An AI disclosure to a client should answer four questions in one or two sentences: which tool, what it was used for, what the model did and did not receive, and who remains accountable for the output. Disclosed in the engagement letter, the SOW or the MSA it is a description of method; disclosed after a client asks, the same fact reads as a concession. Several agencies require a declaration, NICE, Canada’s Drug Agency, INESSS and the EU HTA Coordination Group among them, and several others, including the FDA and EMA, publish their own AI use. Their wording is the most defensible template available, even if some of it could be called insufficiently transparent.
The disclosure nobody prepares for
There is a good body of writing on whether you must declare AI use to a journal or an HTA agency. We have written some of it ourselves. What almost nobody addresses is the conversation people actually dread, which has no rulebook at all: the client asking "did you use AI on our dossier?" And "our policy is not to use AI" does not cut it any more, because a large proportion of professionals admit to using it in a shadow form. Nor does "we only use Copilot on redacted data", which is not a final claim if it cannot be demonstrated.
A journal, and some agencies, tell you what to include as a disclaimer. A client just asks. And because there is no rule to point at, the answer tends to be improvised at the worst possible moment. We simply need a routine way of presenting the reality: AI is here to stay, so let us make it safe, and keeping a proper trace with a deep audit is the least we can do.
This page is about the wording. Which bodies require a declaration, and where it goes in a submission, is a separate guide.
The agencies asking you to declare are disclosing too
This is the part that changes how the conversation feels. Disclosure reads like confession mainly because people imagine they are the only ones doing it. They are certainly not, the bodies reviewing their work are using AI and publishing their own use, sometimes in their own words and on their own sites.
| Body | What it says about its OWN AI use | Where |
|---|---|---|
| FDA | Runs an internal generative AI tool, Elsa, launched June 2025 and since integrated with a consolidated data platform (HALO). The agency states it is built in a FedRAMP High environment and does not train on data submitted by regulated industry. | Agency announcements and trade reporting, 2025–2026 |
| EMA | Extended its AI-enabled knowledge-mining tool, Scientific Explorer, in March 2026 to help EMA and national competent authorities find information relating to initial marketing authorisation applications. Publishes an AI observatory report with the HMA and a data-and-AI workplan for 2026–2028. | EMA AI pages; HMA/EMA observatory report, June 2026 |
| NICE | Its AI delivery plan of 6 August 2026 sets out three strands, one of which is expressly using AI to improve NICE's own work. NICE also publishes a statement of intent for AI (ECD12). | NICE AI delivery plan, 6 August 2026; ECD12 |
| CDA-AMC | Its AI position statement covers internal operations alongside submitted evidence, and its Research Information Services team published a replicable process for evaluating AI search tools, having inventoried 51 of them. | CDA-AMC position statement; published evaluation, 2025–2026 |
| INESSS | An interesting take: its June 2026 submission form states that the dossier may be processed using Copilot unless the submitter objects. It is an opt-out, inside the form rather than the guidance. | “Description sommaire” form, June 2026 |
| HAS (France) | States that since 2023 it has run an internal action plan to trial and deploy AI tools supporting its activities, naming literature review, data exploitation and the analysis of dossiers: “un plan d’action interne pour expérimenter et déployer des outils d’IA en appui à ses activités (revue de littérature, exploitation de données, analyse de dossiers, etc.)”. | has-sante.fr, “Numérique et intelligence artificielle à la HAS”, updated 30 January 2026 |
| IQWiG (Germany, AMNOG) | Its General Methods state that validated machine-learning classifiers are applied in searching, “validierte Klassifikatoren aus dem maschinellen Lernen (z. B. RCT Classifier)”, and that machine-learning approaches may be used to support study selection where sufficient sensitivity is demonstrated. Its own method, in its own manual. | IQWiG Allgemeine Methoden, draft for version 8.0, 25 February 2025 |
| PMDA (Japan) | Has published an internal AI action plan, setting out reliability and security expectations for AI-based technologies and looking ahead to their use in support of increasingly complex regulatory tasks. | PMDA AI action plan (reported) |
| ANVISA (Brazil) | The most concrete of any body here: since 29 July 2025 it has formally recognised AI models as a complementary criterion in sanitary risk analysis, and it built an AI tool to speed the analysis of qualification studies for impurity and degradation limits in medicines. | ANVISA announcements, 2024–2025 |
| EU HTA Coordination Group | Adopted General Principles on the use of AI in preparing JCA dossiers on 15 July 2026. This one governs the SUBMITTER rather than describing the group’s own use, and its main message is that AI does not move accountability: the developer remains responsible for evidence, methods and conclusions. | HTACG General Principles, adopted 15 July 2026 |
Where we looked and found nothing, stated plainly
The pattern in all of them, which is your template
Read those disclosures side by side and they share a structure, or at least a common direction. Each one names tools, states the scope of use, states the limits, and keeps a human accountable. None of them apologises for using productivity tools.
