Something shifted for anyone running an artificial intelligence phone number or a chat bot this year. The EU’s AI Act transparency rules for systems that talk to people became applicable on 2 August 2026. In the US, the FCC has been building out AI-call rules since a February 2024 ruling, and state legislatures keep adding their own bot-disclosure statutes on top. If your business calls customers, takes their calls, or chats with them on your site, you now need a real answer to one question: what, exactly, are you required to say before the conversation starts? Get the fundamentals wrong on the landing page pitch and it’s an embarrassment. Get them wrong in a live call script and it’s a compliance exposure.

This post is a working guide, not a buyer’s guide — if you’re still deciding whether to get a number at all, our AI phone number guide covers that ground. Here we’re assuming you already run an ai caller, an ai call bot, or a chat agent, and you need the exact disclosure language, the triggers that activate it, and the log entries that prove you said it. One honest note up front: this is not legal advice. Rules differ by state, country, and use case, and they’re still moving — check with counsel before you ship anything based on a blog post, including this one.

Two questions that decide your AI caller rules

Before you write a single disclosure string, answer two questions. First: is this voice or text? Second: is it inbound or outbound? Those two variables place you somewhere on a grid, and the grid tells you how strict your obligations are.

Outbound voice is the strictest quadrant, full stop. You’re initiating contact with someone who didn’t ask for it, using a synthetic voice, and in the US that triggers consent regimes built for robocalls decades before anyone said “AI caller.” You need consent before you dial, and you need disclosure the moment the person picks up, because they can’t scroll back to read something they missed.

Inbound voice is a notch easier — the customer called you — but you’re still using a synthetic voice in real time, so most disclosure regimes still expect you to say something in the opening seconds.

Outbound text (cold SMS, for instance) sits in the middle: less regulatory baggage than outbound voice, but you’re still the one starting the conversation.

Inbound text — someone opens your chat widget and starts typing — is the lightest lift by a wide margin. The visitor initiated contact, there’s no synthetic-voice consent regime to trigger, and the disclosure can live quietly in the interface instead of being spoken aloud. That’s not a loophole. It reflects a genuinely smaller footprint of consumer-protection concern. Keep this grid in your head. Every section below maps onto it.

OUTBOUNDINBOUNDVOICETEXTOutbound VoiceSTRICTESTInbound VoiceMODERATEOutbound TextMODERATEInbound ChatLIGHTEST
The four disclosure quadrants: channel and direction set the strictness bar

EU AI Act, Article 50: the transparency duty

The EU AI Act’s transparency obligations for systems that interact directly with natural persons became applicable on 2 August 2026. Article 50 requires that providers and deployers ensure the person on the other end is informed they’re dealing with an AI system — unless it’s obvious to a reasonably well-informed, observant, and circumspect person given the context.

That “obvious” carve-out is doing a lot of work, and it’s tempting to lean on it. Don’t. “Obvious” is a standard a regulator or a plaintiff’s lawyer gets to argue about after the fact, not one you get to declare for yourself in advance. A chat bubble with a friendly human-sounding name and a stock photo avatar is exactly the kind of interface where “obvious” collapses under scrutiny. A synthetic voice on a phone call is almost never obvious — humans are bad at detecting AI voices, and getting worse at it as the models improve.

The safe reading, and the one we’d recommend regardless of what “obvious” might technically cover in your specific case, is: always disclose. It costs you one sentence. The downside of skipping it — an AI Act enforcement action, a bad-faith accusation, a user who feels deceived and posts about it — costs a great deal more than one sentence.

Article 50 applies whether the natural person is on a phone call or in a text interface. The channel doesn’t change the duty to disclose; it changes how you satisfy it, which is the whole reason voice and text need separate playbooks later in this post.

