AI & Automation9 min read

Do You Have to Disclose AI to Customers?

A balanced, honest look at when you have to disclose AI to customers, what the emerging laws say, and how to word disclosure so it builds trust instead of eroding it.

Farhad, founder of GHL Spark
Farhad · Founder, GHL Spark
Cover illustration — a teal node-and-link network on a dark green background, marked GHL Spark, AI and Automation

In short

Sometimes you legally have to disclose AI, and almost always you should. A growing set of laws requires telling people when a bot — not a human — is calling, chatting, or messaging them, and some regulated industries and platforms add their own rules on top. Even where no law applies, hiding AI is a trust risk: customers forgive a bot they were told about and feel deceived when they find out later. The safe, simple standard is to identify AI clearly and early, keep a human reachable, and match the wording to the channel. This article explains where disclosure is required, where it is merely wise, and how to say it well — and it is general information, not legal advice.

Key takeaways

  • Disclosure is legally required in a growing number of situations — treat "tell people it is AI" as the default and hiding it as the exception you have to justify.
  • Several jurisdictions have bot-disclosure laws — California-style rules, for example, target undisclosed bots used to sell or influence, and more regions are following.
  • Phone, chat, SMS, and email each carry their own expectations — AI voice calls face the strictest scrutiny, while a labeled chat widget is usually low-risk.
  • Disclosure done well builds trust rather than costing you sales — customers accept AI they were told about and resent AI they discovered.
  • Regulated fields like healthcare, finance, and legal — plus platform and telemarketing rules — layer extra obligations on top, so check your industry and region.

Picture a customer who has just spent ten minutes in a warm, helpful conversation with "Sarah" from your support team — only to realize halfway through that Sarah is software. For some people that is a shrug. For others it is the moment they stop trusting you. That small experience sits at the center of a question more and more businesses are asking as they automate: do you have to disclose AI to customers, and if so, when?

The honest answer has two layers. There is what the law requires, which is a patchwork that is expanding fast, and there is what good practice suggests, which is broader and simpler than any statute. This guide walks through both, balanced rather than alarmist, so you can make a confident call for your own business. One thing to say up front and to keep in mind throughout: this is general information, not legal advice, and the rules differ by country, state, and industry.

Do you legally have to disclose AI?

There is no single worldwide law that says "always tell people it is AI." Instead there is a growing collection of rules that apply in specific situations — and the direction is unmistakably toward more disclosure, not less.

Broadly, three forces are pushing in the same direction. First, dedicated bot-disclosure laws target the use of automated accounts to influence people. Second, general consumer-protection law can treat a concealed bot as a deceptive or unfair practice, even with no AI-specific statute on the books. Third, broad transparency principles — most visibly in Europe's approach to regulating AI — lean toward telling people when they are interacting with an AI system unless it is already obvious.

Put together, these mean the safe default is to disclose. The circumstances where you can reasonably skip it — a clearly labeled website chat bubble, an internal tool, an AI that merely drafts messages a human then approves — are real but shrinking. If you are automating conversations that sell, persuade, or stand in for a person, assume disclosure is expected.

What do the emerging bot-disclosure laws say?

The clearest example is the wave of California-style bot laws. In general terms, these make it unlawful to use an undisclosed bot to communicate with someone in order to incentivize a purchase or influence how they vote, where the remedy is a clear and conspicuous disclosure that the person is dealing with an automated account rather than a human. The principle is narrow and specific: it is not that bots are banned, it is that hiding a bot to influence someone is.

Europe's approach is broader. Rather than targeting one behavior, it leans on a transparency principle — people should generally be informed when they are interacting with an AI system, unless that fact is already plainly obvious from the context. The details are still settling, and enforcement will shape what "obvious" means in practice, but the underlying expectation is the same: no pretending software is a person.

Layered on top are older rules that were not written for AI but now catch it. Telemarketing and robocall regulations already govern automated and pre-recorded voice calls in many places, and AI-generated voices are increasingly pulled under those same consent and identification requirements. The takeaway is not to memorize any single statute — those change — but to recognize the shared logic running through all of them. When AI acts like a human toward a customer, especially to sell or to call, disclosure is where the law is heading.

