Current through August 13, 2026
Introduction
Artificial intelligence is moving rapidly from the technology department into ordinary business operations. Companies use AI to answer customer questions, generate advertisements, screen applicants, summarize records, recommend products, detect fraud, produce reports, create synthetic voices and images, and perform tasks through increasingly capable automated agents.
That expansion creates a basic question:
When should a business tell someone that artificial intelligence is being used?
There is no single answer, and there is no general United States rule requiring every AI-assisted sentence, image, calculation, or internal process to carry an “AI-generated” label. The answer may depend on what the system does, whether a person could reasonably misunderstand its role, whether it affects an important decision, what information it uses, where the affected person is located, and which federal, state, local, sectoral, contractual, or platform requirements apply.
Transparency is also not the same as legality. A disclosure may help prevent deception, set expectations, or satisfy a specific notice rule. But a label ordinarily does not cure a false advertisement, discriminatory decision, privacy violation, unauthorized use of a person’s likeness, unlawful robocall, breach of contract, or unsafe deployment.
The practical framework for this Codex is:
What does the AI do? Who is affected? What would a reasonable person expect? What disclosure, consent, explanation, or human review is required or appropriate?
CAUTIONARY NOTE: EUROPEAN UNION AND OTHER FOREIGN LAW
This Codex addresses selected United States legal and business considerations concerning artificial-intelligence transparency and disclosure. Artificial-intelligence systems, services, data, or outputs that are offered, deployed, received, or used outside the United States may be governed by the European Union Artificial Intelligence Act, the General Data Protection Regulation, or other foreign laws and regulatory requirements, even when the business is organized or headquartered in the United States.
This Codex does not analyze or provide advice concerning European Union law or the law of any other foreign jurisdiction. CorwinLaw does not provide legal advice or representation concerning foreign-law matters. A business with foreign operations, customers, employees, users, data, vendors, systems, or outputs should consult an attorney properly qualified and authorized to advise on the laws of each applicable foreign jurisdiction. The business should obtain that advice before deploying the relevant AI system or relying on this Codex to evaluate international activities.
1. What Does “AI Transparency” Mean?
AI transparency can describe several different practices. They should not be treated as interchangeable.
Disclosing that AI is being used
A business may tell a customer that a chatbot, voice agent, or automated system is not a human. This helps the person understand the nature of the interaction and decide whether to continue, ask for a human, or verify the response.
Explaining the AI system’s role
In a consequential setting, simply saying “AI was used” may not be enough. A person may need to know whether the system merely organized information, recommended an outcome, ranked candidates, or effectively determined the result.
Identifying AI-generated or AI-altered content
A business may identify an image, voice, video, testimonial, demonstration, or report as synthetic or materially altered. The appropriate disclosure will depend on whether the content could mislead a reasonable audience.
Providing notice about data practices
An AI disclosure does not necessarily explain what data is collected, inferred, retained, shared, or used for model training. Those issues may require separate privacy notices or consent.
Providing an explanation or avenue for review
Where AI materially affects a decision, transparency may include the principal reasons for the decision, the categories of data used, a way to correct inaccurate data, or a meaningful opportunity for human review.
Technical marking
Metadata, content credentials, watermarks, and other machine-readable signals can help identify synthetic content. But technical marking and a disclosure understandable to a person are different. One does not automatically substitute for the other.
2. There Is No Single U.S. AI Disclosure Rule
The U.S. framework is fragmented. Relevant obligations may arise from:
- federal consumer-protection law;
- advertising and endorsement rules;
- telemarketing and communications law;
- state chatbot or bot-disclosure statutes;
- employment laws governing automated decision tools;
- privacy and biometric laws;
- anti-discrimination laws;
- rights of publicity and laws governing digital replicas;
- election and political-advertising rules;
- sector-specific laws governing finance, housing, insurance, healthcare, education, or legal services;
- contracts with customers, vendors, licensors, and business partners; and
- platform terms, advertising policies, or marketplace rules.
