industry · product
US AI Disclosure Laws in 2026: Must You Tell Customers It's AI?
No single US federal law forces it yet, but a fast-growing patchwork of state rules, plus what customers now expect, already does. Here is what businesses must disclose when an AI answers, and how to stay on the right side of it.

There is no single US federal law that requires every business to tell customers they are talking to an AI, but that does not mean you are free to stay silent. In 2026, a fast-growing patchwork of state laws governs AI disclosure, and across the 2025 and 2026 legislative sessions, 19 states passed chatbot or AI-companion bills out of 146 introduced (Center for Democracy and Technology). Layer on top the 87% of consumers who say companies should disclose when AI is used (Avaya, 2025), and the practical answer for most businesses is yes: tell customers it is AI, clearly and up front.
This guide covers what US AI chatbot disclosure laws actually require in 2026, which businesses they hit, what a compliant disclosure looks like, and why transparency is good business even where no statute forces it. It is a companion to our breakdown of what the EU AI Act means for AI chatbots, for the US side of the map.
Does US law require you to tell customers they are talking to an AI?
Sometimes, and increasingly. There is no comprehensive federal AI transparency law, so the rules come from three places: specific state statutes, general consumer-protection and FTC deception law, and sector rules (health, finance, hiring). Whether you must disclose depends on where your customers are, what the AI is doing, and whether staying quiet could mislead a reasonable person.
The clearest trigger is deception. If an AI is used to make a customer believe they are dealing with a human in order to close a sale, that crosses a line in several states and under the Federal Trade Commission's authority over unfair and deceptive practices. The safest posture, and the one that matches customer expectations, is to disclose proactively rather than wait to be asked.
The main US AI disclosure laws in 2026
The map is a patchwork, not a single rule. These are the statutes most likely to touch a business that runs an AI chatbot or voice agent, as of August 2026.
| Law | Where | Who it covers | What it requires |
|---|---|---|---|
| California Bot Disclosure Law (SB 1001) | California (since 2019) | Bots used to knowingly deceive about being human to incentivize a sale or influence a vote | A "clear, conspicuous" disclosure that the user is interacting with a bot |
| California SB 243 | California (effective Jan 1, 2026) | Operators of "companion" chatbots | Disclose the user is talking to AI when a reasonable person could be misled, plus self-harm protocols and minor safeguards |
| Utah AI Policy Act (SB 149) | Utah (since 2024, amended 2025) | Businesses using generative AI with consumers | Disclose on request; disclose proactively in regulated occupations and high-risk contexts like health and finance |
| Texas TRAIGA (HB 149) | Texas (effective Jan 1, 2026) | Government entities (disclosure); private businesses (conduct limits) | Government must clearly disclose AI interactions; businesses barred from harmful or manipulative AI uses |
| EU AI Act, Article 50 | EU (from Aug 2, 2026) | Anyone serving EU users with a chatbot | Tell people they are interacting with an AI (full breakdown here) |
Two things make this landscape genuinely hard to track. First, it moves fast: Colorado passed the first comprehensive US state AI Act in 2024, then postponed and replaced it in 2026 before it ever took effect. Second, the laws overlap unevenly, so a single business selling into multiple states can face several disclosure standards at once. If you operate nationally, plan for the strictest rule that applies to any customer, not the loosest.
Which businesses actually have to disclose?
Most of the headline 2026 laws (like California's SB 243) target companion chatbots, the emotional or character AI apps, not a salon's booking bot. But the obligations that reach ordinary customer-service and sales AI are real and broader than many owners assume:
- You sell in California and the AI nudges a purchase. SB 1001 makes it unlawful to use a bot to deceive someone about being human in order to incentivize a sale. Disclosing removes the risk.
- You are in a regulated or high-risk field. Utah's law requires proactive disclosure when generative AI serves consumers in contexts like healthcare, legal, or financial services, and disclosure on request everywhere else.
- You serve any EU customer. The EU AI Act's transparency duty applies regardless of where your business sits.
- Anyone, under FTC and state consumer-protection law. Even without a named AI statute, presenting a bot as a human to close a deal can be an unfair or deceptive practice.
If your AI books appointments, answers product questions, or qualifies leads, the low-risk move is simple: identify it as an AI assistant at the start of the conversation, everywhere. We go deeper on the design side in our guide to human-in-the-loop AI, and on regulated fields in compliant AI for HIPAA and GDPR businesses.
What counts as a compliant AI disclosure?
The recurring statutory language is "clear and conspicuous," and it means what it says. A disclosure buried in a privacy policy or a terms-of-service link does not count. Across the US and EU rules, a defensible disclosure tends to share four traits:
- Proactive, not reactive. State it up front, before the customer relies on the conversation, rather than only when asked.
- Clear and conspicuous. Plain words in the conversation itself ("Hi, I'm an AI assistant for [business]"), not legalese and not hidden.
- Honest about limits. Do not imply the AI is a licensed professional or a specific named employee when it is not.
- A path to a human. Not always legally mandatory, but 90% of consumers say they should always be able to reach a person (Avaya, 2025), and several rules assume a human escalation route exists.
