Do You Have to Disclose AI to Customers?
A balanced, honest look at when you have to disclose AI to customers, what the emerging laws say, and how to word disclosure so it builds trust instead of eroding it.
In short
Sometimes you legally have to disclose AI, and almost always you should. A growing set of laws requires telling people when a bot — not a human — is calling, chatting, or messaging them, and some regulated industries and platforms add their own rules on top. Even where no law applies, hiding AI is a trust risk: customers forgive a bot they were told about and feel deceived when they find out later. The safe, simple standard is to identify AI clearly and early, keep a human reachable, and match the wording to the channel. This article explains where disclosure is required, where it is merely wise, and how to say it well — and it is general information, not legal advice.
Key takeaways
- Disclosure is legally required in a growing number of situations — treat "tell people it is AI" as the default and hiding it as the exception you have to justify.
- Several jurisdictions have bot-disclosure laws — California-style rules, for example, target undisclosed bots used to sell or influence, and more regions are following.
- Phone, chat, SMS, and email each carry their own expectations — AI voice calls face the strictest scrutiny, while a labeled chat widget is usually low-risk.
- Disclosure done well builds trust rather than costing you sales — customers accept AI they were told about and resent AI they discovered.
- Regulated fields like healthcare, finance, and legal — plus platform and telemarketing rules — layer extra obligations on top, so check your industry and region.
Picture a customer who has just spent ten minutes in a warm, helpful conversation with "Sarah" from your support team — only to realize halfway through that Sarah is software. For some people that is a shrug. For others it is the moment they stop trusting you. That small experience sits at the center of a question more and more businesses are asking as they automate: do you have to disclose AI to customers, and if so, when?
The honest answer has two layers. There is what the law requires, which is a patchwork that is expanding fast, and there is what good practice suggests, which is broader and simpler than any statute. This guide walks through both, balanced rather than alarmist, so you can make a confident call for your own business. One thing to say up front and to keep in mind throughout: this is general information, not legal advice, and the rules differ by country, state, and industry.
Do you legally have to disclose AI?
There is no single worldwide law that says "always tell people it is AI." Instead there is a growing collection of rules that apply in specific situations — and the direction is unmistakably toward more disclosure, not less.
Broadly, three forces are pushing in the same direction. First, dedicated bot-disclosure laws target the use of automated accounts to influence people. Second, general consumer-protection law can treat a concealed bot as a deceptive or unfair practice, even with no AI-specific statute on the books. Third, broad transparency principles — most visibly in Europe's approach to regulating AI — lean toward telling people when they are interacting with an AI system unless it is already obvious.
Put together, these mean the safe default is to disclose. The circumstances where you can reasonably skip it — a clearly labeled website chat bubble, an internal tool, an AI that merely drafts messages a human then approves — are real but shrinking. If you are automating conversations that sell, persuade, or stand in for a person, assume disclosure is expected.
What do the emerging bot-disclosure laws say?
The clearest example is the wave of California-style bot laws. In general terms, these make it unlawful to use an undisclosed bot to communicate with someone in order to incentivize a purchase or influence how they vote, where the remedy is a clear and conspicuous disclosure that the person is dealing with an automated account rather than a human. The principle is narrow and specific: it is not that bots are banned, it is that hiding a bot to influence someone is.
Europe's approach is broader. Rather than targeting one behavior, it leans on a transparency principle — people should generally be informed when they are interacting with an AI system, unless that fact is already plainly obvious from the context. The details are still settling, and enforcement will shape what "obvious" means in practice, but the underlying expectation is the same: no pretending software is a person.
Layered on top are older rules that were not written for AI but now catch it. Telemarketing and robocall regulations already govern automated and pre-recorded voice calls in many places, and AI-generated voices are increasingly pulled under those same consent and identification requirements. The takeaway is not to memorize any single statute — those change — but to recognize the shared logic running through all of them. When AI acts like a human toward a customer, especially to sell or to call, disclosure is where the law is heading.
When is disclosure required?
Requirements cluster around a few high-risk patterns. Disclosure is most clearly expected when AI is doing outbound, persuasive, or automated-call work — the situations where a person could be misled in a way that costs them money or a decision. It is least demanded when the AI's role is obvious, minor, or human-supervised.
The channel you use changes the expectation more than almost anything else, so it helps to see them side by side.
| Channel | Disclosure needed? | Example line |
|---|---|---|
| AI voice call (outbound) | Yes — highest scrutiny, plus consent rules | "Hi, this is an AI assistant calling on behalf of Bright Dental — is now a good time?" |
| AI voice call (inbound) | Recommended, often expected | "You've reached Bright Dental's virtual assistant. I can book appointments or connect you to the team." |
| Website chat widget | Usually yes, but low-risk and easy | "Hi! I'm an AI assistant. I can help right away, or connect you to a person any time." |
| SMS / text (conversational) | Yes when it persuades or poses as a person | "This is the AI assistant for Bright Dental. Reply HUMAN to reach our team." |
| Email (service or drafting) | Usually not, unless posing as a named human | "Sent by Bright Dental's automated assistant." |
| Human-reviewed drafts | Generally not required | (No AI label needed when a person approves each message.) |
Read the table as a spectrum. The top rows — live AI voices and persuasive automated messages — are where laws and expectations bite hardest. The bottom rows — labeled widgets, honest service emails, human-approved drafts — are where a light touch is fine. When you are unsure which row you are in, move up a level and disclose.
When is disclosure just good practice?
