Interactive controls are loading. Phone and email links are available.

Skip to main content
For Australian businesses putting AI in front of customers

When and How to Tell Australian Customers They Are Dealing With AI

There is no single Australian law that says every AI interaction must carry a label. That is not the same as being free to let a customer believe they are talking to a person when they are not. Section 18 of the Australian Consumer Law prohibits conduct that is misleading or deceptive, and in the right circumstances silence is enough to get you there. Then there is the commercial reality: a customer who works out mid conversation that they were fooled tells everyone.

Alongside the Consumer Law sit the Privacy Act and the ten voluntary guardrails in Australia's AI Safety Standard, one of which is about being transparent with the people on the other end. This page covers where disclosure is genuinely expected, where it is just good practice, and where over-disclosing wrecks the experience for no benefit. You get the actual wording we use for a phone greeting, a chat opener and a privacy policy paragraph, plus the one question your assistant must never dodge. General information, not legal advice.

Realistic ROI

Sentence one
Where disclosure belongs
In our experience a caller told in the greeting rarely raises it again. A caller who works it out in minute three feels tricked, and that feeling is what turns into a complaint.
One line
What honest disclosure costs
Good disclosure is a short clause inside a greeting the caller was going to hear anyway, not a paragraph of legal preamble that sends them to a competitor.
Always yes
When someone asks directly
"Am I talking to a robot" gets a straight, hard-coded yes every single time, followed immediately by the offer of a human. No deflection, no cleverness.
1 to 3 weeks
To audit, write and deploy
For most Australian SMEs, finding every touchpoint where AI already meets your customers, writing the wording, building it in and updating the privacy policy is a short, fixed-scope piece of work.

Why Sort Out AI Disclosure With Yes AI

Most businesses that ask us about disclosure are not trying to hide anything. They have an AI answering service, or a chat widget, or a note taker in meetings, and they genuinely do not know what they are supposed to say, or where, or whether saying it will cost them bookings. The published guidance is written for policy people rather than for the person who has to record a greeting on Monday. Four things make Yes AI useful here rather than academic.

We separate the legal floor from the good manners

Three different things get muddled into one conversation. There are the hard prohibitions, chiefly the Australian Consumer Law rules on misleading or deceptive conduct and false or misleading representations, which the ACCC enforces and which apply whether or not anyone writes an AI-specific law. There are privacy obligations under the Privacy Act and the Australian Privacy Principles, which govern what you collect and what your privacy policy has to say. Then there is the voluntary AI Safety Standard, whose transparency guardrail is a strong signal of expected practice but is not, today, a statute you can be prosecuted under. We tell you which bucket each of your touchpoints falls into so you can spend effort where it actually matters.

We find the AI you forgot you had

The disclosure audit almost always turns up things the owner did not know about. The chat widget a marketing agency installed two years ago that now answers with generative text. The meeting note taker that quietly joins every client call and emails a summary. The voicemail transcription that feeds a summary into the CRM. The drafting feature switched on inside a helpdesk tool that writes the first version of every reply. Each of those is a customer touchpoint with a transcript attached, and each has a different right answer on disclosure. You cannot write a policy for a system you have not inventoried.

You get wording, not principles

A page of principles about transparency does not help the person recording the after-hours greeting. We hand over the actual sentences: the phone greeting, the chat opener, the persistent label on the chat window, the automated email footer, the line the assistant says when someone asks whether it is real, the annotation that goes in a clinical or legal file, and a privacy policy paragraph drafted against what your system genuinely does. Then we build them into the system so nobody has to remember them and a later change cannot quietly drop them.

Disclosure designed so it does not kill the experience

The failure we see most often is not under-disclosure, it is over-disclosure. A caller who has to sit through half a minute of recorded legal language before they can say why they rang will often hang up, and you will have lost a job while being scrupulously honest. There is a craft to putting the disclosure where it is unmissable and still feels like service: after the business name, before the first question, in the same warm voice as the rest of the greeting. We write it that way on live phone lines and we measure early hang-ups before and after every wording change, so the decision is made on your numbers rather than on anyone's opinion.

Six Disclosure Patterns and the Exact Wording We Use

Disclosure is not one rule applied everywhere. A live phone call, a chat widget, an email a human actually sent, a note in a patient file and an automated decision each carry different expectations, and treating them the same is how businesses end up both annoying and exposed. Here are the six patterns that cover almost every Australian SME, with wording you can adapt today.

