> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Beyond the Privacy Notice: Transparency for Connected and AI-Enabled Devices
- URL: https://www.thedelatorrereview.com/beyond-the-privacy-notice-transparency-for-connected-and-ai-enabled-devices/
- Published: 2026-08-25T03:50:27.000Z
- Updated: 2026-08-25T03:55:43.000Z
- Description: AI is transforming the Internet of Things (IoT)—and the rules for explaining it. From connected devices and robots to chatbots and AI-driven advertising, this article explores emerging transparency requirements and practical approaches to AI-ready disclosures.
- Author: Lydia
- Tags: Internet of Things (IoT), Mobile Privacy, EU AI Act, Transparency, IoT, ChatBots, Privacy Notices, AI Governance, Advertising

For more than a decade, lawyers advising on connected products have borrowed concepts from mobile privacy guidance and other sources to advise their clients on how to achieve transparency in the Internet of Things (IoT). The analogy made sense: mobile regulators had already confronted many of the issues that became central to IoT, including sensors, persistent identifiers, geolocation, third-party software, unexpected data collection, and the challenge of providing meaningful notice on constrained interfaces.

The resulting transparency model became familiar: a comprehensive privacy notice supplemented by shorter and just-in-time disclosures explaining what information is collected, why, with whom it is shared, how long it is retained, and what choices individuals have.

Those principles remain important. But they are no longer enough.

---

> For years, IoT transparency followed the mobile privacy playbook. **AI is rewriting the rules.**

---

This article accompanies the Practising Law Institute’s [**Advanced Internet of Things 2026: Deeper Dive, Practical Wisdom**](https://www.pli.edu/programs/advanced-internet-of-things---beyond-issue-spotting/444156?ref=thedelatorrereview.com), taking place **October 14, 2026, in San Francisco and online**. The program reflects how far IoT has evolved, with connected technologies now embedded across industries and continuously generating and communicating data.

Our panel, **“Transparency and Privacy for Connected and AI-Enabled Devices,”** brings **me together with** [**Alan Friel**](https://www.squirepattonboggs.com/our-people/alan-friel/?ref=thedelatorrereview.com)**,** [**Linsey Krolik**](https://www.linkedin.com/in/linseykrolik/?ref=thedelatorrereview.com)**, and** [**Irene Mo**](https://www.linkedin.com/in/irenemo/?ref=thedelatorrereview.com) to examine the next stage of that evolution. As connected products incorporate AI, transparency increasingly requires organizations to explain not only their data practices, but also what the AI is, what it does, how it affects users, when users are interacting with AI, and, in some cases, how the AI was developed.

---

> **I certainly do not have all the answers. Fortunately, my fellow panelists are about as close to an IoT and AI transparency all-star team as it gets—and if we do not know the answer, I am pretty comfortable blaming the legislators. Why not?**

---

To be fair, the technology itself has dramatically changed. IoT was once illustrated by the connected thermostat, fitness tracker, television, or refrigerator. Today, consider [**NEO**](https://www.1x.tech/neo?ref=thedelatorrereview.com), a consumer humanoid robot designed to operate inside the home. NEO combines conversational AI, vision-language technology, and systems capable of translating instructions into physical action. It can navigate a home, manipulate objects, respond to spoken commands, and evolve as its underlying systems are updated. 

NEO is still a connected device, but describing it simply as “IoT” understates the transparency challenge. A connected refrigerator may require disclosures about device identifiers, usage information, and account data. A humanoid AI operating inside a home raises additional questions: **What sensors are active? What does it perceive? Are conversations retained or used for training? Can humans remotely access the system? What happens when an AI decision becomes a physical action? And when its models are updated, has the product itself meaningfully changed?**

Robots are only one part of the shift. **Chatbots and conversational AI** create a different transparency problem because an automated interaction can increasingly resemble a human one. Legislatures are therefore asking a question traditional privacy notices were not designed to answer: **Does the person know they are interacting with a machine?**

The transparency question has therefore expanded.

---

> **Yesterday's question was primarily: What are you doing with my data?**

> **Today we must also ask: What are you? What are you doing? Why are you doing it? Who is responsible for you? And (also) am I dealing with a person at all?**

---

## The New Transparency Patchwork: Connected and AI-Enabled Products

As connected products incorporate artificial intelligence, transparency is expanding beyond traditional privacy disclosures. Organizations increasingly need to explain not only **what data they collect and how they use it, but also what the AI is, what it does, when people are interacting with it, how its outputs affect them, and, in some circumstances, how the AI itself was developed.**

[New Jersey's bot law](https://www.thedelatorrereview.com/new-jerseys-bot-disclosure-law-explained-when-automated-accounts-must-identify-themselves/) illustrates this approach. For covered commercial, real-estate, and election-related communications, the law requires disclosure that an interaction is being conducted by or through a bot **at the outset** and in a **clear and conspicuous** manner.

