ConceptAdvancedResponsible AI & Advanced Practice / Compliance and legal partnership / #7

What disclosure obligations apply when users interact with an AI system?

LEAD the product is Coda, an AI companion at Solace Health, a telehealth mental-health platform

Solace Health pairs patients with human therapists and gives them Coda, an AI companion they can message between sessions when a therapist isn't available. Thandiwe Okonjo leads the Coda product team, and keeps a folder of every support ticket that ever used the phrase "I didn't realize."

The direct answer
A one-time disclosure at signup satisfies the letter of most rules and fails the point of all of them. Track how many active users can still correctly say, months later, that they're messaging an AI and not a human. When that number drops, that's the real early warning, weeks before a complaint or a regulator ever gets involved. The fix is a disclosure that repeats itself, visibly, every session, not a checkbox that only ever gets seen once.
Do this, in order
  1. Make the disclosure persistent, not a one-time event.Why: memory of a signup modal fades within weeks, and the obligation doesn't end at signup.
  2. Track user comprehension directly, not just whether the disclosure was technically shown.Why: "we displayed it" and "they understood it" are two different facts, and only the second one matters.
  3. Set a real threshold that triggers a redesign, not just a monitoring dashboard.Why: a metric nobody acts on is decoration, not a safeguard.
  4. Keep a visible path to a human on every screen the disclosure appears on.Why: disclosure without an alternative is just a warning label, not a real choice.
  5. Leave low-stakes, single-use AI touches alone.Why: an appointment-reminder bot doesn't carry the same weight as an ongoing companion chat, and doesn't need the same repeated disclosure.

How to answer this, stage by stage

Nobody is grading whether you can quote a specific law's article number. They're grading whether you know the difference between showing a disclosure and it actually landing.

Stage 1
Scope it to one real feature
Say it like this
"I'll answer this for Coda, an AI companion inside a telehealth app, since disclosure obligations bind tighter the more emotionally significant the conversation is."
Why this works
Grounds an abstract regulatory question in one real, high-stakes conversation.
Stage 2
Say your structure out loud
Say it like this
"I'll use LEAD. Link, the outcome that matters. Early signal, what moves first. Abuse, how the metric gets gamed. Decision, what you'd actually do at each threshold."
Why this works
Signals this is a measurement problem, not just a list of legal requirements to recite.
Stage 3
Reframe the question
Say it like this
"The obligation isn't really 'tell them once.' It's 'make sure they still know,' which is a completely different bar, and most disclosure designs only ever aim at the first one."
Why this works
This is the line that separates a compliance answer from a comprehension answer.
Stage 4
Give the one decision
Say it like this
"Track what share of active users can still correctly identify Coda as AI, months after signup. If that number falls, redesign the disclosure to repeat every session, not just once."
Why this works
This is deliverable 0, spoken as a metric with a real trigger, not a vague promise to "be transparent."
Stage 5
Prove it with a failure
Say it like this
"A new clinical hire asked, in her first week, whether Coda tells people mid-conversation that it's AI, or only once at signup. Nobody on the team had a confident answer, which was itself the answer."
Why this works
A real gap in the team's own knowledge is more convincing than an assertion that disclosure "matters."
Stage 6
Say what you'd watch for
Say it like this
"I'd watch comprehension by cohort age, not just overall. If users six months in test far worse than users six days in, the disclosure isn't failing at signup, it's failing at memory."
Why this works
Shows the measurement is designed to catch the actual failure mode, not just produce a single reassuring number.
Stage 7
Close on the one line
Say it like this
"A disclosure that only ever gets seen once isn't a disclosure that lasts. Measure whether people still know, not just whether they were once told."
Why this works
Leaves the interviewer with the reframe, the sharpest sentence in the whole answer.

Let's learn

Coda messages back and forth with a patient between their scheduled therapy sessions, offering grounding exercises and check-ins when a human therapist isn't available.

At signup, every new patient sees a modal: "Coda is an AI companion, not a licensed therapist." They have to tap "I understand" before the chat unlocks. That one screen was, for a long time, the entire disclosure strategy.

Knowledge spark: why does disclosure need to repeat? Memory of a one-time notice fades the way memory of anything fades: fast at first, then slowly. A person who agreed to a modal in January isn't necessarily still holding that fact in mind in June, especially inside a warm, familiar conversation that feels like talking to someone who knows them. The obligation to disclose isn't really about the moment of signup. It's about every moment someone might reasonably forget.

Now, the turn: the modal was never really the problem. The problem is that "shown once" and "known now" quietly became the same thing in the team's mind, when they had never actually been the same thing at all.

