Do I need to tell users when a service uses AI?
Contrasting
Users do not always need to know the underlying stack, but if AI affects their data or outcomes you must explain that. For AI chatbots, tell users answers are not from a human and may be inaccurate, and provide a human contact route. The Data and AI Ethics Framework also recommends appropriate disclosure when AI produced an output, internally and externally. Organisational openness (including ATRS where required) still applies.
Service Manual: users need not always know the technology, but AI effects on data/outcomes (and chatbot non-human answers) must be disclosed. Playbook: be open about how and where AI is used.
How to navigate this: Disclose AI wherever it affects data or outcomes; follow chatbot rules; meet ATRS/Playbook openness obligations.
From the guidance
Primary (how) Service Manual: Using artificial intelligence (AI) in services
Section: Tell users when AI is being used
Read this in Service Manual: Using artificial intelligence (AI) in services (opens in new tab)
Secondary (normative) Data and AI Ethics Framework
Section: Recommended actions
Read this in Data and AI Ethics Framework (opens in new tab)
Secondary (normative) Code of Practice for the Cyber Security of AI
Section: Principle 10
Read this in Code of Practice for the Cyber Security of AI (opens in new tab)
Contrasting AI Playbook for the UK Government
Section: Principle 7: You are open and collaborative
Read this in AI Playbook for the UK Government (opens in new tab)
Related questions
- Do I need to tell the public when we are using AI or algorithms? Lawful, ethical and responsible use
- Do AI projects still need to meet the government Service Standard?
- Who should own cyber security risk for an AI service under Secure by Design?
- How do people challenge or seek redress for an AI-influenced decision?
- How do teams evidence Secure by Design?