Compliance •

AI Chatbot Disclosure Law by State: What Businesses Must Do

AI chatbot disclosure law differs by state: California, Colorado, Utah, Texas, NYC, and Illinois compared, plus copy-paste widget wording and a checklist.

A

Anas R.

— read

AI Chatbot Disclosure Law by State: What Businesses Must Do

Direct answer: in most cases, yes, disclose that your chatbot is AI, though the exact legal requirement depends on your state and what the bot does. California's B.O.T. Act only forces disclosure on very large platforms selling via a bot, but its safe harbor is free to claim regardless of size. Colorado's AI Act now applies only once a bot drives a "consequential decision" like credit or employment, effective January 1, 2027. Utah requires proactive disclosure only from licensed professionals in high-risk interactions. Texas and NYC's rules target government use and hiring tools, not a storefront FAQ bot.

None of these laws agree on scope, threshold, or penalty. What they agree on is the fix: tell people up front they're talking to AI. This guide compares eight laws across six jurisdictions, gives you copy-paste disclosure wording, and flags the sector traps, healthcare, hiring, lending, ecommerce, where a harmless-looking bot turns out to be legally something else.

This is the US counterpart to our EU AI Act chatbot compliance guide. If your chatbot is reachable by users in both the US and the EU, you need both.

Not legal advice

This article is general information, not legal advice, and it does not create an attorney-client relationship. State AI legislation is being amended, delayed, and rewritten on a roughly quarterly basis, Colorado alone has changed its effective date three times since 2024. Confirm current requirements with a licensed attorney before you finalize a compliance decision, especially for healthcare, hiring, or financial services deployments.

Last reviewed: September 9, 2026. We recheck this page roughly every six months; if you spot a change we've missed, let us know.

Quick verdict

  • The universal safe move: a plain, visible "you're talking to an AI assistant" disclosure before or at the start of the conversation clears the bar in every jurisdiction below, whether or not you're technically in scope
  • California: SB 1001 only binds bots on platforms with 10M+ monthly US visitors; SB 243's companion-chatbot rules are the sharper trap for ecommerce bots with memory/personalization
  • Colorado: AI Act repealed and replaced by SB 26-189; now applies only to "consequential decision" AI, effective January 1, 2027 (not the original 2026 date)
  • Utah: most businesses only disclose if asked; licensed professionals (health, legal, financial) must disclose proactively in high-risk interactions
  • Texas: TRAIGA's disclosure duty targets government agencies and healthcare providers, not general-purpose business chatbots
  • NYC & Illinois: the real exposure is hiring tools (resume screening, candidate ranking), not employee self-service or FAQ bots
  • CCPA: chat transcripts with identifiers are personal information today; new ADMT rules for "significant decision" bots phase in starting April 2027

TL;DR: State-by-State AI Chatbot Disclosure Law Comparison

The table below is the fastest way to find your jurisdiction. It is not exhaustive, most states have no chatbot-specific law at all, but it covers every law and regulation a US business deploying a customer- or employee-facing chatbot needs to check as of September 2026.

