Make AI Disclosure Boring
Your people are hiding their AI use. They are responding to the incentives you gave them.
More than half of employees hide their use of AI and present AI-generated work as their own. That figure comes from a global study led by the University of Melbourne with KPMG, covering 48,340 people across 47 countries. Fifty-seven per cent of employees said they concealed their AI use.
Most organisations read that as a dishonesty problem. Staff are doing something they should not, hiding it and needing to be caught. I read it first as an incentive problem.
The evidence supports that reading. In one preregistered experiment reported in a working paper, 1,026 participants assessed identical code attributed either to an AI-assisted or non-AI-assisted engineer. The experiment also varied the engineer's gender. Engineers believed to have used AI received competence ratings nine per cent lower, and the penalty was larger for women. Field data from 28,698 engineers at one company also showed lower adoption among women and mature-age employees. The working paper is here. A separate series of four experiments involving 4,439 people found that employees who use AI anticipate and receive negative judgements about their competence and motivation, and that those judgements also affected hiring decisions. The researchers called it a social evaluation penalty for using AI. The study was published in PNAS.
Your staff have understood the incentive. Say nothing and the work may be assessed without an AI-related penalty. Disclose AI assistance and risk being assessed as less competent, less diligent or less deserving of credit.
Hiding it is not right. It is rational. That distinction matters, because punishment alone is unlikely to fix an incentive problem. It may simply make concealment better.
This piece is the argument. The practical guidance is in MI-GUIDE-001, AI Disclosure and Use, the free manager guide being published alongside it, which includes a staff-notice template ready to adapt and route through normal internal approval.
The polite word is shame
Using AI often does not feel like real work, and disclosing it can feel like admitting the work is not really yours. Many people who have drafted with these tools have felt some version of that pull, and I include myself. The first answer arrives in seconds. It sounds polished. The empty page is gone. Somewhere underneath the relief is the question: if the machine helped this much, what exactly did I do?
In the humanitarian and development sector, that question has a harder edge. Across much of the sector, teams have been cut while workloads have remained, and people are using AI to survive jobs built for staffing levels that no longer exist. Asking them to disclose that use can sound like asking them to announce that a tool now performs part of their job, in a workplace where posts are already insecure. Nobody writes that fear in a training-needs survey. It appears as silence.
Shadow AI, which I wrote about previously, is this incentive at work. People use whatever helps them complete the job, then keep quiet because visibility feels riskier than the tool. That is a rational response to the incentives we have built, not evidence of a character defect. The answer is not a values poster. It is to change the incentives.
Concealment is not the only risk
There is an important boundary here. AI use carries risks whether it is disclosed or not. Sensitive data can still be mishandled. A tool can still invent a source. A connector can still carry someone's organisational authority into systems it should not reach. An automated task can still run on a weak assumption while nobody is watching. Disclosure does not make any of that safe.
What disclosure does is make the workflow visible so that the other controls can operate. It tells the reviewer what the tool touched, what the person checked and where the uncertainty remains, and it allows a manager to see patterns, correct unsafe practice and provide approved alternatives.
A person can disclose bad use, and a person can conceal work they checked carefully. The point is not that every hidden output is wrong. The point is that an organisation cannot govern a workflow it cannot see. Disclosure is the map. It is not the territory and it is not the evidence.
What concealment takes away
An organisation that sells analysis sells verified judgement. Verification needs a reviewer who knows where to look, and AI-generated text is fluent whether it is true, false or subtly incomplete, so fluency tells the reviewer nothing. A useful disclosure says: this is what the tool did, these are the sources it touched, and this is what I checked. Take that map away and review becomes slower, less targeted and sometimes decorative.
The same global study found that 66 per cent of employees who use AI rely on its output without evaluating its accuracy, while 56 per cent report making mistakes in their work because of AI. Almost half admit to using AI in ways that contravene organisational policies, including putting sensitive company information into free public tools. Concealment does not prove that any one person failed to check. It does prevent the organisation from knowing where checking is weak, where policies are unrealistic and where staff lack an approved route to complete the work.
Hidden use also tends to surface at the worst possible moment, because someone else surfaces it. A donor. A peer reviewer. An expert reader who finds an error, suspects that a machine produced the analysis and moves to the question that actually hurts: why is this organisation being commissioned at all?
