk
- Federal Trade Commission, "FTC Announces Crackdown on Deceptive AI Claims and Schemes", 25 September 2024. ftc.gov
- Davis Polk, "Utah scales back reach of generative AI consumer protection law", 4 April 2025. davispolk.com
- AI for Business, "What Does the EU AI Act Mean for a Small Business Now?" business.theaieducator.io
Dan Fitzpatrick is The AI Educator: a Forbes contributor, bestselling author and keynote speaker who writes a newsletter read by more than 44,000 subscribers and hosts a daily podcast. More about Dan.