Share of active users who correctly identify Coda as AI, by months since signup
100% 50% 0 1 mo 3 mo 6 mo 9 mo 96% 54%
By nine months in, nearly half of active users could no longer correctly say whether Coda was AI. No complaint had been filed by anyone in this chart.
The decision I would take back We built one disclosure modal at signup and treated it as covering the whole relationship going forward, since that satisfied every version of the requirement we'd reviewed at launch. That made sense when Coda was a small, early feature nobody used for more than a few weeks. It stopped making sense once patients kept messaging Coda for months, long after the modal had faded from memory, in conversations that felt more personal with every week that passed.

What I would leave alone: Solace's appointment-reminder texts, sent by a simple automated system with no ongoing conversation, need no repeated disclosure at all. Nobody mistakes a reminder text for a person, and repeating a disclosure there would just be noise.

The modal was never the failure. The failure was assuming that being told once and still knowing months later were the same fact.

The lesson: a disclosure requirement isn't satisfied by a screen someone tapped through once. It's satisfied by what a person still knows, unprompted, on an ordinary Tuesday three months later.

Now here is the same thing as a story

The short version above is what you'd say defending Coda's disclosure design to Solace's clinical safety board. Read this one for how the gap actually got found.

Thandiwe Okonjo has led the Coda product team since it launched. She can usually tell which onboarding screens people actually read versus which ones they tap through on reflex, mostly from how fast users move past them.

Coda's signup modal had a strong completion rate, essentially everyone tapped "I understand" before their first conversation. For a long time, that number was the only evidence anyone tracked, and it always looked fine.

Hand sketched flow diagram titled The one-time disclosure. Five boxes: Signup, Disclosure modal, 30 sessions later, No reminder highlighted, Assumes a human.
Four steps ran exactly as designed. The missing fourth one, a reminder somewhere in those thirty sessions, was the one nobody had built.

Then a new clinical hire, three weeks into the job, asked an ordinary question in a product review meeting: does Coda tell people mid-conversation that it's AI, or only once at the very start?

Hand sketched comparison diagram titled How it gets gamed. Left panel, a document icon labeled Technically disclosed, caption fine print, shown once. Right panel, a question mark box icon labeled Actually understood, caption badge, shown every time.
The team had built the left panel and quietly assumed it was the right one.

Nobody in the room had a confident answer. Thandiwe realized, saying it out loud for the first time, that the team had never actually measured whether users still knew, only whether they'd once agreed.

Hand sketched quadrant titled Sorting touchpoints by disclosure risk. Axes how novel it still feels from familiar to novel, and stakes of the conversation from low to high. Coda companion chat sits high on both. Symptom triage bot sits high on both. Appointment reminders sits low on both.
Coda sat in exactly the corner where a fading memory of disclosure matters most.

Thandiwe ran a quick comprehension check, a short, direct question inserted for a sample of active users: "Just to check, who do you think you're chatting with right now?"

Hand sketched decision tree titled Does this touchpoint need a persistent disclosure. Root AI touchpoint, branching to four leaves: ongoing emotional stakes leads to Persistent badge, single short interaction leads to One-time notice, purely transactional leads to One-time notice, gives health guidance leads to Persistent badge.
Coda took the branch that needed the strongest version of disclosure, the one the team had actually built the weakest version for.

Users six months into using Coda answered correctly barely more than half the time, a sharp drop from the near-universal accuracy of users just a few weeks in.

Hand sketched icon list titled What disclosure obligations actually require. Four items: a document icon labeled Say plainly it's AI, a scale icon labeled Not buried in fine print, a question mark box icon labeled Repeated not just once, a person icon labeled A way to reach a human.
The team had two of these four solidly in place. The third one, repetition, was the one that had quietly gone missing.

Thandiwe's team designed a small, persistent badge in the chat header, always visible, reading "Coda, an AI companion" in plain type, refreshed at the top of every session.

Hand sketched labeled parts diagram titled What a persistent badge needs. Center icon a document labeled Chat header badge, with four callouts: Always visible, Plain language, Link to a human, Shown every session.
Small, constant, and quiet, exactly the opposite of a modal that interrupts once and is never seen again.
Hand sketched timeline titled The disclosure redesign. Four milestones: Audit run Q1, Badge designed Q2, Badge shipped Q3 highlighted, Re-measured Q4.
Nine months from the new hire's question to a redesigned disclosure, measured again the same honest way.

The old approach asked users to remember something told to them once, months earlier, in a completely different emotional state. The new one puts the fact quietly back in front of them, every single time, without ever interrupting the conversation.

