AI-use disclosure worksheet

See where a provider plans to use AI in your service.

Ask for one disclosure per workflow. Record the tool, data, output, system access, human check, limits, evidence, and change-notice owner before work begins.

This is a planning and procurement worksheet, not a legal opinion, AI audit, certification, compliance finding, or universal approval standard. Do not paste secrets, credentials, live customer records, or confidential prompts into it.

Start with the work

Where does AI actually touch the service?

"We use AI" and "we do not use AI" are both incomplete without a named service and workflow. One part of the work may use AI while another does not.

AI prepares work

A tool sorts tickets, summarizes a call, extracts invoice fields, translates text, or drafts a reply for review.

AI affects an action

A tool routes a case, scores an item, updates a record, sends a message, or triggers another system.

AI is built into a tool

The workflow uses a provider platform, third-party SaaS feature, model API, plugin, agent, or subcontractor tool.

Copy-ready worksheet

Use one block for every AI-assisted workflow.

Keep the provider statement, dated evidence, open question, owner, and decision together. Send sensitive evidence through an approved secure channel.

PROVIDER AI-USE DISCLOSURE WORKSHEET

Provider:
Service or team being reviewed:
Proposal, agreement, or disclosure version:
Provider disclosure owner:
Buyer reviewer:
Review date:
Next review date:

Repeat this block for each AI-assisted workflow.

WORKFLOW OR TASK:
SERVICE STAGE: [Input, preparation, draft, recommendation, decision support, customer communication, system action, or monitoring]
CURRENT STATUS: [In use, planned, optional, pilot, not used, or unclear]
TOOL OR MODEL: [Product, model, provider, and version where material and available]
WHO OPERATES IT: [Provider worker, provider system, subcontractor, buyer user, or another party]
PURPOSE: [What the AI does in this workflow]
INPUT DATA: [Data categories used; do not paste the data itself]
SENSITIVE OR RESTRICTED DATA: [Customer, employee, financial, health, legal, authentication, confidential, regulated, or none identified]
DATA HANDLING: [Retention, model training or product-improvement use, processing location, and deletion terms]
OUTPUT OR ACTION: [What the tool produces, recommends, sends, changes, or triggers]
SYSTEM ACCESS: [Connected systems, read/write permissions, and actions available]
HUMAN REVIEW: [What is checked, by whom, before which action, and using what sample or rule]
PROHIBITED OR HELD ACTIONS: [What the tool or provider worker must not do without approval]
FAILURE AND FALLBACK: [What happens when the tool is unavailable, uncertain, or wrong]
THIRD PARTIES: [Model provider, AI vendor, subprocessor, plugin, or subcontractor involved]
EVIDENCE: [Data-flow note, settings record, test summary, contract section, or dated provider statement]
CHANGE NOTICE: [Which changes require notice, who receives it, and the written notice term]
PROVIDER OWNER:
BUYER OWNER:
OPEN QUESTION OR MITIGATION:
NEXT REVIEW DATE:
BUYER DECISION: [Confirmed for this workflow, clarify, approve with mitigation, prohibit, not applicable, or qualified review]

SERVICE-WIDE QUESTIONS

1. Are any AI-assisted workflows already used or planned for this service?
2. If none are used, who confirmed that answer and on what date?
3. Will the provider give notice before adding an AI workflow or materially changing its purpose, data use, model, third party, permissions, or review rule?
4. Can the provider deliver the service through a non-AI or reduced-AI route where required?
5. Which incident, correction, complaint, and offboarding processes cover AI-related records and access?

Do not include passwords, API keys, private keys, recovery codes, live customer records, confidential prompts, or other secrets. Exchange sensitive evidence through an approved secure channel.

The full template stays visible and selectable. Nothing is uploaded or saved.

Disclosure checks

Break a broad AI claim into facts you can review.

Do not ask for proprietary prompts, model weights, secrets, or exploitable system details. Ask for enough information to understand the workflow and decide what needs a specialist.

Workflow check

Workflow and purpose

Name the task, where it sits in the service, and whether the use is live, planned, optional, or still a pilot.

