AI Disclosure Framework: How to Build Trust Before AI Laws Force Your Hand

New York didn’t wake up one day and decide to regulate artificial intelligence. It woke up to a problem it had already been living with for years — brands quietly dropping synthetic humans into ads without telling anyone — and it reached for the bluntest tool available: a disclosure law.
As of June 9, 2026, the state of New York requires any business engaged in the business of dealing in property or services to conspicuously disclose when an advertisement contains a synthetic performer if the company has actual knowledge that one is present.
What is a Synthetic Performer?
A human-like digital asset generated by AI (GenAI) or software that engages in an audiovisual or visual performance.
N.Y. Gen. Bus. Law § 396-b
It’s a narrow law. It only covers commercial advertising, not expressive works like films or games. It exempts audio-only ads and pure translation services. It doesn’t even define what conspicuous means, where the disclosure has to live, or what it has to say. The penalties are almost quaint… $1,000 for a first offense, $5,000 after that, and no private right of action, meaning individuals can’t sue over it directly.
McDermott Will & Emery has a good practical breakdown of what it means for advertisers. Read on its own, § 396-b looks like a modest, slightly toothless statute. Read as a signal, it’s something else entirely: proof that when companies won’t tell people what’s real, legislatures eventually will.
AI Disclosure is a Pattern Worth Paying Attention To
It’s not the specific dollar amount or the specific carve-out for documentaries to pay attention to here, but the arc. A technology gets powerful enough to fool people. Some companies use it quietly, for advantage, without telling anyone. The public starts to feel deceived, even when no individual instance rises to fraud. Enough of that accumulates, and government fills the vacuum that industry declined to fill itself.
New York isn’t an outlier here — California’s SB 942, the AI Transparency Act, became operative August 2, 2026, and requires large AI platforms to offer visible disclosure options and embed machine-readable provenance watermarks in AI-generated media.
27 multinational brands representing $71 billion in combined ad spend were surveyed and found that 78% are actively using AI in marketing — and 80% of those same companies are asking, publicly, for clearer rules on when and how to disclose it.
World Federation of Advertisers
Even the businesses using the technology don’t feel confident they’re handling the transparency question correctly.
I want to make a case in this piece that the discomfort behind that 80% number is solvable — not by waiting for the next state legislature to define “conspicuous” for you, but by building a disclosure practice before anyone forces you to. And I want to make that case by starting somewhere unglamorous: we’ve been doing versions of this for decades, and most of the time nobody called it deception. We called it craft.
Reality Check: We’ve Been Tweaking Since Long Before “AI”
Every product photo on every ecommerce site has been through Photoshop — shadows corrected, backgrounds cleaned, blemishes on the packaging retouched. Every wireframe and mockup a design team has ever shown a client was built in Illustrator or Figma, an idealized, synthetic representation of something that didn’t exist yet, presented as a preview of something that eventually would. Every album you’ve ever loved was shaped in Pro Tools — pitch-corrected vocals, quantized drums, comped takes stitched together from a dozen imperfect performances into one that never actually happened in a single room at a single moment. Every podcast episode worth listening to has had its ums and dead air trimmed in GarageBand or Audition, making the speaker sound more fluent and confident than they did in the raw take.
None of that is new, and almost none of it comes with a disclaimer. Nobody expects a badge on a product photo saying background replaced. No one demands a mockup carry a footnote clarifying that the building doesn’t exist yet. The editing itself was never the ethical line. The line was always about what the audience reasonably believed they were getting, and whether the gap between that belief and reality was being exploited.
Mark Schaefer made this point sharper than I could in a piece he published the day before I started drafting this one, called I Use AI. I Am Not a Criminal. He tells the story of Maxwell Perkins, the legendary editor who spent two years cutting 90,000 words out of Thomas Wolfe’s sprawling manuscript to make it publishable — a level of intervention that, if a machine did it today, plenty of people would call cheating.
Nobody thinks Wolfe was a fraud. Perkins was doing what editors have always done. Then Schaefer draws the contrast that gives the piece its title concept: Milli Vanilli. Rob Pilatus and Fabrice Morvan didn’t get their Grammy revoked because someone helped them sound better. They lost it because they stood on stage lip-syncing vocals recorded by other, uncredited singers, and let the world believe those were their own voices in real time. That’s not editing. That’s impersonation.
