Ask a room of small business owners whether they use AI in client work and nearly every hand goes up. Ask whether their clients know, and the room goes quiet. It is one of the most common unspoken anxieties in professional services right now: you are getting real value from AI, you are not doing anything wrong, and yet you have a nagging feeling that if a client found out the way you would rather they did not, it would be awkward.
That awkwardness is worth taking seriously, because it is a signal. This guide covers when disclosure is legally required, when it is commercially sensible, when it is unnecessary, and exactly how to word it.
Why this question has suddenly got harder
Two years ago, using AI in your delivery was a quiet efficiency trick. In 2026 it is table stakes, and the conversation has moved on. Three things changed at once.
Clients got AI literate. Your clients use the same tools you do. They recognise the cadence of an unedited draft. A copywriting client who pays €2,000 for a campaign and receives something they could have generated themselves in four minutes will notice — not because AI was used, but because nothing was added on top of it.
Regulation arrived. The EU AI Act introduced transparency obligations that bite in specific, narrow situations. Professional bodies in law, accountancy, healthcare and financial advice have issued their own guidance, often stricter than the law.
Procurement caught up. Larger clients now put AI questions directly into supplier questionnaires. "Do you use generative AI in the delivery of services, and if so, how is our data handled?" is standard. Getting caught out by it mid-tender is a bad way to discover you have no policy.
So the question is no longer "will anyone find out". It is "what is my position, and can I state it calmly when asked".
When disclosure is actually required
Start with the narrow set of cases where you do not have a choice. These are the ones worth getting right first, because the downside is regulatory rather than reputational.
Your contract says so. This is by far the most common binding obligation, and the most overlooked. Check the MSAs and statements of work you have already signed. Many enterprise contracts signed since 2025 contain a clause requiring notification or consent before processing client data through third-party AI systems. Some ban it outright. You may already be in breach of one without knowing.
The client is interacting with AI and might think it is a human. Under the EU AI Act's transparency rules, if you deploy a chatbot or voice agent that a person could reasonably mistake for a human, that person must be told they are dealing with an AI system. A line in the chat window opener is enough. This is the rule most SMBs actually touch, usually through a website chat widget or an AI voice agent handling inbound calls.
You are publishing synthetic media. AI-generated or materially altered images, audio and video intended to inform the public generally need to be labelled as such. If you generate a product photo or a spokesperson voiceover for a client campaign, flag it to the client and agree how it will be labelled.
Your professional body requires it. Regulated professions — solicitors, accountants, auditors, medical practitioners, financial advisers — increasingly have specific guidance on AI in client work. Check your own body's position rather than relying on general advice.
Outside these categories, there is usually no legal duty to announce that you drafted a first pass in Claude. What remains is a commercial judgement.
The tool-versus-substitute test
Here is the simplest test we have found for the discretionary cases. Ask one question: is AI a tool I used, or a substitute for the thing the client is paying for?
You do not disclose your tools. Nobody tells a client which spellchecker they use, whether the research started in Google, or that the spreadsheet has macros. If AI sits in that category — accelerating work you then review, correct, shape and take full responsibility for — it is a tool, and disclosure is optional.
It becomes a substitute when the AI output is the deliverable. If a client is paying for your expert judgement and the judgement came from a model you did not meaningfully check, that is a different transaction from the one they agreed to. The issue there is not the disclosure. It is that you are selling something other than what you promised.
A practical test: for each deliverable, ask how much would survive if you removed everything the AI produced. If the honest answer is under about 30%, you are in substitute territory.
Where the line usually falls
In our experience with consultants, agencies and professional services firms, the boundary tends to sit roughly here. Tool (no disclosure needed): research synthesis, first drafts you rewrite, meeting notes, data cleaning, code you review, brainstorming, formatting, translation you proof. Substitute (disclose, and think harder): final client-facing copy sent largely unedited, analysis or recommendations you have not independently verified, generated imagery presented as photography, and any deliverable the client believes was individually crafted for them.
The commercial case for disclosing anyway
Many firms that have no obligation to disclose now do it anyway, and it is not altruism. Disclosure, handled well, is a positioning move.