Three people an output review will not find
Hidden AI use creates three management risks that do not necessarily appear in the finished document.
The person who handed over the judgement
The first person has quietly delegated the judgement they are paid to exercise. The assessment question goes into the tool. The answer comes back, gets polished and leaves under their name.
The document may look better than their previous work, because fluency is the capability these systems deliver most reliably. What has changed is the work behind the document. The organisation is now relying on the tool's judgement rather than the officer's, and nobody made that decision. You find out when a situation departs from the pattern, which is precisely when you were paying for a human to notice.
The person who used AI to hide an impossible workload
The second person was already at capacity, and the capacity limit was doing protective work. It forced prioritisation. It made overload visible. Eventually it forced a conversation about staffing and deadlines.
AI allows that person to absorb an impossible job silently, and from where a manager sits the signs look positive: more output, fewer missed deadlines, your strongest performer coping again. The overload has not disappeared. The signal has. What once surfaced as a missed deadline may now surface later as burnout, resignation or an error that passed through because the person was producing more than anyone could sensibly verify.
The team that stopped developing junior expertise
The third risk is slower and more structural. The work delegated to an "AI intern" is often the work through which real junior staff learn. They read the submissions, prepare the first synthesis, draft the routine report and receive corrections. The output is not the only product. The developing professional is another.
If AI absorbs all the first-draft work, today's manager may become faster while tomorrow's organisation loses its experienced staff pipeline. We learn through reading, writing and being corrected, and a system that optimises away those tasks can also optimise away the learning function.
You will not find these risks in the final document. The first is hidden by competent-looking work, the second by increased output and the third by the delay before its cost arrives. You find them through disclosure, conversation and workload design.
The fix is a rule, and it has to be a rule
The guidance note puts its central rule in one sentence:
Staff may use approved AI tools for permitted work. Staff must disclose substantive AI assistance, in writing, to the person who reviews the work.
"Substantive" matters. Routine spelling, grammar and predictive-text corrections do not need a note. It means disclosing AI use that materially shaped the research, analysis, structure, evidence, argument, wording, conclusions or other material parts of an output, or created a material new record such as a meeting transcript. And the disclosure must be specific enough to tell a reviewer where to look.
Optional disclosure does not solve the incentive problem. As long as disclosure is voluntary, it remains a signal, and the research suggests it can be a costly one. The honest person accepts a visibility cost that the person who stays silent avoids. A universal rule removes that advantage. Silence no longer counts as compliance, and senior staff disclose on the same terms as junior staff.
That does not make the social penalty disappear. Research found that the trust penalty persisted even when disclosure was mandatory. The rule therefore has to be paired with consistent review standards, senior people going first and managers who do not punish people simply for being visible.
Think of citation. Naming a source does not confess weakness. It makes a claim checkable, and footnotes ordinarily strengthen a report because they let the reader inspect the evidence. AI disclosure needs to become just as boring. Universal disclosure makes honesty non-optional. Culture and management determine whether honesty is safe.
Internal disclosure is not the same as a public label
Three different practices are often collapsed into the word "disclosure".
The first is workflow disclosure: the author tells the internal reviewer what AI did, what sources or data it touched and what was checked. This is the minimum organisational rule. The second is methodological disclosure: where AI materially affected research, coding, analysis or another method, the final document explains that use, because readers need it to assess the method. The third is public labelling: a publication tells its external audience that AI was involved, and whether that is needed depends on the type of publication, the nature of the contribution, contractual requirements and applicable rules.
These are related, but they are not identical. Every substantive use should be visible to the internal reviewer. Not every spelling correction needs a declaration to a donor. A methodologically significant use should not be hidden behind a vague internal note. The purpose determines the disclosure.
What a useful disclosure says
A useful disclosure follows four steps:
Name the tool.
Say what it touched or produced.
Say what the author checked.
Name the person taking responsibility.
For example:
In preparing this report, I used Claude to summarise partner submissions and draft the narrative sections. I checked all figures against the source data and reviewed the cited evidence against the original documents. The interpretation and conclusions are mine, and I take responsibility for the final content.
Compare that with:
AI was used in the preparation of this document.
The second statement is confession-shaped. It tells the reviewer nothing except that they should worry. The first is an accountability statement, and it provides a review map. The difference is not cosmetic. The disclosure's job is to make the work checkable.
