Skip to content

AI disclosure in customer support: what the law actually requires

AI disclosure in customer support: what the law actually requiresCommunicate.so
Udit Goenka
Udit Goenka

Where AI chatbot disclosure is now a legal requirement, where it is unsettled, and wording that discloses without scaring customers off.

TL;DR: AI disclosure in customer support means telling a customer, before or at the start of a conversation, that they are talking to an AI system rather than a person. As of 2 August 2026 this is a hard legal requirement across the European Union under Article 50 of the EU AI Act, which obligates providers to make that fact clear unless it is already obvious from context. California has required disclosure since 2019 under its bot law, though the trigger is intent to deceive in a commercial transaction, and disclosure itself is the safe harbor. Utah requires disclosure of generative AI use in a customer service interaction only when a customer asks, after a 2025 amendment narrowed the state's original 2024 rule. Colorado's AI Act was repealed and replaced in 2026 and its remaining disclosure-adjacent duties do not take effect until January 2027. Outside those four jurisdictions no binding law forces disclosure, and this article does not offer legal advice. It maps what is confirmed, what is unsettled, and how to word a disclosure line that satisfies the strictest of those rules without sounding like a warning label.

Support teams that deployed an AI agent in the last two years usually made one decision early and never revisited it: does the bot say what it is. Some picked a discreet badge in the corner of the widget. Some wrote nothing at all.

The wrong version of that decision used to cost you a little trust; as of August 2026 it can cost a company operating in the EU real money, and the safest assumption for everyone else is that the reasoning behind the EU rule is coming for more jurisdictions, not fewer. If you want the fuller regulatory backdrop, the EU AI Act and customer support covers obligations beyond disclosure, including risk classification and human oversight.

This guide sticks to one narrow question: when does the law require you to tell a customer they are talking to AI, and what should you say when it does not. Every jurisdiction named below was checked against its primary legal source at the time of writing, dated 2 August 2026. Where the law is unclear or still pending, that is stated directly rather than guessed at, because a design constraint article that invents legal certainty is worse than no article at all.

What AI disclosure means in customer support

Disclosure is a specific act: a statement, visible or spoken, that tells the person on the other end of a conversation that they are interacting with an automated system rather than a human agent. It is not a privacy policy clause buried three clicks away, and it is not a general terms-of-service mention that a company 'may use AI to assist support.' The laws discussed here consistently define disclosure as something a reasonable person notices at or near the start of the interaction, not something a lawyer can point to after the fact.

The distinction matters because most support tools already do something adjacent to disclosure without doing disclosure itself. A chat widget with a robot icon, a bot name like 'Support Assistant,' or a canned opening line are all signals, but none of them meet a legal disclosure standard unless the interaction is unambiguous from context, which is the exact carve-out several of these laws use. If a customer could reasonably wonder whether they are texting a person, the icon alone will not save you, a point the ai chatbot vs ai agent distinction makes clear given how differently the two present themselves.

It also matters because disclosure and quality are separate problems. A well-grounded AI agent that answers correctly every time still needs to disclose if the law requires it, and a poorly grounded one does not earn an exemption by being vague about what it is. Reducing wrong answers, covered in reducing AI hallucinations in support, is a separate project from disclosure, and treating them as one problem tends to stall both.

The EU AI Act made disclosure a hard requirement

An EU flag beside a chat bubble labeled AI system with a clock marking 2 August 2026Communicate.so

Article 50 of Regulation (EU) 2024/1689, the EU AI Act, entered into application on 2 August 2026. Its first paragraph requires providers to ensure that AI systems intended to interact directly with natural persons are designed so a reasonably informed user understands they are interacting with an AI system, unless that fact is already obvious from the circumstances. A support widget that opens a conversation and starts answering questions is precisely the case the article was written for.

The obligation runs to providers, and downstream to deployers who put the system in front of customers, according to the practical breakdown published by artificialintelligenceact.eu. The notification has to arrive before or at the very start of the conversation, not somewhere mid-thread, and it cannot rely on the customer already suspecting the truth. Penalties for noncompliance with the transparency obligations reach 15 million euros or 3 percent of worldwide annual turnover, whichever is higher, which puts this well above a slap-on-the-wrist tier of enforcement.