Comprehension at 6 months: before and after the persistent badge
100% 50% 0 61% Before badge 94% After badge
The remaining 6 percent are mostly brand-new users who hadn't yet seen the badge long enough for it to register, still far better than the 39-point gap before.

I built one disclosure modal because it satisfied every checklist we reviewed at launch, and Coda was new enough then that nobody used it for more than a few weeks anyway. It took one new hire's plain question, asked without any sense that it was a hard one, to see that the checklist and the actual promise had quietly drifted apart.

LEAD, the signal that moved firstNot a compliance recap. LEAD is what forces you to find the number that would have warned you before anyone complained.

L
Link. The outcome that matters.
Patients who understand they're talking to an AI, so their trust in Solace stays calibrated instead of quietly built on a mistaken assumption.
Names the real outcome, not the model's own accuracy score.
E
Early signal. The hard step.
The share of active users who can still correctly identify Coda as AI, broken out by months since signup.
Falls weeks before any complaint, ticket, or regulatory flag would ever surface.
A
Abuse. How it gets gamed.
A leading, suggestive survey question could inflate the comprehension number without users actually knowing anything more than before.
Names the failure mode of the metric itself, not just the feature.
D
Decision. What you'd do at each threshold.
Below roughly 90 percent comprehension at any cohort age, redesign toward a persistent, repeated disclosure, not a policy note asking for "clearer language."
Turns the metric into an actual trigger, not a dashboard nobody acts on.

The recap, one line per letter: link is calibrated trust in Solace, early signal is comprehension by cohort age falling well before any complaint, abuse is a leading survey question inflating the number falsely, and decision is redesigning toward a persistent badge once comprehension drops below a real threshold.

And if you want to be sure it really works, try it somewhere elseSame four letters, an insurance claims portal instead of a therapy companion. This time the early signal is a click, not a survey answer.

Harrowgate Mutual runs an AI assistant that helps policyholders file and track home-insurance claims through chat. Desmond Achebe manages that product, and the disclosure question there looks different once the relationship is transactional rather than emotional.

Link: policyholders trusting the claims process enough to actually use the chat instead of calling and waiting on hold, which is the whole reason the feature exists. Early signal: the share of chat sessions where a policyholder clicks "speak to a human" within the first minute, specifically citing confusion about who or what they're talking to, tracked as a rate over each week. Abuse: policyholders might click "speak to a human" for entirely unrelated reasons, like an urgent claim, so the metric only counts sessions where the transcript shows an explicit "wait, is this a person" moment. Decision: if that rate crosses roughly 5 percent of sessions in a week, add a firmer identity statement at the top of the chat window, since the claims context is lower-stakes than a therapy companion, but a policyholder still deserves to know who's handling their claim.

Swap the trigger and it still runs.
Speed: an interviewer caps you at sixty seconds. Say "measure whether people still know, not just whether they were once told, and watch for that number by cohort age," and stop.
Cost: there's no engineering budget this quarter for a redesigned badge. Say so honestly, and start with a lightweight monthly in-chat reminder message, since even a repeated text line beats a disclosure that only exists once, on day one.
The model gets better, for real: if Coda's responses get warmer and more helpful, that's exactly when disclosure matters more, not less. A more convincing companion is more likely to be mistaken for a person, not less.

Where people run it wrong.
They treat a high tap-through rate on a signup modal as proof the disclosure is working, when it only proves the modal was shown.
They measure disclosure once, at launch, and never check whether comprehension holds up months later.
They add a repeated disclosure everywhere uniformly, including low-stakes single-use interactions that never needed it in the first place.

How to use it live. When asked about disclosure obligations, don't start with what the law technically requires. Start with what you'd actually measure to know whether anyone still remembers, and let the design follow from that number.

Flashcards (tap any card to flip it)

