All posts
Guides·12 min read

Do You Have to Tell Customers It Is AI? US Chatbot Disclosure Laws (2026)

King Mak·Founder & CEO, Omago·
US AI chatbot disclosure laws explained for small business customer service agents

In 2025, California's privacy regulator fined two companies a combined $977,678 — Honda $632,500 and clothing brand Todd Snyder $345,178 — mostly for botched opt-out plumbing, the exact kind of process an AI agent touches (Cooley/CPPA, 2025). So do you legally have to tell customers they're talking to a bot? In most US states the answer is no, there is no blanket federal "you must disclose AI" law — but California's bot-deception rule (SB 1001) applies in narrow sales situations, and disclosure is fast becoming a baseline expectation regardless. Here's what actually applies to a small business, what the new 2026 companion-chatbot law (SB 243) does and doesn't cover, and the exact one-line bot intro I'd use.


Do you legally have to tell customers they are talking to AI?

In most of the United States, no — there is currently no broad federal law that forces every business to announce that a customer is chatting with AI. Disclosure law is patchy and state-driven, the same way US privacy law is a patchwork rather than one national rule (PrivacyLawMap, 2026). The closest thing to a hard requirement is California's bot law, and it's far narrower than most people assume.

California's SB 1001 (effective 2019) makes it unlawful to use a bot to knowingly deceive a person about its artificial identity in order to incentivize a sale or transaction, or to influence a vote (California Legislative Information). The trigger words there are "knowingly deceive." If your AI agent isn't pretending to be a human to trick someone into buying, you're outside the core of what SB 1001 targets — though the safe, simple way to stay clearly compliant is to just disclose.

So the honest framing for a small-business owner is this: outright legal mandates are limited and mostly tied to deception or specific states. But "I don't strictly have to" and "I shouldn't" are two different things. Customers increasingly notice and resent being fooled, and the trend in 2025–2026 has been toward more disclosure, not less.

It also helps to see how disclosure compares to the rules that do carry teeth. The table below lines up the main US rules an AI customer-service deployment touches, so you can see at a glance which ones are mandatory and which are best practice:

Rule / law What it governs Mandatory for a service bot? Teeth
SB 1001 (CA, 2019) Bot deception in sales/voting Only if you deceive to drive a sale Unfair-competition exposure
SB 243 (CA, 2026) "Companion" chatbots No — service bots exempt Companion-app rules only
Voluntary AI disclosure Telling users it's AI No, but expected Trust / brand risk
CCPA/CPRA (CA) + 19 states Data rights & retention Yes, if thresholds met $2,500–$7,500 per violation, per consumer
TCPA (federal) Automated texts to phones Yes, for SMS marketing $500–$1,500 per message

The takeaway from that table: the "tell them it's AI" line is largely about trust, while the financial pain lives in the privacy and messaging columns (Jackson Lewis, 2026; TCPA / Texty Pro, 2026). That's why I treat disclosure as cheap insurance — it costs a sentence and earns goodwill, while the rules that can actually fine you sit one column over.

What does California's SB 243 mean for a customer-service bot?

If you run a normal customer-service AI agent, California's new SB 243 almost certainly does not apply to you — it explicitly exempts bots used only for customer service and business operations. SB 243 took effect January 1, 2026, and it regulates "companion chatbots," the kind designed for ongoing social or emotional relationships with users (Perkins Coie, 2026). A bot that answers questions about your hours, books appointments, or captures a lead is not a companion chatbot.

This distinction matters because a lot of breathless coverage in early 2026 made small-business owners think a new AI-disclosure mandate had landed on them. It hadn't. The companion-chatbot rules — around things like suicide-and-self-harm protocols and reminders that the user is talking to AI — were written for consumer-facing emotional-companion apps, not for a plumber's after-hours intake bot.

That said, don't read the exemption as a reason to hide the AI. The clear signal from the legislative trend is that transparency is the expected default; several other state bills introduced in 2025 pointed in the same direction (Perkins Coie, 2026). The exemption protects you from the companion rulebook — it doesn't make secrecy a good idea.

It's worth understanding why SB 243 carved out service bots in the first place. The lawmakers were reacting to high-profile concerns about emotional-companion apps — products built to keep vulnerable users, including minors, in long parasocial conversations. A bot that tells a customer your Saturday hours simply isn't the same risk category, and the legislature said so by name. For an owner deciding whether to deploy an AI agent, that's reassuring: the most-publicized 2026 AI-chatbot law was deliberately written to leave ordinary business automation alone.

Still, the exemption is a floor, not a ceiling. Because the broader direction is toward more transparency, the businesses that will age well are the ones disclosing voluntarily today rather than scrambling when a future bill makes it mandatory. Treat the SB 243 carve-out as breathing room to do the right thing on your own terms, not as permission to stay quiet.