Disclosure comes after permission, not instead of it
A disclosure written at the bottom of a report does not cure an inappropriate data decision made at the beginning. Before information enters an AI tool, two questions still come first:
Whose data is it?
Is it about a person?
If it contains personal, confidential, protection, safeguarding, HR, investigation or beneficiary-level information, the individual user should not decide alone whether the use is acceptable. The tool must be approved for that class of information, and the specific use must be approved by the organisation's designated accountable owner for the data. Those are separate decisions.
Disclosure governs visibility and accountability. Permission governs what the system may touch. You need both.
Verification is not "I read it and it looked right"
Disclosure tells the reviewer where to look. Verification determines whether the output can leave. Three requirements matter.
A named person reads the whole output
Not skims. Reads. If nobody will read the full output, nobody should send it. The fact that the AI generated fifty pages quickly does not create a human capacity to review fifty pages quickly.
Every factual claim is traced to a source
Figures go back to the data. Quotations go back to the record. References go back to documents someone has actually opened and read. A model's confident tone is not a confidence rating. The human sets confidence according to what the answer rests on, what was checked and what remains uncertain.
The reviewer must be competent to judge the substance
This is the control most disclosure policies miss. If a person uses AI to produce analysis in a field they do not understand, then sends it to a reviewer who also cannot judge the field, the review is decorative. Fifty AI systems agreeing may still reproduce the same blind spot fifty times.
AI can generate plausible analysis outside the user's expertise. It cannot be the final judge of whether that analysis is sound. Route the work to someone who can judge it, narrow the claim to what can be verified, or do not publish it. Disclosure without competent review is visibility without control.
Saying it was checked is not evidence that it was checked
A disclosure is self-report, not an audit log. For routine, low-risk work, a short statement and ordinary editorial review may be enough. Higher-risk work needs a record behind the statement. That might include:
links to the source material
the checked dataset
a version history
a record of corrections
the reviewer's name
a sign-off showing who verified which claims
The same rule applies here as everywhere else in responsible AI: saying something happened is not evidence that it happened. Do not turn disclosure into a new sentence people paste mechanically onto unchecked work.
The time saved in drafting has to move to checking
AI changes where the time goes. A task that once took two hours to draft may now take ten minutes to produce. If the output matters, much of the apparent saving now belongs to verification, because the cost of producing text has collapsed while the cost of checking facts, judging implications and accepting responsibility has not.
This changes workload planning. If managers treat every minute saved in drafting as capacity for more output, the volume of AI-assisted work will exceed the organisation's ability to review it. That is how the overloaded staff member becomes invisible and how fluent errors enter the record. The productivity gain is not "produce ten times more". It is "spend less time creating the first draft and more time improving the decision".
The rule must account for who is penalised for honesty
The competence penalty is not evenly distributed. In the engineering experiment, women believed to have used AI received a larger competence penalty than men, and the field data found that 31 per cent of female engineers had adopted the company's AI tool, compared with 41 per cent overall. Mature-age employees also adopted more slowly. The evidence does not prove that the competence penalty alone caused every difference in adoption. It does show that people who expect harsher judgement have good reason to be cautious about visible AI use.
A universal disclosure rule does not by itself remove that bias, but it can stop the organisation adding a second penalty for honesty by making disclosure a common requirement. If everyone must disclose substantive use, the honest employee is no longer volunteering a costly signal that colleagues can avoid. The rule stops silence being an advantage. Managers must still judge the work against a common standard and avoid treating disclosure itself as evidence of lower competence. Worth remembering the next time someone calls mandatory disclosure heavy-handed.
But does disclosure itself reduce trust?
Yes. That objection has real evidence behind it. A 2025 paper in Organizational Behavior and Human Decision Processes ran thirteen experiments across tasks including analytics, education, creative work and investment decisions, and people who disclosed AI use were trusted less than those who did not. The researchers called this the transparency dilemma.