Section 5 of the Federal Trade Commission Act prohibits unfair or deceptive acts or practices in or affecting commerce. That established rule applies to AI-related representations just as it applies to other business claims. A company should not make unsupported claims about an AI product’s accuracy, independence, capabilities, safety, bias, privacy, or human equivalence, and it should consider whether omitting the AI’s material role would mislead a reasonable consumer. 15 U.S.C. § 45
The practical consequence is important: a business should not begin with “Do we use AI?” It should begin with “Which use, affecting whom, in which jurisdiction, and for what purpose?”
3. When Should a Business Consider Disclosure?
A business should conduct a focused review when one or more of the following conditions exists.
A person may reasonably believe the system is human
This is the clearest chatbot and voice-agent concern. Human names, realistic voices, photographs, typing indicators, emotional language, or claims of personal experience can make a system appear human. If that impression matters to the interaction, disclosure may be legally required or prudent.
AI materially creates or alters content
The more an image, recording, demonstration, testimonial, or report appears to depict reality, the greater the need to ask whether the audience should be told that it is synthetic or materially altered.
AI affects a consequential decision
Hiring, credit, housing, insurance, education, healthcare, legal services, and access to essential services deserve heightened review. Applicable law may require notice, an explanation, an assessment, correction rights, an appeal, or human review.
AI collects or infers sensitive information
A person may be told that AI is present but still not understand that the system analyzes facial geometry, voice characteristics, location, health information, financial data, emotion, attention, or behavior. A separate privacy and consent analysis may be necessary.
Nondisclosure could make another statement misleading
A technically true statement can still mislead when material context is omitted. A synthetic testimonial, simulated product result, fabricated spokesperson, or AI-generated “customer” may create a false impression even if no sentence expressly says the person or event is real.
Another rule or agreement requires it
A disclosure duty may come from a specific statute, regulation, customer contract, vendor agreement, professional rule, collective-bargaining obligation, platform policy, or advertising standard.
4. AI Chatbots, Virtual Assistants, and Autonomous Agents
Customer-facing AI is now common on websites, telephone systems, messaging platforms, mobile applications, and social-media accounts. These systems can answer questions, recommend products, schedule appointments, generate quotes, collect information, and sometimes take actions.
Avoid human impersonation
A business should review whether the system:
- uses a human name without explaining that it is automated;
- claims personal experience, feelings, credentials, or authority it does not have;
- uses a cloned or realistic voice associated with an actual person;
- implies that a live employee reviewed the response when none did;
- claims to be a lawyer, healthcare provider, financial professional, or other licensed professional; or
- conceals automation in a context where the distinction would matter.
California, for example, prohibits certain uses of bots to communicate online with the intent to mislead another person about the bot’s artificial identity for specified commercial or election-related purposes unless the bot’s use is disclosed clearly and conspicuously. This does not mean every automated California communication requires the same disclosure; the statutory elements and context matter. California Business and Professions Code §§ 17940–17943
Colorado enacted broader provisions requiring disclosure when an AI system intended to interact with consumers does so, subject to an exception where the artificial nature would be obvious to a reasonable person. Colorado has also enacted special rules for conversational AI services, including disclosures beginning January 1, 2027, and additional protections where the operator knows a user is a minor. C.R.S. § 6-1-1704; C.R.S. § 6-1-1708
Provide a practical path to a human
Disclosure without escalation can be frustrating or dangerous. A business should decide:
- when a user may request a human;
- which subjects require immediate transfer;
- whether a human is actually available;
- what happens outside business hours;
- how urgent safety, fraud, legal, or complaint issues are handled; and
- whether the AI must stop rather than continue improvising.
Limit authority
Customer-facing agents should not be given unrestricted authority to:
- enter or amend contracts;
- promise refunds, credits, warranties, or legal outcomes;
- alter payment or banking instructions;
- waive rights;
- send legal notices;
- make regulated recommendations;
- disclose confidential information; or
- access new systems without authorization.
Meaningful human review must be timely, informed, and capable of stopping the action, not merely a person clicking “approve.”
5. AI-Generated Text
Not every AI-assisted sentence needs a label. Businesses have long used spelling tools, templates, mail merges, recommendation engines, and automated drafting aids. The more useful question is whether the AI’s role is material to the audience’s understanding or decision.
