Tuesday, September 15$199late booking, seats still openBook a seat
← All guides

Do I have to tell customers when a reply is written by AI?

There is no single US law that makes you label every AI-written reply. But you must not let a customer be deceived into thinking a bot is a person. California Business and Professions Code § 17941, Maine's 10 M.R.S. § 1500-DD and Utah Code Chapter 13-77 each require disclosure in defined situations, and the FTC treats deception as illegal under Section 5.

The federal position: deception is the line, not AI itself

There is no federal statute requiring you to label AI-written customer replies. The federal exposure is the general one: Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in commerce.

So the question is not "did AI write it?" It is "would a reasonable customer have been misled about something that matters?"

Signing a bot's reply with a fake employee name and photo is a deception problem. Sending an AI-drafted reply under your own business name is generally not.

The FTC has been active here. Its September 2024 Operation AI Comply sweep brought five enforcement actions over allegedly deceptive AI-related conduct (ftc.gov).

A correction worth making. The FTC's impersonation rule, 16 CFR Part 461, is widely cited as an AI-labelling rule. It is not. Read the actual text: § 461.2 prohibits materially and falsely posing as "a government entity or officer thereof", and § 461.3 prohibits materially and falsely posing as "a business or officer thereof", or misrepresenting affiliation with one (ecfr.gov). The rule was published at 89 FR 15030 on 1 March 2024.

So Part 461 bites when your AI pretends to be someone else — a bank, a government agency, a competitor. It says nothing about labelling AI as AI. Anyone telling you otherwise has not opened the regulation.

California § 17941 — the original bot law, and it is narrower than people think

California passed the first US bot disclosure law. It reads:

"It shall be unlawful for any person to use a bot to communicate or interact with another person in California online, with the intent to mislead the other person about its artificial identity for the purpose of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction or to influence a vote in an election." — Cal. Bus. & Prof. Code § 17941(a) (leginfo.legislature.ca.gov)

Four things must all be true before it applies:

  1. The communication is online.
  2. The other person is in California.
  3. You intended to mislead them about the bot's artificial identity.
  4. The purpose was to incentivize a purchase or sale, or influence a vote.

A helpful order-status bot that nobody is trying to disguise does not meet the intent test.

The statute then gives you a clean way out. Subsection (b) states the disclosure "shall be clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot" (leginfo.legislature.ca.gov). Disclose plainly and the section does not apply. It became operative on 1 July 2019.

Maine § 1500-DD — the broader test, and the one to design for

Maine's law is the stricter one, and it is the sensible standard to build against because it has no intent requirement in the California sense.

"A person may not use an artificial intelligence chatbot or any other computer technology to engage in trade and commerce with a consumer in a manner that may mislead or deceive a reasonable consumer into believing that the consumer is engaging with a human being unless the consumer is notified in a clear and conspicuous manner that the consumer is not engaging with a human being." — 10 M.R.S. § 1500-DD(2) (legislature.maine.gov)

The definition is wide. An "artificial intelligence chatbot" means "a software application, web interface or computer program that simulates human conversation and interaction through textual or aural communications" (legislature.maine.gov).

A violation of subsection 2 is a violation of the Maine Unfair Trade Practices Act (legislature.maine.gov). The section was enacted by PL 2025, c. 294, § 1.

Note the trigger: "may mislead or deceive a reasonable consumer". You do not need to have intended it. If your bot is realistic enough that a normal person would assume a human, you disclose.

Utah Chapter 13-77 — disclose when asked, and disclose up front in high-risk work

Utah was the first state with a general generative-AI consumer law, and it was narrowed by SB 226 in 2025. The current framework sits in Utah Code Title 13, Chapter 77 (le.utah.gov).

Two duties matter for a normal business:

  1. On request. If a person in a consumer transaction clearly and unambiguously asks whether they are dealing with AI, you must say so. The nuance is that this is answer-when-asked, not label-everything.
  2. Up front for high-risk interactions. This covers health, financial or biometric information. It also covers personalized advice a person could reasonably rely on for a significant decision. Disclosure must come at the start: spoken at the beginning of a spoken interaction, written before a written one.

There is a safe harbour. Enforcement does not apply where the AI clearly and conspicuously discloses at the outset that it is generative AI and not a human. Civil penalties run up to $5,000 per violation of an administrative or court order. SB 226 took effect 7 May 2025 (le.utah.gov).

California SB 243 — companion chatbots only

SB 243 gets cited in customer-service discussions, and it usually does not apply.

It adds Chapter 22.6 (commencing with § 22601) to Division 8 of the California Business and Professions Code. It targets "companion chatbots": systems with a natural language interface giving adaptive, human-like responses capable of meeting a user's social needs (leginfo.legislature.ca.gov).

Where it applies, the operator must give a clear and conspicuous notification that the chatbot is artificially generated and not human. The duty bites when a reasonable person might otherwise believe they are talking to a real person. § 22605 creates a private right of action with damages of the greater of actual damages or $1,000 per violation, plus attorney's fees (leginfo.legislature.ca.gov). Annual reporting obligations begin 1 July 2027.