There are three important qualifications. First, third-party exposure of undisclosed AI use caused a larger trust penalty than disclosure. The choice is not between a cost and no cost. It is between a manageable cost now and a potentially larger one later. Second, those experiments examined how recipients reacted to knowing about AI use. That does not remove the organisational need for internal workflow disclosure, because an internal reviewer needs to know what happened whether or not the final publication carries a public label. Third, disclosure wording still matters operationally even if it does not erase the social penalty. "AI was used" creates anxiety without helping the reviewer. "Claude drafted these sections from these sources, I checked these claims, and I remain responsible" gives the recipient something usable.
Disclosure may carry a trust cost. Concealment carries a governance cost and a larger exposure risk. There is no risk-free option. There is a controllable one.
It applies upwards first
A disclosure rule that only points downwards is surveillance. Senior staff who use AI well must disclose on the same terms as junior staff who use it badly. Managers must put their own names on the first examples, and the chief executive's report should not carry a lower standard than the programme officer's briefing.
The first visible behaviour teaches the real policy. If a senior person says, "I used Claude to structure this, I checked these sections, and the final judgement is mine", they make honest practice ordinary. If senior people say nothing and the policy appears only in staff monitoring, concealment will continue.
What happens after the first disclosures decides whether the rule survives
Read the disclosure before reading the document. It tells you where to spend your attention. Then ask follow-up questions:
Where did this figure come from?
What does this paragraph mean in your own words?
What assumption is this recommendation resting on?
What did the tool leave out?
What would change your confidence in this conclusion?
These are diagnostic questions, not a one-minute examination. A fluent explanation does not prove that the analysis is correct, and someone working in a second language may understand more than they can explain quickly. Use the questions to locate the review, then check the evidence.
Treat the first undisclosed output as evidence that the rule may not have reached the person clearly. Explain it. Show examples. Give staff a safe route to ask questions. Do not reward disclosure by increasing someone's workload because AI now helps them. Do not humiliate the first person who writes an awkward disclosure. And do not make honesty the event that triggers an investigation while silence remains invisible.
A reasonable implementation begins with a calibration period. Staff practise the wording. Managers respond consistently. Unsafe workflows are corrected. Approved alternatives are provided. Only deliberate concealment after the rule has been clearly communicated should be considered under the organisation's applicable conduct procedures, with normal due process. What you do with the first ten disclosures will matter more than the wording of the policy.
The AI use nobody thinks to disclose
A large part of the AI use in an office begins without anyone opening a chatbot. Meeting transcription. Automated summaries. Drafting assistance in email and documents. Search across organisational files. Software that quietly adds an AI function after an update.
Someone who would never paste a protection case note into ChatGPT may allow a meeting platform to transcribe a case conference because, in their mental model, they have not used AI. But the tool has not merely summarised a meeting. It has created a new record. A conversation that once left handwritten notes may now leave a verbatim transcript showing who said what, stored somewhere, retained under settings nobody in the meeting chose. For safeguarding, HR, investigation and protection meetings, that is a material change in the organisation's risk position.
The rule must therefore say that AI built into existing tools counts, and that substantive assistance from it must be disclosed. It must also tell staff which meeting types must not be transcribed and place that control in the platform settings. Instructions guide behaviour. Settings enforce boundaries. That subject deserves its own piece. It will be the next one.
We apply this rule to ourselves
Every analysis we publish carries a disclosure saying what AI did and what the author did. The guidance note carries its own, and its disclosure includes an admission. An earlier draft contained a detailed section on the legal position. We removed parts of it rather than publish them because we could not trace every claim to a source we had actually read.
That is what disclosure should make possible. In a culture where disclosure is normal, saying "we could not verify this, so we removed it" is evidence that the verification process worked. The disclosure for this article is at the bottom: a handful of sentences saying what the tools helped with, which sources I checked and what I remain responsible for.
The note
MI-GUIDE-001, AI Disclosure and Use, version 2.3, is a practical guide for managers. It is also readable in the browser, where the decision tree, the disclosure builder and the staff notice run as interactive tools, and nothing you type in them leaves your browser.
It covers:
the disclosure rule
practical examples
permission gates
data and tool decisions
verification
AI built into existing systems
what managers do differently
the first thirty days of implementation
It is written for someone who cannot buy new tools this quarter, cannot wait for headquarters and cannot credibly ban AI use, and the staff-notice template is included, ready to adapt and route through normal human-resources, data-protection and policy approval.