Lower-risk examples
Disclosure may be less likely to be material when AI is used only to:
- correct spelling or grammar;
- reformat text;
- summarize internal notes for human review;
- generate preliminary brainstorming that a knowledgeable person independently verifies and rewrites; or
- translate routine internal material, subject to appropriate accuracy and confidentiality controls.
Higher-risk examples
Closer review is appropriate where AI:
- creates public reports or claimed expert analysis;
- writes a product review, testimonial, or endorsement;
- generates personalized financial, health, employment, or legal information;
- fabricates quotations, sources, statistics, or customer experiences;
- responds directly to complaints or disputes;
- makes claims about product performance; or
- generates content that a reasonable reader would believe came from a specifically identified professional or executive.
Human review does not erase the AI’s role if the review is superficial. The business remains responsible for what it publishes under its name.
6. Images, Audio, Video, and Synthetic Media
Synthetic media presents a heightened transparency risk because people tend to believe what they see and hear.
A business should scrutinize:
- AI-generated product photographs;
- virtual models or spokespeople;
- synthetic customer-service voices;
- cloned executive or employee voices;
- altered before-and-after images;
- simulated product demonstrations;
- generated event footage;
- digital replicas of real people; and
- realistic people who do not exist.
Ask what the audience is likely to believe
An obviously stylized illustration generally creates a different risk from a realistic video purporting to show an actual product test. A fictional mascot differs from an avatar presented as a satisfied customer. A licensed voiceover differs from a cloned executive’s voice used without clear authority.
Technical marking is not always enough
Machine-readable metadata and content credentials can be useful. But many consumers will never inspect them, and they may be removed through screenshots, editing, compression, or reposting. Where disclosure to a person is required or appropriate, it should be clear, conspicuous, timely, and understandable in the medium used.
California’s AI Transparency Act, operative August 2, 2026, establishes technical and disclosure-related obligations for specified providers and large online platforms concerning generative-AI content. Its detailed definitions, coverage thresholds, and duties matter; businesses should not assume that every ordinary user of a generative tool is subject to every provider obligation. California AI Transparency Act
7. Deepfakes, Digital Replicas, and Impersonation
“Deepfake” is often used broadly to describe realistic synthetic or altered media. The legal analysis should be more precise.
Ask:
- Does the content depict an identifiable real person?
- Was the person’s name, voice, image, likeness, or persona used?
- Was permission obtained, and does it cover this use?
- Does the content imply endorsement, participation, or authorship?
- Is the content commercial, political, satirical, educational, or news-related?
- Could the content facilitate fraud or confuse customers, employees, investors, or the public?
- Is disclosure required under a state law, contract, union agreement, platform rule, or advertising standard?
A disclosure does not necessarily cure lack of authorization. Labeling a cloned celebrity voice “AI-generated” does not itself create permission to use it. The same is true for employees, executives, customers, influencers, and deceased personalities whose rights may be governed by applicable state law and contract.
8. Advertising, Endorsements, Reviews, and Product Claims
AI does not create an exception to ordinary advertising law.
Claims about AI must be supportable
Businesses should be careful with words such as:
- “accurate”;
- “unbiased”;
- “fully autonomous”;
- “human-level”;
- “guaranteed”;
- “secure”;
- “private”;
- “compliant”;
- “clinically proven”; or
- “eliminates human error.”
The claim should match actual performance under relevant conditions. Limitations should not be hidden in technical documentation if the headline creates a materially different impression.
Synthetic testimonials are especially risky
The FTC’s Consumer Reviews and Testimonials Rule became effective October 21, 2024. It addresses prohibited practices involving fake or false reviews and testimonials, including certain representations by persons who do not exist. The FTC has explained that there is no blanket ban on every AI-generated avatar in marketing, but the use can still be deceptive depending on the message and context. FTC, Consumer Reviews and Testimonials Rule, Questions and Answers
A business should not create a synthetic “customer” who appears to describe an experience that never occurred. A disclaimer may not neutralize the overall misleading impression.
Endorsement disclosures must fit the medium
Where a material connection or other qualifying information must be disclosed, the disclosure should be difficult to miss and understandable. A hyperlink, profile page, or brief flash may be inadequate depending on the context. AI-generated influencer content should be reviewed under the same basic truthfulness and disclosure principles as human-generated advertising. FTC, Endorsement Guides, What People Are Asking
9. AI-Generated Voices and Telephone Communications
Businesses using synthetic voices for outbound calls should not assume that AI avoids laws governing artificial or prerecorded voices.