We can use that. Be conservative, plan for a more regulated future, and build the template out of the regulators’ own words, which gives it a property no wording you invent can have: nobody can argue it is insufficient, because the body that would judge you wrote it. And it makes the point we would rather the field settled on: judging the user of AI should not be anybody’s goal. Preventing misuse, and the disclosure of secret and sensitive data, should be.
Four worked examples
Each of these answers the same four questions, which tool, used for what, what it did and did not receive, who is accountable, in the register the moment calls for. And each of them has to be backed by a complete audit; ours is the Untraceable Protocol.
1 · In the engagement letter, the SOW and if possible the MSA, before work starts
The best way to start is to prepare the field, and it is also the cheapest. Consultants are used to declaring subcontractors in a SOW, and AI is not so different: it sees the data when you do not redact or cloak it, it contextualises your request, and it stores, memorises and screens the content for abuse. At this point the disclosure is a description of your methodology that the client accepts, so it never becomes a disclosure at all.
"[Firm] uses AI tools for templating, drafting, summarisation, augmentation and analysis support. Client-confidential values are not transmitted to any third-party AI service. Where AI is used on material derived from Client information, confidential values are replaced before transmission, and automated breach and coverage tests are passed to confirm that no sensitive value or secret was transmitted. All AI-assisted output is reviewed and approved by the named author, who remains accountable for it. A record of AI use is retained and available to Client on request."
2 · When a client asks mid-project
The question the client is actually asking is about the possible disclosure of their information, not about whether you used AI. It sounds like "did our data leave your computer" and gets phrased as "did you use AI". Clients know by now that when a firm bans AI, people find a way to use it anyway, so their concern is the use of proper tools, not prohibition.
"Yes. We used [tool] for [drafting the background section / restructuring the economic narrative]. Your confidential values were not transmitted, because we replace every secret and sensitive value before anything is sent. Everything was reviewed by [name], who is accountable for the content. I can send you the audit of what was submitted if that is useful."
Why the offer of a record is the load-bearing part
3 · To a subcontractor or partner, which is where the exposure hides
Your obligation to your client covers everyone you delegate to. A disclosure you make confidently is worth very little if a subcontractor pasted the same document into a consumer chatbot.
"AI tools may be used for drafting and analysis support on this engagement. Client-confidential values, sensitive values and secrets must not be transmitted to any AI service, including enterprise services, unless we have authorised that specific system in writing. You must keep an audit of AI use on deliverables you provide to us for at least [##] years after the engagement, recording the tool used, the purpose, the risk assessment (which values were removed from the document) and the reviewer."
4 · The version where the architecture writes the answer
This is the disclosure we recommend when working with Untraceable and the Untraceable Protocol. When the model never receives a confidential value, secret or sensitive value, the declaration and the reassurance become the same sentence.
"AI assisted the drafting of this document, including templating, augmentation and analysis support. Confidential, secret and sensitive values were replaced with semantic and sequential markers, cloaks, on our own systems before any text was transmitted, so no confidential value was disclosed to the AI provider. The author reviewed and approved all output and remains accountable for it. A deep audit of what was cloaked is accessible through direct and free access to the Untraceable Protocol, which includes the tooling and providers used, the risk assessment, the privacy impact assessment and the signature page."
Note what these sentences do not do. They do not claim AI was not used. They do not ask anyone to trust a third party’s promise never to train on your data, or to delete its memory. They disclose the use and answer the objection in the same breath, which is the whole argument for building the record before anyone asks for it.
A view of my own: the saving should be shared
I will go further, at the risk of sounding ahead of my time. I think the disclosure should come with cost-sharing between the consultant and the client. If AI is used, the consultant gains productivity and delivers more, at better quality, and the client should see not only the quality but a quantifiable share of the gain. Where a client does not accept AI use, they should be able to say so and pay a premium for a fully human deliverable, 100%, no shadow AI, as in the old days. Where they accept it under scrutinised conditions, part of the saving should come back to them. I have put this on proposals myself, as a cost saving line. "If we are allowed to use AI, you should get some discount" is, I think, the right posture towards a client.
There is a reason I think this arrives whether anyone likes it or not, and it is not goodwill. For a large consultancy the revenue is either the hours (time and materials) or a fixed bid, with a pre-specified amount and scope, so sharing a saving means changing the way we work, and partially the way we bill. Adjusting fixed-bid projects is a no-brainer: the margin on the project rises with AI, so that difference can be shared. For time-based consulting it can be both an institutional blocker and, in some cases, feel like a cultural one, but it is fully related to the business model. Smaller boutiques do not carry that conflict: the saving is their margin, and giving part of it back is how they win the work. So the gains get taken at the small end first, quietly or openly, and the large firms end up adapting rather than choosing. Fewer hours per deliverable stops being a philosophy and becomes a condition of competing.
The part I think is clearly misread is what happens to the hours. People hear "fewer hours" and assume a smaller amount of work, a weaker pipeline, a rough year in consulting. What I see is a different type of work, an evolving one. The hours AI actually removes are typically the least valuable ones in the engagement, rereading the same deliverable because one input moved, reconciling versions, reformatting to match a template, finding the typos, rewriting to satisfy strict internal guidelines, templating the skeleton of the report, early pearl growing as you iterate through the literature to find inputs. Removing those does not thin the work, it concentrates it in a very interesting way: more time on strategy, deeper argument, and a deliverable carrying more human intelligence than ever, because the consultant was able to focus on depth instead of formatting.