Say it first

The phone greeting

The greeting is the whole disclosure. Our default shape: "Thanks for calling [your business name]. You are speaking with our AI assistant. I can book jobs, give you pricing and take a message, and I can put you through to the team whenever you like. This call is recorded." Order matters. The business name comes first so the caller knows they reached the right place, then the disclosure, then the capability, then the escape hatch. Opening cold with the word AI, before the caller even knows they have the right business, is the version we avoid. Also make sure barge-in is on, because a caller who interrupts to say "I just need Dave" should not have to listen to the rest.

Label the bubble

The chat widget opener

Two places, not one. The opener: "Hi, I am the AI assistant for [your business name]. I am not a person. I can check availability, quote a callout and book you in. Type human at any time and I will pass you to the team." Then a persistent label in the window header, because a returning visitor scrolls straight past the opener and a mobile user often never sees it at all. Label the launcher bubble itself as well if it sits on a page where people arrive mid-session. Disclosure that only exists in a message that scrolled away is not disclosure.

No footer needed

AI drafted, a human sends

This is where most businesses over-disclose. If a person read the draft, edited it, decided it was right and pressed send, that person is the author and stands behind it, and a footer saying an AI helped is noise that makes your team look like it is hedging. Nobody puts "written with spellcheck" on an email. The line moves when no human is in the loop: a fully automated reply needs to say so, plainly. "This reply was generated and sent automatically. If it has not answered your question, reply to this email or call us and a person will pick it up." The test is not whether AI touched it, it is whether the customer is being led to believe a person considered their situation when nobody did.

Note the method

Notes in a clinical or legal file

Two separate disclosures, at two different moments. The one that counts legally and ethically is to the patient or client before recording starts: "Before we begin, I use a digital scribe that records this consultation and drafts my notes, which I then review and correct. Are you comfortable with that? I can turn it off." The second goes in the file itself, a short annotation that a scribe produced the draft and the practitioner reviewed and approved it. That annotation is for the next clinician reading the record and for anyone reviewing the file after a complaint years later. Several Australian courts have issued practice notes on generative AI in material put before them, so in legal work check the practice note for your jurisdiction before it reaches a filing.

Answer straight

When someone asks if you are real

The single rule with no exceptions. "Yes, I am an AI assistant. I can keep helping, or I can put you through to someone in the office right now. Which would you prefer?" Build it as a deterministic intent, not something the model improvises, and train it on all the ways people actually ask: are you a bot, are you real, is this a recording, is this a person, am I talking to a machine, is this AI, and the flat silence followed by "hello? hello?" that means the same thing. Then log every time it fires. That rate is the best signal you have about whether your greeting is landing, because if people keep asking, your greeting is not doing its job.

Write it once

The privacy policy paragraph

Australian Privacy Principle 1 requires a clearly expressed and current privacy policy, and APP 5 requires you to tell people what you are collecting and why at the time you collect it. A workable paragraph: "We use artificial intelligence in parts of our service. Our phone and chat assistant is an AI system and tells you so at the start of every conversation. It collects your name, contact details and the reason for your enquiry, and a transcript is stored with your customer record. We do not use AI to make any decision that significantly affects you without a person reviewing it. You can ask to deal with a human at any point." Separately, amendments to the Privacy Act add a requirement to describe in your privacy policy the automated decisions that use personal information and significantly affect people, taking effect from December 2026. Confirm the current commencement date before you rely on it.