The FCC has ruled that AI-generated human voices fall within the Telephone Consumer Protection Act’s restrictions on calls using an “artificial or prerecorded voice.” Consent and other TCPA requirements may therefore apply depending on the call, recipient, number, and purpose. Businesses should separately review telemarketing rules, do-not-call requirements, caller identification, recording-consent laws, and state restrictions. FCC Declaratory Ruling on AI-Generated Voices
Do not confuse a proposal with a final rule. The FCC has considered additional AI-specific disclosure proposals, but a business should verify the current rule before treating a proposed requirement as binding.
10. AI-Assisted Decisions Affecting People
Transparency becomes more important when AI affects an individual’s livelihood, finances, housing, education, healthcare, insurance, legal services, or access to essential opportunities.
The business should identify whether the AI:
- merely organizes information;
- recommends an outcome;
- ranks or scores people;
- changes the terms offered;
- triggers additional scrutiny;
- excludes a person from consideration; or
- effectively determines the result.
Employment tools
New York City prohibits covered employers and employment agencies from using an automated employment decision tool to screen candidates or employees unless specified conditions are met. These include a recent bias audit and public availability of certain audit information. The law also requires advance notice concerning use of the tool and the job qualifications and characteristics it will assess, with additional data information available in specified circumstances. N.Y.C. Admin. Code § 20-871
The law does not mean every spreadsheet, keyword search, or ordinary office tool is necessarily covered. Definitions, implementing rules, location, and actual use matter.
High-impact systems
Colorado’s framework illustrates a more comprehensive model for “high-risk” AI used in consequential decisions. Among other things, the statutory structure addresses risk management, impact assessments, consumer notice, adverse-decision explanations, data correction, appeal opportunities, and, where technically feasible, human review. The statute has been amended and contains multiple operative dates and versions; businesses should verify the current text before implementation. C.R.S. § 6-1-1703
Disclosure is not a substitute for nondiscrimination
Telling an applicant that AI is being used does not authorize discriminatory screening. The system, data, criteria, accommodations, validation, monitoring, and human process must be reviewed under applicable civil-rights and employment laws.
11. Emotion Recognition, Biometrics, and Sensitive Inferences
Some systems claim to infer emotion, attention, engagement, stress, truthfulness, impairment, or intent from a person’s face, voice, movements, or behavior. These claims may be scientifically contested, context-dependent, and legally sensitive.
A business considering such a system should ask:
- What exactly is measured?
- Is the system identifying a person or analyzing behavior?
- Does it create or use a biometric identifier or template?
- What evidence supports the claimed inference?
- Are accuracy rates reliable across relevant populations and conditions?
- Is the use necessary and proportionate?
- What notice or consent is required?
- How long is the data retained?
- Is the information shared or used for model training?
- Can an affected person challenge the result?
- Is the use prohibited or restricted in this context?
Disclosure alone is not enough. A clearly disclosed system can still be inaccurate, discriminatory, invasive, contractually prohibited, or unlawful.
12. Privacy Notices, Consent, and Customer Data
An “AI in use” message is not a complete privacy notice.
Businesses should map:
- information supplied by the user;
- information imported from other systems;
- inferred traits, scores, or predictions;
- conversation logs and recordings;
- prompts and outputs;
- human access to those materials;
- service-provider access;
- model-training and product-improvement uses;
- retention and deletion periods;
- geographic transfers; and
- incident-response obligations.
The company’s privacy notice, consent mechanism, customer contract, vendor agreement, and actual practices should align. A vendor’s statement that it “does not train on customer data” should be verified against the contract, product configuration, subprocessor terms, and current documentation.
Businesses should also avoid placing privileged, confidential, trade-secret, regulated, or personal information into AI tools without approval and appropriate safeguards.
13. What Makes a Disclosure Effective?
A useful disclosure should be designed for the person who receives it, not merely for the file.
Clear
Use plain language. “You are chatting with an automated AI assistant” is generally clearer than “technology-assisted engagement experience.”
