Over the past year, state after state has passed a law regulating AI chatbots — California, New York, Washington, Oregon, Hawaii, Maine, with more drafting. The coverage has been loud, the headlines use the word "chatbot" without qualification, and a reasonable person running a company with a support bot on their website has concluded they're probably now regulated.
We went and read the statutes. The answer is more interesting than either the panic or the shrug.
There are two different families of law here, and they keep getting merged
Nearly every "states are regulating chatbots" story is about companion chatbot laws — and those were written for a specific and genuinely serious problem: AI systems designed to simulate emotional relationships, and what happens when a teenager forms one.
They were not written about the bot that tells your customer whether you're open on Saturday. And the drafters knew it, because they said so, in the text.
The second family is much quieter, almost never makes headlines, and is the one that actually reaches an ordinary business chatbot. We'll get there — it's the part worth your attention.
The companion laws: read the exclusions
California, SB 243 — signed October 13, 2025, in effect since January 1, 2026, and the first of its kind. It carries a private right of action with a $1,000-per-violation floor, which is why it got attention. But the statute defines a "companion chatbot" as a system "capable of meeting a user's social needs," and then explicitly excludes bots used only for customer service, a business's operational purposes, productivity and analysis, or technical assistance.
New York — General Business Law Article 47, in effect since November 5, 2025. The text is blunt about it. An "AI companion" excludes:
"any system used by a business entity solely intended to provide users with information about available commercial services or products, customer account information, or other information related to a user's customer, or potential customer, relationship with such business entity."
That is a description of a business service bot, written into the law as a thing the law is not about.
Hawaii, SB 3001 — signed this week, and the newest AI law in the country. It defines an "AI companion" as a system designed to simulate a sustained human-like relationship by doing three things: retaining information across sessions to drive ongoing engagement, asking unprompted emotion-based questions that go beyond answering what the user asked, and sustaining dialogue about matters personal to the user. All three. A bot that answers billing questions fails every prong on purpose. Hawaii also states plainly that nothing in it creates a private right of action — enforcement runs through the attorney general.
Oregon (SB 1546) uses a near-identical three-part test and takes effect January 1, 2027.
Four states, four drafting committees, same conclusion: they are regulating the thing that simulates a relationship, not the thing that looks up your order.
Washington is the closest call — and it's our home state
We're in Seattle, so we read Washington's HB 2225 more carefully than the rest. It passed in March 2026 and takes effect January 1, 2027. Violations run through the state Consumer Protection Act.
Washington's definition is the broadest of the bunch. An "AI companion chatbot" is an AI system with a natural language interface giving adaptive, human-like responses, "including by exhibiting anthropomorphic features, and is able to sustain a relationship across multiple interactions."
Anthropomorphic features. Our chat assistant is named Ash. Our voice agent is named Aria. They have personalities, because a nameless bot is a worse experience. So let's take the uncomfortable question seriously instead of skipping it.
Here's the exclusion, verbatim, from Section 2(1)(b)(i). A bot is not a companion chatbot if it's:
"used only for a business' operational purposes, productivity and analysis related to source information, internal research, technical assistance, or customer service, if such bot does not sustain a relationship across multiple interactions and generate outputs that are likely to elicit emotional responses in the user"
Read that conjunction closely, because everything turns on it. To lose the exclusion, a business bot has to do both things — sustain a relationship across multiple interactions and generate outputs likely to elicit emotional responses. Not either. Both.
A support bot that remembers your last ticket is doing the first. It is not doing the second, and no amount of naming it Ash makes it do the second. Having a name is not the test; manufacturing feelings is the test.
There's a second, independent reason too. Washington defines "user" as a natural person who interacts with the bot "for personal use." Someone asking a vendor's bot about an invoice is not there for personal use.
So: two separate paths out, on the text of the strictest law in the country on this point. But we'll say the honest part out loud — if you market your bot on emotional engagement, on being a friend, on how much users love talking to it, you are walking toward that line rather than away from it. The exclusion protects a tool. It does not protect a companion you've dressed up as a tool. That's a product decision, not a legal one, and it gets made long before a lawyer sees it.
The law that actually applies to you
Now the part that gets no coverage.
Maine's chatbot disclosure statute (10 M.R.S. §1500-DD) is not a companion law. It defines an "artificial intelligence chatbot" as, essentially, any software that simulates human conversation — and then says:
"A person may not use an artificial intelligence chatbot or any other computer technology to engage in trade and commerce with a consumer in a manner that may mislead or deceive a reasonable consumer into believing that the consumer is engaging with a human being unless the consumer is notified in a clear and conspicuous manner that the consumer is not engaging with a human being."
No customer-service carve-out. No companion requirement. No exemptions at all. Violations are enforced as unfair trade practices.