Law Who Must Comply What to Disclose Enforcement & Penalty Status (Sept 2026)
California B.O.T. Act (SB 1001) Bots on public platforms with 10M+ monthly US visitors, used to sell or influence a vote, with intent to mislead about being human Clear, conspicuous disclosure that it's a bot (full safe harbor) CA AG/DA via Unfair Competition Law; up to $2,500/violation In force since July 1, 2019
California companion-chatbot law (SB 243) "Companion chatbots" with adaptive, relationship-sustaining responses; excludes plain customer-service bots, but memory/personalization is a risk factor AI-nature disclosure, minor-safety protocols, crisis-referral protocols CA AG; private right of action Effective January 1, 2026
Colorado AI Act (SB 26-189, replacing SB24-205) Deployers of AI that "materially influences" a consequential decision: employment, lending, insurance, healthcare, housing, education, government benefits Pre-use notice + adverse-decision notice within 30 days CO AG only; no private right of action; 60-day cure period Effective January 1, 2027 (date has moved twice; litigation pending)
Utah AI Policy Act (Title 13, Ch. 77) Any business using generative AI with consumers; stricter tier for licensed professionals (health, law, financial services, accounting, engineering, architecture) General: disclose only if asked. Licensed pros in "high-risk" interactions: proactive disclosure Utah Division of Consumer Protection; up to $2,500/violation; no private right of action Current version effective May 7, 2025
Texas TRAIGA (HB 149) State government agencies (always); healthcare providers using AI in diagnosis, treatment, or triage. No general private-sector chatbot mandate AI-use disclosure (gov't/healthcare only); otherwise bans specific harmful practices rather than mandating a label TX AG exclusive; no private right of action; 60-day cure; up to $200,000/violation if uncured Effective January 1, 2026
NYC Local Law 144 (AEDT) Employers/agencies using an automated employment decision tool for NYC-based hiring or promotion (resume screening, candidate ranking) — not general HR self-service Published independent bias audit + 10-business-day advance notice + alternative process NYC Dept. of Consumer and Worker Protection; $500–$1,500/violation, per day In force since July 5, 2023; enforcement tightening in 2026
Illinois HB 3773 + BIPA HB 3773: employers using AI in hiring, promotion, discipline, or discharge. BIPA: anyone capturing biometric identifiers (voiceprint, face geometry) HB 3773: notice that AI is used in the decision. BIPA: written consent before capture HB 3773: IL Dept. of Human Rights, damages + penalties. BIPA: private right of action, $1,000–$5,000/violation HB 3773 effective Jan 1, 2026; BIPA in force since 2008
California CCPA/CPRA (chat transcripts) Businesses meeting CCPA thresholds that collect personal information (identifiers, IP address) in chat transcripts from CA consumers Right to know/delete/correct/opt-out; ADMT pre-use notice once a bot drives a "significant decision" CPPA + CA AG; standard CCPA civil penalty framework CCPA current; ADMT rules finalized, phasing in Jan–Apr 2027

Sources are cited throughout the sections below. Effective dates in this table reflect the status as of September 2026; several have already changed once and may change again — see what's likely coming next.

The Common Denominator: Tell People They're Talking to a Bot

Every law above disagrees on scope, but converges on the same fix: if your chatbot proactively and plainly tells the user it's an AI assistant, before or at the start of the conversation, you clear the disclosure bar in every jurisdiction here, regardless of whether the underlying statute technically applies to you.

Most Heeya-sized businesses fall below the strictest thresholds, California's B.O.T. Act binds only 10-million-visitor platforms, Colorado only bots driving a consequential decision. A five-person firm's FAQ bot is very likely outside the letter of most of these laws today. That is not the same as safe to ignore, for three reasons:

  • Thresholds move. Colorado's AI Act has changed its effective date three times since 2024, most recently getting repealed and rewritten entirely by SB 26-189 in May 2026.
  • Enforcement tightens without new legislation. A December 2025 city comptroller audit found NYC's decade-old Local Law 144 weakly enforced; the city has since adopted a formal enforcement workbook, tightening the posture without changing a word of the statute.
  • Disclosure is nearly free. A one-line opening message and a visible badge cost nothing next to retrofitting disclosure after a demand letter arrives.

If your users also include anyone in the EU, disclosure is not optional at all: see our EU AI Act chatbot compliance guide for Article 50's enforceable transparency duty.

Sector-Specific Traps: Where a "Simple" Chatbot Becomes a Legal Problem

The statutes above mostly exempt general customer-service and FAQ bots. The traps below are the specific features and use cases that pull an otherwise-exempt chatbot back into scope.

