Skip to main content

We use cookies to improve your experience and measure traffic. Decline to opt out of analytics and advertising cookies. Cookie preferences

For Australian businesses putting AI in front of customers

When and How to Tell Australian Customers They Are Dealing With AI

There is no single Australian law that says every AI interaction must carry a label. That is not the same as being free to let a customer believe they are talking to a person when they are not. Section 18 of the Australian Consumer Law prohibits conduct that is misleading or deceptive, and in the right circumstances silence is enough to get you there. Then there is the commercial reality: a customer who works out mid conversation that they were fooled tells everyone.

Alongside the Consumer Law sit the Privacy Act and the ten voluntary guardrails in Australia's AI Safety Standard, one of which is about being transparent with the people on the other end. This page covers where disclosure is genuinely expected, where it is just good practice, and where over-disclosing wrecks the experience for no benefit. You get the actual wording we use for a phone greeting, a chat opener and a privacy policy paragraph, plus the one question your assistant must never dodge. General information, not legal advice.

Realistic ROI

Sentence one
Where disclosure belongs
In our experience a caller told in the greeting rarely raises it again. A caller who works it out in minute three feels tricked, and that feeling is what turns into a complaint.
One line
What honest disclosure costs
Good disclosure is a short clause inside a greeting the caller was going to hear anyway, not a paragraph of legal preamble that sends them to a competitor.
Always yes
When someone asks directly
"Am I talking to a robot" gets a straight, hard-coded yes every single time, followed immediately by the offer of a human. No deflection, no cleverness.
1 to 3 weeks
To audit, write and deploy
For most Australian SMEs, finding every touchpoint where AI already meets your customers, writing the wording, building it in and updating the privacy policy is a short, fixed-scope piece of work.

Why Sort Out AI Disclosure With Yes AI

Most businesses that ask us about disclosure are not trying to hide anything. They have an AI answering service, or a chat widget, or a note taker in meetings, and they genuinely do not know what they are supposed to say, or where, or whether saying it will cost them bookings. The published guidance is written for policy people rather than for the person who has to record a greeting on Monday. Four things make Yes AI useful here rather than academic.

We separate the legal floor from the good manners

Three different things get muddled into one conversation. There are the hard prohibitions, chiefly the Australian Consumer Law rules on misleading or deceptive conduct and false or misleading representations, which the ACCC enforces and which apply whether or not anyone writes an AI-specific law. There are privacy obligations under the Privacy Act and the Australian Privacy Principles, which govern what you collect and what your privacy policy has to say. Then there is the voluntary AI Safety Standard, whose transparency guardrail is a strong signal of expected practice but is not, today, a statute you can be prosecuted under. We tell you which bucket each of your touchpoints falls into so you can spend effort where it actually matters.

We find the AI you forgot you had

The disclosure audit almost always turns up things the owner did not know about. The chat widget a marketing agency installed two years ago that now answers with generative text. The meeting note taker that quietly joins every client call and emails a summary. The voicemail transcription that feeds a summary into the CRM. The drafting feature switched on inside a helpdesk tool that writes the first version of every reply. Each of those is a customer touchpoint with a transcript attached, and each has a different right answer on disclosure. You cannot write a policy for a system you have not inventoried.

You get wording, not principles

A page of principles about transparency does not help the person recording the after-hours greeting. We hand over the actual sentences: the phone greeting, the chat opener, the persistent label on the chat window, the automated email footer, the line the assistant says when someone asks whether it is real, the annotation that goes in a clinical or legal file, and a privacy policy paragraph drafted against what your system genuinely does. Then we build them into the system so nobody has to remember them and a later change cannot quietly drop them.

Disclosure designed so it does not kill the experience

The failure we see most often is not under-disclosure, it is over-disclosure. A caller who has to sit through half a minute of recorded legal language before they can say why they rang will often hang up, and you will have lost a job while being scrupulously honest. There is a craft to putting the disclosure where it is unmissable and still feels like service: after the business name, before the first question, in the same warm voice as the rest of the greeting. We write it that way on live phone lines and we measure early hang-ups before and after every wording change, so the decision is made on your numbers rather than on anyone's opinion.