Most of the time you are not in a courtroom edge case — you are simply deciding how to treat people. And here the standard is easy: never let a customer believe they are talking to a human when they are not.
The reason is trust, and trust behaves asymmetrically. Tell someone up front that they are chatting with an AI, and they adjust — they phrase things more simply, they judge the bot on speed and helpfulness, and they are forgiving when it hands off to a person. Let them discover it afterward, and the helpfulness evaporates behind the feeling of having been fooled. The deception, not the automation, is what does the damage. This is the same trust logic that runs through any good how to use AI for customer service program.
Good practice also means never dressing a bot up as a specific named employee — a stock photo and a human first name with no hint of automation is the exact pattern that generates complaints. It means always offering an easy route to a real person. And it means being honest about what the AI can and cannot do rather than letting it bluff. Follow those and you sit comfortably ahead of nearly every current and likely-future law, which is a far cheaper place to be than catching up after a complaint.
There is also a quieter commercial reason to disclose that has nothing to do with law or ethics. Customers who know they are talking to AI use it better — they ask direct questions, skip the small talk, and reach an answer faster — which means a disclosed bot often outperforms a hidden one on the metrics you actually care about. Concealment, by contrast, invites the exact behavior that breaks bots, as people test whether "the agent" is real instead of getting help. Transparency is not just the safe choice, it is frequently the higher-performing one.
How do you disclose AI well?
Disclosure fails when it is buried, and it succeeds when it is early, plain, and paired with an exit. A few principles cover most situations.
Say it first, not last. The disclosure belongs in the opening of a call or chat, not in a footer or a policy nobody reads. For a voice agent, it goes in the first breath.
Keep it human and short. A friendly one-liner beats a legal paragraph. You want the customer to understand, not to skim past a wall of terms.
Always offer a person. "I can connect you to someone any time" turns disclosure from a warning into a reassurance, and it is also the single feature customers most want from a bot.
Match the tone to your brand. The disclosure is part of the experience, so write it in the same voice as the rest of your customer communication rather than a stiff compliance sentence.
A few sample lines you can adapt: for chat, "Hi! I'm an AI assistant — I can help right away, or connect you with a team member whenever you'd like." For a voice agent, "Hi, this is a virtual assistant calling on behalf of [Business] — I can help you reschedule, and I'll hand you to a person if you need one." For SMS, "This is [Business]'s AI assistant. Reply HUMAN any time to reach our team." Each one names the AI, sets expectations, and offers a way out — which is the whole job.
One more habit is worth building in: disclose once, clearly, and then get out of the way. Repeating "as an AI, I..." at the top of every message is annoying and actually undermines the experience, so make the identification obvious at the start and let the conversation feel natural after that. The goal is informed customers, not a running disclaimer. Set the expectation early, keep the human handoff visible, and trust the customer to remember what they are talking to.
Where do stricter rules apply?
Some contexts raise the bar. Regulated industries — healthcare, finance, legal, insurance — layer their own obligations on top of general disclosure, because the cost of a confident wrong answer is high. In these fields an AI should offer general information and route anything specific to a qualified human, and disclosure is only part of a wider duty of care. If you are building automation in one of these sectors, or standing up a new setup like an AI receptionist, assume the requirements are heavier than average.
Two other layers catch people out. Platform rules — the terms of the messaging, social, and ad platforms you use — often have their own automation and bot-disclosure requirements independent of any law. And telemarketing rules make outbound AI calling one of the most tightly governed things you can do, with consent and identification requirements that predate AI and now extend to it. Verticals that live on the phone, and the AI-automation agencies that build for them, feel this most.
The tooling side is simpler than the legal side. Most modern customer-conversation platforms let you configure a disclosure directly into your AI flows — for example, platforms like GoHighLevel let you add an AI-identification line to the start of automated chats and messages so it fires consistently on every conversation. That turns "remember to disclose" into a setting rather than a habit, which is exactly how it should work.
Getting it right without overthinking it
Strip away the detail and the answer to "do you have to disclose AI to customers" is short. Sometimes the law requires it, especially for voice calls and persuasive automated messaging, and those requirements are expanding. Almost always, good practice recommends it, because transparency protects the trust that is far harder to rebuild than it is to keep. Disclose early, keep it plain, always offer a human, and never let a bot impersonate a specific person, and you will clear both bars at once.
If you would rather not assemble the disclosure logic, escalation paths, and channel wording yourself, that is the kind of thing worth handing to people who set it up every day. You can explore our pricing or book a call to talk through a compliant, trust-first setup — and if you want the wider context, the SaaS, automation and scaling hub collects the rest of the picture. Whatever you choose, remember the one caveat that runs through all of this: it is general information, not legal advice, so confirm the specifics for your industry and region before you rely on any rule here.
Frequently asked questions
Do you legally have to disclose AI to customers?
What do bot-disclosure laws actually require?
Do I have to disclose AI on phone calls?
Do I have to disclose AI in a chat widget?
Do I have to disclose AI in emails and text messages?
Does disclosing AI hurt trust or conversions?
How should I actually word an AI disclosure?
Which industries have stricter AI disclosure rules?
What are the penalties for not disclosing AI?
What is the best-practice standard even where no law requires disclosure?
Do I need to disclose AI if a human reviews everything before it sends?
Is this legal advice?
About the author

Founder, GHL Spark
Farhad is the founder of GHL Spark, where he builds and white-labels GoHighLevel SaaS platforms for agencies and SaaS operators. He writes about the parts of GoHighLevel that actually break in production — A2P registration, onboarding, support load and automation.
More from Farhad