But identifying the bot is only one piece of an emerging transparency patchwork. New laws are requiring different disclosures about different aspects of AI. The following are only a few examples:

- **Training data.** [California's Artificial Intelligence Training Data Transparency Act ](https://www.thedelatorrereview.com/californias-ai-training-data-transparency-law-what-generative-ai-developers-must-disclose/)requires covered generative AI developers to publish information about datasets used in development, including their sources, purposes, scale, data types, licensing, personal information, processing, collection periods, and use of synthetic data. This is transparency about **how the AI was developed**, not merely what happens when someone uses it.
- **AI-generated advertising.** [New York's Synthetic Performer Disclosure Law ](https://www.thedelatorrereview.com/what-is-new-yorks-synthetic-performer-disclosure-law/)requires covered advertisers to conspicuously disclose when commercial advertisements contain certain AI-generated synthetic performers. Here, the transparency question becomes: **Is what the consumer is seeing real?**
- **Automated decisions.** Privacy and AI laws are increasingly addressing systems that make or facilitate decisions affecting individuals, adding transparency requirements concerning the use and purpose of automated processing and, depending on the applicable law, associated consumer rights.
- **AI itself.** States are also beginning to define AI differently. [California](https://www.thedelatorrereview.com/california-defines-ai-ab-2885-and-its-impact/), for example, uses a broad, technology-neutral definition focused on systems that infer from inputs how to generate outputs capable of influencing physical or virtual environments, while [Mississippi](https://www.thedelatorrereview.com/mississippis-definition-of-artificial-intelligence/) uses a somewhat different formulation centered on machine-based systems operating toward human-defined objectives.

These developments point toward a broader change. There is no single “AI transparency notice.” Instead, a connected product may encounter **multiple overlapping disclosure obligations concerning the data, the system, the interaction, the output, and even the development of the underlying AI.**

And the landscape is still developing. As AI becomes embedded in more connected products—and those products become more autonomous, conversational, personalized, and capable of acting in the physical world—the transparency questions are likely to multiply.

---

> **The present challenge is figuring out what must be disclosed about AI. The next may be figuring out how to keep those disclosures meaningful as the AI itself keeps rapidly changing.**

---

# One Product, Multiple Actors, Multiple Disclosure Layers

There is another complication.

With conventional privacy compliance, lawyers often begin by asking whether an organization is a **controller** or **processor**—a **business** or **service provider** in California—or perhaps a **third party**. Yes, in California we like being different, and that includes giving everyone different names.

AI introduces another regulatory supply chain.

The EU AI Act provides perhaps the clearest example. It allocates obligations among **providers, deployers, importers, distributors, authorized representatives, and, in certain circumstances, product manufacturers.** These roles are functional rather than simply contractual, and a single organization may occupy different roles for different systems—or even change roles as it modifies or repurposes an AI system. 

- For more see: [Who Is Regulated Under the EU AI Act? Understanding Providers, Deployers, Importers, Distributors and Other Operators](https://www.thedelatorrereview.com/who-is-regulated-under-the-eu-ai-act-understanding-providers-deployers-importers-distributors-and-other-operators/)

A simplified AI supply chain might look like:

**Provider → Importer → Distributor → Deployer → User**

But real products may be considerably more complicated.

Imagine a connected vehicle, household robot, wearable, or smart appliance incorporating a third-party general-purpose model. The device manufacturer may build the product and interface. Another company may provide the underlying model. Additional vendors may provide voice recognition, cloud infrastructure, analytics, or safety systems. A distributor may bring the product into a particular market. And the business operating the finished system may itself become a regulated deployer.

---

> The disclosure question becomes not merely **what must be disclosed, but who has the information necessary to disclose it.** Transparency today is a **supply-chain governance problem**.

---

This, in fact, will likely become one of the defining practical challenges of AI transparency.

A deployer cannot accurately explain a system it does not understand. A product manufacturer cannot necessarily describe the limitations of an incorporated model without information from the provider. And a provider may not know the context in which a downstream organization ultimately deploys its technology.

## How Should Organizations Disclose AI? A Practical Approach

The solution is unlikely to be a 40-page “AI Notice.” As AI transparency obligations multiply, organizations should instead focus on delivering **the right information, in the right place, at the right time.**

### 1\. Start by Mapping What Needs to Be Disclosed

Before drafting anything, identify the transparency obligations associated with the particular IoT device you are responsible for. Depending on the technology, jurisdiction, and organization's role, these may include disclosures about:

- personal information collected, used, shared, and retained;
- the fact that AI is being used;
- when a person is interacting with a bot or AI system;
- AI functionality and intended purpose;
- automated decisions or recommendations;
- AI-generated or synthetic content;
- training data and model development;
- human oversight or intervention; and
- third parties involved in providing or operating the AI.