That statute reaches your support bot. And notice how little it asks: the prohibition is on misleading people into thinking they're talking to a human. Tell them it's a bot, and you're done. The entire compliance burden is one sentence at the top of the conversation.
This is the shape of the whole regulatory picture, honestly summarized: the laws that sound terrifying almost certainly don't apply to you, and the law that does apply asks for the thing you should already be doing.
Update — August 2026: two transparency laws took effect on the same day, and neither one is yours
On August 2, 2026, two significant AI transparency regimes became applicable within hours of each other — one in Brussels, one in Sacramento. The coverage was loud. Here is what each actually says about a mid-sized American company running a support bot.
The EU AI Act's disclosure duty is real, arrived on schedule, and points at someone else
Article 113 of the AI Act is unambiguous on timing: "It shall apply from 2 August 2026." The much-reported "Digital Omnibus" amendment pushed the high-risk-system deadlines out to 2027 and 2028 — it did not touch the transparency article. If you read a headline saying the EU delayed its AI Act and concluded the chatbot clock had stopped, that headline was right about the Act and wrong about the part that mentions chatbots.
Now read who the duty lands on. Article 50(1):
"Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect…"
Providers. Not deployers. The deployer-facing duties in Article 50 are paragraphs 3 and 4 — emotion recognition and biometric categorisation systems, and deep fakes or AI-generated text published to inform the public on matters of public interest. A company that buys a receptionist bot and points it at its own phone line is a deployer, and none of those describe it.
Then there's territory. Article 2(1) reaches providers who place a system on the market in the Union, deployers "established or located within the Union," and providers or deployers in a third country "where the output produced by the AI system is used in the Union." That last clause is the entire hook. No revenue trigger, no EU-citizen-customer trigger, nothing resembling GDPR's "monitoring behaviour" test. A support bot answering customers in Ohio produces no output used in the Union.
Where it could reach you, stated plainly rather than buried: if you sell or license the bot itself into the EU, you are a provider placing a system on the Union market, and Article 50(1) is yours. And if your web chat is open to the world, an EU-located visitor is a genuine edge case worth raising with counsel. Those are narrow. They are not nothing.
California's new one is scoped to the people who build the models
The California AI Transparency Act — SB 942 as amended by AB 853, signed October 13, 2025 — became operative the same day: "This chapter shall become operative on August 2, 2026."
A "covered provider" is "a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state." Two filters, and a business deploying a vendor's bot fails both: you didn't create, code or produce the system, and your support bot does not have a million monthly users.
Two hard-dated, in-force, genuinely significant laws, landing on the same day — and the honest answer for most readers is the same one we gave about the companion statutes. They are aimed at the people building the systems, not the people running one.
The California one to actually watch is still a bill
California AB 1609 is the first bill we've seen written specifically about customer service chatbots — the first one aimed squarely at the category this post is about.
It is not law. It passed the Assembly on May 27, 2026, went to the Senate, and was read a third time and amended on August 20, 2026, then read a second time again on August 24 and ordered to third reading — so the current text is the version amended in the Senate on 20 August, not the 13 August one an earlier draft of this post cited. The operative language quoted below survived that amendment word for word; what changed is the version number, which is exactly the sort of thing that goes stale quietly on a bill still in motion. It has since cleared the Senate: on August 31, 2026 the Assembly concurred in the Senate's amendments, 58–18, and the bill went to engrossing and enrolling. It was enrolled on September 4, 2026. As of September 5, 2026 it has not been presented to the Governor and has not been signed. The $500 million revenue threshold survived the amendment. The bill is now one signature from law, with the Governor's deadline to sign or veto falling at the end of September 2026 — but until that happens, anyone describing it as a California requirement is describing a bill.
The short version of the status question, narrated:
What it would do, checked against the version amended in the Senate on August 20, 2026 (published 20 August, 21:00): require "a clear and conspicuous disclosure that the customer service chatbot is artificially generated and not human if a reasonable person interacting with the customer service chatbot would be misled to believe that the person is interacting with a human" — and, more interestingly, require a route to a person. A business must "make a good faith effort to provide a customer who requests to connect to a customer service agent" either "connection to a customer service agent within 15 minutes of the request" or "a specific appointment time within one business day," and must make a good-faith effort not to leave a customer on hold more than 15 minutes at a stretch or one hour in total. Penalties run to "$5,000 for an initial violation, and ten thousand dollars ($10,000) for each subsequent violation," and the text says plainly that it "does not establish a private right of action."
And the threshold, which survived the August amendment: a "large private business" means "a business with more than five hundred million dollars ($500,000,000) in gross annual revenue nationally that provides goods and services to customers." This is a bill about airlines, carriers and banks. If you're reading this, it almost certainly isn't about you.