Healthcare: diagnosis and treatment language, not just PHI

Texas's TRAIGA imposes a disclosure duty on healthcare providers using AI in diagnosis, treatment recommendations, or triage, separate from any HIPAA question, and Utah names health care among the occupations subject to its "high-risk interaction" trigger. The safest architecture for a medical, dental, or wellness bot: answer from published content only, hours, insurance, services, scheduling, and hand off anything resembling symptoms or treatment advice to a human. That is the pattern behind Heeya's dental practice chatbot: informational answers, a clear human handoff, nothing diagnostic. It is also the same zero-PHI architecture covered in depth in our HIPAA compliant chatbot guide, which this disclosure duty sits alongside rather than replaces.

HR and hiring: self-service is fine, screening candidates is not

NYC Local Law 144 and Illinois HB 3773 both target one function: using AI to screen, rank, or score candidates, or to influence hiring, promotion, discipline, or discharge. A bot answering PTO or benefits questions from your handbook is not an automated employment decision tool under either law, that's the employee self-service use case. The line is crossed the moment you feed it resume text and ask it to shortlist candidates, triggering NYC's bias audit and 10-day notice, and Illinois's notice requirement from January 1, 2026. Keep hiring with a human and an applicant-tracking tool; use a chatbot for HR only for self-service.

Financial services: information is fine, advice and approval decisions are not

Colorado's consequential-decision trigger names financial and lending services explicitly; Utah's high-risk tier covers licensed financial advisors. Listing loan products or rates is informational. Telling an individual whether they personally qualify is a decision, exactly what these laws target, and the kind of interaction California's coming ADMT rules will treat as "significant" once they phase in. Keep the bot to product and rate information; route applications to a loan officer or secure portal.

Ecommerce is the lowest-risk category, with one caveat. SB 243 explicitly excludes ordinary customer-service and business-operations bots, so a straightforward order-status bot isn't what the law targets. The caveat is personalization: a bot built to remember a shopper's preferences and sustain an ongoing, relationship-like persona is exactly the profile SB 243 was written to catch. Keep an ecommerce chatbot's tone transactional and disclose it's AI regardless.

What to Actually Write in Your Widget

The wording below is deliberately plain, no "smart assistant" euphemisms, because every law reviewed here that requires disclosure requires it to be unambiguous. Adapt these to your product; the structure (state it's AI, state the limitation, give a human option) is what matters.

General customer support (works in every jurisdiction above)

"Hi, I'm an AI assistant trained on [Company]'s help documentation. I can answer questions about [topic], but I'm not a person. Want to talk to someone on our team instead? [Contact link]."

Regulated professional / high-risk interaction (healthcare, legal, financial — Utah's proactive-disclosure tier)

"You're chatting with an AI assistant, not a licensed [clinician / attorney / financial advisor]. Nothing here is medical, legal, or financial advice. For guidance specific to your situation, please [book a consultation / contact our office]."

Employee-facing HR self-service (distinguishes it from an AEDT)

"This assistant answers general HR policy questions (PTO, benefits, payroll) using our employee handbook. It does not screen candidates or make hiring, promotion, or disciplinary decisions. For anything specific to your employment, contact HR directly."

Financing / lending-adjacent ecommerce or real estate

"I can share our pricing, availability, and financing options in general terms. I can't tell you whether you personally qualify or what rate you'd get, that decision is made by [lender/underwriter], not by this chatbot."

Pair the opening message with a persistent visual cue, a small "AI Assistant" label near the chat bubble that's visible without opening the widget. A message the user can scroll past does not satisfy the "clear and conspicuous" standard used across these statutes; a label they see before they click does. Heeya's widget includes a configurable AI disclosure element and opening-message field for exactly this reason, though the specific wording and placement decisions above remain yours to make and have reviewed. That badge also has to be usable by screen-reader visitors, not just visible ones; see our ADA/WCAG chat widget checklist for how to implement it without failing an accessibility audit.

Transcripts: Retention, Deletion Requests, and What Counts as Personal Information

A chat transcript is not exempt from privacy law just because a bot generated half of it. Under the CCPA/CPRA, any identifier collected in the course of a conversation, a name, an email address, an IP address, a user account ID, makes that transcript "personal information," which gives California residents the right to know what's stored, request deletion, request correction, and opt out of its sale or sharing.