An order-status bot for a plumbing company is not a companion chatbot. A product designed for ongoing emotional conversation is.

On the rest of the states: the count of state chatbot laws has moved fast through 2025 and 2026, and several trackers disagree with each other. Verify your own states rather than relying on a list, including this one.

The international note: EU AI Act Article 50

Skip this unless you deal with customers in the European Union. If you do, it reaches you even though you are a US business.

Article 2(1)(c) of the AI Act applies the Regulation to providers and deployers established in a third country "where the output produced by the AI system is used in the Union" (eur-lex.europa.eu). A reply generated in Ohio and read in Ireland can be in scope.

Article 50(1) requires providers to ensure systems intended to interact directly with people are designed so that people "are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use" (eur-lex.europa.eu).

That is the "obvious" exception, in full. It is not a general excuse. It is an objective test about a reasonably observant person in that specific context. A widget labelled "AI Assistant" plausibly qualifies. An email signed with a human name does not.

Article 50(5) fixes the timing: the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and must meet accessibility requirements (eur-lex.europa.eu). First contact, not on request.

Article 50(4) is separate and narrower. It covers deepfakes, and text "published with the purpose of informing the public on matters of public interest". That second duty does not apply where the content had human review or editorial control and a person holds editorial responsibility (eur-lex.europa.eu). Your reply to one customer's inquiry is not published public-interest content.

Timing and penalties: Article 113 provides that the Regulation applies from 2 August 2026, with listed exceptions that do not include Chapter IV, where Article 50 sits (eur-lex.europa.eu). Article 99(4)(g) puts breaches of Article 50 in the tier attracting administrative fines up to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher (eur-lex.europa.eu). The European Commission published guidelines on Article 50 in 2026 (digital-strategy.ec.europa.eu).

UK, briefly. The UK has no general AI-labelling statute. Under PECR the relevant question is marketing, not AI.

A reply to a customer's own inquiry about a current contract or past purchase is a service message, not direct marketing. It must stay neutral in tone and carry no promotional content. The ICO's position is that if a service message contains marketing elements, even incidentally, the marketing rules apply to the whole message (ico.org.uk).

What to actually do

Six steps that satisfy the strictest US rule above, which is Maine's.

  1. Never give a bot a fake human identity. No invented agent name, no stock photo, no fabricated signature. This is the one thing that turns a compliance question into a deception question.
  2. Label at first contact. A line at the top of a chat window: "You're chatting with our AI assistant. Ask for a person at any time." That satisfies Maine's clear-and-conspicuous test and California's § 17941(b) safe harbour in one sentence.
  3. Always answer the direct question honestly. If someone asks "am I talking to a robot?", the bot says yes. This is Utah's core duty and it is free to implement.
  4. Disclose up front in high-risk contexts. Health, money, legal, biometric, or advice someone would rely on for a big decision. Say it before the conversation starts.
  5. Human-reviewed drafts need no label. If a person reads, edits and sends the message under their own name, the message is from that person. Using a tool to draft is not deception.
  6. Write it down once. A short internal policy: where AI runs, what it discloses, when it escalates. If a regulator or a customer asks, you have an answer.

What most articles get wrong about this

"The EU AI Act bans unlabelled AI email from 2 August 2026." No. Article 50(1) covers systems intended to interact directly with people, with the "obvious" exception. Article 50(4)'s text duty covers publication on matters of public interest, not one-to-one replies, and exempts human-reviewed content with editorial responsibility (eur-lex.europa.eu).

"The FTC impersonation rule requires you to label AI." No. 16 CFR §§ 461.2 and 461.3 prohibit posing as a government body or a business (ecfr.gov). Different problem entirely.

"Every AI-assisted draft needs a disclaimer." No US law found in this research requires labelling a message a human reviewed and sent. The duties attach to systems that interact with people, and to conduct that misleads.

"California's bot law covers all chatbots." No. § 17941(a) requires intent to mislead about artificial identity, for the purpose of incentivizing a purchase or sale, or influencing a vote (leginfo.legislature.ca.gov). Maine's test is the broad one, not California's.

Where these figures come from

People also ask


A drafted reply and a follow-up reminder created from an incoming message

Rather do this with someone than read about it?

Automate customer inquiries with AI is a live two-hour class built on exactly this problem. 25 seats, your own files, and you leave with every new message gets a reply written for you, the details saved, and a reminder to chase.

Read next

Can AI answer my customer inquiries for me?

Yes, for the repetitive questions — hours, pricing, order status, returns — if you give it a written source of truth and a clear route to a human.

Can lawyers use ChatGPT and keep client confidentiality?

Yes. ABA Formal Opinion 512, issued 29 July 2024, permits generative AI use under the existing Model Rules.

Can my ChatGPT conversations be subpoenaed?

Yes, and they already have been. In New York Times v. OpenAI, a court ordered OpenAI to produce 20 million de-identified ChatGPT conversations.