Tuesday, 11:20 PM. A tenant is in the chat widget on a property manager's website, disputing a late fee she's sure was charged in error. Four messages in, the answers are coming back a little too fast and a little too smooth, and she types the question that now decides how the whole interaction goes: "Wait - is this a bot?" What the widget says next is no longer just a UX choice. In a growing list of states, it's a question of law.

Last month we covered the disclosure question on the phone - the FCC's TCPA rulings, the trust research, the one-month test. This is the chat-side companion, and the chat side is where state legislatures have been busiest. Here's the map as it stands in August 2026, the California bill that just cleared the Assembly, and the audit that tells you whether your widget would survive any of it.

The map, as it stands in August 2026

There is no single chatbot disclosure law. There's a patchwork, and the rules that touch customer-service chat directly look like this:

  • Maine has the broadest rule in the country. Since September 2025, anyone using a chatbot in trade or commerce with a consumer must clearly and conspicuously disclose that the consumer isn't talking to a human, whenever the bot could mislead someone into thinking otherwise. Enforcement runs through Maine's Unfair Trade Practices Act, and notably, nobody has to prove a consumer was actually fooled - the undisclosed bot is the violation.
  • Utah requires a business using generative AI with consumers to disclose it whenever the consumer clearly asks - meaning the bot that dodges "am I talking to a robot?" is not just annoying in Utah, it's unlawful. State-regulated professionals (think healthcare, legal, financial services) must go further and disclose prominently, at the start of high-risk interactions.
  • Colorado's AI Act took effect June 30, 2026. Deployers must disclose AI use in consumer interactions tied to consequential decisions - finance, healthcare, housing, insurance, legal services and more - unless it would be obvious to a reasonable person that they're talking to a machine. If your chat handles billing disputes or payment plans, read that list again.
  • New Jersey requires clear disclosure at the start of any bot interaction involving the sale or advertising of merchandise or real estate.
  • California's original B.O.T. Act has prohibited using a bot to mislead people about its artificial identity in commercial transactions since 2019 - with disclosure as the built-in safe harbor.

And beneath all of it sits the FTC Act, which doesn't mention chatbots at all but has always prohibited deceptive commercial practices - a standard federal regulators read to require disclosing AI whenever the bot's presence is unexpected and would matter to the consumer. Whatever happens in the state-versus-federal preemption fight, that baseline isn't going anywhere.

If you sell across state lines, the strictest state's rule is effectively your rule - and the strictest rule is simple: say it's a bot, say it clearly, say it early. Nobody has ever been penalized for disclosing too plainly. Every enforcement theory on the map runs through concealment.

California is writing the next chapter - and it's about the exit, not just the label

The bill to watch is California's AB 1609, the "Right to Human Customer Service Act." It passed the Assembly on May 29, 2026 and is now in the Senate. It applies to businesses with more than $500 million in annual revenue that serve Californians, and it does two things. First, the familiar one: a business may not represent that a customer service chatbot is human, and must disclose clearly if a reasonable person would be misled. Second, the new one: during regular business hours, the business must make a good-faith effort to connect a customer to a human agent within 15 minutes of the request - with hold-time limits, wait estimates, and the customer's choice of text, email, or phone. Violations carry civil penalties up to $10,000, enforced by public prosecutors.

Most operators reading this are nowhere near $500 million in revenue. That's not the point. The point is what legislatures now consider the failure mode worth regulating: not AI answering the chat, but AI trapping the customer - the endless loop the bill's own committee analysis calls "chatbot purgatory." The disclosure fight is essentially settled; the human-escape-hatch fight is just starting.

California's other 2026 chatbot law, SB 243, points at the same future from a different angle. It targets companion chatbots - the relationship-simulating kind - and expressly carves out customer-service bots. But it took effect January 1, 2026 with a private right of action: actual damages or $1,000 per violation, whichever is greater. Oregon and Washington followed within months with their own chatbot statutes carrying $1,000-per-violation private actions; Nebraska and Idaho passed conversational-AI safety acts in April. Legislatures have discovered statutory damages for chatbots, and once that mechanism exists, extending it from companion bots to customer-service bots is an amendment, not a revolution. AB 1609 pointedly lacks a private right of action today. The word is "today."

The posture that survives every version of the map

You could track fifty statutes, or you could adopt the one configuration that satisfies all of them at once. It has three parts. Disclose in the first message, in plain words - "I'm the AI assistant for Ridgeline Property Management" - which satisfies Maine's misleading-consumer standard, New Jersey's start-of-interaction rule, and Colorado's obviousness test in one sentence. Never deny being AI, under any prompting, which is the Utah rule and the floor of every deception statute; a chat agent should treat "are you a bot?" the way a good employee treats any direct question, with a direct answer followed by continued competence. And keep a working exit to a human - visible, immediate, and context-preserving, so the person who asks for an agent doesn't restart from "how can I help you today?" That last one is the AB 1609 standard, and it's worth adopting whether or not the bill ever applies to you, because a 15-minute path to a human is simply what resolution looks like.

Notice that none of this is a burden unless your chatbot's strategy depends on being mistaken for a person. A bot that discloses and then actually resolves the issue - pulls the account, explains the fee, takes the payment, books the appointment - loses nothing to disclosure. The operators with a compliance problem are the ones whose bot buys time instead of answers. The same is true on your phone line, where voice agents face the FCC's parallel version of this map.

Run your own numbers: the one-month transcript audit

Don't take a vendor's word - including ours - that your widget is on the right side of this. Your transcripts already hold the answer. Pull one month of chat logs and count four things. First, disclosure coverage: what percentage of conversations contain a clear AI disclosure in the first message? The compliant number is 100; anything else is a configuration fix, not a policy debate. Second, the direct question: how many customers asked some version of "is this a bot?", and what did yours say? Every evasive or cute answer in that pile is a Utah violation and a Maine exhibit. Third, the exit: of the customers who asked for a human, how many reached one, and what was the median time? Score yourself against AB 1609's 15 minutes - it's the only concrete benchmark any legislature has written down. Fourth, the loop: how many conversations ended with neither a resolution nor a handoff? That's your chatbot-purgatory rate, and it's the number the next wave of bills is aimed at.

An hour with your own transcripts will tell you more about your legal exposure than any fifty-state survey - because every statute on the map ultimately punishes the same two transcripts: the bot that lied, and the customer who couldn't get out.

Start small, measure it

Verlingo agents ship with the strict configuration as the default: first-message disclosure in plain language, a hard rule against ever denying AI status, and a human handoff that carries the full transcript with it - on chat and voice alike, in 100+ languages. Every conversation is logged and exportable, so the four-count audit above is a report you can run, not a project you have to staff.

Pick one channel - the website widget is the natural start - and run it disclosed and audited for a month. If your current setup passes all four counts, you've spent an hour confirming you're ahead of the map. If it doesn't, you've found out from your own transcripts instead of a demand letter. Setup takes minutes, and the rates are published. The legislatures have made the direction of travel clear. The only question is whether you get there on your schedule or theirs.

V

Verlingo

AI voice & chat agents, in production

Field notes from the front lines - phone calls and chat windows, collections floors and front desks. We build the agents, run them in production, and write down what works.