Home  /  Blog

Buyer's guide · 15 min read · · Updated

Is It Legal to Use an AI Receptionist? What US Small Businesses Need to Know

Short answer: yes. The robocall rules everyone worries about govern outbound AI calls — not an AI answering the calls your customers place to you. Here's the real, much shorter list of what applies.

It's the first question almost every business owner asks us before deploying an AI voice agent: "Wait — is this even legal?" It's a fair question, and the honest answer is reassuring: using an AI receptionist to answer your inbound business calls is legal in the United States. The fear usually comes from headlines about "AI robocalls" and FCC crackdowns — but those rules are about a completely different activity than what an AI receptionist does.

Let me clear up the confusion, then give you the two things that actually matter.

This is general information for business owners, not legal advice. Laws vary by state and change over time, and how they apply depends on your specifics. For your situation, confirm with a qualified attorney.

The one distinction that clears up 90% of the worry

Almost all of the legal anxiety around AI on the phone collapses once you separate two very different things:

  • Outbound AI calls — your business uses an AI voice to place calls to people: telemarketing, reminders, follow-ups, callbacks. This is heavily regulated.
  • Inbound AI answering — a customer dials your number, and an AI answers, qualifies, routes, takes a message, or books a time. This is what an AI receptionist is.

The rules people are scared of — the federal TCPA (Telephone Consumer Protection Act) and the FCC's 2024 ruling that AI-generated and cloned voices count as "artificial" — apply to calls a business initiates. In February 2024 the FCC confirmed that if you place an outbound call using an artificial or AI voice, you generally need the called party's prior express consent, you have to identify yourself, and for telemarketing you need a way to opt out. Those are outbound obligations.

When a customer calls you, they initiated the contact. The TCPA's consent machinery for outbound artificial-voice calls simply doesn't attach to your AI picking up. That single distinction resolves most of the worry. An AI answering your phone is, legally, much closer to a voicemail system or an IVR menu than to a robocall campaign.

The takeaway: if your AI receptionist only answers inbound calls, the TCPA "AI robocall" rules are not your problem. They become relevant only if you later have the same system make outbound calls — and even then, it's manageable with consent and disclosure.

The two things that actually apply to an inbound AI receptionist

1. Call-recording consent — the one most businesses overlook

Most AI receptionists transcribe calls so they can summarize them for you. Transcribing usually means recording, and recording is where real obligations live. Federal law allows recording if one party consents, but about a dozen states — including California, Washington, and Florida — require all parties to consent.

The fix is simple and standard: a short notice at the start of the call, such as "This call may be recorded for quality and scheduling." In most all-party states, continuing the call after that notice is treated as consent. If you take calls from customers in multiple states — which most businesses do — the safe default is to treat the strictest all-party standard as your baseline and disclose recording on every call. We build that disclosure into every deployment by default.

2. Letting the AI identify itself as AI

A handful of states (California's "bot" disclosure law and Utah's AI Policy Act are the notable ones) have rules around disclosing that someone is interacting with AI, particularly in commercial or regulated contexts. The application of these laws to ordinary phone answering is still unsettled — but the smart, low-cost move is obvious: have the assistant identify itself as an AI assistant up front.

This isn't just compliance hygiene; it's good business. Callers who are told plainly "Hi, I'm the AI assistant for [Company]" relax faster than callers who feel something is off. Transparency lowers the legal surface area and improves the experience. There is no federal law forcing you to announce "I am an AI" on every call — but doing it anyway is the right call.

What about all the "AI laws" in the news?

You've probably seen headlines about the Colorado AI Act, the EU AI Act, and a wave of state AI bills. Here's why they don't change the answer for a receptionist: nearly all of them target high-risk AI that makes consequential decisions — approving loans, screening job applicants, setting insurance rates, making housing or healthcare or legal determinations. An AI that answers your phone, takes a message, and books a meeting isn't making any of those decisions.

Colorado is a useful example of why not to panic over a headline. Its original AI Act (SB 24-205) kept getting pushed back — and then, in May 2026, the legislature amended and effectively replaced it. The new version, SB 26-189, signed May 14, 2026, delayed the start date to January 1, 2027 and slimmed the law down to a lighter disclosure-and-transparency framework, dropping the original's sweeping "duty of care" and impact-assessment mandates. It's still aimed at consequential automated decision-making — lending, hiring, and the like — not a voice that answers your phone and books appointments. (It's also drawing legal challenges, so the fine print may shift again before it takes effect.) The trend is real and worth watching; it's just not pointed at receptionists.

A dated status check, re-verified August 2026: there is still no finalized federal rule requiring an AI to announce itself at the start of a phone call — the FCC floated one, but it remains a proposal, not law. And the newer state chatbot-disclosure laws that have taken effect — California's SB 243 and New York's companion-AI law — are written for "companion" chatbots that simulate relationships and friendships, not for a receptionist that answers, routes, and schedules. We date this post on purpose: this corner of the law moves, and we update it when it does.