There is a narrow carve-out for AI systems authorized by law for detecting, preventing, investigating, or prosecuting criminal offenses, which has nothing to do with customer support and can be set aside. There is no carve-out for 'the bot is obviously good enough that nobody would ask.' The article assumes ambiguity is the default and puts the burden of resolving it on the provider, not the customer.

If your support operation serves EU customers at all, whether or not your company is headquartered there, this is the rule that should set your baseline. Building the disclosure line into the AI agent itself, rather than into a settings page nobody checks, is the difference between a compliant conversation and a compliant policy document sitting unread in a drawer.

California requires disclosure as the price of using a bot to sell

California's SB 1001, the Bolstering Online Transparency Act, took effect on 1 July 2019 and works differently from Article 50. It does not ban undisclosed bots outright. It makes it unlawful to use a bot to communicate with a person online with the intent to mislead them about the bot's artificial identity, for the purpose of knowingly deceiving them in order to incentivize a purchase or sale of goods or services, or to influence a vote.

The safe harbor is built directly into the statute: a person using a bot is not liable if they disclose that it is a bot, and the disclosure must be clear, conspicuous, and reasonably designed to inform the person they are dealing with an automated system. That is a lower bar than the EU rule in one sense, because the law only bites when there is intent to deceive for a commercial or electoral purpose, and a support conversation that never tries to hide the bot's nature falls outside the prohibited conduct entirely.

The catch for support teams is that a lot of commercial support conversations are, functionally, sales conversations. An AI agent that upsells a plan, processes a renewal, or talks a customer out of canceling is arguably incentivizing a purchase, which puts it inside the statute's scope if the bot's identity is ever in question. Enforcement runs through California's Attorney General and potentially local prosecutors, with civil penalties up to 2,500 dollars per violation under the state's unfair competition law, a detail confirmed by Perkins Coie's summary of the statute.

Utah narrowed its disclosure rule to when a customer asks

Utah's Artificial Intelligence Policy Act took effect 1 May 2024 and originally required proactive disclosure whenever a business used generative AI in a customer-facing interaction. A 2025 amendment, SB 226, scaled that back. Under the amended rule, described by Davis Wright Tremaine, proactive disclosure at the start of a conversation still applies to people practicing a licensed or regulated occupation who use generative AI to provide those services.

Outside of regulated occupations, the disclosure obligation becomes reactive: you only have to tell the customer they are talking to AI if they ask, or during what the statute treats as a high-risk interaction.

That two-tier structure matters for any support operation that also handles licensed activity, such as insurance guidance, certain financial services, or healthcare-adjacent questions, where the underlying human role would itself require a license. A general e-commerce support bot answering shipping and refund questions in Utah sits in the lighter, reactive tier, the kind of coverage described in 24/7 customer support AI. A support agent standing in for licensed advice does not.

Colorado delayed and narrowed its AI law before it took effect

Colorado passed a broad AI Act in 2024 aimed at algorithmic discrimination in consequential decisions, and support-related disclosure was never its central focus. On 14 May 2026 Governor Polis signed SB 26-189, which repealed the original act and replaced it with a narrower measure, moving the effective date from 30 June 2026 to 1 January 2027 and dropping the 'high-risk artificial intelligence system' framework entirely, according to Skadden's summary of the revision.

The replacement law regulates automated decision-making technology used in consequential decisions, a category built for hiring, lending, and housing rather than general customer service chat. Whether an AI agent that approves a refund or denies a warranty claim counts as a consequential decision under the new Colorado framework is not settled as of this writing, and this article states that plainly rather than guessing at a scope the statute itself has not yet been tested against.

The table below summarizes the four jurisdictions reviewed against the same three questions: is disclosure legally required at all, does it have to happen proactively at the start of the conversation, and does the rule specifically name customer support as covered.

JurisdictionDisclosure requiredProactive at conversation startNames customer support
EU (AI Act Article 50)
California (SB 1001)✓ if commercial intent to deceive✓ as the safe harbor✗ general commerce rule
Utah (AI Policy Act, amended)✓ for regulated occupations✗ reactive outside those✗ occupation-based
Colorado (SB 26-189)Unsettled for general support✗ not yet in force✗ consequential decisions

Where no law requires disclosure, and why that is not the whole story

Most of the United States has no statute on the books that forces a company to tell customers they are talking to AI. There is no federal disclosure law for customer-support bots. Most US states have not passed anything comparable to California's, Utah's, or Colorado's rules, and this article does not claim otherwise for any state not named above.

