The One-Way Asymmetry of AI Disclosures
Last week I wrote about a video I saw on LinkedIn, where someone’s AI agent negotiated a bill with a company’s customer service agent and filed a regulatory complaint while it was doing it.
If you have shipped a customer-facing bot in the last few years, you probably had a disclosure conversation with legal. The disclosure that a user is talking to AI (or AI may be incorrect) is a common placement in the user experience. It became standard well before it was strictly required, because the alternative looked bad and nobody wanted to defend it. That instinct was right.
What I can’t find is anyone applying the same instinct in the other direction.
The rule was written with one person in mind
The EU AI Act’s transparency rules require that systems interacting directly with people be built so those people know they are dealing with an AI, and those obligations start applying in August. California has had a bot disclosure law since 2019, which covers use of a bot to mislead someone about its artificial identity in order to incentivize a purchase or sale, or to influence a vote.
I want to be upfront: I’m not a lawyer.
These rules paint the same picture. There is a consumer, and there is a company with a machine, and the worry is that the company’s machine will fool the consumer into buying something or believing something.
That’s a real worry. But are the people drafting these rules picturing a person on a customer service floor, on the receiving end of a customer’s AI agent that was told to get a credit and will keep working until it does?
Are the human agents already covered?
The EU provision is written as an obligation to inform natural persons who interact with the system. It doesn’t specifically say consumers. A customer care agent is a natural person. On a plain reading, the provider of that customer’s AI may already owe the human agent the same disclosure the law demands in the other direction.
I haven’t seen anyone build for that, either as a norm or a product requirement. The obligation may exist on paper, but do the systems people actually use reflect it?
I wonder if the disclosure to human agents is a design problem. Agent-facing tools have fields for account information and sentiment, and they presume an authorized customer is the one contacting them. None of them have a field for who or what is typing.
More importantly, if a human agent learns that they are interacting with a customer’s AI agent, what are they allowed to do differently? If they don’t have autonomy or at least methods and procedures telling them what to do, then the disclosure is just theater.
Can they ‘disconnect’ from the AI agent to avoid being harassed by it?
Can they escalate/transfer to a supervisor?
Can they sue? If so, who? On what grounds?
The visible asymmetry
We built the bot disclosure quickly, ahead of the law in some cases, because the reputational risk was obvious and the person to protect was a customer.
The logic applies to human agents, but the asymmetry is on the pressure, because the person on the receiving end is an employee. And employees don’t generate the kind of risk that changes roadmaps.
I’d rather we notice that now, while the volume is still low enough to design for, than after it becomes the normal condition of the job.
What would it take for the person taking the conversation to be told what they are talking to?