Conspicuous
Do not hide a material disclosure in lengthy terms, a footer, an unrelated privacy policy, or text that is difficult to see or hear.
Timely
Give the disclosure before it affects the person’s decision or before sensitive information is collected, not after the interaction is complete.
Appropriate to the medium
A telephone disclosure should be audible. A video disclosure should remain visible long enough to be understood. A chatbot disclosure should appear where the interaction begins. An accessibility-compatible alternative should be available.
Accurate
Do not overstate or understate what the AI does. If the system does more than answer routine questions, say so where that additional role is material.
Persistent when necessary
A single disclosure may be forgotten during a long interaction, especially if the system becomes more human-like or changes functions. Some laws may prescribe repeated or persistent disclosures for covered uses.
Connected to a real remedy
Where appropriate, explain how to reach a human, correct information, appeal a decision, report an error, or complain.
14. Your AI Vendor Does Not Necessarily Handle Compliance for You
A vendor can provide tools, documentation, and contractual commitments. It cannot automatically eliminate the customer’s independent obligations.
Before deployment, determine:
- who is responsible for the user-facing disclosure;
- who decides the system’s intended purpose;
- who configures prompts, thresholds, tools, and integrations;
- who tests the system in the actual deployment context;
- who monitors output and complaints;
- who preserves logs;
- who handles access, correction, appeal, or deletion requests;
- who reports incidents;
- who responds to regulators and litigation; and
- who bears the cost when the system changes or fails.
Contract provisions to review
Vendor agreements should be evaluated for:
- accurate descriptions of capabilities and limitations;
- permitted and prohibited uses;
- compliance cooperation;
- data ownership, confidentiality, and security;
- model-training rights;
- subprocessors and data locations;
- audit and verification rights;
- logging and evidence preservation;
- notice of model, feature, policy, and subprocessor changes;
- infringement and third-party claims;
- indemnification;
- limitations of liability;
- suspension and termination rights;
- transition assistance; and
- incident notification and remediation.
A contract may allocate costs between vendor and customer, but it does not necessarily prevent a regulator or affected person from asserting that the deploying business violated its own duties.
15. Product-Change Management
AI systems can change without a traditional product launch. A vendor may replace the underlying model, modify safety controls, add voice or vision capabilities, connect external tools, alter retention, or enable autonomous actions.
Reassessment should be triggered by changes to:
- the underlying model;
- training, fine-tuning, or retrieval sources;
- system prompts;
- user population;
- geographic availability;
- sensitive-data access;
- biometric or emotion-related features;
- external tools and permissions;
- autonomous functions;
- output-marking mechanisms;
- retention or model-training practices;
- the intended purpose; or
- the consequences of an error.
A chatbot approved to provide store hours should not automatically be treated as approved to negotiate contracts, recommend financial products, screen applicants, or access customer accounts.
16. Meaningful Human Review
“A human is involved” is not a complete control.
Meaningful review generally requires a reviewer who:
- has appropriate training and subject-matter knowledge;
- receives enough information to understand the issue;
- has sufficient time to review it;
- knows the system’s limitations;
- can identify missing information and errors;
- is authorized to disagree with the AI;
- can stop or reverse the action; and
- documents significant overrides or approvals when appropriate.
Warning signs of ineffective review include:
- automatic approval of nearly every output;
- reviewers measured only on speed;
- no access to source information;
- no ability to alter the result;
- unclear responsibility;
- no escalation path; and
- reliance on the AI’s own explanation as the sole verification.
17. Documentation and Evidence Preservation
A business should be able to reconstruct what happened and why.
For material systems, retain appropriate records of:
- the system and version used;
- owner and responsible department;
- intended and prohibited uses;
- vendor documentation;
- data sources and categories;
- testing and validation;
- approved disclosure language;
- where and when disclosure appears;
- human-review procedures;
- permissions and integrations;
- relevant prompts, configurations, and tool calls;
- material outputs and decisions;
- complaints, incidents, corrections, and overrides;
- model or feature changes; and
- periodic reassessments.
Recordkeeping should be coordinated with privacy, security, litigation-hold, regulatory-retention, and data-minimization requirements. “Preserve everything forever” is not a sound policy.
