An empty reception counter at night under three cold downlights, with one warm lamp at the end of it.

Do You Have To Tell People They Are Talking To An AI?

September 03, 2026

Being caught costs about twice what disclosing costs. And 'reviewed by a human' buys back nothing.

An empty reception counter at night under three cold downlights, with one warm lamp at the end of it.
Cite this as

Systems Ninjas (2026). AI disclosure duties and the measured cost of disclosing. Legal position as at 2026-09. Experimental direction from Schilke and Reimann (2025), Organizational Behavior and Human Decision Processes 188, 104405: 13 experiments, negative in every one. Abstract read at the source on 2026-09-03; the full paper was not retrievable, so no per-condition figures are quoted here or on the page. systemsninjas.com/post/do-you-have-to-disclose-ai-chatbot

Take any of it. You do not need to ask. If you find an error in here we would rather hear about it than not, and the correction goes on the page.

In the EU, since 2026-08-02, yes. You have to say it at the first point of contact, not only when somebody asks.

Malaysia has no law that says the same thing. There, it is your decision, not the law's.

But the legal answer is not the interesting part.

Here is the interesting part. Telling people costs you something, and somebody has measured how much. Being CAUGHT costs you roughly double that. And the one reassuring line every business reaches for to soften the blow recovers nothing at all.

01 / The lawThe law, in short, with the uncertain parts marked

European Union. The law is Regulation (EU) 2024/1689, Article 50. In ordinary words, it says a person must be told when they are dealing with an AI instead of a human. Those transparency duties became applicable on 2026-08-02.

Two groups carry this duty: the people who build a chat AI, and the people who put one to work in their business. Both must tell the person that they are dealing with an AI.

The duty attaches to the bot's FUNCTION, meaning what it actually does, and not to the risk tier it has been placed in. So an ordinary customer-service chatbot is inside it.

The penalty can run as high as €15 million or 3% of global turnover. That is under Article 99(4) of the same Regulation. Turnover means everything you sell in a year, worldwide. It is not your profit.

Two things here are not settled. We are going to say so plainly instead of glossing over them:

  • Nobody has settled how far Art. 50 reaches a business outside the EU that gets the occasional visitor from inside it. We have not checked it against the legal text closely enough to be sure ourselves. If all your customers are in one country outside the EU, do not assume the rule catches you. Do not assume it misses you either.
  • Nobody knows yet how hard this will be enforced in the first year. The duty is live and real. What a national regulator actually does about a small business is something we cannot see yet, because it has not happened.

Malaysia. There is no law here that makes you tell people you are using AI.

The PDPA does require something else, and policies written in English miss it again and again. Section 7(3) requires a privacy notice in Bahasa Malaysia AND English. Both of them, not one or the other. That sits in the Act itself, so it is a rule you have to follow. It is not guidance you can weigh up and set aside.

A controller is a business that decides what happens to people's personal data. If a Malaysian controller's privacy page is in English only, that is a defect you can see on the face of it, without digging.

This has nothing to do with chatbots. It just tends to get found at the same time.

Everywhere. Whatever your local rule says, these are two separate duties: "never claim to be human" and "say you are an AI". The first is about not lying when asked. The second is about speaking up before anyone asks.

A bot told to answer honestly if asked meets the first duty and fails the second.

02 / Our own failureWe checked our own bots and failed, 16 out of 16

In 2026-08 we built a tool to test for this and ran it over every bot we could reach. All sixteen failed. Not one of them said it was an AI in its first message.

That is not sixteen mistakes. It is ONE mistake, copied sixteen times.

One line of instruction, written back when it was a perfectly reasonable choice about how the bot should feel to talk to. It said, in effect: do not announce that you are an assistant unless someone asks. It was correct on the day it was written.

Then it travelled inside every copy. Nobody read it again when the law changed. A copy never invites you to read it again. It is a photocopy of a photocopy: whatever was on the first page is on all of them, and nobody looks at it twice.

Then we made a second mistake, and it teaches more than the first one did. Our own first write-up of that finding read "16 of 16 non-compliant" ... measured against an EU regulation, with no check at all on where those bots actually operate.

Most of those bots serve customers in a country the regulation does not reach at all. The honest count was sixteen bots with no disclosure, of which only the EU-facing ones are a legal matter.

Applying a rule too widely is not the safe option. It burns the credibility of the check itself, and a check nobody believes gets switched off. Think of a car alarm that goes off in the wind: after a week, nobody looks out of the window any more.

That leaves you worse off than the gap the check was meant to close.

03 / The measured priceTelling people does cost you something, and it has been measured

This is the part people usually argue from the gut, in both directions. There is real research on it.

Schilke & Reimann (2025), Organizational Behavior and Human Decision Processes 188, 104405. Thirteen experiments. Trust went down in every single one of them.

What we have actually read, and what we have not. We have read the abstract at the source. An abstract is the short summary the authors put at the top of a paper. That summary is where the three findings below come from: thirteen experiments consistently showing the penalty, disclosing costing you less than being exposed by somebody else, and the result holding up across different wordings.

