I just found this by accident ... Looking at the policy, for purposes of the US, disclosing the use of the client ID to combine your sessions that start with AMP sessions in the Google cache with sessions that continue on your main site, requires only that you disclose that in your privacy policy.
The EU issue is the trickier one I think, and I'm no lawyer, and can't therefore give legal advice. What I've noticed though, is that lots of sites now put a message on the bottom of the browser window telling you something like "By using this site you are consenting to the use of cookies" or something along those lines. I wonder if they are doing that to meet the spirit of the EU regulations? I'd be interested to see if you learned anything since you posted the question above.