Mark calls the boundary between those two situations the Milli Vanilli Line — the point where an audience stops perceiving assistance and starts perceiving substitution. His test for whether a given use of AI is fine is refreshingly simple: will this breach the trust my audience has placed in me and my brand? He also tells a smaller, sharper story about YouTuber Hank Green, whose famously tech-literate audience caught a single AI-generated sentence in one of his videos and reacted badly — not necessarily because that sentence was wrong, but because it felt like a substitution for Green’s own voice. Green’s own conclusion was blunt:
The internet does not really need more videos. It needs more of me.
Hank Green
That’s the thing Photoshop, Illustrator, Pro Tools, and GarageBand all have in common that generative AI initially doesn’t: the audience has had decades to build an intuitive, socially negotiated understanding of what those tools do and don’t change. Nobody thinks a retouched product photo is lying to them about the product existing. Generative AI hasn’t earned that same shared understanding yet — partly because it’s new, and partly because, unlike a decade of retouching, it can now originate the substance of the thing itself, not just polish it.
A retouched photo of a real product is still a photo of a real product. A synthetic performer in an ad is not a real performer at all. That’s a difference of kind, not degree, and it’s exactly why a law like § 396-b exists specifically for synthetic performers and not for, say, color correction.
The Real Problem Isn’t the Tool. It’s the Silence.
Here’s the uncomfortable part for many companies: McDermott’s summary of § 396-b and the WFA’s own numbers point to the same gap. The law was written vaguely, with no defined format, no required language, no placement rules, because the people writing it were reacting to a practice, not designing a system. They knew disclosure needed to happen. They didn’t have, and weren’t given, a model for how a business should actually think through which of its many AI-touched outputs deserve a label and which don’t.
That’s not a knock on New York’s legislature. It’s an observation that industry had the chance to build that model first, and mostly didn’t, until very recently. The IAB’s AI Transparency & Disclosure Framework is the most serious attempt so far — a risk-based approach that tries to separate AI use that’s merely assistive from AI use that materially affects authenticity, identity, or representation, and that offers advertisers a standardized visual marker (a small sparkle icon, or clear text) for the cases that clear that bar. It’s a good framework, and it’s specifically built for advertising.
What it isn’t is something a mid-sized software company, a services firm, or a media brand can pick up and apply across its entire operation (product development, marketing copy, sales enablement, customer support macros) because that was never its job.
The overwhelming majority of companies are actively exploring AI, roughly three-quarters have no AI governance framework at all, and fewer than a third have any clear policy on disclosing AI use to their own customers.
PwC
So you have a reactive, narrow regulatory patchwork (New York), a big-platform law focused on watermarking and detection tools rather than everyday business communication (California), a well-built but ad-specific industry standard (IAB), and most companies with no internal policy whatsoever. Nobody has handed ordinary businesses — the ones not buying Super Bowl ads or building foundation models — a simple, adoptable answer to How much AI did we use on this, and how do we say so plainly?
That’s the gap I want to try to fill here.
A Practical Framework: The AI Transparency Ladder
The idea is simple: instead of a binary we use AI / we don’t, give every piece of output (a product photo, a landing page, a support macro, a demo video, a sales deck) a rung on a short ladder that describes how much of it originated from a machine versus a person, and publish what that ladder means once, publicly, so every individual disclosure can just be a short label pointing back to it.
Six levels, from none to fully automated:
- Unassisted. No AI involved anywhere in the process — ideation, drafting, editing, or production. A person wrote it, shot it, designed it, or said it, start to finish. This is the baseline every other level gets measured against, and it should stay common, not become a relic.
- Assisted. AI is used only for narrow, mechanical cleanup on human-originated work — spell-check, grammar suggestions, background noise removal, auto-transcription, basic photo retouching. This is the direct modern descendant of Photoshop dodge-and-burn or a GarageBand noise gate: it changes nothing about the substance, only the polish. No disclosure is typically warranted at this level, the same way nobody expects a caption disclosing that a photo was color-corrected.