Jul 2019CaliforniaB.O.T. ActFeb 2024FCC declaratoryruling2024-2025Utah AI Policy Act+ amendment2 Aug 2026EU AI Act Art. 50applicableProposedFCC AI-calldisclosure rule
The disclosure landscape so far, with the FCC’s AI-call rulemaking still proposed, not final

FCC, TCPA, and AI voice

In the US, the relevant starting point is the FCC’s declaratory ruling of 8 February 2024. It held that calls using AI-generated voices qualify as calls using an “artificial voice” under the Telephone Consumer Protection Act. That’s a bigger deal than it sounds: it means the TCPA’s existing consent machinery — prior express consent before you dial, which the FCC’s rules require to be written for telemarketing calls — now unambiguously applies to automated phone calling that uses a synthetic voice, not just old-school pre-recorded messages.

Practically, if you’re running ai outbound sales calls with an AI voice, you need documented consent before you dial, an easy opt-out, and records to prove both. That obligation exists independent of any disclosure requirement — it’s a consent requirement, and it kicks in before the call even happens.

One wrinkle worth knowing about: in February 2026 the Fifth Circuit held in Bradford v. Sovereign Pest Control of TX that the TCPA itself only requires “prior express consent,” which can be oral, and that the FCC exceeded its authority in demanding written consent for telemarketing calls. That decision binds only courts in Texas, Louisiana, and Mississippi. Read the scope carefully before you lean on it anywhere else. Everywhere else the FCC’s written-consent rule still stands, and the practical advice is unchanged: get it in writing, keep the record, and don’t build a national calling program on a single circuit’s reading.

Here’s the hedge you need to sit with: the FCC has floated further rulemaking specifically about AI-call disclosure — requiring callers to affirmatively state that a call uses AI. As of August 2026, that rulemaking is proposed, not final. Treat it as a strong signal of where enforcement priorities are heading, not as a rule you’re already bound by. Build your disclosure practice as if it were already law, because building it later under a compliance deadline is worse, but don’t cite it to anyone as current federal law, because it isn’t yet.

If you’re weighing whether outbound AI calling is worth this regulatory weight at all, our piece on what AI agents can actually do on outbound calls is a useful reality check before you build the consent infrastructure this section describes.

The US state patchwork

Federal rules aren’t the only layer. States have been adding their own bot- and AI-disclosure statutes, and the map keeps shifting — which is exactly why we’re naming only two here and pointing you to counsel for the rest.

California’s B.O.T. Act (SB 1001) has been in force since 1 July 2019. It applies to online bots used to incentivize a sale of goods or services, or to influence a vote in an election. It requires disclosure that is “clear, conspicuous, and reasonably designed” to inform the person they’re interacting with a bot, and it’s enforced by the state Attorney General. Note the scope: it’s about bots with a commercial or electoral persuasion purpose, which covers a lot of sales-oriented chat and call agents.

Utah’s AI Policy Act (SB 149, 2024), as amended by SB 226 in 2025, takes a two-tier approach. For most interactions, you need to disclose that the person is dealing with AI if they ask. For regulated occupations and higher-risk interactions, the duty flips to proactive disclosure — you tell them up front, without waiting to be asked.

Beyond California and Utah, several other states have enacted or proposed similar rules, and the details vary enough that we won’t summarize them here — misquoting a bill number or an effective date is worse than saying nothing. If you run ai outbound sales calls across state lines, this patchwork is a strong argument for building your disclosure practice to the strictest standard you can find and applying it everywhere, rather than maintaining fifty different scripts. Our cold-calling compliance breakdown goes deeper on how this patchwork interacts with actual dialing costs.

What “clear and conspicuous” actually means

Every statute above uses some version of “clear and conspicuous,” and none of them define it precisely enough to code against. Here’s the practical translation we use.

Not buried in your terms of service. If a disclosure only exists in a document nobody reads before they call or start typing, it doesn’t count. The person has to encounter it during the interaction that’s actually happening, not in a legal document they agreed to at signup three years ago.

Not behind a scroll or a tap. If someone has to expand a menu, scroll past a wall of text, or tap “learn more” to find out they’re talking to a bot, that’s not conspicuous — that’s hidden with extra steps.