18. Practical Examples
Example 1: E-commerce shopping assistant
A website assistant recommends products and answers routine questions. The business should consider a clear opening statement that the user is interacting with an AI assistant, prohibit invented product claims, provide a human escalation path, and preserve appropriate records. If the assistant accesses account or purchase history, privacy and security controls also matter.
Example 2: Automotive dealership chatbot
A dealership uses AI to schedule service, answer inventory questions, and collect financing leads. The system should not invent vehicle availability, prices, incentives, credit terms, warranties, recall information, or repair advice. It should identify itself, distinguish estimates from binding terms, protect customer information, and transfer regulated or disputed issues to trained personnel.
Example 3: Synthetic spokesperson
A business creates a realistic spokesperson who does not exist. The legal review should address whether the presentation could be mistaken for a real customer, employee, expert, or endorser. If the avatar makes testimonial or expert claims, merely labeling it synthetic may not cure deception.
Example 4: AI-generated marketing campaign
A marketing agency creates images, copy, voices, and product demonstrations. The company should verify factual claims, permissions, likeness rights, music and content rights, endorsement disclosures, platform requirements, and whether the synthetic nature is material to the audience.
Example 5: Applicant-screening system
An employer uses AI to score résumés and recorded interviews. It should identify the jurisdictions involved, determine whether automated-employment-tool rules apply, examine disability accommodations and discrimination risks, validate relevant criteria, provide required notices, and establish genuine human review.
Example 6: White-labeled AI product
A SaaS company sells an assistant under its own name using another company’s model. It should not assume the model provider handles user disclosures, customer contracts, monitoring, logs, or regulatory responses. Branding, modification, and control over intended use may affect responsibility.
Example 7: AI-generated public report
A company publishes an AI-assisted market report under an executive’s name. A qualified person should verify calculations, citations, quotations, methodology, and conclusions. Whether AI disclosure is appropriate depends on the role AI played and what readers would reasonably understand, but the company remains responsible for the publication.
Example 8: AI voice appointment agent
An automated voice calls customers to schedule appointments. The company must analyze federal and state calling restrictions, consent, do-not-call rules, identification and disclosure requirements, recording laws, and vendor practices. A realistic voice does not avoid artificial-voice regulation.
19. A Practical Implementation Checklist
Inventory
- Identify approved and unapproved AI tools.
- Include embedded AI in existing software.
- Identify business owners, vendors, versions, and integrations.
- Record the intended and actual use.
Classify
- Is the system customer-facing, employee-facing, or public-facing?
- Does it make or influence consequential decisions?
- Does it use sensitive, confidential, privileged, or biometric information?
- Does it create realistic synthetic media?
- Can it take actions outside the chat window?
Map geography and audience
- Where is the business operating?
- Where are customers, applicants, employees, and users located?
- Where is data processed?
- Could foreign law apply?
Review disclosures
- Is AI identity material?
- Is the system’s role accurately described?
- Is the disclosure clear, conspicuous, timely, accessible, and appropriate to the medium?
- Is a separate privacy notice or consent required?
- Is repeated or persistent disclosure necessary?
Establish controls
- Restrict high-impact actions.
- Require meaningful human authorization.
- Create escalation and complaint procedures.
- Test for errors, bias, security, and manipulation.
- Preserve appropriate logs and evidence.
Review contracts
- Confirm vendor representations.
- Allocate disclosure and response responsibilities.
- Address data use, security, changes, audit, cooperation, indemnification, and liability.
- Ensure the contract matches the configured product.
Train and reassess
- Train employees by role.
- Prohibit unauthorized tools and uses.
- Review incidents and complaints.
- Reassess after material changes.
- Confirm that legal materials remain current.
20. Myth Versus Reality
Myth: “Every AI-generated item needs a label.”
Reality: There is no single universal U.S. rule requiring every AI-assisted output to be labeled. The answer depends on applicable law, the use, audience, jurisdiction, medium, and risk of deception or harm.
Myth: “No U.S. law requires AI disclosure.”
Reality: Targeted federal, state, and local rules can require notice or disclosure in particular contexts, including certain bots, employment tools, consequential decisions, synthetic content, and communications.
Myth: “Our vendor handles compliance.”
