Yes, in most markets you're likely serving: the EU's AI Act now legally requires it, California's SB 243 requires it for a wide category of bots, and the FTC treats an undisclosed AI chatbot as a potentially deceptive practice nationwide in the US regardless of state law. The specific rule that just took effect is Article 50 of the EU AI Act, which became binding on August 2, 2026 and requires any AI system that interacts directly with a person to make that fact clear from the very first message, unless it's already obvious.

If your business runs a website chatbot, a WhatsApp support bot, or a phone-answering voice agent, this isn't a hypothetical compliance topic anymore — it's a design requirement you need to have built into the bot itself, not buried in a privacy policy nobody reads. This guide covers what actually changed, who it applies to, what the penalties look like, and how to build the disclosure in without it feeling like a legal disclaimer bolted onto your customer experience.

Want a chatbot that's compliant by design instead of retrofitted? See our custom AI agents service, or book a call to have your current bot reviewed.

What EU AI Act Article 50 Actually Requires

Article 50 applies to providers of AI systems that interact directly with natural persons — chatbots, AI agents, voice assistants, avatars. The core obligation, confirmed via the European Commission's own FAQ on the rule, is that people must be informed they're interacting with AI "from the start of the first interaction in a clear and distinguishable manner," not through fine print. There's a narrow exception for cases where it's obvious from context — but the Commission has said that exception is read restrictively, and a disclosure sitting only in your terms and conditions won't satisfy it.

The obligation entered into force on August 2, 2026, with a limited grace period running to December 2, 2026 for marking AI-generated content on systems already on the market before that date. If you have EU users interacting with a chatbot, voice agent, or AI-generated content on your site right now, that grace period for new deployments has already closed.

The US Picture Is Messier — and Growing Fast

The US has no single federal chatbot-disclosure law. Instead, it's a patchwork of state bills, several already in effect and dozens more moving through legislatures. Conferbot's compliance tracker counted 78 chatbot-related bills introduced across 27 US states as of mid-2026, with 14 already enacted into law and 23 more actively advancing through committee — and that count moves every legislative session, so treat any specific number as a snapshot, not a ceiling.

The most consequential one so far is California SB 243, effective January 1, 2026. It requires a clear, conspicuous disclosure that a user is talking to a bot, delivered before any meaningful interaction occurs, with the bot identity reinforced throughout the conversation and a clear path to a human. The law technically exempts bots used strictly for customer service — but that carve-out is narrower than most businesses assume, since a bot that drifts into open-ended, relationship-style conversation can move outside it regardless of what it was originally built for.

Underneath state law, the FTC has maintained since 2018 that an undisclosed AI chatbot can constitute a deceptive practice under Section 5 of the FTC Act — a federal standard that applies to every US business regardless of which state's specific bill has or hasn't passed. The FTC hasn't yet brought a dedicated enforcement action against an undisclosed chatbot, but the guidance has been on the books for years, and it doesn't take a new law for the agency to act on it.

Jurisdiction Snapshot: What's Required Where

JurisdictionRuleTriggerPenalty exposure
European UnionAI Act, Article 50Any AI system interacting directly with a personEnforced under national AI Act penalty regimes; can reach a percentage of global turnover for the Act generally
CaliforniaSB 243Companion-style bots; customer-service bots narrowly exemptUp to $2,500/violation (AG); $1,000/violation minimum via private right of action
Federal (US, all states)FTC Act, Section 5Any undisclosed AI interaction judged deceptiveCase-by-case; no chatbot-specific action yet, but standing authority
14+ other US statesVaries by billVaries — some target consequential decisions (credit, employment), others any conversational AIVaries — some carry no customer-service exemption at all

The practical read: there's no jurisdiction where "don't disclose and hope nobody asks" is currently a safe position, and the direction of travel across every list above is toward more coverage, not less.

Does Your Bot Need to Disclose? A Fast Self-Test

  1. Do you have any EU users? If yes, Article 50 applies to you now — there's no minimum-users threshold.
  2. Does your bot do anything beyond narrow transactional support? If it makes small talk, remembers personal details across sessions, or is styled as a "friend" or "companion," California's customer-service exemption likely doesn't cover you.
  3. Is it obvious you're talking to AI without being told? A bot named "Sarah" with a human-sounding voice or avatar generally isn't obvious — the regulatory bar for "obvious" is intentionally high.
  4. Is your only disclosure in a privacy policy or terms page? That doesn't satisfy Article 50 or most state laws — disclosure has to happen inside the conversation itself.

If you answered yes to any of the first three, or yes to the fourth, you have a gap worth closing before it's someone else's discovery, not yours.

Building Disclosure In Without Killing the Experience

Done well, disclosure is a one-line addition, not a redesign. For a text or WhatsApp chatbot, that's typically an opening message identifying it as an AI assistant before it asks or answers anything substantive, plus a persistent label ("AI Assistant") near the input field so it stays visible through a long conversation, not just at the start. For an AI voice agent, the equivalent is a short spoken line at the start of the call — "Hi, this is an AI assistant for [Business]" — before the caller is asked for anything. Both patterns take minutes to add to a well-built bot and take nothing away from the conversation quality; they only become a real project if the underlying bot was built as a black box you can't easily edit, which is one more reason a custom-built bot tends to be easier to keep compliant than a rigid off-the-shelf widget where you can't control the opening script.

The human-handoff requirement matters just as much as the initial disclosure. Regulators in both the EU and California are explicit that ongoing awareness counts, not just a first-message notice — so the bot also needs a clear, working path to a human when a conversation genuinely needs one, and that handoff itself should be disclosed rather than silent.

Key Takeaways

  • EU AI Act Article 50 took effect August 2, 2026 and requires clear, upfront AI disclosure for any bot interacting directly with people — burying it in terms and conditions doesn't count.
  • California SB 243 (in effect since January 1, 2026) carries real penalties — up to $2,500 per violation from the AG, plus a $1,000-per-violation private right of action — and its customer-service exemption is narrower than most businesses assume.
  • The FTC's Section 5 authority applies to every US chatbot regardless of state law, even though it hasn't yet brought a dedicated enforcement action.
  • Disclosure needs to live inside the conversation — an opening line plus a persistent label — not just in a policy page nobody opens before chatting.
  • Voice agents are covered too; the requirement is modality-agnostic even though most guidance is written with text chat in mind.

Not sure where your current setup stands? Run the numbers on a compliant rebuild with the ROI calculator, or book a call and we'll review your bot's disclosure and scope together.