Which is also why I do not think the budget shrinks in the long run. It simply moves. If production costs less, the client can finally fund what kept getting cut, the quality-of-life study nobody had room for, the ex-payer discussion that would have pressure-tested the strategy before it was submitted rather than after, the manuscript or white paper instead of the budget poster. Total spend will hold in the long run, probably with more deliverables and more quality; what falls out of it is the reformatting and the iterating. That is a better engagement for everyone in the room, and it is the version of this future I would like us to have helped along.
One aspect deserves its own guide, which we have not written yet: training and the retention of junior staff. The reduction in hours falls disproportionately on them, and that has to be faced honestly rather than waved through, though I believe the evolution ends up positive for them too.
What not to do
- Do not say "we used AI" and stop. An unscoped disclosure invites every question a scoped one answers.
- Do not offer the vendor's terms as your answer. A no-training commitment binds the vendor to you; it is not your client's permission. A real AI compliance officer will know the difference.
- Do not disclose and then hedge. "Only for minor edits" invites an audit of what counts as minor, and of whether there were confidential values in the minor thing.
- Do not assume redacting or cloaking excuses the declaration. It removes the data disclosure, not the duty to declare AI assistance. Those are different obligations to different parties, and the second one still stands. We are not here to reduce the burden of declaration. We are here to make it safe.
- Do not write a disclosure you cannot evidence with a deep audit. If you cannot produce the record when asked, the disclosure becomes the problem rather than the solution.
Related reading
- Do you have to disclose that AI wrote it? , which bodies require a declaration, and where the duty hides.
- Does AI break your NDA? , the data disclosure, which is the other half of this.
- An AI use policy you can adopt , what you decide internally, before any of this is said out loud.
- AI in US market access: what binds you today , why the duties arriving are documentation duties.
Frequently asked questions
Do I have to tell my client I used AI?
If your engagement terms or the client's own policy require it, or if you have an NDA or any clause concerning confidentiality, the answer is yes. Beyond that, the practical answer is that disclosure is cheap in advance and expensive after the fact: a line in the engagement letter costs nothing, while the same fact surfacing later reads as something that was concealed. Separately, if the deliverable is going to an HTA agency or a journal, several of them require a declaration regardless of what your client asked for. This is an orientation, not legal advice, consult your corporate counsel before relying on it.
Do regulators and HTA agencies use AI themselves?
Several say so publicly. The FDA has run an internal generative AI tool, Elsa, since June 2025, now integrated with its HALO data platform. The EMA extended its Scientific Explorer knowledge-mining tool in March 2026 to support initial marketing authorisation applications. NICE's AI delivery plan of 6 August 2026 names using AI to improve NICE's own work as one of three strands. Canada's Drug Agency covers internal operations in its AI position statement. France's HAS states it has run an internal action plan since 2023 to deploy AI tools supporting literature review, data exploitation and the analysis of dossiers. Brazil's ANVISA has recognised AI models as a complementary criterion in sanitary risk analysis since 29 July 2025. And Quebec's INESSS goes furthest in the other direction: its June 2026 submission form tells you the dossier may be processed with Copilot unless you object in the form.
What should an AI disclosure to a client actually say?
Four things, in a sentence or two: which tool, what it was used for, what it did not receive, and who is accountable for the output. Naming the tool matters more than people expect, "we used AI" invites the question, while "drafting assistance from a named tool, with no confidential values transmitted, reviewed and approved by the named author" answers it. Vagueness is what turns a disclosure into a conversation.
Does cloaking mean I no longer have to disclose AI use?
No, and this is the most common misreading. Cloaking removes the data disclosure: if the model never receives a confidential value, nothing confidential was disclosed to a third party. The duty to declare AI assistance is separate and survives untouched, because agencies and journals require it on the basis that AI helped produce the document, not on the basis of what the model saw. What cloaking changes is the cost of disclosing: you can declare the AI assistance and show, in the same breath, that no confidential value left your machine.
When is the best time to disclose AI use to a client?
Before the work starts, in the engagement letter or statement of work. At that point it is a description of your method and the client can agree to it, which means it never becomes a disclosure at all. Mid-project it is an update. After delivery, or in answer to a direct question, it is the same fact carrying the worst possible framing, and it is the version that damages the relationship, not the AI use itself.
About the author
Gabriel Tremblay, DBA, Founder & CEO, Untraceable. Gabriel holds a doctorate in business administration (DBA) specialising in decision-making, and has published health economics and outcomes research on de-identification, cloaking methods and AI writing quality. Publications and DOIs are listed on the publications page.
This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary, so review your own agreements with qualified counsel before relying on any framework described here.
Work with AI on data you can't share with it.
Untraceable cloaks confidential values on your computer before any AI model sees the text. The model never receives the secret at all.