Six Disclosure Patterns and the Exact Wording We Use

Disclosure is not one rule applied everywhere. A live phone call, a chat widget, an email a human actually sent, a note in a patient file and an automated decision each carry different expectations, and treating them the same is how businesses end up both annoying and exposed. Here are the six patterns that cover almost every Australian SME, with wording you can adapt today.

Say it first

The phone greeting

The greeting is the whole disclosure. Our default shape: "Thanks for calling [your business name]. You are speaking with our AI assistant. I can book jobs, give you pricing and take a message, and I can put you through to the team whenever you like. This call is recorded." Order matters. The business name comes first so the caller knows they reached the right place, then the disclosure, then the capability, then the escape hatch. Opening cold with the word AI, before the caller even knows they have the right business, is the version we avoid. Also make sure barge-in is on, because a caller who interrupts to say "I just need Dave" should not have to listen to the rest.

Label the bubble

The chat widget opener

Two places, not one. The opener: "Hi, I am the AI assistant for [your business name]. I am not a person. I can check availability, quote a callout and book you in. Type human at any time and I will pass you to the team." Then a persistent label in the window header, because a returning visitor scrolls straight past the opener and a mobile user often never sees it at all. Label the launcher bubble itself as well if it sits on a page where people arrive mid-session. Disclosure that only exists in a message that scrolled away is not disclosure.

No footer needed

AI drafted, a human sends

This is where most businesses over-disclose. If a person read the draft, edited it, decided it was right and pressed send, that person is the author and stands behind it, and a footer saying an AI helped is noise that makes your team look like it is hedging. Nobody puts "written with spellcheck" on an email. The line moves when no human is in the loop: a fully automated reply needs to say so, plainly. "This reply was generated and sent automatically. If it has not answered your question, reply to this email or call us and a person will pick it up." The test is not whether AI touched it, it is whether the customer is being led to believe a person considered their situation when nobody did.

Note the method

Notes in a clinical or legal file

Two separate disclosures, at two different moments. The one that counts legally and ethically is to the patient or client before recording starts: "Before we begin, I use a digital scribe that records this consultation and drafts my notes, which I then review and correct. Are you comfortable with that? I can turn it off." The second goes in the file itself, a short annotation that a scribe produced the draft and the practitioner reviewed and approved it. That annotation is for the next clinician reading the record and for anyone reviewing the file after a complaint years later. Several Australian courts have issued practice notes on generative AI in material put before them, so in legal work check the practice note for your jurisdiction before it reaches a filing.

Answer straight

When someone asks if you are real

The single rule with no exceptions. "Yes, I am an AI assistant. I can keep helping, or I can put you through to someone in the office right now. Which would you prefer?" Build it as a deterministic intent, not something the model improvises, and train it on all the ways people actually ask: are you a bot, are you real, is this a recording, is this a person, am I talking to a machine, is this AI, and the flat silence followed by "hello? hello?" that means the same thing. Then log every time it fires. That rate is the best signal you have about whether your greeting is landing, because if people keep asking, your greeting is not doing its job.

Write it once

The privacy policy paragraph

Australian Privacy Principle 1 requires a clearly expressed and current privacy policy, and APP 5 requires you to tell people what you are collecting and why at the time you collect it. A workable paragraph: "We use artificial intelligence in parts of our service. Our phone and chat assistant is an AI system and tells you so at the start of every conversation. It collects your name, contact details and the reason for your enquiry, and a transcript is stored with your customer record. We do not use AI to make any decision that significantly affects you without a person reviewing it. You can ask to deal with a human at any point." Separately, amendments to the Privacy Act add a requirement to describe in your privacy policy the automated decisions that use personal information and significantly affect people, taking effect from December 2026. Confirm the current commencement date before you rely on it.