What is the difference between disclosure laws and privacy laws?

Disclosure law is about telling customers that they're interacting with AI; privacy law is about what you do with the data that conversation generates. They're easy to confuse and they're enforced very differently. You can be perfectly transparent about being a bot and still get fined for mishandling chat logs.

On the privacy side, the US has no single federal statute — it's a state-by-state patchwork. As of May 2026, 20 US states have an active comprehensive consumer privacy law, with Indiana, Kentucky, and Rhode Island all coming online on January 1, 2026 (PrivacyLawMap, 2026; IAPP, 2026). California's CCPA, as amended by the CPRA, gives residents rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive data (California Attorney General, 2026). Chat transcripts and the inferences drawn from them count as personal information.

The penalties are not theoretical for the privacy side. CCPA violations run $2,500 per unintentional violation and $7,500 per intentional violation, and each affected consumer can count separately (Jackson Lewis, 2026). That's the math that turned the Honda and Todd Snyder cases into six-figure fines (Cooley/CPPA, 2025). I cover the data side in depth in our guide to CCPA and the US state privacy patchwork for AI customer service — this article stays focused on the disclosure-and-transparency question.

Here's the quick way to keep them straight:

  • Disclosure / transparency: "We're telling you this is an AI agent." Governed mainly by SB 1001 (deception) and, for companion apps only, SB 243.
  • Privacy / data rights: "Here's what we collect, how long we keep it, and how to delete it." Governed by CCPA/CPRA and 19 other state laws.
  • The overlap: A good bot intro can satisfy both by disclosing the AI and linking to the privacy notice in the same opening message.

What should a small business put in its bot intro?

Put four things in the first message: that it's an AI agent, what it can do, how to reach a human, and a link to your privacy policy. That single intro line covers the transparency expectation, sidesteps any SB 1001 deception concern, and quietly handles the CCPA's notice-at-collection point — all without a wall of legal text.

The mistake I see is businesses either saying nothing (which feels sneaky when the customer figures it out) or dumping a paragraph of disclaimers that nobody reads. Neither works. You want one clean, friendly sentence that sets expectations and offers an exit to a human, because the fastest way to make people distrust a bot is to trap them in it.

Here's a template I'd actually ship:

"Hi! I'm the AI agent for [Business Name]. I can answer questions, book appointments, and take your details so the team can follow up. Want a person instead? Just say 'human.' By chatting, you agree to our [Privacy Policy]."

A few rules of thumb for that intro:

  1. Say "AI agent" or "automated assistant" plainly — don't give the bot a human name and a fake headshot and let people assume it's a person. That's the behavior SB 1001 was written to stop.
  2. Always offer a human handoff in the first message. It builds trust and it's your safety valve for anything sensitive or high-stakes.
  3. Link the privacy policy at the point of collection, because the CPRA requires you to disclose what you collect and how long you keep it at or before collection (Clym, 2026).
  4. Keep it to one or two sentences. Disclosure that nobody reads protects nobody.

If you want the deeper version of how to make a bot trustworthy rather than just compliant, our piece on whether you can trust AI customer service and how to set guardrails goes further into escalation rules and human oversight.

What can AI disclosure do — and what can't it do?

Disclosure builds trust and keeps you on the right side of deception rules, but it does not make you immune to liability for what the bot actually says. This is the part that gets glossed over. Telling a customer "this is a bot" is not a legal shield for bad answers.

The clearest warning here is the Air Canada case, where a tribunal held the airline responsible for inaccurate information its chatbot gave a customer — the company couldn't disown its own bot. We broke that down in the Air Canada chatbot ruling and what it means for AI liability, and the lesson holds for any US small business: if your AI agent promises a refund, a price, or a policy, you may be on the hook for it. Disclosure doesn't change that.

So here's the honest split. AI agents are genuinely good at instant first response, FAQs, lead capture, and routing — the high-volume, lower-risk work. They are not the right call for binding price quotes, complex diagnostics, or emergency decisions, where a wrong answer creates real exposure. The right design keeps a human in the loop for the consequential calls. That's why a clean handoff line in your intro isn't just polite — it's risk management.

It also matters which channel you're on. A web-chat widget makes the "you're talking to AI" disclosure visually obvious and is the easiest place to start. If you later add messaging channels, the disclosure logic stays the same, but the consent and compliance picture gets more involved — that's a TCPA topic, covered separately in our 2025–2026 TCPA changes and quiet-hours guide. TCPA statutory damages run $500 to $1,500 per message (TCPA / Texty Pro, 2026), so once you're sending automated texts, the disclosure conversation becomes a consent conversation too. Tools like Omago, an AI agent platform that helps SMEs automate customer conversations across WhatsApp, Telegram, and web chat, let you set that intro disclosure once and reuse it everywhere.

