Case Study 2 of 4SHIPPEDAI Disclosure & Consent System

Responsible AI, Written Down

In May 2026, outside AI-law counsel audited every AI product at Ecolab: the products were out of compliance, and nobody knew what compliance would look like inside the product.

  • In three weeks I created Ecolab’s AI disclosure and consent system, with guidance, not just components.
  • It brought current products into compliance and gave future ones a way to stay there.
  • Counsel approved it on the first review.
A page from the enterprise reference guide, AI Legal Disclosure and Disclaimer Patterns. It lists the eight patterns and the laws behind them (EU AI Act, FTC Act section 5, state chatbot laws), then walks through pattern 01, AI identity disclosure at session start, with real examples from Wells Fargo, Microsoft Copilot and the State of Michigan, why each works, and the legal risk of leaving it out. Two Ecolab Virtual Agent screens sit beside it.

At a glance

  • 3 wk

    From audit to a legal-approved standard: 80 to 90 hours studying AI law and enterprise AI legal patterns, most of it on my own time, then two weeks of design

  • 1 review

    One round with outside AI-law counsel, approved on the first pass and robust enough to satisfy the conditions of the entire audit

  • 8

    Disclosure and consent patterns in one system, adopted by Legal, engineering, product and the design department, with guidance that keeps future products in compliance as the law changes

The Decision

What I Chose

With AI legal requirements still ambiguous, I created a system with thorough guidance, not just static components, so the current AI products came into compliance and future products could stay there. It had to reduce risk proactively, for both Ecolab and its users.

I designed it on two separate axes:

  • Type: a disclaimer informs the user and asks nothing of them; a disclosure asks the user to act (consent, approve, deny, cancel and so on).
  • Escalation level: how loudly it speaks to the user, independent of type: base, info, caution or critical. A base disclaimer is a small, quiet line beside an AI answer; a critical disclosure stops the user’s work until they decide.

What I Rejected, and Why

  • One disclaimer on everything, at one volume: the small gray line under every AI answer that has become the common shortcut in enterprise software. It is noise where the stakes are low and invisible where they are high, and users stop reading it within a week.
  • Handling each new AI moment as a one-off. Teams were already debating severity every time a new AI feature appeared, and it would have meant repeating the audit for every product that followed.

Context & Constraints

Four screens of the Ecolab Virtual Agent panel. The first shows a Good Morning greeting that says the agent is AI, not a person, with a Support Cases menu of three options and a Tools and Help list. The second shows the greeting scrolled, with a still-working message while the assistant thinks. The third shows an answer with a Double-Check Before You Apply warning and Review Protocol and Continue to Dosing buttons. The fourth shows an automated-decision result with a model confidence score and a Request Human Review button.

Constraints

  • Outside Legal Audit, May 2026
  • No Known Path to Compliance
  • No Authority Over Legal
  • Chat, Canvas, Desktop & Mobile
  • AI Law Still Changing

In May 2026, a month after the assistant in Case Study 1 went live, outside legal counsel who specialize in AI law audited all of Ecolab’s AI products. The design department learned the results in a one-hour meeting with the lawyer:

  • The products were out of compliance
  • Nobody, in design or elsewhere, knew what compliance would actually require inside a product
  • Nearly every designer in that meeting said it was impossible to design for

I disagreed. I had already been studying the AI laws established so far and the AI legal patterns enterprises had put in place to meet them, and not only for chatbots. That distinction mattered: much of the organization believed AI meant agentic and agentic meant chat, so anything outside a chat window was assumed to be out of scope. It is not. A large part of the work was responsible AI guidance and education, not just design.

What the system had to work within:

  • No authority over Legal or engineering, so both had to be able to adopt it without a mandate.
  • Everywhere the Case Study 1 assistant lives: the copilot panel, the product canvas, desktop and phone.
  • Busy users: consent in a work product is designed for someone doing their job, not someone browsing.
  • A law still moving: built to be revised, not built once.

It was frustrating for many people. For me, it was a lot of fun.

Two Axes Everyone Conflated: What It Is, and How Loud

I separated what a message is from how loudly it speaks, so every new AI moment becomes one of eight predefined patterns instead of a debate.

1 · What It Is?

Informs. Nothing to do.

2 · How Loud It Is?

Always on.

3 · Where does it appear?

This moment lands in

Disclaimer · Base

AI Label

"AI-generated" on every response and insight card.

In chat: A message container with a color hierarchy and, for disclosures, checkboxes and buttons.

Color shows how serious the level is. Icons show who speaks and who acts.

What It Is ↓
How Loud It Is →

Base

Always on.

Info

Worth knowing.

Caution

Verify first.

Critical

Stop and decide.

smart_toy

Disclaimer

Informs. Nothing to do.

AI Label

"AI-generated" on every response and insight card.

Source Note

"Summarized by AI from your site data. Check the source."

Low Confidence

"Confidence is low. Verify before acting."

Safety-Critical

The action is withheld and routed to a human.

smart_toyperson

Disclosure

The user must act.

First Use

"You're working with an AI assistant." Acknowledge to continue.

Mode Shift

"Open full-screen?" The assistant offers; the user chooses.

Review Before Submit

A pre-filled case is reviewed and edited before it's sent.

Irreversible Action

Consequence first. "Cannot be undone." The one way back is named before the choice.

Logged · name + time

  • User
  • Agent
  • Gate
  • Log

Color shows how serious the level is. Icons show who speaks and who acts.

The diagram is the system: how loud it is across the top, what it is down the side.