Two things are changing on a defined timeline, not speculatively:

  • ADMT rules are finalized, not proposed. The California Privacy Protection Agency's regulations on automated decision-making technology were approved by the Office of Administrative Law on September 23, 2025. Compliance for AI that drives a "significant decision" (employment, financial or lending, healthcare, housing, or education access) begins January 1, 2027, with pre-use notice and risk-assessment obligations specifically starting April 1, 2027.
  • A plain customer-service chatbot likely falls outside the "significant decision" trigger, the same logic that keeps most support bots out of Colorado's consequential-decision rules, but this is a reasoned interpretation of the regulation's scope, not a bright-line carve-out stated explicitly for chatbots. If your bot influences employment, lending, healthcare, or housing outcomes in any way, treat ADMT as applicable and get counsel's read before 2027.

Practically, every deployment needs a retention and deletion policy before launch: how long transcripts are kept, who can retrieve them, and a documented process to fulfill a delete request in time. Our guide on AI chatbot data security for enterprise deployments covers the operational side. One caveat for US buyers: Heeya's infrastructure is EU-hosted (OVH), a genuine advantage under GDPR, but EU hosting doesn't exempt a US business from CCPA, those obligations run to your business, not to where a vendor's servers sit.

A Deployment Checklist

Work through this before launch, and again every time you add a new capability (scheduling, personalization, document upload) to an existing bot.

  • Identify every state (and NYC specifically, if hiring is involved) where your customers or employees interact with the chatbot
  • Add a plain, visible "AI assistant" disclosure before or at the start of every conversation, the shared baseline across every law in this guide
  • Add a persistent visual badge near the chat widget, not just an opening message that can be scrolled past
  • Confirm the bot never screens, ranks, or scores job candidates without a full review against NYC LL144 and Illinois HB 3773
  • Keep healthcare-adjacent bots limited to hours, insurance, services, and scheduling; hand off anything diagnostic or treatment-related to a human
  • Keep financial or lending bots limited to product and rate information; route applications and personal eligibility questions to a licensed professional
  • Add a visible, working human-contact option inside the widget itself
  • Document which AI model or vendor powers the bot and what data sources inform its answers
  • Set and document a transcript retention and deletion policy, and confirm how a CCPA access or delete request would actually get fulfilled
  • Calendar a compliance review every six months; this landscape has changed materially more than once in the past eighteen months alone
  • Have counsel review the final configuration before launch, especially for HR, healthcare, or financial services use cases

What Is Likely Coming Next

Three things to watch rather than assume are settled:

Colorado's January 2027 date may not be final. The AI Act has already been rewritten once, from SB24-205 to the narrower SB 26-189, and law firm trackers note pending litigation (including a challenge from x.AI) that could still affect implementation.

California's ADMT enforcement ramps up through 2027. The regulations are final, but phased compliance dates (January 1 and April 1, 2027) mean the practical enforcement reality, including clearer guidance on what counts as a "significant decision", is still ahead.

NYC and Illinois enforcement is tightening without new statutes. NYC's 2025 comptroller audit and new enforcement workbook, plus Illinois rulemaking still being finalized for HB 3773, both point toward stricter enforcement of laws already on the books. A wait-and-see approach to hiring-tool compliance is riskier in 2026 than it was in 2023.

More states are actively considering AI transparency and employment-AI bills; this list will be out of date within months by design, exactly why disclosure-by-default, not disclosure-by-threshold, is the more durable strategy.

Need a chatbot with disclosure built in, not bolted on?

Heeya's widget includes a configurable AI-assistant disclosure and opening message by default, answers are grounded in your own documents so you can always document what informs a response, and conversation retention is yours to configure. See pricing or explore the Heeya chatbot platform.