- Augmented. AI contributes meaningfully to the process, but a human originates the substance and does the real editorial work — brainstorming angles, generating a rough first-draft outline that gets substantially rewritten, producing a quick mockup a designer then rebuilds by hand. This is the Maxwell Perkins tier: heavy intervention, but the author remains unmistakably the author. Internal disclosure (a workflow note) is good practice; public disclosure is optional unless the audience would reasonably assume otherwise.
- Co-Created. AI generates a substantial share of the actual finished content — full drafts, image compositions, code scaffolding, voiceover scripts — from a detailed human brief, framework, or set of source material, and a human then reviews, verifies, edits, and takes accountability for the result before it goes out. The person didn’t originate most of the words or pixels; they directed, edited, and approved them. This is the tier where public disclosure starts to matter, because the audience’s mental model of “who made this” is genuinely different from reality if they’re not told.
- Delegated. AI produces the finished asset largely end-to-end — a synthetic voice, an AI-generated video, a digital avatar, a computer-generated performer — with a human setting the parameters and approving the output, but doing little direct editing of the content itself. This is precisely the territory § 396-b was written for, and it’s where disclosure stops being a best practice and starts becoming a legal or reputational necessity, regardless of jurisdiction.
- Autonomous. AI generates and publishes without a human reviewing the specific output before it goes live — an automated content pipeline, an AI agent responding directly to customers, a bot posting on a schedule. Full loop, no human check between generation and publication. This tier carries the highest disclosure obligation and the highest risk, and any company operating here should be able to explain, in plain language, what oversight exists around the pipeline even if no one reviews each individual output.
The point of naming these isn’t bureaucracy for its own sake. It’s that We use AI is a meaningless sentence today — nearly every business does, in some form, somewhere. The useful sentence is:
This landing page was assisted, this product demo video was co-created, our support chatbot is delegated to AI-powered tools with human escalation available.
That’s specific enough to be honest and short enough to publish. And you can define the terminology in your legal disclosure pages or documents.
Making It Real Inside a Company
A framework like this only works if it’s cheap to run, so the implementation should be boring on purpose:
- Publish a short, plain-language How We Use AI page — one paragraph explaining the ladder, one sentence per level, linked from the footer next to the privacy policy. It doesn’t need to be long. It needs to exist and be easy to find.
- Tag AI involvement at the level of workflows, not individual pieces, wherever possible. A marketing team doesn’t need to relitigate the level of every blog post; it decides Our blog process is generally assisted and augmented with AI and documents the exceptions.
- Reserve visible, in-context disclosure — a label on the asset itself, not just a policy page — for augmented and above, and treat delegated and autonomous disclosure as close to non-negotiable, independent of whether your state has a law like New York’s yet.
- Revisit the policy at least annually, because the tools and the norms around them are both moving quickly enough that last year’s boundary won’t hold.
- Apply it beyond marketing. Product screenshots showing AI-suggested features, sales collateral built from AI-summarized case studies, support macros drafted by a model — the ladder is meant to travel across the whole business, not sit inside one department’s style guide.
None of this requires waiting for federal legislation, or even for your own state to pass something like § 396-b. It requires deciding, once, as a matter of company policy, that the gap Schaefer describes… the Milli Vanilli Line between assistance and substitution… is worth drawing on purpose instead of discovering by accident after a customer notices.
What This Article Actually Is
In the spirit of the argument above, it seems dishonest to make that case without applying it to the thing you’re reading. So: this article’s central theme, the disclosure-ladder concept, the specific source articles, and the framing of we’ve always tweaked outputs, the question is disclosure all came from me — a set of instructions and a long-running writing style guide I’ve built up over time. Claude did the drafting, working from that brief and those sources, and I edited the result before publishing. By its own scale, that makes this piece roughly a Co-Created: I set the direction and did the final editorial pass; the AI produced most of the words in between.
That’s not a confession. It’s the disclosure the rest of this piece argues every company should be comfortable making. New York had to legislate a version of this only because too many companies chose silence over a sentence like the one above. It rarely is. The businesses that get ahead of that choice — that publish their own ladder before a regulator hands them one — are the ones that get to keep the trust Schaefer is talking about, instead of spending years trying to earn it back.
Note: I’m not an attorney, and this isn’t legal advice.