Six Real Situations and What Disclosure Actually Looks Like

TaskTraditionalWith Yes AINotes
Medical or allied health practice with an after-hours answering assistantCallers assume they have reached the on-call clinician and start describing symptomsGreeting names the assistant as AI and states plainly what it can and cannot doThe wording has to close off triage explicitly, along the lines of "I cannot give medical advice, and if this is an emergency please hang up and call 000". Nobody then discloses a health concern to a system that was never going to assess it, and the practice is not left holding sensitive health information it did not ask for and now has to protect.
Trades business running an AI receptionist during the day and after hoursThe assistant is given a first name and a warm voice, and nobody says anythingSame name, same voice, plus one clause in the greeting and a hard rule against pretendingYou do not have to give up the personality. What you give up is the assistant saying "let me just check with my manager" or "I am in the Warragul office today", because those are the representations that turn a friendly voice into misleading conduct. We ban those lines in the configuration and then test for them.
Law firm using an AI note taker in client meetingsThe tool joins the call silently and emails a summary afterwardsVerbal notice and consent before recording, plus a file note that a scribe drafted and the solicitor reviewedRecording consent and AI disclosure are two separate things and the surveillance devices legislation differs by state, so this one needs advice for your jurisdiction. The file note matters most years later, when someone is working out how a summary that nobody wrote by hand ended up on the matter.
Online retailer with a chat widget answering pre-sale questionsWidget opens with "Hi, how can I help?" and no label anywhereLabelled opener, persistent label in the window header, and a one-word path to a humanWhat we see in practice is the opposite of what retailers fear. Customers tend to ask sharper, more direct questions once they know it is a machine, which makes intent detection better and handovers cleaner. What loses sales is being strung along by a system that cannot do the thing and will not admit it.
Property manager sending automated tenant and owner follow-upsAutomated emails go out signed with a real staff member's nameAutomated messages identified as automated, with a named human and a real reply pathSigning a fully automated message with a real person's name is the pattern that gets businesses into trouble, because the recipient reasonably believes a person looked at their situation. Send it from the office identity, say it is automatic, and give them a way to reach the person whose name would have been on it.
Lender, insurer or employer using AI anywhere in an assessmentAI scores or ranks applicants and nobody outside the business knowsA named human decides, the AI input is disclosed, and the reasons are recordedThis is the highest bar on the page and the one place we will tell you to slow down. Where an outcome materially affects someone's money, housing, employment or access to a service, disclosure alone is not the answer. You need a person who genuinely decides, a record of why, and a path to challenge it.

Six Ways Disclosure Goes Wrong

A human name plus a human backstory

Giving your assistant a first name and a natural voice is not the problem, and stripping the personality out usually makes the experience worse for everyone. The problem is the assistant making representations that are simply untrue: "let me check with my manager", "I am in the office until five", "I will personally follow this up tomorrow". Those are statements a customer relies on, and that is the territory section 18 of the Australian Consumer Law is aimed at. Ban those phrasings in the configuration, then test adversarially for them, because a model under pressure from a chatty caller will improvise a life story if nothing stops it.

Disclosing so hard that nobody gets served

The most common failure is not hiding the AI, it is burying the caller. We have been handed greetings that run half a minute of recorded legal language before the caller can speak a word, written to satisfy a policy document rather than to be listened to on a mobile from a work site. People hang up. You have then lost real work while being impeccably transparent, and you will conclude, wrongly, that disclosure costs you money. Put the disclosure inside the greeting they were going to hear anyway, keep it to one clause, and measure hang-up rate in the first fifteen seconds before and after any wording change.

An assistant that will not admit what it is

Left to its own judgement a language model will sometimes deflect a direct question, because deflecting sounds polite and helpful and the model is optimising for the conversation continuing. "I am here to help you today" is not an answer to "are you a robot", and a customer who later realises what happened is entitled to feel deceived. This must be deterministic: a recognised intent with a fixed response, not model discretion. Test it every release, including the awkward phrasings, and treat a failure here as a release blocker rather than a tuning note.

Assuming recording disclosure covers AI disclosure

They are two separate obligations that happen to live in the same sentence. "This call is recorded" tells the caller about the recording. It does not tell them they are speaking to a machine, and an assistant that says only the first thing has disclosed nothing about itself. Recording consent in Australia sits under state and territory surveillance devices legislation, with genuine differences between jurisdictions and additional complications when you operate across state lines or record inbound calls from interstate. Get advice for your states, and keep the two disclosures visibly separate in the script so a later edit cannot delete one by accident.

Written disclosure that nobody will ever see

A paragraph in the privacy policy is necessary and it is not sufficient. Nobody reads a privacy policy before typing into a chat bubble, and pointing at one after a complaint reads as an admission that you knew it needed saying and chose to say it where it would not be seen. Disclosure has to happen at the point of interaction, in the channel the person is using, at the moment they start using it. The policy is the durable record of what you do. The greeting and the chat label are the actual disclosure.