But look at what it asks for, because this part deserves attention regardless of whether it passes: disclosure, plus a working escape hatch to a human within a stated time. That is item 1 and item 4 on our list below. Legislatures drafting independently keep converging on the same two things — which is usually the sign that they're the right two things to build whether or not anyone makes you.
Update — August 12, 2026: Colorado wrote the strictest disclosure rule in the country, then exempted customer service from it
Ten days after the two laws above, a third one took effect — and this is the one that finally points at the category this post is about. It is also, on its face, the most demanding chatbot-disclosure text any state has enacted.
Colorado HB 26-1263, the Conversational Artificial Intelligence Service Operator Requirements act, was signed May 29, 2026 and took effect at 12:01 a.m. on August 12, 2026. Its duties don't begin until January 1, 2027, and every one of them is prefaced that way in the statute itself. Here is what it will ask for:
"ON AND AFTER JANUARY 1, 2027, AN OPERATOR SHALL CLEARLY AND CONSPICUOUSLY DISCLOSE TO A USER THAT A CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE IS ARTIFICIAL INTELLIGENCE. THE DISCLOSURE MUST: (a) BE PROVIDED AT THE BEGINNING OF A USER'S FIRST INTERACTION WITH A CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE FOR EACH DAY OF INTERACTION; (b) APPEAR AT LEAST ONCE EVERY THREE HOURS IN A CONTINUOUS CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE INTERACTION OR APPEAR AS A PERSISTENT DISCLOSURE VISIBLE TO THE USER; AND (c) BE PROVIDED IN RESPONSE TO USER PROMPTS REGARDING WHETHER THE CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE IS ARTIFICIALLY GENERATED AND NOT HUMAN."
A re-disclosure every three hours, and again at the start of every day. That is further than anything else on this page.
Then read the definition it hangs on, because Colorado put the carve-out in the statute rather than leaving it to a regulator:
"'CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE' DOES NOT INCLUDE A SOFTWARE APPLICATION, WEB INTERFACE, OR COMPUTER PROGRAM THAT… (II) IS PRIMARILY DESIGNED TO PROVIDE COMMERCE-RELATED OR TRANSACTIONAL ASSISTANCE, INCLUDING PRODUCT OR SERVICE RECOMMENDATIONS, SHOPPING, ORDERING, PAYMENTS, DELIVERY, RETURNS, CUSTOMER SUPPORT, OR CUSTOMER SERVICE"
Customer support and customer service, named in the exclusion list. Two more sit beside them: tools "primarily designed and marketed for commercial use by business entities for the purpose of business operations, productivity, information analysis, internal research, training, or technical assistance," and anything "used by a business solely for internal purposes." An internal IT helpdesk bot is excluded twice over.
So the state with the most aggressive disclosure schedule in the country also wrote your support bot out of it. That isn't a loophole — it's a legislature deciding that the harm it cared about was companion-style engagement, particularly with minors, and that a bot which processes returns is a different animal. The act's other duties make the intent unmistakable: a suicide-and-self-harm response protocol, and restrictions on services offered to users the operator knows are minors.
The honest caveat. "Primarily designed to provide… customer service" is a scoping test, not a magic word, and nobody has litigated it. A bot that handles support tickets is plainly inside the exclusion. A general-purpose assistant on your site that will cheerfully talk about anything is a harder question. The Colorado Attorney General filed proposed rules for this act on August 11, 2026, with comments open until October 26, 2026 — that is where the edges get drawn, and it's worth watching if your bot looks more like the second description than the first.
So: does your chatbot have to say it's a bot?
Legally, in most states, today: no statute forces it for an ordinary business service bot. In Maine, yes — if a reasonable consumer might otherwise think they're talking to a person. And more states are drafting in that direction, not away from it.
But answer it as an operator instead of a lawyer and the question dissolves. The disclosure costs you one line. Concealment buys you nothing — people work out they're talking to a bot within two exchanges regardless, and the only thing you've earned by hiding it is the moment they realize you tried. That moment is more expensive than any statute.
Every deployment we run discloses. Not because Maine says so. Because a customer who knows they're talking to software and gets a fast, correct answer is a satisfied customer, and a customer who feels tricked is a support ticket with a grudge.
What to actually do
- Disclose at the start of the conversation. One clear sentence. Not buried in a tooltip, not in the privacy policy, not on hover.
- Don't let it claim to be human. If someone asks "am I talking to a person?", the honest answer is the only safe answer — and several of these laws specifically require the bot not to refute its own disclosure.
- Don't design for emotional attachment. A name and a personality are fine. Manufactured feelings, guilt about leaving, prompts to come back and talk — that's the behavior these laws target, and it's what moves you from "tool" to "companion" in the text.
