Insights

Almost everyone expects AI disclosure. Almost nobody enforces it.

Sep 16, 2026, 4:16:23 PM · Rick Bawcum

← All insights

Sooner or later a member emails and asks how you use AI. Not as a complaint — just as a question. Which tools, what happens to their data, whether a person reads the thing before it reaches them.

Most associations cannot answer it. That is not a failure of diligence. It is what happens when software you already pay for starts shipping AI features without asking, and staff quite reasonably adopt tools that make their week easier. The tools arrived faster than anyone's ability to describe them.

What makes this worth attention now is that the question has stopped being hypothetical.

The numbers

The clearest evidence comes from inside the association world itself. ISACA — a professional association of digital trust practitioners — surveyed more than 3,400 members for its 2026 AI Pulse Poll. These are the people best equipped to govern AI, reporting on their own organizations. Asked whether their organization requires disclosure when AI has been used to create or substantially assist a work product:

  • Around 18% both require disclosure and enforce it
  • About 20% require it but do not enforce consistently
  • Roughly 32% have no disclosure requirement at all

Set that against what people expect. Fractl's Q2 2026 survey of 1,008 US consumers found roughly 84% want AI-assisted written content labelled, rising for audio, images and video. Association members are consumers too, and they do not suspend that expectation when they open a message from their professional body.

So: roughly four in five organizations cannot stand behind a disclosure practice, while roughly four in five people expect one.

Requiring is not the same as enforcing

The middle number is the one worth sitting with. Around a fifth of organizations have a disclosure requirement that is not consistently applied.

Under scrutiny, that is a weaker position than having no policy at all. A missing policy is a gap. A policy that exists on paper but is not operating implies a control that is not working — and it invites exactly the follow-up question you least want. If a board member asks whether you disclose AI use and the answer is "we have a policy", the next question is how you know it is being followed.

This is the difference between having a rule and being able to show the rule works. For an organization whose authority rests on standards it sets for others, that distinction is not academic.

The trap: disclosure on its own can backfire

The obvious response to a gap this wide is to start disclosing. Done without care, the evidence suggests that makes things worse.

The same Fractl research found the share of people who say heavy AI use would reduce their trust in an organization they favour roughly doubled between 2025 and 2026 — from about 20% to around 40%. Only about 14% said it would increase their trust. The effect was strongest among younger respondents, at roughly 54% of Gen Z, and stronger among women than men.

Those are the cohorts most associations are working hardest to recruit and retain.

Disclosure on its own reads as an admission. Disclosure backed by evidence reads as competence. Same sentence, opposite effect.

An organization that says "we use AI" invites the penalty and offers nothing to weigh against it. An organization that says "we use AI, here is what it touches, here is where a person decides, here is who is accountable" is making a materially different claim. The second one is harder to write, which is precisely why it carries weight.

What generic guidance misses about associations

Most AI governance writing is aimed at companies. Four things are specific to membership organizations, and each raises the stakes.

Credentialing. AI now touches exam item generation, adaptive preparation, scoring support and eligibility screening. A credential is worth exactly what the market believes about its rigour, and that belief does not survive a story about an algorithm deciding who passed.

Members whose careers AI threatens. National polling in March 2026 found around 70% of Americans expect AI to reduce job opportunities, rising to roughly 81% among Gen Z. Using AI carelessly on the very members whose livelihoods feel exposed is a particular kind of misstep, and they read it that way.

Member-company data. Trade associations hold pricing, volume and wage data from competing companies under long-established antitrust discipline. Whether that data reaches an AI tool, and whether a vendor trains on it, is a question with no clean equivalent in the general market.

Chapters and components. Local chapters adopt tools independently, under the national brand, usually with no governance capacity at all. The risk is federated. The reputation is not.

Four things worth doing

None of these require budget or a consultant.

Build the inventory. One spreadsheet: tool, owner, what data it touches, whether a person reviews the output. Go system by system through your AMS, LMS, certification platform, CRM and email tools and list what AI is switched on. Most organizations find something they did not know about. Half a day of work.

Decide what always gets human review. Write down which categories of output a person must approve before they go out, and which may go automatically. Ambiguity here is where incidents come from.

Write the paragraph you would send. Draft the reply you would give if a member asked tomorrow. If it is hard to write, that difficulty is the finding — and it tells you exactly which of the other three to do first.

Name someone accountable. One person, written into a role description, responsible for answering to leadership on AI use. Not who operates the tools — who answers for them. This costs nothing and changes how every other question gets answered.

What this evidence does not tell you

Worth being straight about the limits, since this piece is arguing for candour.

None of the research above asks association members directly how their organization's AI use affects their view of it. ISACA surveyed professionals about their own organizations. Fractl surveyed consumers in general. The closest stakeholder research sits in the charitable sector, and members are not donors — dues are not gifts, and the relationship is different.

The direction of travel is consistent across sources and well corroborated. The precise percentages should not be treated as census data, and we try not to quote them that way.

That gap is itself worth naming. Nobody has published credible research on how members respond to their association's AI use. Until someone does, everyone in this conversation — including us — is reasoning from adjacent evidence.

Where to start

If you want a structured view of where your organization actually sits, our AI Trust Readiness Scorecard walks the same five areas in sixteen questions. It takes about five minutes, there is no sign-up to see your result, and if the answer is that you are in reasonable shape, it will say so.

Where does your organization actually stand?

Sixteen questions, about five minutes, no sign-up to see your result.