The note is free and ungated. It is licensed under CC BY 4.0. You may share, adapt and rebrand it, including commercially, provided you credit AidGPT and MarketImpact, link to the licence, indicate whether changes were made, link back to the current source where practicable and do not imply our endorsement. Do not apply legal terms or technological measures that restrict reuse permitted by the licence. If it is useful, use it.
We are also launching AidGPT email updates for people responsible for practical AI adoption, training and governance. If that is useful to you, you can sign up here. These are separate from my LinkedIn newsletter, Tom's Aid and Dev Dispatches, which covers wider humanitarian and development trends.
Start with your own name
Put a disclosure on the next substantive document you send. Two or three sentences. Name the tool. Say what it touched. Say what you checked. Take responsibility. Then ask whether the person reviewing it is competent to judge the substance, and then adapt the notice, complete your normal internal approvals and issue it.
Expect the first disclosures to be clumsy. Someone will write a line that says almost nothing. Someone else will declare a spellchecker. Another person will disclose the tool but not the source material it touched. Fine. Clumsy and honest is a better starting point than polished and hidden, and calibration comes quickly when good examples are visible and nobody is punished for going first.
The policy matters. The senior person going first matters more.
If you want to go further
If you do not know what is actually being used in your organisation, that is a visibility gap. It is diagnostic work before it is training work, and mapping AI use across teams, including features nobody consciously switched on, is consultancy we undertake at MarketImpact Digital Solutions Ltd.
If your people need the judgement the rule assumes, including verification, data classification, permission decisions and knowing when they lack the expertise to check an answer, that is what the AidGPT cohorts teach.
If you need to redesign real workflows, disclosure is the starting point rather than the final product. The next questions are what to automate, what evidence must remain visible, where human checkpoints sit and which decisions must never be delegated.
And if you do none of those things, take one question into your next senior management meeting. Would anyone here feel safe disclosing exactly how they used AI last week? If the honest answer is no, that is the finding.
Training your teams: AidGPT.org. Assessing your organisation: MarketImpact Digital Solutions Ltd.
Share what you are seeing in the comments, or by message if it cannot be public. I would particularly like to hear from organisations that have already issued a disclosure rule. What happened after the first disclosures arrived?
Tom
Thomas Byrnes is CEO of MarketImpact Digital Solutions Ltd and runs the AidGPT responsible AI training programme. AidGPT is MarketImpact's training brand and the publisher of MI-GUIDE-001.
Tom's Aid and Dev Dispatches is my LinkedIn newsletter on humanitarian and development trends. AidGPT email updates are a separate service focused specifically on practical AI adoption, training and governance.
Previously in this series: Shadow AI in Humanitarian Work, November 2025. Use AI's Mind Not Its Memory, March 2026. Most AI Training in the Humanitarian Sector is Teaching the Wrong Thing, April 2026. SAFE AI is Live, June 2026. Your AI Has a Passport Problem, July 2026. The Model Was Never the Whole Story, August 2026.
AI disclosure. Claude helped draft and revise this piece from my outline and writing, and helped locate and cross-check the four studies cited below. OpenAI Codex helped audit the evidence and claims, reconcile the article with MI-GUIDE-001 and prepare the piece for publication. I read the cited sources before publication. No beneficiary-level data, client-confidential material or unpublished operational datasets were used. The argument, selection of evidence, edits and final judgement are mine, and I take responsibility for the content. MarketImpact's full position on AI use is at marketimpact.org/how-we-use-ai.
Sources
Gillespie, N., Lockey, S., Ward, T., Macdade, A. and Hassed, G. (2025), Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025. University of Melbourne and KPMG.
Reif, J.A., Larrick, R.P. and Soll, J.B. (2025), "Evidence of a social evaluation penalty for using AI", Proceedings of the National Academy of Sciences, 122(19), e2426766122.
Gai, P.J., Hou, J. and Tu, Y. (2025), Competence Penalty Is a Barrier to the Adoption of New Technology, working paper.
Schilke, O. and Reimann, M. (2025), "The transparency dilemma: How AI disclosure erodes trust", Organizational Behavior and Human Decision Processes, 188, 104405.
Enjoyed this article?
This post is from Aid and Dev Dispatches, a LinkedIn newsletter with expert analysis on humanitarian reform, AI adoption, crisis economics, and the politics of aid. Join 9,000+ subscribers.