Almost every business I talk to wants a chat bubble on its website now, and more of those bubbles are powered by AI rather than a person typing back. The question I get asked next is a fair one: do you legally have to tell visitors they are talking to an AI?
The short answer: in a growing number of places, yes, and in the places where it is not strictly required, disclosing is still the safer and more honest choice. California, Utah and Texas each have their own rules, the EU AI Act’s chatbot transparency duty started applying on 2 August 2026, and the FTC has made clear that AI does not get a pass from ordinary consumer protection law. Here is how I read each one, and the wording I put into chat widgets.
California: the bot disclosure law
California was first. Its bot disclosure law, Business and Professions Code sections 17940 to 17943, has been operative since July 1, 2019. It defines a bot as an automated online account where all or substantially all of the actions or posts are not the result of a person.
Section 17941 makes it unlawful to use a bot to communicate with someone in California online with the intent to mislead them about its artificial identity, in order to knowingly deceive them and incentivize a purchase or sale of goods or services, or to influence a vote. The key line for a business is the safe exit built into the same section: a person using a bot is not liable if they disclose that it is a bot. That disclosure has to be “clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot.”
The law turns on intent to mislead, so a plainly labeled chatbot is not the target. And the statute’s 10 million monthly visitor figure only defines an “online platform,” whose service providers section 17942 excuses. It is not a size exemption for businesses running bots.
California’s newer AI laws, briefly
Two later California laws often come up, so it helps to know where they stop:
- Companion chatbots. SB 243, approved October 13, 2025, requires a clear and conspicuous notice that a companion chatbot is artificially generated and not human, if a reasonable person would otherwise be misled. Its definition expressly excludes a bot used only for customer service or a business’s operational purposes. A typical website support or booking bot is outside it, as I read the text.
- Health care communications. AB 3030, approved September 28, 2024, requires health facilities, clinics, physician’s offices and group practices that use generative AI to write patient communications about clinical information to include a disclaimer that AI generated it, plus clear instructions for reaching a human. Communications read and reviewed by a licensed or certified provider are exempt.
Utah: disclose when asked, and up front for regulated services
Utah’s rules were narrowed and restructured in 2025 by SB 226, which took effect May 7, 2025. As enacted in Utah Code 13-75-103, there are two tiers:
- Any supplier in a consumer transaction that uses generative AI to interact with someone must disclose that the person is interacting with generative AI and not a human, if the person asks. The question has to be a clear and unambiguous request to find out whether they are talking to a human or AI.
- People in regulated occupations (occupations that need a state license or certification through Utah’s Department of Commerce) must prominently disclose AI use when it is a “high-risk” interaction, which includes collecting health, financial or biometric data, or giving personalized advice someone could rely on for significant personal decisions. That disclosure goes at the start of a voice interaction, and in writing before a written one starts.
The same bill adds a safe harbor in 13-75-104: no enforcement action if the AI clearly and conspicuously discloses, at the outset and throughout the interaction, that it is generative AI, is not human, or is an AI assistant. Administrative fines run up to $2,500 per violation. The safe harbor is the practical takeaway: disclose at the start, keep it visible, and the “only if asked” rule never matters. SB 226 also moved the repeal date of Utah’s Artificial Intelligence Policy Act to July 1, 2027, so watch for changes before then.
Texas: TRAIGA
Texas passed the Texas Responsible Artificial Intelligence Governance Act as HB 149, signed June 22, 2025 and effective January 1, 2026. Because I work in Texas, as Solutions Architect at Lonestar Home Healthcare, I read the enrolled text closely. Its disclosure section, Business and Commerce Code section 552.051, does two things:
- A governmental agency that offers an AI system meant to interact with consumers must disclose, before or at the time of interaction, that the consumer is interacting with AI. It applies even if that would be obvious to a reasonable consumer.
- If an AI system is used in relation to a health care service or treatment, the provider of that service must give the same disclosure to the patient or their personal representative no later than the date the service is first provided (or as soon as reasonably possible in an emergency).
The disclosure must be clear and conspicuous, in plain language, and must not use a dark pattern. It may be delivered through a hyperlink to a separate web page. TRAIGA does not impose a general chatbot disclosure duty on ordinary private businesses. The attorney general has exclusive enforcement authority, there is no private right of action, violators get a 60-day cure period, and uncured violations carry civil penalties starting at $10,000.
For the home health and home care agencies I work with, the health care clause is the one to take seriously. Whether a marketing chat on your public website counts as AI used “in relation to” a service is exactly the kind of question for your attorney. I simply disclose, which makes the question moot.