Update — August 2026: Colorado passed a second AI law, and this one is about chatbots

The section above describes SB 26-189, Colorado's replacement for its original AI Act, and that is still accurate — it is aimed at consequential automated decisions and it starts January 1, 2027. But Colorado passed a second AI law in the same session, and this one points directly at conversational AI. It is the first state statute we've covered here that could plausibly be read to describe a receptionist.

HB 26-1263, the Conversational Artificial Intelligence Service Operator Requirements act, was signed May 29, 2026 and took effect at 12:01 a.m. on August 12, 2026. Its disclosure schedule is the most demanding we've seen in a state statute: from January 1, 2027, an operator must disclose that the service is AI at the start of the user's first interaction each day, again "at least once every three hours" in a continuous interaction or as a persistent visible disclosure, and whenever a user asks whether they are talking to a human.

Read that much and you would reasonably assume an AI receptionist is squarely inside it. Then read the definition, because Colorado wrote the carve-out into the statute itself. A "conversational artificial intelligence service" expressly does not include a program primarily designed to provide commerce-related or transactional assistance — and that list ends, in the statute's own words, with "customer support, or customer service." Two further exclusions sit beside it: tools sold to business entities for business operations, productivity, internal research or technical assistance, and anything "used by a business solely for internal purposes." We walk through the full text, and the rest of the 2026 state chatbot laws, in Colorado HB 26-1263 and the 2026 chatbot disclosure laws.

And Colorado is not the first state to draw that line. California's SB 243 — the companion-chatbot law already in force — carries the same shape of exclusion, for "a bot that is used only for customer service, a business' operational purposes, productivity and analysis related to source information, internal research, or technical assistance." Two states, drafting separately, reached for the same carve-out. That is not a drafting accident; it is a considered judgment that a bot which books appointments is a different thing from one that simulates a relationship.

Where that leaves an inbound receptionist, stated honestly. A bot whose job is answering, routing, taking messages and booking appointments reads onto the customer-service exclusion on the face of the text. We are not going to tell you it is settled. "Primarily designed to provide… customer service" is a scoping test, nobody has litigated it, and a phone assistant that also holds open-ended conversation is a genuinely harder question than a support-ticket bot. The Colorado Attorney General filed proposed rules for this act on August 11, 2026, with comments open until October 26, 2026 — that is where questions like this one get answered. And nothing is required of anyone before January 1, 2027 in any case.

The pattern is the one this post keeps running into. The state with the most alarming chatbot-disclosure text in the country is also the state that named customer service in its list of things the law does not cover.

Update — September 2026: Colorado's own Attorney General has the dates wrong

A small thing with a practical lesson attached. The Colorado Attorney General is currently writing the rules that will interpret HB 26-1263, and the office's rulemaking page at coag.gov/ai describes the statute it is interpreting like this: the bill "was signed into law on July 1, 2026 and goes effect January 1, 2027."

Neither date matches the legislature's own record. The Colorado General Assembly's official bill history for HB 26-1263 shows "05/29/2026 — Governor — Governor Signed", with an effective date of 08/12/2026. That is the record we used when we wrote the section above, and we have re-checked it: signed May 29, 2026, effective August 12, 2026, operator duties beginning January 1, 2027. The AG's page appears to have collapsed the effective date into the duties date and attached a signing date that does not appear anywhere in the bill's history.

We are not making a point about the Attorney General's office, which is doing the substantive work here and whose rulemaking is the thing actually worth watching. The point is about which source you check. An agency summary page is written by people interpreting a statute, not recording it; the legislature's bill history is the record. If a compliance date matters to a decision you are making, take it from the bill history and not from the agency page, the trade press, or a vendor's summary — including ours. Ours is checkable against the same record, which is the only reason it is worth anything.

The dates that matter for an AI receptionist are unchanged: HB 26-1263 has been in effect since August 12, 2026, its operator duties begin January 1, 2027, and the customer-service exclusion described above is written into the statute itself. What is still genuinely open is whether the AG's rules narrow that exclusion — a revised draft is due to circulate no later than September 23, 2026, with formal comments closing October 26, 2026. That draft, not the summary page, is the next thing we will be reading.

The same point, narrated in about a minute:

Update — August 2026: a federal judge let wiretap claims proceed against an AI notetaker

This one is not a disclosure law, and that is exactly why it matters. On Thursday 13 August 2026, Judge Eumi K. Lee of the U.S. District Court for the Northern District of California declined to throw out the core claims in In re Otter.AI Privacy Litigation (No. 5:25-cv-06911), a putative class action over an AI meeting assistant that joined Zoom calls and transcribed them.

What survived the motion to dismiss: claims under the California Invasion of Privacy Act (Penal Code §631 et seq.), the federal wiretap statute, Illinois’ biometric privacy law, unjust enrichment, and California’s unfair competition law. Dismissed: the computer-fraud counts, Washington’s privacy act, and most of the common-law privacy claims.

The reasoning is the part worth reading twice. The court did not hold that recording a meeting is unlawful. It held that the plaintiffs had plausibly alleged the vendor kept the conversations and reused them to train its own models — and that this is what makes it arguable the vendor was a third party listening in, rather than a tool acting on behalf of the person who invited it. The distinction is not “was there a recording”. It is who else got something out of it.

