Blog/AI
AI

AI Chatbot Disclosure Law: What Your Business Actually Owes

California, Maine, Utah, and Colorado now regulate chatbot disclosure differently. Here is which rule actually reaches a normal business chatbot.

BY SUVYSOFT TEAM
A person typing a message into a website chat widget on a laptop

Four states regulate AI chatbot disclosure, and each one uses a different trigger. California requires it only when a bot is used to sell something or sway a vote, or, under a separate 2026 law, when the bot behaves like a companion. Maine requires it whenever a reasonable consumer could be fooled. Utah requires it only if a customer asks. Colorado's rule is not enforceable until 2027. Most business chatbots owe far less than owners assume.

Coverage of this topic tends to run one of two ways. Some pages treat "AI disclosure law" as a single national rule, which it is not. Others lead with California's flashy new companion chatbot statute and imply every business bot now needs a disclosure banner, which also is not true for the ordinary support or lead-qualification bot most small businesses run. Neither framing tells you which specific rule, if any, actually reaches your chatbot.

Does every business chatbot need an AI disclosure?

No. Most US states have no general chatbot disclosure statute at all. Four do: California, Maine, Utah, and, starting in 2027, Colorado. Within those four, the rule that reaches a standard sales or support chatbot is usually the older, less-covered one, not the one getting news coverage.

The practical test is simple: does your bot try to pass as a person, and does a state with a disclosure law actually apply to your customers? If the answer to the first question is no, most of what follows barely matters. If it is yes, or you are not sure, read on.

California has two chatbot laws, and they are not the same rule

California's Bots Disclosure Law, SB 1001, has been in effect since July 1, 2019 and is still the one most likely to apply to an ordinary business chatbot. It makes it unlawful to use a bot to communicate with a California resident with the intent to mislead them about talking to a human, specifically when that deception is meant to incentivize a sale or influence a vote. The disclosure it requires has to be "clear, conspicuous, and reasonably designed to inform" the person they are talking to a bot, meaning visible in the conversation itself, not buried in a linked policy page. Enforcement sits with the California Attorney General, and penalties run up to $2,500 per violation. (California Legislative Information)

Here is the detail that changes how much this matters for most businesses: SB 1001 requires intent to deceive. A chatbot that identifies itself as an assistant, shows a bot icon, or opens with "Hi, I'm an AI assistant" is not the bot this law was written to stop, because there is no deception to disclose around. Most commercial chatbot widgets already clear this bar without any legal review, simply because vendors default to labeling their bots for product reasons.

California's second chatbot law, SB 243, became enforceable on January 1, 2026, and it targets something different: AI companion chatbots, defined by human-like, socially adaptive behavior that sustains a relationship across sessions. Transactional bots limited to customer service, technical support, or similar single-purpose functions fall outside its scope, though a support bot that remembers a specific user's preferences and adapts its tone to them can drift into companion-chatbot territory even without meaning to. SB 243 is the one with real teeth: it creates a private right of action, letting anyone injured by a violation sue for the greater of actual damages or $1,000 per violation, plus attorney's fees. (California Legislative Information)

The two laws answer different questions. SB 1001 asks whether your bot is trying to pass as human to close a sale. SB 243 asks whether your bot is built to feel like a relationship. A typical lead-qualification or support chatbot usually only has to clear the first bar.

Does Maine's law reach a business outside Maine?

Yes, if the business has customers there. Maine's disclosure statute took effect on September 16, 2025 and applies more broadly than California's SB 1001: it covers any use of an AI chatbot "to engage in trade and commerce" with a consumer in a way that could mislead a reasonable consumer into believing they are talking to a person, with no carve-out limited to sales or elections. A violation is treated as a violation of the Maine Unfair Trade Practices Act. (Maine Legislature)

The "reasonable consumer" standard is a lower bar to trip than California's intent requirement. It does not ask whether the business meant to deceive anyone, only whether the interaction, as designed, could plausibly fool a typical person. A chatbot with no bot label, a human first name, and a conversational tone can satisfy that test even if deception was never the goal.

What actually triggers Utah's disclosure rule?

Utah was first to pass a general AI consumer-protection statute, in 2024, but a 2025 amendment narrowed it substantially. As of May 7, 2025, Utah only requires upfront chatbot disclosure for "high-risk" interactions, meaning the bot is handling health, financial, or biometric information, or giving financial, legal, or healthcare advice. Outside that category, a business only has to disclose that a customer is talking to AI if the customer directly and unambiguously asks, per a Davis Polk client alert tracking the amendment.

That "if asked" standard is the most forgiving trigger of the four states. The practical requirement it leaves in place is narrow but real: your chatbot, or the person operating it, has to have an honest answer ready when a customer asks whether they are talking to a bot. Ducking the question is the actual violation, not simply having an unlabeled bot.

Is Colorado's AI Act actually enforceable right now?