The EU AI Act: Article 50
If your site serves people in the EU, the EU AI Act (Regulation (EU) 2024/1689) matters even if you are based elsewhere. Article 2 extends it to providers and deployers outside the EU when the output of their AI system is used in the Union.
Article 50(1) requires providers to design AI systems that interact directly with people so that those people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. Article 50(5) says this information must be given in a clear and distinguishable manner at the latest at the first interaction, and must meet accessibility requirements. Under Article 113, these rules apply from 2 August 2026. Breaching Article 50 can draw fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, under Article 99.
The 2026 “Digital Omnibus” amendment, Regulation (EU) 2026/1744, delayed several high-risk obligations, but as I read it, its only changes to Article 50 are to the codes of practice paragraph and a transition to 2 December 2026 for the machine-readable marking of AI-generated content in 50(2), for systems already on the market. The chatbot disclosure in 50(1) was not postponed.
The duty sits with the provider. If you buy a chat product, that is usually the vendor; if you build your own on a model API, it may be you. Either way, I would not lean on the “obvious” exception. A floating bubble with a stock avatar is not obviously a machine.
The FTC: no AI exemption
The US has no single federal chatbot disclosure statute. What it has is Section 5 of the FTC Act, which declares unfair or deceptive acts or practices in commerce unlawful. When the FTC announced its Operation AI Comply sweep in September 2024, then-Chair Lina Khan said the cases “make clear that there is no AI exemption from the laws on the books.”
One of those cases is a useful warning for anyone marketing a chatbot. The FTC finalized an order against DoNotPay, which promoted its service as “the world’s first robot lawyer.” The FTC charged that the company did not test whether its AI performed at the level of a human lawyer. The order required $193,000 in monetary relief and bars the company from claiming its service performs like a real lawyer without evidence.
So the federal risk runs both ways. Letting people think a bot is human can be deceptive, and so can claiming your bot does more than it does.
What I put in a chat widget
When I designed the AI receptionist for a home healthcare agency, disclosure was part of the script from day one, not a legal patch added later. In my experience, people are far more annoyed to discover halfway through that they have been typing to a bot. This is the wording pattern I use, written to fit the strictest of the rules above at once.
1. A label that never disappears
Put it in the widget header, visible for the whole conversation, not only in the first message that scrolls away:
Virtual assistant (AI) · A person can take over anytime
2. An opening message that says it plainly
Hi, I’m an AI assistant for [Business name], not a person. I can answer common questions and help you book a call. Please don’t share medical or financial details here. If you’d like to talk to someone on our team, just type “human.”
That one message discloses up front, sets expectations and offers a human. For healthcare clients the “don’t share medical details” line also supports my HIPAA website guide.
3. A straight answer to “am I talking to a real person?”
Hard-code this instead of leaving it to the model, which can be talked into role-play. Utah’s rule is triggered by exactly this question:
No, I’m an AI assistant, not a human. Would you like me to connect you with a member of our team?
4. A clean handoff
When a person takes over, say so: “You’re now chatting with Maria from our intake team.”
5. Voice needs its own line
Utah’s regulated-occupation rule asks for a spoken disclosure at the start of a voice interaction. For phone agents I open with: “Thanks for calling [Business name]. You’ve reached our AI assistant. I can help with most questions, or connect you to a person anytime.” I cover phone setups more in my guide to AI receptionists.
6. A link to the details
Add a “How this assistant works” link to a page explaining what the AI is, what it stores and how to reach a person. Texas explicitly allows a hyperlink for its disclosure.
If you are still deciding whether a chatbot is worth it at all, I wrote about why most small businesses don’t need AI yet.
Frequently asked questions
Is there a federal law requiring chatbot disclosure in the US?
Not a dedicated one that I have found. The FTC Act’s ban on deceptive practices is the federal backstop, and the FTC has said there is no AI exemption from existing law. State laws in California, Utah and Texas add specific requirements on top of it.
Do I need to disclose if my business is small?
Not as I read these laws. California’s 10 million visitor figure defines large online platforms, not a threshold for businesses using bots, and Utah applies to any supplier in a consumer transaction. Disclosing costs one sentence, so I treat it as required for every client.
Can my chatbot have a human name?
Yes, as long as it never implies a person. “Ava, our AI assistant” works. “Ava from our front desk” with no AI label is what California’s law and the FTC’s deception standard are aimed at.
Does the EU AI Act apply to a US business website?
It can. Article 2 covers providers and deployers outside the EU where the AI system’s output is used in the Union. If you actively serve EU customers, ask your chat vendor how they meet Article 50 and talk to counsel about your own role.
Want me to check yours?
Most chat widgets need only a header label, a better first message and a fixed answer to “are you human?” If you would like me to look at yours, get in touch.