For anyone running AI on live calls, that turns a vague worry into a concrete question with a checkable answer: does your vendor train on your conversations? If the answer is yes, the “it is just software the host switched on” defence is weaker than it was on 12 August. If the answer is no, and you can point at the contract term that says so, you are in a materially different position.

Two cautions, because this is a ruling that is easy to over-read. It is a pleading-stage decision: it decides that the case may continue, not that anyone broke the law, and the defendant has not had its evidence tested. And the order itself is not publicly fetchable from here — the analysis above is corroborated across four independent outlets rather than quoted from the docket, including the Metropolitan News-Enterprise’s 17 August report. Treat the claim list as reported, not as read.

None of this is legal advice, and a two-party-consent question about your own calls is worth twenty minutes of a lawyer’s time rather than twenty minutes of ours.

How we keep Aria on the right side of all of this

When we deploy Aria — the same AI voice agent we use on our own line — compliance isn't an afterthought, it's part of the build:

  • Recording disclosure on by default, tuned to the strictest standard for the states you take calls from.
  • Clear AI self-identification, so callers always know what they're talking to.
  • Inbound-first by design. If you later want outbound (reminders, callbacks), we treat that as a separate, deliberate step with the consent and disclosure it requires — not something that quietly turns on.
  • Your data, handled responsibly — transcripts and summaries flow to you, with retention you control.

The bottom line

An inbound AI receptionist is legal for US small businesses today. The heavy robocall rules are about outbound calling, and the two obligations that genuinely apply to answering — recording consent and AI self-identification — are easy to satisfy and largely just good practice. Don't let a misread headline keep you stuck sending real customers to voicemail.

Want to hear exactly how a disclosure-compliant deployment sounds? Call our own line at (206) 578-5242 — the agent discloses the recording and identifies itself as an AI, the same way it would on yours.

Related reading: Does your chatbot legally have to say it’s a bot? — the disclosure side of the same question, including the Colorado text above and why customer service is carved out of it. And we answer our own phone with a voice agent — what running one on a real business line actually involves, including the parts that are labour rather than software. The service page for this work is AI integration.

Questions we get asked

Is it legal to use an AI receptionist for my business?

Yes. In the United States, using an AI voice agent to answer your inbound business calls is legal. The strict consent and disclosure rules people associate with 'AI robocalls' come from the TCPA, which governs outbound calls a business places to consumers — not technology you use to answer calls customers place to you. The two things that realistically apply to an inbound AI receptionist are call-recording consent (if you record or transcribe calls) and the good practice of having the assistant identify itself as AI. This is general information, not legal advice.

Do I need a caller's consent before an AI answers their call?

No. When a customer dials your business, they initiated the contact, so the TCPA's prior-express-consent rules for outbound artificial-voice calls do not apply to your AI answering. Consent obligations attach to outbound AI calling — callbacks, reminders, or marketing the AI places on your behalf — which is a separate decision you control.

Does my AI receptionist need to record calls, and is that legal?

Recording is optional, but most AI receptionists transcribe calls to produce summaries. If yours records, about a dozen US states — including California, Washington, and Florida — require all parties to consent to recording. The standard, safe practice is a brief notice at the start of the call ('This call may be recorded for quality and scheduling'); continuing the call is treated as consent in most of these states. For businesses that take calls from multiple states, default to the strictest all-party standard.

Do laws like the Colorado AI Act make AI receptionists illegal?

No. The wave of state 'AI laws' targets high-risk systems that make consequential decisions — lending, hiring, housing, insurance, healthcare, legal services. An AI receptionist that answers calls, takes messages, and books appointments is not making those decisions. Colorado's original AI Act was delayed and then, in May 2026, replaced by a lighter law (SB 26-189, signed May 14, 2026) that takes effect January 1, 2027 and focuses on disclosure and transparency for consequential automated decisions — not phone answering. Newer state chatbot-disclosure laws that have taken effect, like California's SB 243 and New York's companion-AI law, target 'companion' chatbots, not business receptionists. Colorado added a second law in 2026, HB 26-1263, which is aimed at conversational AI rather than consequential decisions and took effect August 12, 2026. Its definition expressly excludes programs primarily designed to provide customer support or customer service, and its duties do not begin until January 1, 2027.

Curious whether an AI receptionist fits your business — legally and practically? Book a 20-minute scoping call. We'll walk through your call flow, your states, and exactly how we'd handle disclosure for you. No deck, no pressure.

Written by Mat Wolfley, Founder of Leverage Automated · Seattle, WA.

Related service: AI integration — voice is one surface among several, built into the phone system you already run.

Leverage Automated

Ask us before you have to answer.

If somebody asked you to find out what your company should do about AI, send us the question you were sent with. No budget, no decision, and no obligation to become a client — including when the honest answer is that you should not do this yet.

Email us a question Call (206) 578-5242

Two ways we work: a fractional CIO when nobody owns the technology decision, and AI integration when the decision is made and it has to work against what you already run.

Call (206) 578-5242