If your support traffic is entirely domestic and outside those three states, you are very likely operating in legally unregulated territory on this specific question, though general consumer-protection and deceptive-practices statutes still apply to any interaction where you actively lie about a bot's identity.

The absence of a mandate is not the same as the absence of a reason to disclose. CMSWire reports that the share of organizations reporting a negative consequence from generative AI rose from 44 percent in 2024 to 51 percent in 2025, and undisclosed bots are a recurring source of exactly that kind of blowback when customers discover the deception after the fact rather than being told upfront. A customer who finds out later feels misled twice: once by the wrong answer, and once by not knowing who gave it to them, a dynamic the customers hate chatbots research covers from the trust side.

The design constraint: disclosure that does not scare customers off

Comparison of a defensive AI disclosure banner versus a plain one-line opening statement in a chat widgetCommunicate.so

Support leads who resist disclosure usually cite the same fear: telling a customer they are talking to a bot will make them abandon the chat and demand a human. The evidence for that fear is thinner than the fear itself. Customers overwhelmingly object to being deceived about a bot's identity, not to bots existing, and the complaint patterns documented by Twig list hallucinated answers, missing escalation paths, robotic tone, and poor context awareness as the top frustrations with AI support tools, not the disclosure itself.

The design problem is real, but it is a wording problem, not a disclosure-versus-no-disclosure problem. A disclosure line written like a legal disclaimer, in a different font, set off in a warning-colored box, reads as a defensive gesture and primes the customer to expect a bad interaction before it starts. A disclosure line written in the same voice as the rest of the conversation reads as information, and most customers process it as such and move straight to their question.

Wording patterns that satisfy the law without sounding like a warning

The strictest standard among the jurisdictions above, Article 50's requirement that a reasonably informed user understand they are talking to an AI system before or at the start of the conversation, sets a wording bar the others clear automatically if you meet it. A first message along the lines of "Hi, I'm an AI assistant for [company]. I can help with most support questions, and I'll bring in a person if you need one" satisfies the notification requirement, states the escalation path up front, which answers the top complaint about missing escalation, and takes under two seconds to read.

Avoid two failure modes on either end of the spectrum. The first is over-hedging: repeating 'I am an AI, I may be wrong, please verify everything I say' turns a single disclosure into a running disclaimer that erodes confidence in every subsequent answer, which is neither required by any of the laws above nor good for resolution rates. The second is under-disclosing through cuteness: a bot name like 'Alex' with no indication of what Alex is does not meet the 'reasonably informed user' bar in the EU, does not meet the 'clear, conspicuous' bar in California, and would not survive scrutiny under Utah's proactive tier either.

A disclosure line that also states the escalation path does double duty. It satisfies the legal requirement and it defuses the single biggest driver of frustration with AI support, according to the same Twig complaint data cited above. Tools like communicate.so let a team set that opening line once and have every conversation start with it, rather than depending on individual configuration choices made inconsistently across channels.

Building disclosure into the conversation, not the terms of service

Flow showing a disclosure message positioned as the first line of a chat conversation rather than buried in a settings menuCommunicate.so

A disclosure clause in your terms of service does not satisfy any of the laws discussed here, because none of them ask whether disclosure exists somewhere in your legal documents. They ask whether the specific person in the specific conversation was informed at the specific moment it started. That means the disclosure has to live in the product, not the policy page, and it has to fire every time an AI system opens a chat, a voice call, or a messaging thread, not just the browser-based widget.

Channel coverage is where most disclosure implementations quietly fail. A team that writes a compliant opening line for its website widget often forgets the same AI agent also answers on WhatsApp, email, or an embedded widget on a partner site, and each of those channels needs the same notification, adapted to its format. A WhatsApp opener can be a single text line; an embedded widget can show the same line as the first chat bubble before any customer input is required.

