Whether your chatbot legally needs an AI disclosure depends on which kind of bot it is and which state your users are in β California’s widely covered SB 243 only targets “companion chatbots,” not ordinary customer-service bots, while an older California law and several other states’ statutes apply more broadly to any bot used in a commercial interaction. Because writing a disclosure line takes under 30 minutes, the practical move for almost any small business is to add one regardless of which specific law technically applies to your exact setup β the honest complexity here is in knowing whether “regardless” is really the safest default, and it usually is.
“Does my state have an AI chatbot law” is the wrong first question
The more useful question is which type of chatbot you’re actually running, because the loudest 2026 headlines are almost all about one specific category β companion chatbots β that most small business customer-service or FAQ bots don’t fall into at all. Confusing the two leads either to unnecessary panic or, worse, to false confidence that a narrow law’s exclusion means you’re covered by every law.
The patchwork, honestly presented
| Law | What it actually covers | What it requires |
|---|---|---|
| California SB 243 (Companion Chatbot Law, effective Jan 1, 2026) | Chatbots that remember users across sessions, adapt to emotional state, or are marketed as a companion rather than a tool β explicitly not ordinary customer-service bots | Disclosure of non-human status, mental health crisis protocols, protections for minors; enforceable via private lawsuit, $1,000+ per violation |
| California’s older bot-disclosure law (SB 1001, since 2019) | Any bot used to communicate with a person online with intent to mislead about commercial transactions or to influence a vote | Disclosure that must be “clear, conspicuous, and reasonably designed to inform” the user β this is the one most likely to actually apply to a typical small business marketing or sales bot |
| Utah AI Policy Act (SB 149/SB 226) | Any business using generative AI to interact with consumers | Disclosure only when a user directly and unambiguously asks whether they’re talking to AI, or proactively during high-risk interactions involving health, financial, or biometric data β not a blanket up-front requirement |
| Colorado AI Act | Chatbots and other AI communication tools generally | Disclosure required unless “it would be obvious to a reasonable person” they’re interacting with AI β sources disagree on the exact effective date (February 2026 per one legal tracker, mid-2026 for major provisions per another), so confirm current status directly rather than trusting either date without checking |
| FTC Act (federal, nationwide) | Any AI chatbot engaged in deceptive practices | No specific disclosure format mandated, but deceptive AI-driven interactions can trigger federal enforcement regardless of whether your state has passed a chatbot-specific law at all |
Washington, Maine, Nebraska, and New Hampshire have also enacted chatbot-specific disclosure laws as of 2026, each with its own scope and triggers β the pace of new state activity here is genuinely fast, with more than 40 AI-related bills enacted across 16 states in 2026 alone. Treat any specific summary, including this one, as a snapshot rather than a permanent reference.
Watch the difference between a proposed bill and an enacted law
California AB 1609 would be the first US law to specifically regulate customer-service chatbot disclosure β the exact category most small businesses actually operate in. As of this writing, it has advanced out of committee but is not yet enacted. Don’t build a compliance program around a bill that hasn’t passed, but do treat it as a signal of where California is heading β the same is true of several other proposed bills mentioned in ongoing legal coverage, which get cited in comparison tables as if they were settled law when they aren’t yet.
What a basic compliant disclosure actually looks like
California’s older bot law offers useful concrete language: a disclosure has to be “clear, conspicuous, and reasonably designed to inform” a person that they’re interacting with a bot, not a person. A short, visible line near the start of a conversation β something like “You’re chatting with an AI assistant” β meets that bar for most ordinary use cases. Utah’s law hinges on a specific trigger rather than constant visibility: if a user directly and unambiguously asks whether they’re talking to AI, the bot has to say so. The practical fix is building a reliable canned response into your bot’s configuration that fires the moment a user asks any version of “are you a real person” or “am I talking to AI” β a five-minute setup task that covers Utah’s exact requirement regardless of whether your state has a broader law on the books.
Who needs to go further than a basic disclosure line
If your chatbot is used in a regulated field β health, legal, or financial services β Utah’s law requires proactive disclosure at the start of the interaction, not just on request, and several other states apply similar heightened standards to “high-risk” interactions regardless of whether a user asks. If your business serves Colorado users, the “obvious to a reasonable person” standard means an ambiguous or human-sounding bot needs a clearer disclosure than one that’s obviously automated. And if your product genuinely fits the companion-chatbot category β persistent memory across sessions, adapting to a user’s emotional state, marketed as a relationship or companionship product rather than a task tool β you’re in a materially heavier compliance category, with crisis-intervention protocols and minor-safety requirements that a standard customer-service bot doesn’t need to worry about at all.