When is disclosure required?

Requirements cluster around a few high-risk patterns. Disclosure is most clearly expected when AI is doing outbound, persuasive, or automated-call work — the situations where a person could be misled in a way that costs them money or a decision. It is least demanded when the AI's role is obvious, minor, or human-supervised.

The channel you use changes the expectation more than almost anything else, so it helps to see them side by side.

ChannelDisclosure needed?Example line
AI voice call (outbound)Yes — highest scrutiny, plus consent rules"Hi, this is an AI assistant calling on behalf of Bright Dental — is now a good time?"
AI voice call (inbound)Recommended, often expected"You've reached Bright Dental's virtual assistant. I can book appointments or connect you to the team."
Website chat widgetUsually yes, but low-risk and easy"Hi! I'm an AI assistant. I can help right away, or connect you to a person any time."
SMS / text (conversational)Yes when it persuades or poses as a person"This is the AI assistant for Bright Dental. Reply HUMAN to reach our team."
Email (service or drafting)Usually not, unless posing as a named human"Sent by Bright Dental's automated assistant."
Human-reviewed draftsGenerally not required(No AI label needed when a person approves each message.)

Read the table as a spectrum. The top rows — live AI voices and persuasive automated messages — are where laws and expectations bite hardest. The bottom rows — labeled widgets, honest service emails, human-approved drafts — are where a light touch is fine. When you are unsure which row you are in, move up a level and disclose.

When is disclosure just good practice?

Most of the time you are not in a courtroom edge case — you are simply deciding how to treat people. And here the standard is easy: never let a customer believe they are talking to a human when they are not.

The reason is trust, and trust behaves asymmetrically. Tell someone up front that they are chatting with an AI, and they adjust — they phrase things more simply, they judge the bot on speed and helpfulness, and they are forgiving when it hands off to a person. Let them discover it afterward, and the helpfulness evaporates behind the feeling of having been fooled. The deception, not the automation, is what does the damage. This is the same trust logic that runs through any good how to use AI for customer service program.

Good practice also means never dressing a bot up as a specific named employee — a stock photo and a human first name with no hint of automation is the exact pattern that generates complaints. It means always offering an easy route to a real person. And it means being honest about what the AI can and cannot do rather than letting it bluff. Follow those and you sit comfortably ahead of nearly every current and likely-future law, which is a far cheaper place to be than catching up after a complaint.

There is also a quieter commercial reason to disclose that has nothing to do with law or ethics. Customers who know they are talking to AI use it better — they ask direct questions, skip the small talk, and reach an answer faster — which means a disclosed bot often outperforms a hidden one on the metrics you actually care about. Concealment, by contrast, invites the exact behavior that breaks bots, as people test whether "the agent" is real instead of getting help. Transparency is not just the safe choice, it is frequently the higher-performing one.

How do you disclose AI well?

Disclosure fails when it is buried, and it succeeds when it is early, plain, and paired with an exit. A few principles cover most situations.

Say it first, not last. The disclosure belongs in the opening of a call or chat, not in a footer or a policy nobody reads. For a voice agent, it goes in the first breath.

Keep it human and short. A friendly one-liner beats a legal paragraph. You want the customer to understand, not to skim past a wall of terms.

Always offer a person. "I can connect you to someone any time" turns disclosure from a warning into a reassurance, and it is also the single feature customers most want from a bot.

Match the tone to your brand. The disclosure is part of the experience, so write it in the same voice as the rest of your customer communication rather than a stiff compliance sentence.

A few sample lines you can adapt: for chat, "Hi! I'm an AI assistant — I can help right away, or connect you with a team member whenever you'd like." For a voice agent, "Hi, this is a virtual assistant calling on behalf of [Business] — I can help you reschedule, and I'll hand you to a person if you need one." For SMS, "This is [Business]'s AI assistant. Reply HUMAN any time to reach our team." Each one names the AI, sets expectations, and offers a way out — which is the whole job.