It removes the discovery risk. The damage in these situations almost never comes from the AI use itself. It comes from the client feeling they were not told. Once it is in the engagement letter, the conversation cannot be had at your expense later.
It reframes your pricing. Owners frequently worry that admitting to AI invites a discount demand. In practice the opposite framing works better: you are not billing for hours of typing, you are billing for judgement, accountability and outcomes. Saying so explicitly is the strongest defence against hourly-rate erosion. Our guide on pricing your services in the AI era covers this shift in detail.
It signals competence. A supplier with a written AI policy, a named human reviewer and a clear data-handling position reads as more professional than one who has never thought about it. In competitive tenders, this increasingly separates shortlisted from not.
How to word it: templates you can adapt
Disclosure fails when it is either buried in legalese or delivered apologetically. Aim for a confident, factual sentence that emphasises human accountability. Adapt these to your own situation and have a lawyer check anything contractual.
For an engagement letter or statement of work:
"We use AI tools to support research, drafting and analysis in the course of delivering this engagement. All outputs are reviewed, verified and approved by a named member of our team before they reach you, and we remain fully responsible for the accuracy and quality of every deliverable. We do not input your confidential information into any system that trains on that data. If you have restrictions on AI use, tell us before work begins and we will accommodate them."
For a proposal or pitch, where brevity matters:
"We use AI to work faster; we do not use it to think for us. Every deliverable is reviewed and signed off by a human, and we stand behind all of it."
For a chatbot or voice agent, where it is legally required:
"You are chatting with an AI assistant. Ask for a human at any point and we will connect you."
When a client asks you directly and you were not expecting it:
"Yes — we use it for [specific tasks]. What we don't do is send you anything we haven't checked ourselves. Happy to walk you through exactly where it sits in our process, and to adjust if you'd prefer we didn't use it on your work."
Notice the structure in each: what you use it for, who is accountable, what you protect, and an offer to accommodate. Four beats, no defensiveness.
The mistakes that cause actual damage
Disclosing in the terms and nowhere else. A clause on page nine the client never read is not a conversation. If AI is central to how you deliver, say it in the kick-off call.
Over-disclosing until it becomes the story. Some firms now lead every proposal with their AI process. The client did not hire you for your tooling. One clear paragraph, then move on to their problem.
Promising something you do not do. "Every output is reviewed by a senior consultant" is a commitment. If it is not true on a busy week, do not write it. Vague-but-true beats specific-but-aspirational.
Ignoring the data question. Clients care far more about where their information goes than about whether a draft was machine-assisted. Know which of your tools train on inputs, which offer zero-retention or enterprise terms, and be able to say so. If you have not audited this, our piece on AI data security for small business is the place to start.
Having no written policy. The single most common failure is that the owner has a clear position in their head and the team has three different ones. A one-page internal policy — which tools are approved, what data must never be entered, who reviews what — resolves this. See how to write an AI policy for your small business for a template.
A 30-minute action plan
You can close most of your exposure in one sitting.
Minutes 1–10. Search your three largest client contracts for "artificial intelligence", "machine learning", "automated" and "subcontractor". Note anything that constrains you. This is where real liability hides.
Minutes 11–20. List every AI tool in active use across your team, and for each, record whether it trains on your inputs under your current plan. Anything handling client data and lacking a zero-retention or enterprise setting goes on a fix list.
Minutes 21–30. Paste the engagement-letter clause above into your standard template, amend it to match what you actually do, and send it to whoever owns your contracts. Add one line to your kick-off call agenda: "How we use AI, and any restrictions on your side."
Then set a calendar reminder to revisit in six months. Tools change, contracts get renewed, and the regulatory picture is still moving — see our EU AI Act guide for small businesses for what is phasing in next.
The bottom line
Disclosure is only a hard question when you are unsure whether what you are delivering is what the client thinks they are buying. Resolve that first, and the disclosure becomes easy — a confident sentence about tools, accountability and data, delivered once, early, without apology. The firms getting uncomfortable about this question in 2026 are usually the ones who quietly let AI become the product. The ones who kept it as a tool, and priced their judgement accordingly, find the conversation entirely unremarkable.
Where does your business stand on AI?
Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.
Take the Free Quiz →