Treadstone Associates
Article · 7 min read

Disclosing AI in customer conversations

No Canadian statute requires a business to tell a customer they are talking to an AI system rather than a person. That does not make the question settled — Canada’s own voluntary federal guidance and its privacy regulators already treat disclosure as the baseline expectation, and ordinary deceptive-marketing law can still reach the problem indirectly, without needing an AI-specific rule at all.

Treadstone Associates · Updated 2026

Key takeaways

  • • There is no Canadian statute requiring disclosure that a customer is talking to an AI system rather than a person.
  • • ISED’s Voluntary Code of Conduct commits signatories to “ensure that systems that could be mistaken for humans are clearly and prominently identified as AI systems” — but it is voluntary and binds only its 46 named signatories.
  • • Canada’s privacy commissioners tell organisations to “ensure that system outputs that could have a significant impact on an individual or group are meaningfully identified as being created by a generative AI tool” — guidance, not law.
  • • Ordinary deceptive-marketing law does not need an AI-specific rule to reach the problem: if a business’s conduct creates a false general impression — implying a person is responding when a script is — that is assessed under the Competition Act regardless of any AI-labelling requirement.

The direct legal question — “must I tell a customer they are talking to a bot” — has a short answer in Canada: no statute says so. The more useful question is what actually governs the situation in the absence of that rule, and there is more there than the short answer suggests.

The rule that does not exist

No Canadian statute currently requires a business to label AI-generated content or disclose AI involvement in a customer interaction as a general matter. Where disclosure obligations do exist in Canadian law, they sit elsewhere and cover a narrower situation — Ontario’s Employment Standards Act, for instance, requires disclosure of AI use in screening job applicants for publicly advertised postings at employers with 25 or more employees, which is a rule about job seekers, not customers, and should not be read across into the customer-service context.

The two guidance documents that do speak to this

ISED’s Voluntary Code of Conduct on advanced generative AI commits managers of a public-facing system to a specific measure: “Ensure that systems that could be mistaken for humans are clearly and prominently identified as AI systems.” (ISED, Voluntary Code of Conduct) That is the closest thing in Canadian federal policy to a chatbot-disclosure norm, but the page is explicit about its own limits: “this code does not in any way change existing legal obligations that organizations may have.” It binds only its signatories, and it is not law.

Canada’s federal, provincial and territorial privacy commissioners take a similar position from the privacy side, telling organisations using generative AI to “ensure that system outputs that could have a significant impact on an individual or group are meaningfully identified as being created by a generative AI tool.” (OPC, generative AI principles) This, too, is guidance rather than a binding rule — but it comes from the regulators a business would actually deal with if a complaint were made.

Where ordinary deceptive-marketing law can still reach it

A business does not need a dedicated AI-disclosure statute to have a legal problem here. The general impression test asks whether a representation — “by any means whatever” — creates a false or misleading impression, and that test applies to how an interaction is presented, not only to the words exchanged in it. (Competition Bureau, the general impression test) A chat interface deliberately styled to imply a licensed human advisor is responding, when it is in fact an automated script with no such person involved, is a fact pattern that ordinary misrepresentation principles were already built to evaluate.

The wider transparency obligation behind the disclosure measure

The disclosure measure does not stand alone in ISED’s code — it sits inside a broader transparency outcome the code commits signatories to: “Sufficient information is published to allow consumers to make informed decisions and for experts to evaluate whether risks have been adequately addressed.” (ISED, Voluntary Code of Conduct) A one-line disclosure that a chat is automated satisfies the narrow measure; genuinely following the outcome the code is describing usually means also being clear about what the system can and cannot reliably help with, not just that it exists.

A narrower, real rule this is easy to confuse with

Ontario’s Employment Standards Act does require disclosure of AI use in a specific, different context: publicly advertised job postings, at employers with 25 or more employees, must state whether AI is used to screen, assess or select applicants for the position. (Ontario, ESA job posting requirements) That is a genuine statutory disclosure requirement — it is just about job applicants, not customers, and folding it into a general “Canada requires AI disclosure” claim overstates what it actually covers.

A worked example

A support chat is set up to answer as “Alex from support” without stating anywhere that Alex is an automated system. If a customer relies on something “Alex” told them and it turns out to be wrong, the absence of an AI-labelling statute does not end the analysis — the question becomes whether the overall presentation created a false general impression, and whether the business took reasonable care over what its own customer-facing system said. Neither ISED’s code nor the OPC’s principles are binding here, but both point in the same direction as the safer design choice: say plainly, somewhere in the interaction, that the customer is talking to an automated system.

Related: what happens when a chatbot promises something the business did not intend, and why language models make things up.

How a business designs disclosure into an AI-driven customer channel without undermining it is covered on the AI growth and marketing hub.

Common questions

Is a business legally required to disclose it is using AI in a customer chat?

No Canadian statute currently requires it as a general rule. ISED’s Voluntary Code and the federal, provincial and territorial privacy commissioners’ guidance both point toward disclosure as good practice, and disclosure is also the more defensible position if a false-impression complaint were ever raised under ordinary deceptive-marketing law.

What if a business discloses AI use once, in a general policy, rather than in every conversation?

Neither ISED’s code nor the OPC’s principles specify a required format or frequency — only the outcome they are aiming for, that a system which could be mistaken for a human is clearly identified. That leaves a genuine judgement call for a business, calibrated to how easily its particular system could be mistaken for a person and how significant the impact of a wrong answer would be.

Is this the same rule as Ontario’s AI-in-hiring disclosure requirement?

No — that is a separate, genuinely mandatory rule under Ontario’s Employment Standards Act, and it applies to disclosing AI use in screening job applicants, not to customer-facing conversations. The two are easy to conflate into a single “Canada requires AI disclosure” claim, which overstates what either rule actually covers.

Does the size of the business change any of this?

Neither ISED’s Voluntary Code nor the OPC’s principles set a size threshold for the disclosure measures discussed here — that is a contrast worth noting against Ontario’s hiring-disclosure rule specifically, which applies only to employers with 25 or more employees. The customer-facing guidance above is written to apply regardless of how many people the business employs.

Work out where disclosure actually belongs in a specific customer flow.

A short call is enough to walk through a chat, voice or email flow against the guidance above.