None of this hurts conversion. A one-line "I'm an AI assistant, and I can connect you to the team anytime" sets expectations and builds trust, which is the opposite of a friction cost.
Beyond the law: why disclosure is good business
Compliance is the floor. The stronger reason to disclose is that customers reward it and punish the alternative. Only 54% of consumers feel confident they can tell when they are interacting with an AI chatbot (SurveyMonkey, 2025), so many will not realize it is AI unless you tell them, and 14% say they would lose trust in a business that used an AI agent without clearly explaining it is AI. Trust in AI is already fragile: Avaya found overall consumer trust in AI slipped from 62% in 2023 to 59% in 2025.
The takeaway is not "use less AI." It is "be visible about it." Businesses that disclose clearly and offer a human handoff capture the efficiency of AI without paying a trust penalty when a customer figures out, mid-conversation, that they were not told. Getting caught concealing it is the expensive outcome, not the disclosure itself.
How Entagl makes AI disclosure and human handover simple
Entagl is built around the principle that AI acts and humans govern, which is exactly the posture these laws reward. A few capabilities make transparent, compliant deployment straightforward:
- You control how the agent introduces itself. The AI receptionist's persona and instructions are configurable, so you can have it identify as an AI assistant at the start of every conversation, in the customer's own language (the agent detects and replies in 30+ languages).
- Human handover is built in. Every conversation can escalate to your team in a unified inbox, so the "let me reach a human" path that customers expect, and that several rules assume, is always available.
- Guardrails on every reply. Output guardrails and intent rules keep the agent inside the boundaries you set, across the channels your agent runs on (WhatsApp, Instagram, Facebook Messenger, Telegram, web chat, and API).
- A compliance posture for regulated fields. Signed BAAs, AES-256-GCM encryption at rest, and PHI audit logging support the health and financial contexts where proactive disclosure is required, the same foundation we describe in our HIPAA and GDPR guide.
Because those controls are centralized, disclosure and handover are configuration, not a custom engineering project bolted onto a brittle chatbot.
What this does and does not mean
This article is general information, not legal advice, and the law here is moving monthly. Verify your specific obligations with counsel, especially if you operate in health, finance, hiring, or across multiple states or countries. Two honest caveats worth stating: most of the 2026 headline laws target companion and character AI, not routine business bots, so do not assume every statute applies to you; and disclosure alone does not cure a bot that gives bad or deceptive answers. The durable strategy is to disclose clearly, keep a human in the loop, and govern what the AI is allowed to say, which is good practice under any regime. For the broader ungoverned-AI risk picture, see our post on shadow AI and governance.
FAQ
Do I legally have to tell customers my chatbot is an AI?
It depends on where your customers are and what the AI does. There is no blanket US federal rule, but California, Utah, Texas, and 19 states passed AI or chatbot laws in the 2025 to 2026 sessions, the EU requires it, and the FTC can treat a bot posing as a human to close a sale as deceptive. The safe, expectation-matching move is to disclose proactively everywhere.
What is California's SB 243 and does it apply to my business chatbot?
SB 243, effective January 1, 2026, regulates "companion" chatbots: emotional or character AI, not a typical booking or support bot. It requires operators to disclose the user is talking to AI when a reasonable person could be misled, plus self-harm protocols and safeguards for minors. A standard customer-service agent is more likely to be touched by California's older SB 1001 bot-disclosure law than by SB 243.
What makes an AI disclosure "clear and conspicuous"?
Plain language inside the conversation itself, stated up front, that a normal customer would notice and understand, such as "I'm an AI assistant for [business]." A note hidden in a privacy policy or terms link does not meet the standard. Offering an easy way to reach a human strengthens it further.
Does disclosing that it is AI hurt conversions?
The evidence points the other way. Most consumers already expect it (87% want disclosure), and a meaningful share lose trust when they discover undisclosed AI. A short, upfront disclosure plus a human-handoff option sets expectations and protects trust, which supports conversion rather than undermining it.
Is disclosure enough to be compliant?
No. Disclosure is one requirement among several. Depending on the law you may also need a human escalation path, minor safeguards, limits on high-risk use, and data-protection controls. Treat disclosure as the visible floor, then govern what the AI is allowed to do underneath it.
The practical takeaway
In 2026, "no federal law requires it" is the wrong question. Enough states now regulate AI disclosure, and enough customers now expect it, that transparent AI is both the compliant choice and the commercially smarter one. Build it in from day one: identify the AI clearly, keep a human reachable, and control what the agent can say.
If you want to see how transparent, human-in-the-loop AI works across every channel your customers use, book a 30-minute demo and we will walk through it on your real use case.
Sources: Center for Democracy and Technology, 2026 State and Federal AI Legislation Updates; Taft, The Big Long List of U.S. AI Laws; Financier Worldwide on California SB 1001; Buckley Law on state AI laws; Avaya customer experience statistics (2025); SurveyMonkey consumer AI-sentiment research (2025). This article is general information, not legal advice.