- Give people a way to a human. Not legally required in most places. It's the thing that makes the disclosure land as confidence rather than a warning.
- Re-check if you sell into Maine, or in 2027. Washington, Oregon and now Colorado all land January 1, 2027 — and Colorado's rules are being written right now, with comments open until October 26, 2026. This area is moving fast, and this post is a snapshot dated the day it was written.
That's the entire list. It's shorter than the headlines suggested, and you were probably going to do most of it anyway.
Questions we get asked
Does my business chatbot legally have to disclose that it's AI?
In most US states, no statute currently forces an ordinary business service chatbot to disclose that it is AI. The 2026 state chatbot laws that got the most coverage are companion chatbot laws, and California, New York, Washington, Oregon and Hawaii all explicitly exclude bots used for customer service or a business's operational purposes. Maine is the notable exception: 10 M.R.S. section 1500-DD prohibits using an AI chatbot in trade and commerce in a manner that may mislead a reasonable consumer into believing they are talking to a human, unless the consumer is clearly and conspicuously notified they are not. There is no customer-service carve-out in the Maine statute. Regardless of the law, disclosing costs one sentence and is the recommended practice.
Does California's SB 243 apply to a customer service chatbot?
Almost certainly not. SB 243 was signed October 13, 2025 and took effect January 1, 2026. It regulates 'companion chatbots' — systems capable of meeting a user's social needs and sustaining a relationship across multiple interactions — and expressly excludes bots used only for customer service, a business's operational purposes, productivity and analysis, or technical assistance. The law does carry a private right of action with a $1,000 per violation floor, which is why it drew attention, but the exclusion for business service bots is written into the statute itself.
Does giving my chatbot a name and personality make it a 'companion chatbot'?
Not on its own. Washington's HB 2225 has the broadest definition — it includes systems exhibiting 'anthropomorphic features' that can sustain a relationship across multiple interactions — but its exclusion for business bots is conjunctive. A customer service bot only loses the exclusion if it both sustains a relationship across multiple interactions AND generates outputs likely to elicit emotional responses in the user. A named support bot that remembers a prior ticket does the first but not the second. Washington also defines 'user' as a natural person interacting for personal use. The risk comes from designing for emotional attachment, not from having a name.
When do the new state chatbot laws take effect?
California's SB 243 has been in effect since January 1, 2026, and New York's General Business Law Article 47 since November 5, 2025. Maine's chatbot disclosure statute (10 M.R.S. section 1500-DD, PL 2025 c. 294) is already in force. Washington's HB 2225 and Oregon's SB 1546 both take effect January 1, 2027. Hawaii's SB 3001 took effect on approval in July 2026. Colorado's HB 26-1263 took effect August 12, 2026, though its operator duties do not begin until January 1, 2027 and its definition excludes bots primarily designed for customer support or customer service. This area is moving quickly, so verify the current status before relying on any summary, including this one.
Does the EU AI Act require my US business's chatbot to disclose that it is AI?
For a US-only business, almost certainly not. The EU AI Act's transparency obligations in Article 50 became applicable on 2 August 2026, but Article 50(1) places the disclosure duty on providers of AI systems, not on the deployers who use one. The deployer-facing duties in Article 50 are paragraphs 3 and 4, covering emotion recognition and biometric categorisation systems and deep fakes, none of which describe a customer service bot. Territorial scope is set by Article 2(1), which reaches providers placing a system on the market in the Union, deployers established or located within the Union, and providers or deployers in a third country where the output produced by the AI system is used in the Union. There is no revenue threshold and no EU-customer trigger. A support bot answering US callers produces no output used in the Union. The cases worth raising with counsel are selling or licensing the bot itself into the EU, or a public web chat used by EU-located visitors.
Does the California AI Transparency Act apply to my customer service chatbot?
Almost certainly not. The California AI Transparency Act, SB 942 as amended by AB 853, became operative on August 2, 2026 and applies to a covered provider, defined as a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state. A business deploying a vendor's chatbot fails both parts of that test: it did not create, code or produce the system, and a support bot does not have a million monthly users. A separate bill, AB 1609, would regulate customer service chatbots specifically, but as of September 2026 it is not law. It passed both chambers on August 31, 2026, when the Assembly concurred in the Senate's amendments, and now awaits the Governor's signature or veto by the end of September 2026. It would apply only to businesses with more than $500,000,000 in gross annual revenue nationally.
Related reading: Is an AI receptionist even legal? — the call-recording and disclosure rules for voice, including why the “AI robocall” panic is about outbound calling and not about you, and what our own deployed agent sounds like on a real business line.
Related service: AI integration — built, disclosed properly, and operated in your environment rather than ours.