Present at the moment of the encounter. This is the core idea behind every version of the standard: disclosure has to land when the person is deciding how much trust to extend to what’s about to happen, not after.

Voice and text satisfy this differently, and that difference matters for implementation. Audio disclosure has to land in the opening seconds of a call, full stop, because a caller can’t scroll back to catch something they missed at second forty. There’s no equivalent of a persistent visual label in a phone call — you get one shot, early, or you don’t get it at all.

Visual disclosure has more flexibility. A persistent label — a small “AI Assistant” badge sitting next to the chat avatar for the entire conversation — satisfies “clear and conspicuous” without needing a one-shot modal that the visitor might dismiss without reading. That persistence is actually a stronger compliance posture than a single disclosure line, because it stays true even if the person joins the conversation midway through a page refresh or comes back to a saved tab.

VSXNot conspicuousBuried in terms of serviceBehind a tap or menuAfter data collectionOKConspicuousIn the first messagePersistent visible labelBefore data collection
Clear and conspicuous means present at the moment of the encounter, not buried or delayed

AI caller disclosure wording that works

Here are working templates. Adapt the company name and channel details, but keep the structural choices — they’re not stylistic.

  • Outbound voice opener: “Hi, this is an automated call from [Company] using an AI voice assistant. If you’d like to speak with a person, just say so at any time.”
  • Inbound voice greeting: “Thanks for calling [Company]. You’re speaking with an AI-powered call agent today. Say ‘agent’ anytime to reach a human.”
  • Chat widget first message: “Hi! I’m an AI assistant for [Company]. I can answer most questions right now — just ask for a human anytime.”
  • Chat header / persistent label: a small, always-visible “AI Assistant” tag next to the bot’s name in the chat header, not a one-time popup.
  • ”Are you a robot?” answer: “Yes, I’m an AI assistant. I’m happy to connect you with a person on our team if you’d like.”

Three design rules sit behind every one of these strings. Say “AI” or “automated,” not “virtual assistant”: the softer phrase reads as ambiguous to a regulator and to a person who’s genuinely unsure whether they’re talking to a human, which defeats the purpose. State it before you collect anything — name, email, phone number, account details — because disclosure after data collection doesn’t give the person a chance to decide whether they want to proceed on those terms. And keep the human-escalation path in the same breath as the disclosure itself: “you’re talking to AI” without “and here’s how to reach a person” reads as a dead end rather than a transparent choice.

Resist the urge to make these clever. A disclosure line isn’t the place for brand voice. It’s the place for a sentence a tired person can parse in two seconds, on a phone call, mid-conversation.

What to log to prove it

Saying the right words once means nothing if you can’t demonstrate you said them to everyone, every time. Build an audit trail from day one — retrofitting one after a complaint is much harder than logging it up front.

At minimum, record: the disclosure text version actually delivered (wording changes over time, so version it), a timestamp, the channel (voice or chat), a session or call ID, whether the person acknowledged or engaged after the disclosure, and any escalation events where the person asked for a human.

A minimal schema looks like this:

CREATE TABLE disclosure_events (
  id BIGSERIAL PRIMARY KEY,
  session_id TEXT NOT NULL,
  channel TEXT NOT NULL CHECK (channel IN ('voice_inbound', 'voice_outbound', 'chat')),
  disclosure_version TEXT NOT NULL,
  disclosed_at TIMESTAMPTZ NOT NULL DEFAULT now(),
  acknowledged BOOLEAN,
  escalated_to_human BOOLEAN DEFAULT false,
  escalated_at TIMESTAMPTZ
);

And a logged event:

{
  "session_id": "chat_8f2a1c",
  "channel": "chat",
  "disclosure_version": "widget-header-v3",
  "disclosed_at": "2026-08-19T14:02:11Z",
  "acknowledged": true,
  "escalated_to_human": false
}

On retention: don’t invent a number for how long to keep these records. Align it with the data-retention policy you already run for the rest of your customer data — if you’re deleting chat transcripts and lead records after a defined window under GDPR, your disclosure log should follow the same cadence rather than living forever as an orphaned table nobody remembers to prune. Our GDPR guide for chat widgets covers the deletion and retention mechanics this log needs to plug into.