One more habit is worth building in: disclose once, clearly, and then get out of the way. Repeating "as an AI, I..." at the top of every message is annoying and actually undermines the experience, so make the identification obvious at the start and let the conversation feel natural after that. The goal is informed customers, not a running disclaimer. Set the expectation early, keep the human handoff visible, and trust the customer to remember what they are talking to.

Where do stricter rules apply?

Some contexts raise the bar. Regulated industries — healthcare, finance, legal, insurance — layer their own obligations on top of general disclosure, because the cost of a confident wrong answer is high. In these fields an AI should offer general information and route anything specific to a qualified human, and disclosure is only part of a wider duty of care. If you are building automation in one of these sectors, or standing up a new setup like an AI receptionist, assume the requirements are heavier than average.

Two other layers catch people out. Platform rules — the terms of the messaging, social, and ad platforms you use — often have their own automation and bot-disclosure requirements independent of any law. And telemarketing rules make outbound AI calling one of the most tightly governed things you can do, with consent and identification requirements that predate AI and now extend to it. Verticals that live on the phone, and the AI-automation agencies that build for them, feel this most.

The tooling side is simpler than the legal side. Most modern customer-conversation platforms let you configure a disclosure directly into your AI flows — for example, platforms like GoHighLevel let you add an AI-identification line to the start of automated chats and messages so it fires consistently on every conversation. That turns "remember to disclose" into a setting rather than a habit, which is exactly how it should work.

Getting it right without overthinking it

Strip away the detail and the answer to "do you have to disclose AI to customers" is short. Sometimes the law requires it, especially for voice calls and persuasive automated messaging, and those requirements are expanding. Almost always, good practice recommends it, because transparency protects the trust that is far harder to rebuild than it is to keep. Disclose early, keep it plain, always offer a human, and never let a bot impersonate a specific person, and you will clear both bars at once.

If you would rather not assemble the disclosure logic, escalation paths, and channel wording yourself, that is the kind of thing worth handing to people who set it up every day. You can explore our pricing or book a call to talk through a compliant, trust-first setup — and if you want the wider context, the SaaS, automation and scaling hub collects the rest of the picture. Whatever you choose, remember the one caveat that runs through all of this: it is general information, not legal advice, so confirm the specifics for your industry and region before you rely on any rule here.

