Does your chatbot have to say it's AI? The honest answer, state by state.
AI chatbot disclosure law went live in the EU on August 2 and four US states already have a version. Here is who it covers, who it does not, and the ten minute fix.
BlueFort AI
BlueFort AI
Go to your own website right now. Click the chat bubble. Type: “Am I talking to a real person?”
If your bot dodges, deflects, or answers in a way that leaves the question open, you have a problem that got a little more expensive five days ago.
AI chatbot disclosure law is no longer a thing that might happen. It went live in Europe on August 2, it has been live in Maine since last September, and one US version has been on the books since 2019. Most owners running a chat widget or an AI phone line have never read a word of it.
Here is the whole picture in one sitting, including the parts that do not apply to you. (Not legal advice. I run IT, not a law firm.)
What actually changed on August 2
The EU AI Act’s transparency rules, Article 50, became applicable on August 2, 2026.
In plain English: if an AI system talks directly to a person, that person has to be told they are talking to a machine, unless it is already obvious. Same idea for labeling deepfakes and AI-written articles on matters of public interest.
Two things make this bigger than “a European rule.”
It reaches outside Europe. The Act covers providers based outside the EU when the output of their AI system is used inside the EU. If your bot serves a customer in Dublin, you are in scope.
The numbers are not small. Penalties for breaching the transparency obligations run up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.
Now the calm part. That first duty sits on the provider of the system, meaning whoever built it and put it on the market. Buy an off-the-shelf bot and it is your vendor’s obligation, not yours. So the practical version: check that your vendor actually switched the disclosure on. And if you built the bot yourself on somebody’s API and put your own name on the front, stop assuming you are just a customer here.
The American one nobody talks about
Here is my favorite fact in this whole area.
California has required bot disclosure since July 1, 2019.
SB 1001, the B.O.T. Act, makes it unlawful to use a bot to communicate online with a person in California in order to incentivize a sale of goods or services, or to influence a vote, without clearly disclosing that it is a bot. Seven years. Almost nobody outside legal departments knows it exists.
Two details worth having. It is written around sales and elections, not every conversation, so the bot on your pricing page matters more than the one tracking orders. And the disclosure has to be clear and conspicuous, with the law saying plainly that if you disclose, you are not liable. A linked terms page does not count. In the conversation does.
Maine and Utah: the two that hit an ordinary business
Maine passed the broadest one. LD 1727 took effect September 16, 2025. If you use an AI chatbot with consumers in trade and commerce, and a reasonable consumer could not tell it was not human, you have to say so clearly. It is enforced under Maine’s Unfair Trade Practices Act, so the Attorney General can come after you and so can a private plaintiff. That private-suit door is the part worth your attention. It does not need a regulator to notice you first.
Utah went the other way and narrowed its rule. Under the amended AI Policy Act, effective May 7, 2025, you disclose when a consumer clearly asks whether they are dealing with a human or a machine, plus proactively in regulated professions. There is an explicit safe harbor: if the AI itself says it is not human at the outset and throughout, you are out of enforcement range.
Read those two together and you have the design brief. Say it up front, and answer honestly when asked.
The ones that are not yours
This is where most compliance content wastes your time, so let me clear the desk.
California’s AI Transparency Act (SB 942 as amended by AB 853) carries the same August 2, 2026 date and shows up in the same headlines. It applies to large generative AI providers with more than a million monthly users. That is OpenAI and Google. Not you.
Companion chatbot laws are a separate lane. California SB 243 took effect January 1, 2026, and Washington’s HB 2225 starts January 1, 2027. Both aim at bots built with a persona to sustain an ongoing relationship. Your return policy bot is not what they were written for.
Colorado keeps sliding. SB 189, signed May 14, 2026, pushed the AI Act to January 1, 2027 and cut it back to a narrower notice and transparency framework. The exemption for deployers under 50 employees survived. If you have been bracing for Colorado, unbrace.
What this means for you
Ten minutes, this week. Five steps.
1. Say it in the first message. Not the footer, not the terms link. The first thing in the chat bubble: “Hi, I’m the AI assistant for [business].”
2. Name it so the name gives it away. “Ava, AI assistant” beats “Ava.” Every one of these laws turns on whether a reasonable person could be fooled. Make that impossible and the question never arises.
3. Make it answer the direct question. Type “are you a human?” into your own bot. It has to say no, plainly, without a paragraph of hedging. Utah’s rule hinges on exactly this, and a bot that squirms is worse for trust than one that never labeled itself at all.
4. Do the phone line too. Voice counts. If you have an AI receptionist picking up, the greeting is where the disclosure lives.
5. Write down where AI touches a customer. One page. Which bots, on which channels, what each says at hello. Same discipline that stops shadow AI from becoming an incident: you cannot govern what you have not listed.
The verdict
Do it this week. It is a sentence, not a project.
And here is the part I actually believe, separate from the law. Every one of these rules has the same escape hatch: just tell people. Regulators landed there because it is the cheapest fix available and it solves the real problem.
The real problem is not that anyone will audit your chat widget. Nobody in Brussels is coming for a 30 person HVAC company. It is the customer who spends eleven minutes explaining their situation to what they thought was a person, works it out, and feels played. That customer does not file a complaint. They never call you again, and they tell people.
An honest label costs nothing and buys you the benefit of the doubt when the bot gets something wrong. Hiding the bot buys you nothing at all.
Reading about AI rules is free. Untangling one after a customer complaint is not. If you want someone to look at where AI already talks to your customers, and whether it says the right thing when it does, that is BlueFort IT’s day job. Still deciding what to trust with real work? We covered whether AI agents are worth it yet.
Want this kind of thinking applied to your business?
BlueFort IT helps you adopt AI safely and put it to work.
Talk to BlueFort IT