The other thing disclosure can't do is replace human judgment on the calls that matter. An AI agent that takes actions — capturing a lead, running a guided intake flow, routing the request to the right person, even writing the details to a connected system like Airtable — is doing real work, not just chatting. But the more a bot does, the more important it is that the consequential decisions still land with a person. Disclosure tells the customer what they're dealing with; a good handoff design makes sure that, when it counts, what they're dealing with is human.

How is AI disclosure law likely to change in 2026 and beyond?

Expect more states to introduce AI-transparency bills, but don't expect a single tidy federal rule any time soon. The direction of travel is clear: legislators want users told when they're dealing with AI, and several states floated disclosure bills in 2025 (Perkins Coie, 2026). The pace and exact shape, though, are uncertain — flag this as evolving, not settled.

The bigger near-term shift for AI customer service is actually on the automated-decision side. California's privacy regulator adopted automated decision-making technology (ADMT) regulations in 2025, with key provisions becoming applicable January 1, 2026 (IAPP, 2026). ADMT is defined broadly enough to potentially capture AI agents that process personal information to make or facilitate decisions — though the precise scope will develop through 2026, so treat it as a watch item rather than a current obligation for a basic Q&A bot.

There's also a privacy-side change worth watching even if you only run a simple bot. The notice-at-collection expectation under the CPRA — disclosing what you collect and how long you keep it, at or before collection — is exactly the kind of operational detail that drew 2025 enforcement (Clym, 2026; Cooley/CPPA, 2025). As AI tools make it trivial to log and store every conversation, the gap between "we collect chat data" and "we told people and can delete it on request" is where small businesses get exposed. The fix is boring but effective: a retention period in your privacy notice and a real way to honor deletion requests within the CCPA's 45-day window.

My practical advice for a time-poor owner: disclose now, voluntarily, in your bot intro. It costs you one sentence, it future-proofs you against the most likely direction of new rules, and it's simply what customers increasingly expect. You don't need to wait for a law to tell you that being upfront is the safer bet. As the old service line goes, you want to stay open while you're closed — and you want customers to feel good about who, or what, is answering.

Frequently Asked Questions

Is it illegal to use a chatbot without telling customers in the US?

Generally no — there's no broad federal law requiring AI disclosure, and most states don't mandate it either. California's SB 1001 only prohibits using a bot to knowingly deceive someone into a sale or to influence a vote (California Legislative Information). A normal, non-deceptive customer-service bot isn't illegal to run undisclosed, but disclosure is strongly recommended as best practice and is increasingly expected by customers.

Does California's SB 243 apply to my customer-service bot?

Almost certainly not. SB 243, effective January 1, 2026, regulates "companion chatbots" built for social or emotional relationships, and it explicitly exempts bots used only for customer service and business operations (Perkins Coie, 2026). A bot that handles FAQs, bookings, and lead capture falls under that exemption.

What's the difference between disclosure laws and privacy laws for AI?

Disclosure law is about telling customers they're talking to AI; privacy law governs the data that conversation creates. Privacy is a 20-state patchwork led by California's CCPA/CPRA, with penalties of $2,500 to $7,500 per violation, per affected consumer (PrivacyLawMap, 2026; Jackson Lewis, 2026). You can be fully transparent about the bot and still violate privacy law by mishandling chat logs.

Does telling customers it's AI protect me from liability for what the bot says?

No. Disclosure addresses deception, not accuracy. In the Air Canada case, the company was held responsible for wrong information its chatbot gave a customer despite the bot being clearly automated. Keep a human in the loop for binding quotes, complex issues, and anything high-stakes, and always offer an easy handoff to a person.

What's the simplest compliant bot intro for a small business?

One or two sentences that name the AI, say what it does, offer a human handoff, and link your privacy policy — for example: "Hi! I'm the AI agent for [Business]. I can answer questions and book appointments. Say 'human' for a person. By chatting, you agree to our Privacy Policy." That covers transparency, sidesteps SB 1001 deception concerns, and meets the CPRA's notice-at-collection point (Clym, 2026).

This article is general information current as of June 2026, not legal advice; consult counsel for your specific situation.

Sources: PrivacyLawMap (2026), IAPP (2026), California Legislative Information / SB 1001 & SB 243, Perkins Coie (2026), California Attorney General (2026), Jackson Lewis (2026), Cooley/CPPA (2025), Clym (2026).

Ready to try Omago?

Set up your AI agent in minutes. Free to start, no credit card required.