Most product teams disclose that AI is used. Far fewer disclose what it decides, what data it uses, and how a person can contest the result.
A disclosure that says "this product uses AI" satisfies nobody. Regulators reading the EU AI Act, enterprise buyers reading your security questionnaire, and users reading your interface all want the same three facts: what the system decides, what it decides with, and what a person can do about the outcome.
Start with the decision. Name the specific action the model influences — ranking, pricing, eligibility, moderation, routing — in the surface where that action happens, not buried in a policy page. If the decision has legal or material effect, say so plainly.
Then name the inputs. You do not need to publish a feature list, but you do need to disclose categories of personal data used, whether customer content is used for training, and which subprocessors receive it. A vendor term that permits training on your customers' data is the single most common finding we raise in AI audits.
Finally, give a path out. Human review, correction, and opt-out mechanisms must be reachable from the same screen as the decision. A contact form three clicks away is not a contestation mechanism.
Write the disclosure once, then test it: hand it to an engineer and ask them to point at the code that implements each claim. Anything they cannot point at is a finding waiting to be written by someone else.
Want this checked on your product?
We run the same review across privacy, consent, accessibility, AI disclosure, and public security surfaces — and ship the remediation.
Request an audit