---

> **Practice Tip:** Do not start with the privacy notice. Start with an inventory of the **system, use case, applicable laws, and required disclosures**. Otherwise, important AI-specific obligations may disappear into the traditional privacy-review process.

### 2\. Match the Disclosure to the Moment

Not every disclosure belongs in the same place. Consider which layer is appropriate for each piece of information:

- **Long-form disclosures** can provide the complete picture, including data practices, AI functionality, automated processing, retention, third-party involvement, rights, and other legally required information.
- **Short-form disclosures** can surface the information users are most likely to need during onboarding or setup, with links to additional detail.
- **Just-in-time disclosures** can appear when an AI feature activates, sensitive information will be collected or used, or the user is about to encounter an unexpected practice.
- **Persistent indicators** can communicate an ongoing condition—for example, that a microphone, camera, location sensor, recording function, or AI assistant is active.
- **Interaction-level disclosures** can tell users that they are communicating with AI rather than a person.

---

> **Practice Tip:** Ask **when the information would matter to a reasonable user's decision**. That is often a better guide to placement than asking where there happens to be room for another disclosure.

### 3\. Put Important Disclosures in the Interaction Itself

Some information cannot effectively be relegated to a privacy policy or terms of use.

[New Jersey's bot law](https://www.thedelatorrereview.com/new-jerseys-bot-disclosure-law-explained-when-automated-accounts-must-identify-themselves/) provides a useful example. For covered communications, disclosure that the interaction is being conducted by or through a bot must occur **at the outset** and be **clear and conspicuous**.

The broader lesson is straightforward: if the information changes how a person would understand the interaction, consider presenting it **as part of that interaction**.

---

> **Practice Tip:** Test disclosures in the actual product. A notice that looks conspicuous in a legal review document may be practically invisible on a watch, vehicle display, chatbot window, voice interface, or device without a screen. Not to mention Neo...

### 4\. Do Not Assume One Disclosure Satisfies Every Law

The same AI-enabled product may require several different kinds of transparency. A privacy notice explaining data collection does not necessarily satisfy a requirement to identify a bot. A bot disclosure does not explain automated decision-making. Neither necessarily addresses required training-data disclosures.

---

> **Practice Tip:** Build a **disclosure matrix** mapping each legal requirement to the responsible party, required content, audience, timing, and disclosure location. This is particularly important when multiple companies participate in the AI supply chain.

---

There is also a new wrinkle for IoT products with conversational or bot capabilities: **users may ask the AI directly about its privacy practices.** Questions such as *“Are you recording me?” “What information do you collect?” “Do you remember our conversations?”* or *“Do you share my data?”* may turn the bot itself into another source of privacy representations. Organizations should test how the system answers these questions and ensure those answers are accurate and consistent with the product’s actual practices and formal disclosures.

---

> **Practice Tip:** Add common privacy questions to chatbot testing and governance. An accurate privacy notice will not help much if the AI tells users something different.

### 5\. Treat Transparency as an Ongoing Product Requirement

AI-enabled products can change after launch. Models may be updated, functionality added, new data sources introduced, or an AI system repurposed for a different use. The disclosure that accurately described the product at launch may therefore become inaccurate later.

> **Practice Tip:** Make disclosure review part of **AI change management**. Material model updates, new AI features, changes in intended purpose, new data uses, and new third-party integrations should trigger a review of existing disclosures.

---

> **Disclose practices where the information matters to the user's decision—not merely where lawyers can find space for it.**

---

## The Next Frontier: When Conversations Become Advertising Data

Conversational AI creates a new intersection between **AI transparency, privacy, and advertising law**. One issue is familiar: a chatbot may recommend products based on sponsorships, paid placement, or other commercial relationships, raising questions about when that influence must be disclosed.

A more novel issue arises when **the user's prompts themselves are used to select advertising**. If a user tells a chatbot, *“I am training for a marathon and need new running shoes,”* and receives a shoe ad, is that merely contextual advertising? Or does it become targeted advertising when the prompt is retained, linked to the user, combined with other data, or used across sessions?

---

> The emerging question is therefore not only **“Is the AI selling something to me?” but “Is what I tell the AI being used to sell something to me?”**

---

The distinction matters because targeted advertising—and particularly advertising based on sensitive information—may trigger additional notice, opt-out, or consent requirements.

> **Practice Tip:** Map the flow from **prompt → inference → advertising selection**. Determine what information is used, whether it is retained or linked to the user, and whether it influences advertising beyond the immediate conversation. If consent is required, the chatbot should clearly disclose **before the practice occurs** that information provided in conversations may be used to personalize advertising and provide the required choice.