12345DisclosuredeliveredLog eventversiontimestampchannelsession idAcknowledge-mentEscalationeventRetentionpolicyprune
The audit trail: five events, logged in order, prove disclosure happened

Why text chat is a lighter lift than an AI phone number

Put voice and text side by side and the compliance gap is stark. No pretending every channel carries the same weight.

DimensionVoice (especially outbound)Text chat widget
Consent before contactTCPA prior express consent required — written for telemarketing under FCC rulesNone needed — visitor opened the widget themselves
Disclosure timingMust land in opening seconds, no way to review it laterCan persist as a visible label for the whole session
Extra exposureCall recording and biometric voice-data rules in some statesNone — it’s text, not biometric data
Audit trailNeeds new logging built specifically for callsChat transcripts you already keep do most of the work

Voice carries a consent regime, a real-time disclosure window with no do-over, and in some jurisdictions extra rules around recording and voice biometrics. Text carries none of that. The disclosure sits in the widget chrome, the transcript log you already keep for support and QA purposes doubles as your audit trail, and there’s no consent-before-contact problem because the visitor is the one who clicked to open the chat. Tooling follows the same split — in a hosted flow builder the disclosure step is a node on the vendor’s canvas rather than a string in your own config, which is one of the trade-offs our Voiceflow comparison works through.

This is exactly where a product like AI Chat Agent fits: not as a replacement for voice, but as the channel you reach for when you want the same “AI is doing the talking” value without inheriting the voice consent regime. It solves the same “let AI handle the first response” problem, minus the phone number, minus the TCPA exposure, minus the real-time audio disclosure window. If you’re currently routing a chunk of your ai phone call volume to a human team that’s really just answering the same handful of questions, moving that volume to chat, where the disclosure burden is this much lighter, is worth the look our call deflection guide walks through in detail.

4 layersNew call loggingRecording / biometric rulesReal-time audio disclosureConsent before contactVoice2 layersExisting transcript logsIn-widget disclosureChat
Compliance surface by channel: voice stacks four requirements, chat needs two

Owning the disclosure string

There’s a second, quieter argument for text chat over an artificial intelligence phone number, and it’s not about the legal regime — it’s about who controls the words.

When a rule changes — and this whole landscape has been changing every few months since the FCC’s 2024 ruling — you need to update your disclosure wording fast. If you’re running a SaaS call agent or chat platform, that means either the vendor ships the update on their timeline, or you’re stuck filing a feature request and waiting. Compliance deadlines don’t wait for a vendor’s product roadmap. The hosting model itself can move under you as well: Botpress retired self-hosting in favor of a cloud-only platform, a shift our Botpress comparison covers.

With a self-hosted setup where you hold the source code, that update is yours to make the day the rule changes. AI Chat Agent ships as proprietary, source-available software — not open source, but you get the full codebase under the license — deployed via Docker Compose on infrastructure you control. That means the disclosure string lives in your own widget config, the audit log lives in your own Postgres database, and none of it passes through a third party’s servers before it reaches you. For a compliance record you might need to produce on request, that’s a meaningfully different posture than trusting a vendor’s export tool and hoping their retention settings match yours.

It’s not a knock on hosted platforms generally — plenty of businesses are well served by them. But if disclosure wording and audit logs are things you expect to touch repeatedly as rules evolve, owning the string outright is worth weighing against a subscription. Our AI Chat Agent vs Intercom comparison lays out that self-hosted-versus-SaaS trade-off in more detail, including what changes about data location and update speed.