This is also where human handoff needs to be unambiguous in the other direction. If an AI agent hands a conversation to a person, the customer should be told that too, not left assuming they are still talking to the system that introduced itself minutes earlier. The AI human handoff pattern and a properly configured shared inbox make that transition visible instead of silent, which closes the loop the disclosure requirement opened.

What happens when disclosure is skipped and a customer finds out

Scale weighing a small compliant disclosure line against a large warning triangle representing discovered deceptionCommunicate.so

The reputational cost of a discovered, undisclosed bot tends to outweigh the operational cost of adding a compliant one-liner by an order of magnitude. When a cloud storage company's chatbot cited a downgrade policy that did not exist in February 2026, the story that spread was not just about the wrong answer, according to SocialIntents's account of the incident; it was about a company letting a system speak with unqualified authority on its behalf. Disclosure does not prevent hallucination, but it does reset customer expectations about how much weight to put on any single answer, and it gives you a documented, defensible position if a regulator ever asks whether you tried to conceal the bot's role.

Skipping disclosure also compounds badly with other AI support failures. A DPD chatbot was disabled in January 2024 after it swore at a customer and criticized its own employer in response to a prompt, an incident The Register covered in detail. A customer who already suspects deception reacts to an incident like that as proof of bad faith, while a customer who was told upfront they were talking to an evolving automated system is more likely to read it as a bug rather than a betrayal.

Frequently asked questions

Does the EU AI Act apply to a US company with EU customers

Yes, if the AI system interacts with people located in the EU, regardless of where the provider or deployer is headquartered. Article 50 attaches to the interaction, not to the company's registered address, so a US-based support team serving EU customers through the same chat widget needs to meet the disclosure standard for those conversations.

Is a robot icon in the chat widget enough to satisfy disclosure law

Not on its own, under any of the four jurisdictions reviewed here. Icons and bot-sounding names are signals a customer might notice, but the EU standard requires a reasonably informed user to understand they are talking to an AI system, and California's standard requires a clear, conspicuous disclosure, both of which ask for more than an icon a customer could plausibly miss or misread.

Do I need to disclose AI use if a human reviews every response before sending

That configuration is closer to AI-assisted human support than an autonomous AI system interacting directly with a customer, which is the category Article 50 targets. If a person genuinely reviews and approves each message before it sends, the interaction is arguably human-to-human with AI drafting help, though the line gets blurry fast if review becomes a rubber stamp. When the volume shifts to near-instant approval, treat it as effectively autonomous and disclose accordingly.

See how a shared inbox for AI and humans keeps that distinction visible in the workflow itself.

What counts as a commercial transaction under California's bot law

The statute covers using a bot to incentivize a purchase or sale of goods or services, or to influence a vote in an election. A support conversation that processes a renewal, upsells a plan, or talks a customer out of canceling falls inside that scope if the bot's identity is ever in question, even though the primary purpose of the interaction was support rather than sales.

Does Utah require disclosure for a general e-commerce support bot

Only reactively, under the amended 2025 version of the law. If the support role is not a licensed or regulated occupation, you only need to disclose that the customer is talking to generative AI if they ask, or if the interaction falls into a high-risk category the statute defines. A general shipping and refunds bot in Utah sits in that lighter, ask-triggered tier.

What is the penalty for violating Article 50 of the EU AI Act

Noncompliance with the transparency obligations under Article 50 can draw fines up to 15 million euros or 3 percent of worldwide annual turnover, whichever amount is higher. That places transparency violations in a serious enforcement tier even though Article 50 obligations are lighter in substance than the Act's rules for high-risk AI systems.

Does adding an AI disclosure line hurt conversion or resolution rates

There is no confirmed data in the source pool for this article showing a measurable drop from disclosure specifically, and this piece will not invent one. The documented complaint patterns from Twig point to hallucinated answers and missing escalation paths as the drivers of dissatisfaction, not disclosure itself, which suggests the wording and follow-through matter more than the presence of the line.

Can I disclose once at account creation instead of at the start of every chat

No, under the EU standard. Article 50 requires the notification before or at the very beginning of the specific conversation, so a one-time disclosure buried in onboarding does not meet the bar for a chat that starts weeks or months later. Repeat the disclosure at the start of each new AI-led conversation, not just once per relationship.