## Conclusion: Transparency Has Graduated

We have graduated from the days when transparency meant finding enough screen space for a privacy notice. AI-enabled products can now **collect, infer, recommend, converse, decide, learn—and increasingly, act.** Our disclosures need to keep up.

The practical lesson is to think of transparency not as a document, but as an **architecture**: the right disclosure, from the right actor, at the right moment.

And if that sounds easier said than done, it is. **Come watch our PLI panel.** We may not solve every transparency question—but, as noted above, if this panel cannot figure it out, I remain comfortable blaming the legislators.

---

> **And yes, that might have been advertising. Unintended advertising, perhaps. Or was it? And while we’re at it: am I a bot? How can you know for sure?**

---

## Additional Resources

For readers who want to explore the issues discussed in this article in greater depth, the following resources provide additional background on IoT transparency, emerging AI disclosure requirements, and the expanding AI regulatory framework:

### About the PLI IoT Event

- [**Advanced Internet of Things 2026: Deeper Dive, Practical Wisdom — PLI Program**](https://www.pli.edu/programs/advanced-internet-of-things---beyond-issue-spotting/444156?ref=thedelatorrereview.com) — The October 14, 2026 PLI program accompanying this article. The program includes **“Transparency and Privacy for Connected and AI-Enabled Devices,”** featuring Lydia F. de la Torre, Alan Friel, Linsey Krolik, and Irene Mo, as well as sessions addressing IoT agreements, data law, litigation, and emerging AI-related risks.

### IoT and Transparency

- [**Turning Mobile Privacy Guidance into IoT Best Practices**](https://www.thedelatorrereview.com/turning-mobile-privacy-guidance-into-iot-best-practices/) — Examines practical transparency approaches for connected devices, including layered notices, just-in-time disclosures, consent, third-party integrations, retention, and privacy by design.

### Emerging U.S. AI Transparency Requirements

- [**California’s AI Training Data Transparency Law: What Generative AI Developers Must Disclose**](https://www.thedelatorrereview.com/californias-ai-training-data-transparency-law-what-generative-ai-developers-must-disclose/) — Explains California's requirements for covered generative AI developers to disclose information about training datasets, including sources, contents, personal information, licensing, modifications, collection periods, and synthetic data. It also addresses substantial modifications and the need to integrate transparency into AI release management.
- [**New Jersey’s Bot Disclosure Law Explained: When Automated Accounts Must Identify Themselves**](https://www.thedelatorrereview.com/new-jerseys-bot-disclosure-law-explained-when-automated-accounts-must-identify-themselves/) — Examines New Jersey's requirement that certain automated accounts identify themselves when communicating with people in the state in connection with specified commercial, real-estate, or election-related activities, including the requirement for clear and conspicuous disclosure at the outset of the interaction.
- [**What Is New York’s Synthetic Performer Disclosure Law?**](https://www.thedelatorrereview.com/what-is-new-yorks-synthetic-performer-disclosure-law/) — Discusses New York's requirement for advertisers to disclose the use of certain AI-generated synthetic performers in commercial advertisements, illustrating the growing intersection between AI transparency and advertising law.
- [**California Defines AI: AB 2885 and Its Impact**](https://www.thedelatorrereview.com/california-defines-ai-ab-2885-and-its-impact/) — Explains California's technology-neutral definition of AI, including autonomy, inference, objectives, inputs and outputs, and the important distinction between an AI model and the broader AI system in which it operates.
- [**Mississippi’s Definition of Artificial Intelligence**](https://www.thedelatorrereview.com/mississippis-definition-of-artificial-intelligence/) — Examines Mississippi's statutory definition of AI and compares it with California's approach, illustrating why organizations cannot necessarily assume that the same technology will be defined—or regulated—the same way in every state.

### European Union: The EU AI Act

- [**The EU AI Act Explained: A General Guide to Europe’s Risk-Based AI Regulation**](https://www.thedelatorrereview.com/the-eu-ai-act/) *(Free subscription to The de la Torre Review Newsletter is required)* — Provides a practical introduction to the EU AI Act, including its risk-based framework, territorial reach, AI system and GPAI classifications, transparency requirements, regulated actors, phased implementation, governance, and enforcement.
- [**Who Is Regulated Under the EU AI Act? Understanding Providers, Deployers, Importers, Distributors and Other Operators**](https://www.thedelatorrereview.com/who-is-regulated-under-the-eu-ai-act-understanding-providers-deployers-importers-distributors-and-other-operators/) — Examines the actors regulated throughout the AI value chain—including providers, deployers, importers, distributors, authorized representatives, and product manufacturers—and explains why an organization’s role can determine its transparency and other compliance obligations.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Jul-4--2026-at-04_44_14-PM.png)

###