What to actually do β five steps
- Identify which type of bot you’re actually running. An ordinary FAQ or customer-service bot faces a very different set of rules than anything with persistent memory or emotional adaptation marketed as a companion.
- Add a basic, visible disclosure line regardless of which specific law applies to you. Given how little effort this takes and how fragmented the legal landscape is, treating disclosure as a default rather than something to legally argue your way out of is the lower-effort, lower-risk choice for almost every small business.
- Build a canned “yes, I’m an AI” response for direct questions. This specifically covers Utah’s on-request trigger and similar provisions in other states, and it’s a one-time configuration task rather than an ongoing burden.
- Disclose proactively, not just on request, if you’re in a regulated field or serve Colorado users. The “wait until asked” approach that satisfies Utah’s general rule doesn’t satisfy the stricter standards that apply to high-risk interactions or Colorado’s broader test.
- Recheck this twice a year. This is one of the fastest-moving areas of state law active right now, and a summary that’s accurate today, including this one, may not describe next year’s landscape.
This is genuinely a question for an attorney familiar with your specific business and the states you operate in, not something a general article can settle for your particular situation β the patchwork above is a starting map, not a substitute for legal advice on your exact setup. The same due-diligence habit matters here that our piece on shadow AI for small business recommends for any tool touching your customers or their data: know exactly what you deployed before assuming it’s compliant by default.
Where this connects to decisions you’ve likely already made
If you’ve built a customer support system using an AI chatbot, the disclosure requirement belongs in the same setup checklist as the design decisions covered in our guide to building an AI customer support system and our no-code chatbot guide β add it before launch, not as a retrofit after a complaint. The same “check what actually applies to you rather than assuming” discipline applies here that our piece on AI insurance exclusions recommends for liability coverage, and if this disclosure line ends up in a written policy for your team, our AI usage policy guide is the natural place to record it. If EU users are part of your audience, the chatbot-specific disclosure obligation under the EU AI Act, covered in our EU AI Act guide, is a separate requirement to check alongside whichever US state rules apply to you. If part of what you’re weighing is whether a chatbot even improves your customer experience in the first place, that’s a separate question covered in our guide to AI customer service.
Does every AI chatbot legally need a disclosure?
Not under every law, but functionally yes as a practical default. Given how cheap a basic disclosure is to add and how fragmented state requirements are, most small businesses are better off disclosing regardless of whether their specific bot technically falls under a given state’s narrower definition.
Does California’s SB 243 apply to my customer-service chatbot?
Probably not. SB 243 specifically targets companion chatbots β ones with persistent memory, emotional adaptation, or companion-style marketing β and explicitly excludes ordinary customer-service bots. An older California law (SB 1001) is more likely to apply to a typical commercial chatbot instead.
What does Utah’s AI Policy Act actually require?
Disclosure only when a user directly and unambiguously asks whether they’re interacting with AI, or proactively during high-risk interactions involving health, financial, or biometric data. It’s not a requirement to display an AI disclosure constantly and visibly for every ordinary interaction.
What’s the difference between a “companion chatbot” and a regular chatbot under these laws?
A companion chatbot typically remembers users across sessions, adapts to their emotional state, and is marketed as a relationship or companionship product rather than a task tool. Laws like California’s SB 243 and New York’s companion chatbot statute apply specifically to that category, with much heavier requirements than an ordinary FAQ or support bot faces.
Is there a federal AI chatbot disclosure law?
Not a dedicated one yet, though a federal bill targeting AI impersonation of licensed professionals was introduced in March 2026 and hasn’t been enacted. The FTC Act already applies nationwide to deceptive AI chatbot practices regardless of state-specific legislation, so a state without its own chatbot law doesn’t mean you’re free of federal exposure.
What should a basic AI chatbot disclosure actually say?
A short, visible line near the start of the interaction β something like “You’re chatting with an AI assistant” β satisfies the “clear, conspicuous, and reasonably designed to inform” standard from California’s older bot law, which is a reasonable baseline even where a stricter or narrower law doesn’t technically apply to your specific bot.
Shurah is the founder of AI Tools Daily, tracking pricing, licensing and policy changes across AI tools so readers can make decisions without wading through marketing claims themselves.