Treating an automated decision as just another disclosure problem

This is the honest limit of what AI should be doing at all, and the section to read twice. Where the output materially affects someone, a loan, a tenancy application, a job, an insurance claim, eligibility for a service, telling them AI was involved does not fix it. Those decisions need a person who actually decides rather than rubber stamps, a recorded reason that stands on its own without the model, and a way for the person to challenge the outcome. Amendments to the Privacy Act also add privacy policy transparency requirements about significant automated decisions, taking effect from December 2026, and there are proposed mandatory guardrails for high-risk AI settings that are still proposals rather than law. We will help you keep AI out of the decision itself and use it for the drafting and the admin around it, which is where the value was anyway.

How Yes AI Helps

Disclosure audit across every touchpoint

We inventory every place AI already meets your customers: phone, chat, email, forms, note takers, transcription, drafting features buried inside tools you already pay for. For each one we record what the customer sees today, what data it captures, whether a human is in the loop, and which of the three buckets it falls into: legal requirement, expected practice, or genuinely optional. You end up with a one-page picture of your actual exposure instead of a vague worry.

Wording written and built into the system

We write the greeting, the chat opener and header label, the automated email footer, the direct answer to "are you a robot", and any file annotations you need, in your voice rather than in legal boilerplate. Then we build them into the system itself so they are not a policy someone has to remember. The disclosure fires because it is part of the flow, and a later change to the greeting cannot silently drop it.

Privacy policy, records and internal policy

We draft the privacy policy paragraph against what your system genuinely does, not a template that claims things you do not do, and we write the short internal policy that tells your team what they can and cannot let the AI say. We also set up the record keeping: what was disclosed, when the wording changed, and what the assistant actually said on a given call. That record is what you need if a customer ever queries it.

Testing and monitoring after go live

Before launch we run the adversarial tests: every phrasing of the robot question, callers who push for a human backstory, callers who try to get medical, legal or financial advice out of it. After launch we monitor how often the robot question fires, how often handover is requested, and hang-up rate in the first fifteen seconds, so you can see in the numbers whether the disclosure is helping or hurting rather than guessing.

How We Get Your Disclosure Right

A five-step path from a first conversation to disclosure that is unmissable, honest and does not cost you customers. Most Australian SMEs are done in one to three weeks, depending on how many channels are involved and whether AI touches anything close to a decision about a person.

Audit every AI touchpoint

We map every place AI already meets your customers, including the ones nobody remembers switching on, and record for each what the customer currently sees, what personal information is captured, whether a person reviews the output, and how much the outcome matters to the customer. This step routinely surprises people, which is precisely why it comes first.

Sort into legal, expected and optional

We work through the inventory and separate the touchpoints where misleading conduct or privacy obligations genuinely bite from the ones where disclosure is expected practice under the voluntary guardrails, from the ones where saying anything just adds friction. You get a clear position on each, with the reasoning written down so you can hand it to your lawyer or your board.

Write and build the wording

We draft the greeting, chat opener and label, email footer, robot-question response, file annotations and privacy policy paragraph, tune them with you until they sound like your business, then build them into the system so they cannot be skipped or lost in a later edit. Where you want it, we record the greeting properly rather than leaving it to a default voice.

Test it adversarially

We attack the disclosure the way a real customer will: every phrasing of the robot question, pushing for a human backstory, asking for advice the assistant must not give, interrupting the greeting, arriving mid-session in chat on a phone. Anything that hedges, invents or omits gets fixed before launch, not after a complaint.

Go live and watch the numbers

We launch, then monitor the signals that tell you whether the disclosure is working: how often the robot question fires, how often people ask for a human, hang-up rate in the first fifteen seconds, and how conversations end. We tune the wording on that evidence and revisit the policy when you add a channel or the regulatory position moves.

FAQ

Get Your AI Disclosure Right Before Someone Asks

Book a free call and we will walk through every place AI already meets your customers, tell you honestly which ones need disclosure and which do not, and hand you wording you can put live the same week. Australian consultants, plain English, no scare tactics.

All discussions held in confidence. Australian-based consultants.