Does voice support need the same disclosure as chat support

Yes. Article 50 applies to AI systems intended to interact directly with natural persons regardless of modality, and a voice assistant answering a support call is squarely within that description. The disclosure needs to be spoken, at or near the start of the call, in language a listener will actually register rather than a fast legal-sounding preamble.

What if the AI system only handles pre-chat triage before a human takes over

Triage is still an interaction with a natural person, so disclosure applies to the triage step itself even if a human ultimately answers the substantive question. Tell the customer they are starting with an automated system, then make the handoff to a person clear and visible rather than assuming the earlier disclosure still applies once a human takes over. A well-built support escalation workflow already tracks that transition; extending it to cover the disclosure moment is a small addition.

Is there a federal US law requiring AI disclosure in customer support

Not as of this writing. There is no federal statute mandating AI disclosure in customer-facing support interactions in the United States. General federal consumer-protection authority, exercised through the Federal Trade Commission, can still reach interactions where a company actively deceives customers, but that is a different legal basis than a dedicated disclosure mandate.

Does China require AI disclosure for customer support chatbots

This article does not have a verified primary source for China's generative AI labeling rules as they apply specifically to customer support interactions, and it will not assert a position without one. If China is a material market for your support operation, that question needs jurisdiction-specific legal review rather than an assumption borrowed from EU or US rules.

What wording should the very first line of an AI-led chat contain

At minimum, a plain statement that the customer is talking to an AI system, in the same tone as the rest of the conversation, plus a route to a human if they want one. Something like stating the assistant is AI-powered, naming what it can help with, and confirming a person is available on request covers the legal notification and the top customer complaint about missing escalation in one line, a pattern the launch your first AI agent guide walks through end to end.

Does disclosure need to repeat if the conversation moves across channels

Yes, because each channel is a separate interaction from the customer's perspective even if the underlying AI agent and conversation history are shared. A customer who starts on the website widget and later messages on WhatsApp needs the same notification on WhatsApp, since nothing in Article 50 treats a channel switch as covered by an earlier disclosure. Consistent multilingual customer support setups tend to already template this per channel, which makes adding a disclosure line straightforward.

Can a customer opt out of talking to an AI agent entirely

None of the four laws reviewed here create an affirmative right to opt out of AI-led support; they require disclosure, not consent. As a practical and trust matter, most support teams still offer a route to a human on request, both because it addresses the top complaint about missing escalation and because several state laws, including Utah's, effectively require offering a human path in specific regulated contexts.

Does an AI system that only sends automated status updates need to disclose

A one-way automated notification, such as a shipping update or a ticket-status email, is not the kind of two-way interaction Article 50 targets, since there is no exchange for a customer to be confused about. The moment the system starts responding to customer input in a live back-and-forth, the disclosure obligation attaches, so the line is drawn at interactivity, not at automation generally.

How does disclosure interact with GDPR or other data protection law

Disclosure of AI identity under Article 50 is a separate obligation from GDPR's rules on automated decision-making and data processing transparency. A support conversation can satisfy AI-identity disclosure while still needing a separate GDPR-compliant privacy notice covering what data is collected and how it is used, and one does not substitute for the other.

Should the disclosure line mention which AI model or vendor powers the agent

None of the laws reviewed require naming the underlying model or vendor, only that the customer understands they are interacting with an AI system. Naming the vendor is a business choice, not a legal one, and most companies choose not to, since the customer's relationship is with the brand they contacted, not the infrastructure behind it.

Does disclosure differ for a fully automated AI agent versus a triage bot

Both need disclosure whenever they interact directly with a customer, but the wording can differ. A fully autonomous AI agent that resolves the whole conversation should state upfront what it can do end to end, while a triage bot that only routes the conversation should be clear that a person will take over shortly, so the customer's expectations match what actually happens next.

Write one compliant opening line, apply it to every channel where an AI agent talks to a customer, and treat California's, Utah's, and the EU's standards as the union to satisfy rather than trying to write separate versions per jurisdiction. A single well-worded line that states the AI system's identity, what it can do, and how to reach a person clears the bar in every jurisdiction covered in this guide, and reviewing it against security and compliance documentation once a year catches drift as the law continues to move.