Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai policy / ai-receptionist-disclosure-law-by-state
AI Policy

Does your AI receptionist have to say it's AI?

Thirteen states passed chatbot laws this year. None of them cover your phone line. Here are the two rules that actually bind an AI receptionist.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedJul 30, 2026
read6 min
Does your AI receptionist have to say it's AI?

Thirteen states passed new chatbot laws in 2026. Fourteen separate acts, in seven months. Not one of them regulates the phone line at the front of your business. That gap is the whole story. The AI disclosure rules getting written right now

Thirteen states passed new chatbot laws in 2026. Fourteen separate acts, in seven months.

Not one of them regulates the phone line at the front of your business.

That gap is the whole story. The AI disclosure rules getting written right now are aimed at companion bots and minors, not at the voice agent booking your 3pm. Meanwhile the two rules that genuinely bind an AI receptionist are older, quieter, and almost never mentioned by the vendors selling you one.

14New state chatbot laws enacted in 2026, across 13 states
0Of those covering a commercial customer-service phone line
2States whose live rules clearly reach an inbound AI receptionist
$2,500Utah's maximum civil penalty, per violation

Thirteen states wrote chatbot law this year and skipped your phone

Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island, South Carolina, Washington and Wyoming all enacted chatbot legislation in 2026. The Transparency Coalition's July tally counts fourteen acts.

Read them and a pattern shows up fast. They are about companion bots: systems designed to simulate a relationship, harms to minors, crisis referral when someone mentions self-harm, disclosure reminders every hour or three. Washington and Oregon take effect January 1, 2027. Nebraska and Idaho reach wider into "conversational AI" but land in 2027 too.

None of them say anything about a dental practice using a voice agent to book cleanings.

That is not a loophole to celebrate. It is a forecast. The legislative attention is moving toward voice, and the businesses that already disclose will not notice when it arrives.

California's bot law is the one everyone cites and it does not cover phone calls

Every second compliance page on a voice AI website points at California. It is the wrong statute.

California's bot law defines a bot as "an automated online account where all or substantially all of the actions or posts of that account are not the result of a person." It then defines online as "appearing on any public-facing Internet Web site, Web application, or digital application." That is the actual statutory text, sections 17940 through 17942 of the Business and Professions Code.

A telephone call is not a public-facing website. The law was written in 2018 about social media manipulation, and it stayed there.

California's SB 243, effective January 1, 2026, is the companion-chatbot rule, with penalties of $5,000 per violation per day. Also not your reception desk.

Maine and Utah are the two rules that reach an inbound call today

Maine is the broad one. Title 10 §1500-DD says a person may not use "an artificial intelligence chatbot or any other computer technology" in trade and commerce in a manner that may mislead a reasonable consumer into believing they are engaging with a human being, unless the consumer is notified clearly and conspicuously that they are not. A violation is a violation of the Maine Unfair Trade Practices Act, enforced by the Attorney General. It has been in force since September 2025.

"Any other computer technology" is doing the heavy lifting there. Nothing in it limits the rule to text.

Utah is the narrower and more interesting one. Under the AI Policy Act as amended by SB 226 in March 2025, a supplier using generative AI in a consumer transaction has to disclose it when the consumer clearly and unambiguously asks whether they are talking to a human. Disclosure on request, not by default.

The exception is what matters for our clients. For a high-risk AI interaction, disclosure has to be prominent and at the outset. High-risk covers collecting sensitive personal information such as health, financial, or biometric data, and giving advice a person might rely on for a significant decision: medical, legal, financial services.

Which describes a clinic's phone line almost exactly. A caller giving symptoms to book an appointment is handing over health information in the first twenty seconds. We wrote up what a real clinic deployment looks like if you want the operational side of that.

If the caller could plausibly be surprised later, disclose now. Surprise is the thing that generates complaints, and complaints are what generate enforcement.

Our rule of thumb across every AI phone build

The TCPA rule is about calls you make, not calls you answer

This one gets conflated constantly, and the distinction is worth real money.

In FCC 24-17, adopted February 2, 2024, the Commission confirmed that AI technologies generating human voices count as "artificial" voices under the Telephone Consumer Protection Act. Callers using them need the prior express consent of the called party.

Paragraph 9 is the sentence to remember: those requirements apply to "any AI technology that initiates any outbound telephone call using an artificial or prerecorded voice to consumers."

Outbound. A customer ringing your published number and reaching an AI assistant is not a robocall, because nobody initiated anything at them.

Flip that around and the exposure is real. Use the same voice agent to work a callback list, chase no-shows, or run a reactivation campaign and you are squarely inside the TCPA, where statutory damages start at $500 per call. That is the line we draw in every build: inbound is a service decision, outbound is a compliance project.

Colorado moved to 2027 and Europe lands on Sunday

Colorado had the broadest US disclosure duty on the books: notify every consumer interacting with an AI system. It never took effect. SB 26-189, signed May 14, 2026, repealed and reenacted the Colorado AI Act as the Automated Decision-Making Technology Act, with clear and conspicuous notice at the point of interaction, starting January 1, 2027.

Europe is the opposite situation: not delayed, and three days out. EU AI Act Article 50 applies from Sunday, August 2, 2026, and requires deployers to tell people when they are interacting with an AI system. If you take calls from EU customers, that deadline is already covered here and it is a deployer duty, not something your vendor absorbs for you. The same logic runs through the rules on labelling AI-generated ad creative: the obligation follows the business publishing the thing, not the tool that made it.

We disclose on every call regardless, because it costs nothing

Every AI receptionist we build opens with the disclosure. Not because Utah requires it in some cases and Maine in more, but because the alternative is indefensible the first time a caller feels tricked.

The line is one sentence and it sits before anything is collected. Name the business, name the assistant, offer the human. Then move on and never mention it again, because repeating it every turn is the fastest way to make an otherwise good call feel like a phone tree.

The thing operators worry about is that disclosure kills the call. It does not, in our experience, and the research on customer attitudes points the same way: people object to being trapped with an AI, not to meeting one. We went through what customers actually object to in detail. The short version is that the exit matters more than the greeting.

Legally you are not covered everywhere, because most places have not written the rule yet. Practically you are covered everywhere, because the honest version of the call is also the one nobody complains about.

— share
— keep reading

Three more from the log.