No, not yet. Colorado passed the first broad, risk-based AI consumer protection law in the country in 2024, then delayed it twice and rewrote it. The current version does not take effect until January 1, 2027, and it drops the original risk-management framework, which covered every stage from impact assessments to ongoing audits, for a narrower disclosure-focused rule that exempts a chatbot when it would already be obvious to a reasonable person that they are talking to AI. If you are budgeting compliance work now, Colorado belongs on a 2026 roadmap, not this quarter's task list, according to Hunton Andrews Kurth's tracking of the delay.

Does the FTC require disclosure even without a state law?

Yes, indirectly, everywhere in the country. The FTC has no chatbot-specific disclosure regulation, but it has repeatedly used its Section 5 authority over unfair and deceptive practices to go after businesses whose AI misled customers about what they were dealing with, through an enforcement sweep it named Operation AI Comply. The agency's own guidance puts it plainly: a company should "be careful not to mislead consumers about the nature of the interaction" and make clear when a customer is not talking to a human representative. (FTC)

This is the backstop that matters even for a business with no California, Maine, Utah, or Colorado customers at all. There is no state-law carve-out from federal deceptive-practices law, and a chatbot that impersonates a person to close a sale is the kind of conduct the FTC has already shown it will pursue on its own authority.

LawWhat triggers disclosure
California SB 1001 (2019)Bot used to deceive toward a sale or a vote
California SB 243 (2026)Companion-style bot, relationship features
Maine LD 1727 (2025)Any bot a reasonable consumer could mistake for a person
Utah AI Policy Act (2025)High-risk topic, or customer asks directly
Colorado AI Act (2027)Not enforceable yet; exempts obvious bots

How do you build disclosure in without hurting conversion?

A visible bot label costs almost nothing and clears every one of these standards at once. A small icon or a first line reading "You're chatting with our AI assistant" satisfies California's intent test, Maine's reasonable-consumer test, and the FTC's "don't mislead" standard simultaneously, and it costs nothing measurable in conversion, since the small business chatbots we have built rarely see a meaningful engagement drop from an upfront label people already expect on a support widget.

Give the bot a clean, honest answer for "am I talking to a real person," and route a "talk to a human" request to an actual queue instead of a dead end. That single behavior covers Utah's ask-triggered rule completely and gives every other state's standard nothing to complain about, since a bot that answers the direct question honestly is, by definition, not concealing anything.

Avoid designing the bot to sustain a persistent, personalized relationship unless that is genuinely the product. Features like remembering a specific user across sessions and adapting tone to them are exactly what pulls an otherwise ordinary support bot toward California's companion-chatbot rule and its private right of action. If your bot answers questions and qualifies leads, keep it built that way instead of adding relationship-style memory it does not need.

Suvysoft builds bot labeling and honest-answer handling into every website chatbot we deploy, as part of the same AI setup work that covers scoping, deployment, and tuning. When the chatbot is one piece of a larger custom agent build, the same disclosure logic gets designed in at the start instead of patched on after a demand letter.

Frequently asked questions

Does my customer-service chatbot count as a "companion chatbot" under California law?

Almost never, if it stays limited to answering questions, routing tickets, and qualifying leads. SB 243 exempts transactional and utility bots explicitly. It only applies once the bot remembers a specific user's preferences across sessions, adapts its tone to that user personally, or is designed to sustain an ongoing relationship rather than resolve a single interaction.

Does labeling my chatbot "AI Assistant" satisfy every state's law?

For California's SB 1001 and Maine's statute, yes in most cases, since both are built around whether a customer could reasonably be misled, and a visible bot label removes that possibility. Utah is different: it only requires an honest answer when a customer directly asks, so the label helps but is not the specific legal requirement there.

Do these laws apply if my business is not based in California, Maine, Utah, or Colorado?

Usually yes, if you have customers or website visitors in those states. All four statutes are written around where the consumer is located, not where the business is incorporated or headquartered, the same way most state consumer-protection laws work. A Kansas business selling nationally through a website chatbot can trigger any of them.

What is the fastest way to get compliant?

Add a visible bot indicator at the start of every chat session and make sure the bot gives an honest, direct answer when asked whether it is AI. That combination satisfies California's SB 1001, Maine's statute, the FTC's deceptive-practices standard, and Utah's ask-triggered rule in one pass, and it takes a developer a few hours, not a redesign.

Is there a federal law that requires AI chatbot disclosure everywhere?

Not a chatbot-specific one. The FTC enforces its existing unfair-and-deceptive-practices authority against bots that mislead customers, regardless of state, but there is no single nationwide statute naming chatbots the way California, Maine, and Utah's laws do. Compliance still has to be checked state by state.

Does a live chat widget that sometimes hands off to a human need this disclosure too?

Yes, for the portion of the conversation the bot handles. The moment a real person takes over, that is no longer bot communication and none of these laws apply to it. The trigger is specifically about a customer believing they are talking to a human when they are actually talking to software, so a clear handoff moment, not just a chat widget in general, is what needs to be honest about which one is happening.

Not sure whether your current chatbot needs a disclosure under any of these rules? Talk to us and we will walk through your setup before a demand letter forces the question.

Want us to do this for you?

Free 20-minute call

Tell us your goal. We will come back with a one-page document of the smallest moves to make for your business.

Start the conversation