  • What does the tool prepare, recommend, send, change, or trigger?
  • Can this workflow run without AI when the buyer requires it?
Workflow check

Tool, model, and operators

Record the product, model provider, material version, and the people or systems that operate it.

  • Is the tool supplied by the provider, a software vendor, a subprocessor, or a subcontractor?
  • Which users, plugins, or connected services can reach it?
Workflow check

Input data and handling

List data categories, not the data itself. Separate retention, logging, model-training use, product-improvement use, deletion, and processing location.

  • Could the workflow receive customer, employee, financial, health, legal, authentication, or confidential data?
  • Do the written terms also cover backups, logs, support access, and downstream providers?
Workflow check

Output and system access

A draft is different from an action. Record what the tool can write, send, update, score, route, or approve in the purchased service.

  • Which systems are connected, and are permissions read-only or read/write?
  • Which actions stay blocked until a named person approves them?
Workflow check

Human review and output checks

Replace broad claims about human oversight with a named reviewer, a clear check, and the point when review happens.

  • What does the reviewer inspect before a customer message or system action?
  • How are errors, complaints, uncertain outputs, and repeated failures recorded and corrected?
Workflow check

Evidence, fallback, and incidents

Keep the provider statement separate from contract terms, test records, settings, independent reports, and buyer observations.

  • What dated evidence covers this workflow and service?
  • What happens when the tool is unavailable, wrong, or involved in an incident?
Workflow check

Change notice and buyer decision

Agree which changes need notice, who reviews them, and which uses are confirmed, limited, prohibited, or still unclear.

  • Does notice cover a new purpose, model, data use, third party, permission, or review rule?
  • Who can accept a gap, require a mitigation, prohibit the use, or ask for qualified review?
Fictional example

A support-reply draft is not the same as an automatic send.

This example shows the level of detail to request. It does not prove that a workflow is safe or set a control for every service.

Workflow
Fictional example: draft replies for shipping-delay tickets
Purpose
Prepare a reply from the approved help-center article and order-status fields.
Input
Ticket text, order number, shipping status, and the approved reply policy. No payment data or account credentials.
Output
A draft inside the support platform. The tool cannot send, refund, cancel, or change an order.
Review
A trained support worker checks the order facts, policy match, promise, tone, and escalation rule before sending.
Evidence
Current data-flow note, permission screenshot, retention terms, test summary, and dated provider statement.
Open question
Confirm whether ticket text is kept in vendor logs after the provider's stated retention window.
Decision
Clarify retention before approval. Keep sending and order changes blocked.
Review process

Turn the disclosure into a written service rule.

A first pass finds missing facts. The right owner then reviews the gaps that matter for the service, data, and decisions involved.

  1. Name the service and list each current, planned, optional, or pilot AI-assisted workflow.
  2. Ask for one disclosure block per workflow instead of accepting a company-wide yes or no answer.
  3. Confirm the data, output, permissions, human check, third parties, fallback, and held actions.
  4. Record dated evidence and mark unsupported answers as open questions.
  5. Send important gaps to the right security, privacy, legal, procurement, compliance, or business owner.
  6. Carry accepted limits and change-notice terms into the agreement, onboarding packet, access plan, and review schedule.
Clarify before approval

Pause when the answer hides the workflow.

A familiar tool name or a general policy does not answer what happens in the service you are buying.

  • The answer describes the provider company but not the service or workflow being purchased.
  • Human review is promised, but no one can name who checks what before which action.
  • Retention, logging, training use, support access, or subprocessors remain bundled into one vague answer.
  • The tool can write to customer, finance, HR, or production systems without a held-action rule.
  • A customer message can be sent without a named person checking facts, policy, and promises.
  • The provider can change the model, purpose, data use, integration, or review rule without notice.
  • Evidence is a general marketing statement rather than a dated record for the named service.
Official source notes

Use AI guidance to ask better questions, not to claim approval.

These sources support workflow, data, third-party, testing, oversight, and change-management questions. They do not certify this worksheet or any provider.

Before provider approval

Bring the open AI-use questions to the right reviewer.

Share the named service, workflow disclosures, dated evidence, unresolved gaps, and proposed limits. Do not send secrets through the contact form.