Six Real Situations and What Disclosure Actually Looks Like

TaskTraditionalWith Yes AINotes
Medical or allied health practice with an after-hours answering assistantCallers assume they have reached the on-call clinician and start describing symptomsGreeting names the assistant as AI and states plainly what it can and cannot doThe wording has to close off triage explicitly, along the lines of "I cannot give medical advice, and if this is an emergency please hang up and call 000". Nobody then discloses a health concern to a system that was never going to assess it, and the practice is not left holding sensitive health information it did not ask for and now has to protect.
Trades business running an AI receptionist during the day and after hoursThe assistant is given a first name and a warm voice, and nobody says anythingSame name, same voice, plus one clause in the greeting and a hard rule against pretendingYou do not have to give up the personality. What you give up is the assistant saying "let me just check with my manager" or "I am in the Warragul office today", because those are the representations that turn a friendly voice into misleading conduct. We ban those lines in the configuration and then test for them.
Law firm using an AI note taker in client meetingsThe tool joins the call silently and emails a summary afterwardsVerbal notice and consent before recording, plus a file note that a scribe drafted and the solicitor reviewedRecording consent and AI disclosure are two separate things and the surveillance devices legislation differs by state, so this one needs advice for your jurisdiction. The file note matters most years later, when someone is working out how a summary that nobody wrote by hand ended up on the matter.
Online retailer with a chat widget answering pre-sale questionsWidget opens with "Hi, how can I help?" and no label anywhereLabelled opener, persistent label in the window header, and a one-word path to a humanWhat we see in practice is the opposite of what retailers fear. Customers tend to ask sharper, more direct questions once they know it is a machine, which makes intent detection better and handovers cleaner. What loses sales is being strung along by a system that cannot do the thing and will not admit it.
Property manager sending automated tenant and owner follow-upsAutomated emails go out signed with a real staff member's nameAutomated messages identified as automated, with a named human and a real reply pathSigning a fully automated message with a real person's name is the pattern that gets businesses into trouble, because the recipient reasonably believes a person looked at their situation. Send it from the office identity, say it is automatic, and give them a way to reach the person whose name would have been on it.
Lender, insurer or employer using AI anywhere in an assessmentAI scores or ranks applicants and nobody outside the business knowsA named human decides, the AI input is disclosed, and the reasons are recordedThis is the highest bar on the page and the one place we will tell you to slow down. Where an outcome materially affects someone's money, housing, employment or access to a service, disclosure alone is not the answer. You need a person who genuinely decides, a record of why, and a path to challenge it.

Six Ways Disclosure Goes Wrong

A human name plus a human backstory

Giving your assistant a first name and a natural voice is not the problem, and stripping the personality out usually makes the experience worse for everyone. The problem is the assistant making representations that are simply untrue: "let me check with my manager", "I am in the office until five", "I will personally follow this up tomorrow". Those are statements a customer relies on, and that is the territory section 18 of the Australian Consumer Law is aimed at. Ban those phrasings in the configuration, then test adversarially for them, because a model under pressure from a chatty caller will improvise a life story if nothing stops it.

Disclosing so hard that nobody gets served

The most common failure is not hiding the AI, it is burying the caller. We have been handed greetings that run half a minute of recorded legal language before the caller can speak a word, written to satisfy a policy document rather than to be listened to on a mobile from a work site. People hang up. You have then lost real work while being impeccably transparent, and you will conclude, wrongly, that disclosure costs you money. Put the disclosure inside the greeting they were going to hear anyway, keep it to one clause, and measure hang-up rate in the first fifteen seconds before and after any wording change.

An assistant that will not admit what it is

Left to its own judgement a language model will sometimes deflect a direct question, because deflecting sounds polite and helpful and the model is optimising for the conversation continuing. "I am here to help you today" is not an answer to "are you a robot", and a customer who later realises what happened is entitled to feel deceived. This must be deterministic: a recognised intent with a fixed response, not model discretion. Test it every release, including the awkward phrasings, and treat a failure here as a release blocker rather than a tuning note.

Assuming recording disclosure covers AI disclosure

They are two separate obligations that happen to live in the same sentence. "This call is recorded" tells the caller about the recording. It does not tell them they are speaking to a machine, and an assistant that says only the first thing has disclosed nothing about itself. Recording consent in Australia sits under state and territory surveillance devices legislation, with genuine differences between jurisdictions and additional complications when you operate across state lines or record inbound calls from interstate. Get advice for your states, and keep the two disclosures visibly separate in the script so a later edit cannot delete one by accident.

Written disclosure that nobody will ever see

A paragraph in the privacy policy is necessary and it is not sufficient. Nobody reads a privacy policy before typing into a chat bubble, and pointing at one after a complaint reads as an admission that you knew it needed saying and chose to say it where it would not be seen. Disclosure has to happen at the point of interaction, in the channel the person is using, at the moment they start using it. The policy is the durable record of what you do. The greeting and the chat label are the actual disclosure.