AI caller disclosure checklist

Use this as a working punch list, grouped by channel since the obligations diverge.

For voice (inbound and outbound):

  1. Confirm prior express consent is on file before any outbound AI voice call, in writing wherever the FCC rule applies to you
  2. Script the disclosure into the first 5-10 seconds of every call, inbound and outbound
  3. Build a spoken human-escalation phrase into the same opening turn as the disclosure
  4. Log call ID, disclosure version, and timestamp for every call, not a sample
  5. Track escalation requests separately so you can audit how often humans got pulled in

For chat:

  • Add a persistent “AI Assistant” label to the widget header, not a one-time popup
  • Put a plain-language AI disclosure in the first bot message, before any data collection
  • Write a direct answer for “are you a robot?” and similar variants into the bot’s instructions
  • Version your disclosure text and log which version each session saw
  • Align disclosure-log retention with your existing GDPR deletion policy, not a separate clock

Run this checklist before your next AI calling or chat rollout, and again any time you touch the disclosure wording itself — a version you can’t prove you delivered is functionally the same as no disclosure at all.

If your business is weighing whether to keep investing in AI voice compliance overhead or shift more of that first-response work to a channel with a lighter disclosure burden, take a look at the getagent.chat blog for more on both sides of that trade-off, try the live demo to see the disclosure label and escalation flow in action, or go straight to the EUR 79 one-time license to self-host it on your own infrastructure today.

Frequently asked questions

Do I legally have to tell people they’re talking to an AI?

In many cases yes, but the trigger depends on where you operate and what the bot is doing. The EU AI Act’s Article 50 transparency obligations became applicable on 2 August 2026 and require that a person be informed they are interacting with an AI system unless that is obvious from the context; California’s B.O.T. Act has required disclosure for commercial and electoral bots since 1 July 2019. This is a summary and not legal advice — confirm the rules for your own jurisdiction and use case with counsel before you ship a script.

When does the EU AI Act disclosure requirement apply?

Article 50’s transparency obligations for AI systems that interact directly with natural persons became applicable on 2 August 2026. They cover both channels, so an artificial intelligence phone number and a website chat widget carry the same underlying duty to inform. The only relief is the carve-out for cases obvious to a reasonably well-informed, observant and circumspect person, which is a standard a regulator argues about after the fact rather than one you declare for yourself in advance.

Does an AI phone call need to disclose that it’s AI in the US?

There is no finalized federal rule that says so outright. The FCC’s declaratory ruling of 8 February 2024 held that AI-generated voices count as an “artificial voice” under the TCPA, which pulls automated phone calling into the existing consent machinery, and the FCC’s follow-on AI-call disclosure rulemaking is still proposed rather than final. State law can require disclosure independently, so an AI caller working across state lines should assume the strictest standard that applies to it.

What should an AI disclosure actually say?

Use the words “AI” or “automated” rather than a softer phrase like “virtual assistant”, deliver it before you collect any personal data, and pair it with a way to reach a human in the same breath. A workable inbound line: “Thanks for calling [Company]. You’re speaking with an AI-powered call agent today. Say ‘agent’ anytime to reach a person.” Keep it short enough that someone mid-conversation can parse it in about two seconds.

Do AI chat widgets need the same disclosure as AI phone calls?

The underlying duty to inform is the same, but the mechanics and the surrounding burden are not. A chat widget satisfies “clear and conspicuous” with a persistent “AI Assistant” label plus a disclosure in the first bot message, and because the visitor opened the widget there is no consent-before-contact problem to solve. Voice gets one shot in the opening seconds, with no way for the listener to scroll back and catch what they missed.

How do I prove I disclosed?

Log it as a structured event rather than a note buried in a transcript: the disclosure version actually delivered, a timestamp, the channel, a session or call ID, and any escalation to a human. Version the wording so you can show exactly which string a given session saw when the copy or the rule changes. Align retention of that log with the data-retention policy you already run for customer records instead of letting it live forever as an orphaned table.