1 · THE FRAMEWORK
What framework fits "what disclosure obligations apply when users interact with an AI system"?
Tap to flip
ANSWER
LEAD: link, early signal, abuse, decision. The early signal is comprehension by cohort age, falling weeks before any complaint would.
2 · THE PEOPLE
Who is this answer about?
Tap to flip
ANSWER
Thandiwe Okonjo, who leads the Coda product team at Solace Health and keeps a folder of every support ticket saying "I didn't realize."
3 · THE OLD MEASURE
What did the team track before the redesign, and why was it misleading?
Tap to flip
ANSWER
The signup modal's tap-through rate, which stayed near 100 percent but only proved the modal was shown, not that users still knew months later.
4 · THE EARLY SIGNAL
What's the real leading indicator this answer proposes?
Tap to flip
ANSWER
The share of active users who can still correctly identify Coda as AI, tracked by how many months since they signed up.
5 · THE OLD DECISION
What decision would you take back?
Tap to flip
ANSWER
Building one signup modal and treating it as covering the entire relationship going forward, which made sense only while Coda was a brief, early feature.
6 · THE NUMBER
Fill in the blank: by 9 months since signup, only about ___ percent of active users could still correctly identify Coda as AI.
Tap to flip
ANSWER
54 percent. Down from 96 percent at 1 month, with no complaint filed anywhere along that decline.
7 · THE REPLAY
Same 6-month cohort, redesigned disclosure. What changes?
Tap to flip
ANSWER
Comprehension rises from 61 percent to 94 percent, once a persistent chat-header badge replaces the one-time signup modal.
8 · CROSS PRODUCT TRANSFER
Section 4 answers this again for a different product. Which product, and what's the early signal there instead of a survey?
Tap to flip
ANSWER
Harrowgate Mutual's claims chat assistant. There, the early signal is the rate of policyholders explicitly asking "is this a person" within the first minute of a session.

Check yourself Score: 0 / 0

Short answer, recall the signal
1. What is the early signal this answer proposes tracking, and why does it move before a complaint would?
Show hint
Look at the line chart of comprehension by months since signup.
Show answer
Model answer: Comprehension by cohort age, the share of active users who still correctly identify Coda as AI. It falls gradually for months before anyone files a complaint about it.
Multiple choice
2. Why doesn't the signup modal's near-100 percent tap-through rate settle the disclosure question on its own?
  • A. Because most users never actually saw the modal.
  • B. Because it proves the disclosure was shown, not that users still remember or understand it months later.
  • C. Because tap-through rates are always inaccurate.
  • D. Because the modal was shown in the wrong language.
Show hint
Look at the reframe in stage 3 of the walkthrough.
Show answer
B. "Shown once" and "known now" are different facts. The tap-through rate only ever measured the first one.
True or false
3. True or false: this answer recommends adding a repeated disclosure to Solace's appointment-reminder texts too.
  • True
  • False
Show hint
Look at "what I would leave alone."
Show answer
False. Appointment reminders carry no ongoing conversational relationship, so nobody mistakes them for a person and a repeated disclosure there would just be noise.
Short answer, name the reversal
4. What old decision does this answer take back, and why did it make sense when it was made?
Show hint
Look at "the decision I would take back."
Show answer
Model answer: Treating one signup modal as covering the whole ongoing relationship. It made sense while Coda was a brief early feature nobody used for more than a few weeks.
Short answer, where it wouldn't matter
5. Name a touchpoint at Solace where repeated disclosure genuinely doesn't matter.
Show hint
Look at the quadrant sorting touchpoints by disclosure risk.
Show answer
Model answer: The appointment-reminder texts. Low stakes, single-use, no ongoing conversation, so nobody is at risk of forgetting who or what they're talking to.
Short answer, apply it yourself
6. Think of an AI chat or assistant you've used for a while. Could you say, right now without checking, whether you were told it was AI, and do you still remember that fact clearly?
Show hint
Think about apps you've used for months rather than ones you just signed up for.
Show answer
Model answer: Many people find they technically knew at some point but couldn't say confidently in the moment, the same gap this answer is built to catch.
Before you close the answer
Why this works
Tests whether you understand disclosure as an ongoing comprehension fact, not a one-time compliance event, and whether you can name a real metric that would catch the gap before anyone complains.
Follow-up traps
"Doesn't a persistent badge get annoying over time, and hurt engagement?" Response: the badge is small and quiet by design, and comprehension jumped from 61 to 94 percent with no measurable drop in session length, so it isn't costing the warmth of the conversation.

"Couldn't users just say they understood in the survey without really meaning it?" Response: that's exactly the abuse case this answer names. The check uses a direct, unprompted question, "who do you think you're chatting with," not a leading yes-or-no that's easy to agree with reflexively.
If pressed
Solace's real comprehension check excludes any user who has messaged Coda in the last 24 hours, specifically to avoid the badge itself acting as a crib sheet for the very question being tested.
From U2xAI Academy

From answering questions to owning outcomes.

A live workshop where you ship a working AI agent, defend a launch decision, and walk away with a portfolio recruiters can't wave off, not just more questions to study.

  • A live AI agent you actually shipped
  • A launch decision you can defend under pressure
  • An interview-ready portfolio, not more flashcards
Know more