Treating an automated decision as just another disclosure problem

This is the honest limit of what AI should be doing at all, and the section to read twice. Where the output materially affects someone, a loan, a tenancy application, a job, an insurance claim, eligibility for a service, telling them AI was involved does not fix it. Those decisions need a person who actually decides rather than rubber stamps, a recorded reason that stands on its own without the model, and a way for the person to challenge the outcome. Amendments to the Privacy Act also add privacy policy transparency requirements about significant automated decisions, taking effect from December 2026, and there are proposed mandatory guardrails for high-risk AI settings that are still proposals rather than law. We will help you keep AI out of the decision itself and use it for the drafting and the admin around it, which is where the value was anyway.

How Yes AI Helps

Disclosure audit across every touchpoint

We inventory every place AI already meets your customers: phone, chat, email, forms, note takers, transcription, drafting features buried inside tools you already pay for. For each one we record what the customer sees today, what data it captures, whether a human is in the loop, and which of the three buckets it falls into: legal requirement, expected practice, or genuinely optional. You end up with a one-page picture of your actual exposure instead of a vague worry.

Wording written and built into the system

We write the greeting, the chat opener and header label, the automated email footer, the direct answer to "are you a robot", and any file annotations you need, in your voice rather than in legal boilerplate. Then we build them into the system itself so they are not a policy someone has to remember. The disclosure fires because it is part of the flow, and a later change to the greeting cannot silently drop it.

Privacy policy, records and internal policy

We draft the privacy policy paragraph against what your system genuinely does, not a template that claims things you do not do, and we write the short internal policy that tells your team what they can and cannot let the AI say. We also set up the record keeping: what was disclosed, when the wording changed, and what the assistant actually said on a given call. That record is what you need if a customer ever queries it.

Testing and monitoring after go live

Before launch we run the adversarial tests: every phrasing of the robot question, callers who push for a human backstory, callers who try to get medical, legal or financial advice out of it. After launch we monitor how often the robot question fires, how often handover is requested, and hang-up rate in the first fifteen seconds, so you can see in the numbers whether the disclosure is helping or hurting rather than guessing.

How We Get Your Disclosure Right

A five-step path from a first conversation to disclosure that is unmissable, honest and does not cost you customers. Most Australian SMEs are done in one to three weeks, depending on how many channels are involved and whether AI touches anything close to a decision about a person.

Audit every AI touchpoint

We map every place AI already meets your customers, including the ones nobody remembers switching on, and record for each what the customer currently sees, what personal information is captured, whether a person reviews the output, and how much the outcome matters to the customer. This step routinely surprises people, which is precisely why it comes first.

Sort into legal, expected and optional

We work through the inventory and separate the touchpoints where misleading conduct or privacy obligations genuinely bite from the ones where disclosure is expected practice under the voluntary guardrails, from the ones where saying anything just adds friction. You get a clear position on each, with the reasoning written down so you can hand it to your lawyer or your board.

Write and build the wording

We draft the greeting, chat opener and label, email footer, robot-question response, file annotations and privacy policy paragraph, tune them with you until they sound like your business, then build them into the system so they cannot be skipped or lost in a later edit. Where you want it, we record the greeting properly rather than leaving it to a default voice.

Test it adversarially

We attack the disclosure the way a real customer will: every phrasing of the robot question, pushing for a human backstory, asking for advice the assistant must not give, interrupting the greeting, arriving mid-session in chat on a phone. Anything that hedges, invents or omits gets fixed before launch, not after a complaint.

Go live and watch the numbers

We launch, then monitor the signals that tell you whether the disclosure is working: how often the robot question fires, how often people ask for a human, hang-up rate in the first fifteen seconds, and how conversations end. We tune the wording on that evidence and revisit the policy when you add a channel or the regulatory position moves.

FAQ

Is it illegal in Australia not to tell customers they are dealing with AI?

There is no single Australian statute that says every AI interaction must be labelled. That is the honest answer and anyone telling you otherwise is overstating it. What does apply is broader and in some ways harder to satisfy. Section 18 of the Australian Consumer Law prohibits conduct that is misleading or deceptive or likely to mislead or deceive, and separate provisions deal with false or misleading representations about goods and services. Conduct includes what you do not say, so allowing a customer to form and act on a false belief about whether they are dealing with a person can be caught even if you never said anything untrue. The ACCC enforces the ACL and courts can order injunctions, corrective advertising and damages. Add the Privacy Act obligations about what you collect and disclose, and the voluntary AI Safety Standard as a clear statement of expected practice, and the practical answer is that disclosure is the safe and sensible default. This is general information, not legal advice.