Start free: no credit card View pricing

Frequently Asked Questions About AI Chatbot Disclosure Law

Do I have to disclose that my chatbot uses AI?

It depends on your state and what the bot does, but disclosing is the safer default. Most laws only mandate it above a threshold (California's B.O.T. Act: 10 million-plus monthly US visitors) or a use case (Colorado: once a bot drives a consequential decision). A plain, visible "you're talking to an AI" statement before the conversation starts satisfies the strictest version of every law here and costs nothing to implement.

Does California law require me to tell customers I'm using a chatbot?

California's B.O.T. Act (SB 1001, Bus. & Prof. Code §17941) only legally requires this for bots on platforms with 10 million-plus monthly US visitors used to incentivize a sale or influence a vote, a threshold most small and mid-sized businesses don't meet. A separate law, SB 243, targets "companion chatbots" and excludes ordinary customer-service bots, though heavy personalization can pull a bot back into scope. Disclosing anyway avoids the analysis entirely.

What is the Colorado AI Act and does it apply to my chatbot?

The original Colorado AI Act (SB24-205) was repealed and replaced by SB 26-189 in May 2026, effective January 1, 2027. It now applies only to AI that "materially influences" a consequential decision: employment, lending, insurance, healthcare, housing, education, or government benefits. A general FAQ chatbot that doesn't drive one of those decisions is very likely outside its scope. Enforcement is by the Colorado AG only; there's no private right of action.

Does Utah require AI disclosure for all businesses?

No. Under Utah's AI Policy Act (Utah Code Title 13, Chapter 77), most businesses only have to disclose if a user directly asks. A stricter, proactive rule applies only to state-licensed occupations, health care, law, financial services, accounting, engineering, architecture, when the interaction is "high-risk": sensitive personal data plus personalized advice a user might rely on for a significant decision.

Is there a Texas law requiring AI chatbot disclosure for businesses?

Texas's Responsible AI Governance Act (TRAIGA, HB 149), effective January 1, 2026, includes a disclosure duty, but it's narrow: government agencies and healthcare providers using AI in diagnosis, treatment, or triage. Ordinary retail, SaaS, or professional-services chatbots have no TRAIGA-specific disclosure obligation. TRAIGA otherwise bans specific harmful AI practices rather than mandating a general label.

Does NYC Local Law 144 apply to a customer service chatbot?

Almost certainly not. Local Law 144 covers "automated employment decision tools", AI used to screen, score, or rank job candidates for NYC-based hiring or promotion. It doesn't cover general customer-service bots or employee-facing HR chatbots that answer policy questions without influencing hiring outcomes. It requires a published independent bias audit and 10 business days' advance notice before use on a candidate.

What counts as an "automated employment decision tool" in Illinois?

Illinois doesn't use that exact term, but HB 3773, an Illinois Human Rights Act amendment effective January 1, 2026, covers AI used in recruitment, hiring, promotion, discipline, or discharge. It requires notice to employees or applicants when AI is used, bars ZIP code as a proxy for a protected class, and imposes liability for discriminatory effect regardless of intent. A bot only answering general HR policy questions isn't the target.

Is a chatbot transcript considered personal information under CCPA?

Yes, if it contains an identifier like a name, email, or IP address, which most do. That makes it "personal information" under CCPA/CPRA, giving California residents the right to know, delete, correct, or opt out of its sale or sharing. Separately, California's finalized ADMT regulations add pre-use notice and risk-assessment duties once a chatbot drives a "significant decision," phasing in January and April 2027.

What's the simplest way to comply with every state's chatbot disclosure law at once?

Disclose by default, not by legal threshold: a plain, visible statement that the user is talking to an AI, shown before or at the start of every conversation, plus a persistent badge and an accessible human-contact option. That single practice satisfies the strictest requirement in every law covered here and stays valid even as thresholds keep shifting.

Further Reading

Share this article:
Published on September 9, 2026 by Anas R.

Ready to build your AI assistant?

Join Heeya and transform your customer service with conversational AI.