Do I Need to Tell Clients or Customers When My Business Uses AI?
12 August 2026
Do I Need to Tell Clients or Customers When My Business Uses AI?
UK GDPR's transparency principle requires you to tell people when AI is processing their personal data, and Article 22 gives customers specific rights when a decision about them is made largely by automation. From 2 August 2026, the EU AI Act's Article 50 also requires any chatbot serving EU customers to identify itself as AI, with fines of up to 15 million euros for non-compliance. There is no blanket UK advertising law requiring AI disclosure, but 87% of UK consumers say businesses should disclose it anyway, so treating this as optional is a trust risk even in the situations where it is not a legal one.
What UK Law Actually Requires Today
There is no single AI disclosure law in the UK that applies to every business in every situation. What exists instead is a set of existing rules that already cover most of the situations where disclosure matters, built on top of UK GDPR rather than any AI-specific statute.
The starting point is the UK GDPR transparency principle. If an AI tool processes personal data as part of how you deliver a service, whether that is a chatbot logging enquiry details, a triage tool reading incoming emails, or a scoring model assessing an application, you have an existing legal duty under Articles 13 and 14 to tell people what is happening to their data and, in practice, that includes being clear that AI is involved in processing it. The Information Commissioner's Office has published detailed guidance on AI and data protection confirming that transparency and explainability sit at the centre of how organisations should be using AI responsibly, and its wider guidance on explaining decisions made with AI sets out what a reasonable explanation looks like in practice.
The sharper legal requirement sits in UK GDPR Article 22. If a decision about someone is made solely by automated means and has a legal effect or similarly significant effect on them, for example an automatic rejection of a credit application, a loan quote, or a job screening decision, the person has a specific right to be informed, a right to request human review, and a right to challenge the outcome. This is not a grey area. If your AI is making that kind of decision without a human genuinely in the loop, disclosure and a review route are not optional extras, they are a legal requirement you are likely already failing to meet if you have not built them in.
Outside of these two areas, for most day-to-day uses, such as AI helping draft a proposal, summarising a call, or answering a routine enquiry that a human reviews before it is sent, there is currently no separate UK statute forcing you to add a disclosure banner. That gap is closing quickly, and it closes fastest for anyone serving customers outside the UK.
The EU AI Act Change That Affects UK Businesses Too
If your business has any EU customers, this is the development to pay attention to. Article 50 of the EU AI Act became enforceable on 2 August 2026, and it is specific: any chatbot, virtual assistant, or system designed to interact with people must be built so that users are told, clearly and at the point of interaction, that they are talking to an AI rather than a human. The same article requires synthetic audio, images, video, and text content to be marked as AI-generated in certain contexts. Enforcement is not symbolic. The authority to fine businesses up to 15 million euros, or a percentage of global turnover for larger organisations, came into force on the same day as the disclosure obligation itself.
A common misconception is that UK businesses are automatically outside the scope of an EU regulation. That is not how the AI Act works. If you place an AI system on the EU market or your outputs are used within the EU, for example an English chatbot serving customers in Ireland, France, or Germany, the Act's extraterritorial reach can bring you into scope regardless of where your company is registered. If any meaningful share of your customer base is based in the EU, this is worth a proper compliance check now rather than after a complaint.
Even for businesses trading UK-only, the direction of travel is clear. The European Commission published draft guidelines in May 2026 on how the marking and labelling requirements should work in practice, and UK regulators including the ICO are actively watching this space through their own forthcoming statutory code on AI and data protection. Building disclosure habits now, before it is mandatory everywhere, is considerably cheaper than retrofitting them under regulatory pressure later.
What the Advertising Rules Say
For marketing and advertising specifically, the position in the UK is more relaxed than many businesses assume, and it is worth being precise about it rather than over-cautious. The Advertising Standards Authority and its regulatory arm, the Committee of Advertising Practice, have confirmed there is currently no blanket legal requirement in the UK to disclose the use of AI in advertisements. CAP guidance issued in 2025 was explicit on this point, while also making clear that existing rules do not disappear simply because AI was involved in creating the content.
What that means in practice is that the existing CAP and BCAP Codes apply in full to AI-generated or AI-assisted advertising exactly as they would to any other advert. If an AI-generated image misrepresents a product, if AI-written copy makes a claim you cannot substantiate, or if an AI-generated testimonial implies a real customer said something they did not, that is a straightforward Code breach regardless of the tool used to produce it. The ASA has already upheld complaints against AI-generated advertising content on exactly these grounds, treating it no differently to a photoshopped image or a scripted testimonial.
The practical takeaway for a UK small business is that you are not currently required to caption every AI-assisted social post or blog article with a disclosure label purely because AI was involved in drafting it. You are required to make sure whatever the AI produced is honest, substantiated, and not misleading, which is exactly the same bar that applied before AI existed. Where this shifts back towards disclosure is anywhere a customer might reasonably believe they are dealing with a real, specific human, such as a named team member's social profile or a review that reads as personal testimony.
Why Disclosure Is Good Business Even When It Is Not Required
Setting the legal minimum aside, the consumer research is consistent and worth taking seriously. Recent UK survey data puts the figure at 87% of consumers saying businesses should disclose when AI is being used in an interaction, and 90% believe they should always have the option to reach a real human instead. Separately, an ICO-commissioned YouGov omnibus survey (fieldwork 26-27 March 2026, n=2,157) found that 74% of UK adults had interacted with an AI chatbot, and 53% specifically want chatbots to be required to disclose that they are AI. That is a majority actively asking for the rule Article 50 is about to bring in anyway.
The gap that should concern small businesses most is the trust gap sitting underneath that adoption figure. Industry research published in mid-2026 found that while roughly three-quarters of UK consumers now use AI regularly, trust in how businesses deploy it is not keeping pace, with only around 14% of consumers comfortable with fully autonomous, agent-led AI making decisions on their behalf, and overall trust scores sitting below 45%. Adoption is not the problem. Confidence in how it is being used is.
This is precisely the gap a small, relationship-driven business can close faster than a large enterprise can. A short, honest note that a first-reply message is AI-assisted, or a chatbot that says 'I'm an AI assistant, and I can get a real person if you'd prefer' costs almost nothing to implement and directly answers what most customers say they want. Businesses that get ahead of disclosure now are treating it as a trust signal rather than a compliance burden, and that positioning becomes more valuable, not less, as AI use becomes universal and indistinguishable without being told.
A Practical Disclosure Framework for UK SMEs
Rather than treating this as a single policy decision, it works better as a short set of rules applied per use case. Four situations cover the vast majority of what a small UK business actually does with AI.
Chatbots and automated messaging: always self-identify, regardless of legal minimums. A single line, such as identifying the assistant as AI-powered with an easy route to a human, satisfies both the incoming EU AI Act requirement and the 53% of UK adults who already want it.
AI-assisted content a human reviews and sends under their own name: no disclosure is currently required by UK law, provided the content is accurate, substantiated, and not misleading under the CAP Code. Many businesses choose to be transparent about AI-assisted workflows in a general 'how we work' page rather than on every individual piece of content, which keeps the trust benefit without cluttering communications.
Automated decisions about a customer: if an AI tool is scoring, filtering, approving, or rejecting something that has a real effect on a person, for example a quote, an application, or eligibility for a service, UK GDPR Article 22 requires disclosure, a route to human review, and a way to challenge the outcome. This is the one category where getting it wrong carries direct legal exposure, not just reputational risk.
Personal data processed by AI as part of service delivery: covered by the UK GDPR transparency principle regardless of whether a decision is being made. Update your privacy notice to reflect where AI tools sit in your data processing, and make sure that update is genuinely accessible, not buried three clicks deep.
When This is NOT Right For You
If your AI use is genuinely internal, for example drafting your own notes, summarising a meeting for your own reference, or tidying an internal spreadsheet that no customer ever sees, none of this applies. Disclosure exists to protect the person on the receiving end of an interaction or decision, not to flag every tool used somewhere in your internal workflow.
It is also worth avoiding the opposite mistake of over-disclosing to the point of undermining trust rather than building it. Slapping an 'AI-generated' label on every single social post, email, or piece of marketing copy where a human genuinely reviewed and approved the final output can read as either performative or confusing, and it does not match what the research above is actually asking for. Customers are asking to know when they are dealing with AI instead of a human, not for a running commentary on every tool in your production process.
If you are a sole trader or very small business with no EU customers, no automated decision-making, and AI use limited to drafting assistance that you personally review before anything goes out, you are currently operating within the legal minimum in the UK. The recommendation to build disclosure habits now is about positioning ahead of where regulation and customer expectation are both heading, not a claim that you are currently non-compliant.
Is This Right For You?
This question matters most if your business does any of the following: runs a chatbot or automated reply system on your website or social channels, uses AI to draft or generate content customers read as coming directly from you or your team, uses AI to score, filter, or make decisions about applications, quotes, or customer requests, or processes any personal data through an AI tool as part of delivering a service.
It matters less if AI is purely an internal productivity tool, for example using it to summarise your own notes, tidy up an internal spreadsheet, or draft an email that a human then reviews, edits, and sends under their own name. The law is concerned with how AI affects the person on the other end, not with whether AI touched a task somewhere in your workflow.
If you are unsure which category a specific use case falls into, the honest test is this: would the customer feel misled if they found out later? If yes, disclose it now rather than explain it later.
Frequently Asked Questions
Do I need to disclose AI use if I only serve UK customers, not the EU?
There is no blanket UK law requiring general AI disclosure, but UK GDPR still applies. If AI processes personal data or makes a significant automated decision about a UK customer, disclosure and, in the case of automated decisions, a human review route are already required under UK GDPR Articles 13, 14, and 22, regardless of whether any EU customers are involved.
Does my chatbot legally have to say it is AI?
If you have EU customers, yes, from 2 August 2026 under EU AI Act Article 50, with fines of up to 15 million euros for non-compliance. There is no equivalent standalone UK statute yet, but 53% of UK adults surveyed by the ICO's YouGov omnibus want this to be a requirement, and it costs almost nothing to add voluntarily.
Do I have to label AI-generated blog posts or social content?
Not under current UK advertising rules, provided the content is reviewed by a human, is accurate, and does not breach the existing CAP and BCAP Codes. The ASA has confirmed there is no blanket requirement to label AI-generated ad content, but the usual rules on honesty and substantiation apply exactly as they would to any other content.
What counts as an automated decision under UK GDPR Article 22?
A decision made solely by automated means, without meaningful human involvement, that has a legal effect or similarly significant effect on someone, for example an automatic rejection of a loan, insurance quote, or job application. If a human genuinely reviews and can override the AI's output before it takes effect, Article 22's strictest requirements typically do not apply, but the transparency principle still does.
What is the simplest first step for a small business with no formal AI policy?
Add a single self-identifying line to any chatbot or automated messaging system, and update your privacy notice to mention where AI tools sit in how you process customer data. Those two changes cover the highest-risk areas (Article 22 exposure and chatbot transparency) with a few hours of work.
Does using AI to write emails to clients need to be disclosed?
Not currently under UK law, provided a human reviews the content before sending and it is accurate and not misleading. Many businesses choose to mention AI-assisted workflows generally, for example on a website 'how we work' page, rather than disclosing on every individual email, which tends to build trust without adding friction to every interaction.