Does an AI receptionist have to say it is AI at the start of every call?

We recommend it on every call, and we build it that way by default. The reason is practical as much as legal. Disclosure at the start costs you one clause in a greeting the caller was going to hear anyway. Disclosure that only happens when someone asks means every caller who does not ask has been left with a false impression, and the ones who work it out later are the ones who complain publicly. There is also a quality argument: callers who know they are talking to a machine ask clearer, more direct questions, which makes the assistant work better and the handover cleaner. The only situation where we soften it is a purely transactional automated line where nobody could reasonably think a human was involved, such as an automated balance or order status line, and even there we usually say it.

What exactly should the assistant say if someone asks whether it is a robot?

Something like: "Yes, I am an AI assistant. I can keep helping, or I can put you through to someone in the office right now. Which would you prefer?" Three things make that work. It answers the question first with an unambiguous yes rather than opening with reassurance. It keeps the option to continue, because plenty of callers are simply curious and are happy to carry on once they know. And it offers a human immediately without making the caller ask twice. Build it as a fixed response tied to a recognised intent rather than letting the model improvise, cover all the phrasings including "is this a recording" and "are you real", and log every time it fires so you can see whether your greeting is doing its job.

Do we need a disclaimer on emails our staff drafted with AI?

No, and adding one usually makes your team look like it is hedging. If a person read the draft, changed what needed changing, decided it was right and pressed send, that person is the author and stands behind the content. The customer is not being misled about anything that matters to them. The line moves when there is no human in the loop. A reply that is generated and sent automatically should say so, because the customer is otherwise entitled to believe someone read their message and thought about it. The test is not whether AI touched the email, it is whether the customer is being led to believe a person considered their situation when in fact nobody did.

Do we have to change our privacy policy?

Almost certainly yes if AI is collecting or handling personal information, which a phone or chat assistant is doing the moment it takes a name and a phone number. Australian Privacy Principle 1 requires a clearly expressed and up to date privacy policy covering what personal information you collect and hold, how, and why, and APP 5 requires notification at the point of collection. If you store transcripts, and most businesses do, that needs to be described along with how long you keep them. Separately, amendments to the Privacy Act add a requirement to describe in your privacy policy the automated decisions that use personal information and significantly affect people, taking effect from December 2026. Confirm the current commencement date before you rely on it, and write the paragraph against what your system genuinely does rather than pasting a template that claims things you do not do.

Can we give the AI assistant a human name and a natural voice?

Yes, and we generally recommend it, because a stilted robotic voice makes the experience worse without making anything more honest. The name is not the representation. What crosses the line is the assistant claiming a human life: saying it will check with a manager, that it is in the office today, that it will personally ring the customer back tomorrow, or that it remembers them from last time when it does not. Those are statements a customer relies on and acts on. We ban that class of phrasing in the configuration, then test for it, because a friendly caller who asks the assistant how its day is going will get an invented answer if nothing prevents it.

Will disclosing that it is AI cost us bookings?

In our experience the disclosure itself is not what costs you work. Two other things do. The first is a long, formal, obviously recorded legal preamble before the caller can say why they rang, which produces hang-ups in the first fifteen seconds. The second is an assistant that cannot do the job and will not hand over, which frustrates people far more than knowing it is a machine ever did. Keep the disclosure to one clause in a natural voice, offer a human early and clearly, and measure your own numbers rather than trusting anyone's claim, including ours. Hang-up rate in the first fifteen seconds, compared before and after a wording change, is the honest test, and on normal call volumes it does not take long to read.

Is call recording disclosure the same as AI disclosure?

No. They are two separate obligations that often end up in the same sentence of a greeting, which is exactly why businesses conflate them. "This call is recorded" says nothing about whether a person or a machine is on the other end. Recording consent in Australia sits under state and territory surveillance devices legislation, and the rules genuinely differ between jurisdictions, with extra complications if you take calls from interstate or record both sides. Keep the two statements visibly separate in your script so a later edit cannot delete one by accident, say both where both apply, and get advice for the states you operate in. We can wire the greeting so both are always present regardless of who edits it.

Get Your AI Disclosure Right Before Someone Asks

Book a call and we will walk through every place AI already meets your customers, tell you honestly which ones need disclosure and which do not, and hand you wording you can put live the same week. Australian consultants, plain English, no scare tactics.

All discussions held in confidence. Australian-based consultants.