  • Placement: a base disclaimer sits near the thing it qualifies and never interrupts; a critical disclosure is a modal that stops the flow until the user decides.
  • In chat, the levels are message containers with a color hierarchy, plus checkboxes and buttons for disclosures.
  • On the product canvas, they are modals, banners or notifications that interrupt on purpose.

The cell decides the anatomy, and the anatomy is one component with settings. That is why engineering could build it once and Legal could review it once: there is nothing to argue about in the fifth new AI feature that was not already settled in the first.

A Consent Moment Sized to the Consequence

I gave the highest-stakes moment its own pattern, because when an agent can act for the user, a yes or no is not enough: the consequence and the way back come first.

The irreversible-action consent pattern at the critical level: a modal titled Permanently delete audit records that states what the action does, its consequence, a warning that it cannot be undone from the app and the only way back, an unchecked acknowledgment box, a Cancel button and a disabled Delete records button, with a note that the action is recorded with a name and timestamp. Beside it, an Anatomy list of six numbered parts: activity, consequence, irreversibility and reversal, affirmation, consent and cancel, and accountability.

The irreversible-action consent pattern received featured treatment because it is where the stakes are highest. Its anatomy is fixed, and its order matters:

  1. The activity
  2. The consequence
  3. The fact that it cannot be undone
  4. The only reversal path (a restore-from-backup ticket, a settings restore, whatever is true)
  5. Only then, the Consent and Cancel buttons

Destructive actions add an acknowledgment checkbox that is never pre-checked. The primary button stays disabled until it is checked, Cancel is always available, and the action is recorded with the user’s name and a timestamp.

The user reads what will happen before they see a choice, and knows the escape hatch exists before they decide. It is the mode-shift consent line from Case Study 1 at a higher severity, and in Case Study 4 it is the gate before the agent rearranges a dashboard.

Why Legal Approved It on the First Review

I argued in their vocabulary (statute, precedent and exposure) rather than in design vocabulary, and I wrote it all down so it could outlive me.

The container components of the disclosure system. Disclaimers are informational notes in base, info, caution and critical styles. Disclosures carry actions (Not now and Open guide, Cancel and Acknowledge, Cancel and Apply change, Cancel and Submit) or a How sourcing works link. Below them sit text disclaimers and disclosures, and release-status pills such as Alpha, Pilot, Beta, Preview and Limited Release.

The system came with an enterprise reference guide. For each of the eight patterns it gives:

  • The requirement and its legal basis
  • Documented in-product examples from other Fortune 500 companies
  • The risk of leaving it out

The guide is why a designer with no authority over Legal got a first-pass approval from outside counsel: it did not ask them to trust a design; it showed them the law the design came from. It shipped with the spec pages engineering needed: the 2×4 grid as a one-pager, the consent-modal and card anatomies, and the first-run flow (sign-in, terms, AI consent) for desktop and mobile.

Adoption followed the same logic:

  • Engineering got one component and a set of settings.
  • Product got a decision rule instead of a meeting.
  • Designers across the department got a guide they could apply without me.

I was told afterward that counsel was shocked at the level of detail, comprehensiveness and thoroughness in the system, and that it was clear to her that I cared. That meant a great deal, because the care was for the user.

The same principle (AI proposes, the user decides) runs through the Insights & Recommendations cards that shipped in Ecolab3D. Each card carries what the agent observed, its source, the problem, the impact level (low, medium, high or safety), the justification and a recommended action. The user reviews, approves, defers, edits, comments or tags someone, and the decision is recorded as the card moves through new, reviewed, approved and deferred states. Deferral carries no penalty, because a user on a site cannot always act right now. That card anatomy is the subject of Case Study 4.

Where the User Stays in Charge

Disclosure, consent, confidence, feedback and escalation are not five separate components. They are one system, and its job is the user’s safety as much as their trust:

  • Disclosure: the user always knows when an answer is AI-generated.
  • Consent sized to the consequence: nothing irreversible happens on a misread.
  • Confidence shown as evidence (what was observed and what it is based on): the user can judge rather than simply believe.
  • Feedback with reasons: the product learns where it is wrong.
  • Escalation: a human is reachable from every level of the ladder.

Evidence & Outcome

  • Approved on First Review

    One round with outside AI-law counsel, May to June 2026. The system was robust enough to satisfy the conditions of the entire audit of Ecolab's AI products, and the products came into compliance with existing U.S., E.U. and international AI law.

  • 3 Weeks, 80–90 Hours of Study

    From audit to standard: the hours studying AI law and enterprise AI legal patterns were mostly my own time; the design itself took two weeks.

  • Adopted Across Four Functions

    Legal, engineering, product and the designers across the department adopted it with no mandate, on the strength of the guide. The Insights & Recommendations cards shipped inside Ecolab3D.

Dates and the review outcome are from my own project records. Law references are verified against the primary sources before publish. No card review-rate or was-this-accurate data is published because I do not have it.

What It Cost, and What I’d Do Differently

What It Cost

  • The hours: most of the 80 to 90 were mine, outside of work, because the audit did not come with time.
  • Untested copy: the consent copy was never tested with field workers in a second language, and I do not have data on how often users actually read a base label versus a caution container.
  • A law still moving: some of the vocabulary was mine before it was anyone’s, a strength for the audit and a risk for whoever maintains it without the guide.

What I’d Do Differently

  • Push for evidence statements instead of a confidence label: what was observed, what it is based on and what would change the call, because a score invites belief and an evidence line invites judgment.
  • Instrument the was-this-accurate control from day one, so the escalation levels can be tuned from data.
  • Test the consent copy with the users who will see it, in the languages they work in.