Reality: The vendor may have its own obligations, but the business choosing, configuring, and deploying the system may retain independent responsibilities.
Myth: “A website disclaimer covers every use.”
Reality: A disclosure must be appropriate to the particular interaction. A general footer may not adequately disclose a chatbot, synthetic testimonial, consequential-decision system, or sensitive data practice.
Myth: “If we disclose the AI, the use is lawful.”
Reality: Disclosure ordinarily does not cure deception, discrimination, privacy violations, infringement, unauthorized likeness use, unlawful calling, professional-practice restrictions, or contractual breaches.
Myth: “A human clicking approve solves the problem.”
Reality: Oversight must be informed and meaningful. A reviewer who lacks time, information, training, or authority may be only a nominal safeguard.
Myth: “Internal AI creates no transparency issue.”
Reality: Internal systems can affect employees, applicants, confidential information, business records, and consequential decisions. Notice, consent, labor, privacy, discrimination, and governance questions may still arise.
Myth: “Metadata and human-facing disclosure are the same.”
Reality: Technical signals may assist detection, but they may not communicate anything understandable to an ordinary person.
Myth: “Calling a product ‘AI-powered’ proves it works.”
Reality: AI terminology is a marketing claim, not validation. The business should substantiate performance and describe material limitations accurately.
Myth: “Once reviewed, the system stays approved.”
Reality: Models, features, data, integrations, users, and purposes change. Material changes should trigger reassessment.
21. What U.S. Businesses Should Do Now
Businesses do not need to panic merely because they use AI. They do need a repeatable process.
- Inventory AI systems, including tools employees adopted informally.
- Identify what each system actually does and what data it uses.
- Determine who is affected and where they are located.
- Classify customer-facing, synthetic-media, sensitive-data, and consequential-decision uses.
- Review applicable federal, state, local, sectoral, contractual, and platform rules.
- Design clear disclosures, privacy notices, consent, explanations, and review procedures where required or appropriate.
- Restrict actions that require human authorization.
- Test claims, accuracy, bias, security, and foreseeable misuse.
- Contract carefully with vendors.
- Train employees and assign ownership.
- Document decisions, versions, controls, incidents, and changes.
- Reassess periodically and after material changes.
Conclusion
The goal of AI transparency is not to place an “AI” sticker on everything. It is to prevent material misunderstanding, comply with applicable requirements, protect affected people, and build systems that can be explained and governed.
A business should focus on six questions:
What does the system do? Who receives or is affected by its output? What data does it use? What would a reasonable person expect? Which laws and agreements apply? What meaningful control exists when the system is wrong?
Disclosure is one component of responsible AI governance, not a substitute for accuracy, fairness, privacy, security, authorization, contractual discipline, or human judgment.
Because AI systems and the governing law are changing rapidly, businesses should periodically reassess their practices and consult CorwinLaw at https://www.corwinlaw.net regarding applicable United States legal issues.
Important Legal and Tax Notice
This Codex is provided by CorwinLaw, www.corwinlaw.net, for general educational and informational purposes only. It is not legal, tax, accounting, cybersecurity, technical, or financial advice and is not a substitute for advice concerning a particular business, technology, or deployment.
Artificial-intelligence laws and regulatory guidance are developing rapidly and vary by jurisdiction, industry, technology, data, and use. This Codex is not a 50-state survey and does not determine whether any particular AI system, disclosure, automated decision process, or business practice complies with applicable law. Disclosure that AI is being used does not, by itself, make the underlying use lawful, accurate, fair, secure, non-discriminatory, or non-infringing.
Reading this Codex, visiting a website, or contacting CorwinLaw does not create an attorney-client relationship. An attorney-client relationship arises only through a written engagement agreement accepted by CorwinLaw and the client. Do not send confidential or time-sensitive information unless and until CorwinLaw confirms that it represents you.
Businesses should consult appropriate legal, privacy, cybersecurity, tax, accounting, insurance, and technical professionals. CorwinLaw can assist with applicable United States legal issues involving AI governance, commercial contracts, disclosures, data-use provisions, advertising, risk allocation, incident response, and compliance planning.
The CorwinLaw Codex
Explore additional legal guides, practical resources, and practice-area reference materials at:
