Workplace AI Disclosure: When You Actually Have to Say So
Intermediate7 min readWorkplace AI for Individuals

Workplace AI Disclosure: When You Actually Have to Say So

Beyond the general norm of disclosing appreciable AI use, four specific workplace triggers turn disclosure from good practice into an actual requirement: an explicit company policy clause, a client contract term, a regulatory transparency rule for systems that interact directly with people, and a formal evaluation process that asks directly. A decision framework for telling the two apart.

What you should be able to do

The general rule - disclose appreciable AI use where the distinction matters to the reader - covers most everyday work. A smaller set of workplace situations turn disclosure into an actual requirement rather than a norm: your company's written policy says so, a client contract specifies it, a regulation requires it for systems that interact directly with people, or a formal process asks you directly. Know which category you're in before you decide how much to say.

AI Expert TeamPublished: Jul 31, 2026
Saved only in this browser.
In this article

Keeping your name on AI-assisted work covers the general disclosure norm that applies across most contexts: disclose appreciable AI use where the reader would want to know and would feel misled without it. That norm is the right default for most everyday work. This article covers a narrower and more consequential question: the specific workplace situations where disclosure stops being a norm you apply with judgment and becomes something closer to a requirement - set by your employer’s policy, a client contract, a regulation, or a formal process that asks you directly.

Getting these two registers confused causes trouble in both directions. Treating an actual requirement as optional judgment risks a real compliance or contract problem. Treating the general norm as if every use of AI needs a formal disclosure process buries genuinely important disclosures in noise. The decision framework below is for telling them apart.

The four workplace-specific triggers

1. Your company’s AI policy names an explicit disclosure requirement

Some companies’ AI policies specify exactly when and how employees must disclose AI use - for a specific deliverable type, to a specific person, in a specific format. If your policy has this, it overrides your own judgment call: follow it exactly, do not improvise a version you think is close enough. Finding and reading your employer’s actual AI policy is the prerequisite step here - you cannot follow a disclosure rule you have not located and read.

2. A client contract or statement of work specifies it

Some client contracts, especially in consulting, legal, and creative-services work, specify how a deliverable must be produced or what must be disclosed about its production - including AI use. If you are not the person who owns the contract relationship, ask your manager or the account owner whether such a clause exists rather than assuming your standard practice is covered; a client-facing team can have contractual obligations that never reach an individual contributor’s desk unless someone specifically flags them.

3. A regulation requires disclosure for systems that interact directly with people

This trigger is different in kind from the other three: it is usually not a decision an individual employee makes at all, but a compliance obligation that belongs to the organization. It also splits by role, which is worth getting right before you raise it. Under the EU AI Act, from 2 August 2026, providers - the organizations that develop an AI system and place it on the market under their own name - must design and develop systems that interact directly with natural persons, such as chatbots and voice agents, so that people are informed they are interacting with AI, unless that is obvious (Article 50(1)). Providers of systems that generate synthetic audio, image, video, or text also have machine-readable marking duties under Article 50(2); for systems already on the market before 2 August 2026, that marking obligation has a limited grace period to 2 December 2026 under Article 111(4), inserted into the AI Act by Regulation (EU) 2026/1744. Deployers - organizations using such a system under their own authority - carry different duties under the same article: informing people exposed to emotion recognition or biometric categorisation systems (Article 50(3)), and labelling deepfakes and AI-generated text published to inform the public on matters of public interest (Article 50(4)) (European Commission, “Transparency obligations under Article 50 of the AI Act”; AI Act Article 50 full text). This applies to organizations in scope of the EU AI Act; other jurisdictions have different or no equivalent rules, and the specifics depend on your company’s footprint and the system’s classification.

If your work involves building, configuring, or operating something that interacts directly with customers or the public - not just using AI to help you write internally - this is a flag to raise with your compliance, legal, or product team, not a decision to make unilaterally at the individual level. Which duty applies, and whether your employer is the provider or the deployer of that particular system, is exactly the kind of question those teams exist to answer. Your role as an employee is to recognize that the trigger applies and escalate it to the people responsible for organizational compliance, not to personally determine whether your company’s specific system meets the legal bar.

If you build, configure, or operate a system that directly interacts with customers or the public using AI, and you are not certain your organization’s compliance or legal team has reviewed it against applicable transparency requirements, raise it as a specific, named question to that team rather than assuming someone else already checked. This is an organizational compliance question, not an individual judgment call.

4. A formal evaluation or process asks you directly

Some performance reviews, audits, or client intake processes include an explicit question about AI use - “did you use AI to produce this document,” “was this response AI-assisted.” When a formal process asks directly, answer honestly and specifically; do not give a vague or evasive answer to a direct question on a form, even if you would have made a different judgment call under the general norm.

The decision framework

SituationWhat governsWhat to do
Company policy names a specific disclosure ruleThe policyFollow it exactly
Client contract or SOW specifies disclosureThe contractFollow it; ask the contract owner if unsure it applies to your deliverable
Your work builds/operates something interacting directly with customers via AIApplicable regulation (in EU AI Act scope: provider duties under Article 50(1)-(2), deployer duties under 50(3)-(4))Escalate to compliance/legal - not an individual decision
A formal review, audit, or intake form asks directlyThe form/processAnswer honestly and specifically
None of the above applyThe general authorship normUse the judgment test in keeping your name on AI-assisted work

Validation and fallback

If you asked about a disclosure requirement and got an unclear or no answer, default toward more disclosure rather than less, and keep a written record that you asked - an email or message to a named person, not just a verbal conversation you cannot point back to later. This mirrors the same practice covered in finding your workplace AI policy: when the written answer is missing, ask in writing and act conservatively while you wait.

Do not treat “nobody has specifically told me to disclose this” as equivalent to “disclosure is not required.” Company policy language and regulatory requirements can lag behind actual practice, especially for a newly built customer-facing AI feature. If you have a specific reason to suspect a compliance gap - a system that talks to customers with no visible AI disclosure, for example - raise it as a named question rather than assuming silence means it was already handled.

Two ways this goes wrong

The first is assuming every AI-assisted work product needs the same level of formal disclosure, which either causes disclosure fatigue that makes people stop reading the disclosures that actually matter, or causes people to skip the genuinely required ones because they feel like just more of the same routine language. Reserve the formal, specific disclosure language for the four triggers above; use the general judgment-based norm for everything else. The distinction is not about being more or less cautious across the board - it is about matching the right level of process to the right kind of situation.

The second, specific to the regulatory trigger, is assuming that because you personally did not build the customer-facing AI system, its compliance is not your concern. If you operate, maintain, or represent a system that talks directly to customers or the public, you are well positioned to notice a gap even if you did not create it - and flagging it costs little compared to the cost of an undetected compliance issue surfacing through a customer complaint or a regulator instead.

Work through your own situation

Use the workplace AI disclosure decision guide to check your specific situation against the four triggers above before deciding how - or whether - to disclose. If none of the specific triggers apply, the general disclosure norm in keeping your name on AI-assisted work is the right one to use instead of building a formal process where none is actually required.

Read next

Continue through the same learning path with the next practical articles.