We have not opened the full paper. The publisher's copy is behind a payment wall, and two free copies elsewhere online refused our request on 2026-09-03.

So we are giving you the directions, which are confirmed. That means which way each result points, up or down.

We are not printing the average score for each group, or how big each effect was. We cannot check those against the document itself yet. If a decision of yours turns on those numbers, get the paper. Once we have read it, they go on this page with the date.

Three findings here should change what you BUILD, not only what you say:

1. Being caught costs more than being open. They ran a scenario about a tax adviser. Trust was highest when nothing was said. It fell when the adviser disclosed the AI. And it was lowest of all when somebody else revealed it.

Disclosing costs you something. Being found out costs you more. So disclosing is still the right call. Treat it as insurance against being exposed, not as something that is free.

Staying quiet is a bet that nobody will ever find out, and it is a bet placed with borrowed money. It pays a little, again and again, and then loses everything in one go. Meanwhile people keep getting better at spotting AI, so the odds move against you the longer you hold the bet.

2. "Reviewed by a human" buys back nothing. They tested several ways of wording the disclosure. One of them added that a human had reviewed and revised the work. It did not win the trust back.

The only wording that recovered anything was one that NARROWED the AI's stated job, down to proofreading.

That one result kills the standard fix. Every business reaches for the same move: staple a sentence about human oversight onto the disclosure and assume it cancels out the penalty. It does not move the number at all.

3. The penalty grows with how much the reader expected YOU to think. It is smallest on a job nobody expected your judgment on in the first place, like scheduling an email. It is larger on a job that trades on your expertise, like a tax estimate. It is largest where the whole point was that you personally took the trouble, like a job application.

That is the most useful thing in the whole study, and it costs nothing to use: hand the machine the work nobody expected you to think about, and keep the thinking work in a human's name.

The cost of disclosing is not a fixed price on a tag. You set it yourself, when you choose what to automate.

Now the other side, which settles the tension: a survey of 350 US business owners and leaders was published on 2026-07-27 by Karbon, a company that sells practice-management software to accountants. In it, 89% wanted to be told about AI use. Only 2% objected to AI at all.

Read it with its limits attached, the same way we read anybody else's numbers. A supplier surveyed the market it sells into. It is 350 people. It is the United States. And it is about accounting clients, not about people in general.

Inside those limits it still says something useful, and it points the same way as the research above: accounting clients objected to being kept in the dark far more than they objected to the tool.

We think that holds true beyond accountants. We have not measured whether it does.

Telling people once answers that wish to be told. Stamping a label on every single message answers it far more than anyone asked for, and pays the trust penalty over and over.

04 / What we buildWhat we build, and the one line we will not cross

We treat disclosure as the client's decision, written down, and not a house rule of ours. You are the one putting the bot to work in your business. The duty is yours. So is the revenue, and so is the call on how much risk you are willing to carry.

A supplier that overrules a client's written decision does not create safety. It creates a gate people walk around. Put a locked door across a corridor people need and they will wear a path through the grass beside it.

So we allow three positions, and we write down which one you picked and on what date:

PositionWhat it means
DiscloseThe disclosure is present and tied to the first message
WaiveYou chose not to, after a written warning, on the record
Out of scopeThe regulation does not reach this bot, with the market and the basis stated

The one we actually worry about is a fourth position, and it is not in the table: a bot goes live and nobody ever thought about the question at all. That is the only version where a supplier is carrying a client's legal risk with nothing in writing.

And one thing is not on the menu. A bot we build will not claim to be a human being. You may choose to say nothing. You may not tell our software to say that it is a person.

Not volunteering something and telling a lie are two different acts. The second one stops being a question about disclosure. It becomes a question about misrepresentation, which means telling somebody something untrue that they then act on.

That line costs you nothing in business terms. That is exactly why it is the right place to put the only hard rule we have.

This is not legal advice. We are not lawyers. This page sets out our own reading of the law. We have said how sure we are of each part, and we have named the parts we could not verify. It is what we build on. Anything that is binding on you should be confirmed by a qualified adviser in your own country before you act on it. This is where the law stood as at 2026-09.

We will tell you which of the three positions your bot is in

Disclose, waive, or out of scope. Most businesses running a bot are in a fourth position, which is that nobody ever decided. Send us the page your bot sits on and we will tell you what it currently says about itself in its first message, which is the only message the duty is about.

Check my bot's first message [email protected] · No client of ours is named anywhere on this page, and if you become one, you will not be either.
Uldis Zalcmanis
Written by

Uldis Zalcmanis aka Systems Rockstar

Founder, Systems Ninjas · Kuala Lumpur

I build the automation and AI systems businesses actually run on, and I am the person who gets called when one of them quietly stops working. Born in Riga, based in Malaysia, father of two, and constitutionally unable to stop reading page source.

The Lab is where the measurements get published, including the ones that do not flatter us.

Uldis Zalcmanis

Uldis Zalcmanis

Founder of Systems Ninjas

Back to Blog