Frequently asked questions

Do you legally have to disclose AI to customers?
Sometimes yes, and increasingly often. There is no single global rule, so it depends on where you operate, what industry you are in, and how you are using the AI. A number of jurisdictions now require disclosure when a bot interacts with people in specific contexts — particularly selling, political messaging, and automated calls — and consumer-protection law can treat a concealed bot as a deceptive practice even where no AI-specific statute exists. The practical answer is that the safe default is to disclose, and the situations where you can quietly skip it are narrowing every year. This is general information, not legal advice, so confirm the rules for your own region and sector.
What do bot-disclosure laws actually require?
Most bot-disclosure laws share a simple idea — a business should not use an automated account to pretend to be a real person in order to influence someone. California-style bot laws, for instance, generally make it unlawful to use an undisclosed bot to incentivize a purchase or influence a vote, with the fix being a clear, conspicuous disclosure that the person is dealing with a bot. The European approach under its AI rules leans toward a broad transparency principle — people should be told when they are interacting with an AI system unless it is already obvious. The specifics vary, but the common thread is disclosure that a reasonable person would actually notice. Treat these as examples of a direction of travel rather than a complete list, and this is general information rather than legal advice.
Do I have to disclose AI on phone calls?
Phone is the highest-scrutiny channel, so this is where you should be most careful. AI voice agents can sound convincingly human, which is exactly why regulators pay attention — synthetic and pre-recorded voices in calls are already governed by telemarketing and robocall rules in many places, and AI-generated voices are increasingly pulled under those same requirements alongside consent rules. If your AI is making outbound calls, assume you need clear consent and a prompt, plain identification that the caller is an automated or AI assistant. On inbound calls the risk is lower but the courtesy still matters. This is general information, not legal advice, and telecom rules are strict, so verify before you dial.
Do I have to disclose AI in a chat widget?
A web chat widget is usually the lowest-risk channel, and it is also the easiest to label. Because customers increasingly expect the little bubble on a website to be a bot, a short line naming it as an AI assistant at the start of the conversation typically satisfies both expectation and any applicable transparency rule. The main mistake is designing the bot to imply it is a named human employee — giving it a person's photo and first name with no indication it is automated is the pattern that invites deception complaints. Name it clearly, offer a route to a human, and you are on safe ground for most everyday use. This is general information rather than legal advice.
Do I have to disclose AI in emails and text messages?
For everyday service messages, an AI that drafts or sends email and SMS on your behalf is generally treated like any other business message, and heavy-handed "this was written by AI" labels are not usually required. The obligations that bite are the existing ones — consent to message, honest content, and a working opt-out — and those apply whether a human or an AI composed the text. Where you should disclose is when the AI is presented as a specific human it is not, or when it is doing automated selling or political outreach that a bot-disclosure law covers. Keep the messages honest and consented, and add a clear AI note when the interaction is conversational or persuasive. This is general information, not legal advice.
Does disclosing AI hurt trust or conversions?
The evidence and experience point the other way — hiding it is what damages trust. Customers routinely accept a bot they were told about, especially when it is fast and helpful and offers an easy path to a person, and they feel genuinely deceived when they discover after the fact that the friendly "agent" was software. That sense of being tricked does far more damage to your brand than a one-line disclosure ever could. Framed well, disclosure can even help — people relax when they know what they are dealing with and adjust their expectations accordingly. Treat transparency as a trust feature, not a tax on conversions.
How should I actually word an AI disclosure?
Keep it short, plain, and early, and pair it with a way to reach a human. A good disclosure names the assistant as AI, sets a friendly tone, and does not bury the fact in legalese or a footer nobody reads. For chat you might open with a line that says you are an AI assistant and can connect the customer to a person any time. For a voice agent, say it in the first breath — that you are a virtual or AI assistant calling on behalf of the business. The test is simple: would a reasonable person come away clearly understanding they were dealing with AI. If yes, you have done it well.
Which industries have stricter AI disclosure rules?
Regulated fields carry the heaviest obligations. Healthcare adds patient-privacy and medical-advice constraints, financial services layer on rules about advice and fair dealing, and legal services worry about unauthorized advice — in all of these an AI should give general information and hand specific decisions to a qualified human. Sectors that do outbound calling or texting, like insurance and lending, also sit under telemarketing rules that tighten as AI voices enter the mix. If you operate in a licensed or regulated industry, assume the bar for disclosure and human oversight is higher, and check your specific regulator. This is general information and not a substitute for advice tailored to your field.
What are the penalties for not disclosing AI?
They vary a lot by law and location, but the exposure is real. Bot-disclosure and consumer-protection statutes can carry fines, and deceptive-practice findings can bring regulatory action and civil claims, while telemarketing violations for improper automated calls are among the more expensive because penalties can stack per call or message. Beyond formal penalties there is the reputational cost — a public story about a business secretly using bots to pose as people does lasting brand damage. The cost of a clear disclosure is essentially zero, which makes non-disclosure a poor trade. Since penalties and enforcement differ by jurisdiction, treat this as general information and confirm your own exposure.
What is the best-practice standard even where no law requires disclosure?
Adopt a simple house rule — never let a customer believe they are talking to a human when they are not. In practice that means identifying AI clearly and early on any conversational channel, never dressing a bot up as a specific named employee, always offering an easy path to a real person, and being honest about what the AI can and cannot do. This standard keeps you comfortably ahead of most current and likely-future laws, and it protects the thing that is hardest to rebuild once lost, which is customer trust. Build disclosure in from the start rather than bolting it on after a complaint.
Do I need to disclose AI if a human reviews everything before it sends?
When a person genuinely writes, reviews, and approves each message before it goes out, the interaction is meaningfully human-led, and heavy AI labeling is generally not expected for that kind of assisted drafting. The line to watch is autonomy — the more the AI is conversing, deciding, or persuading on its own in real time, the more a clear disclosure matters. A human spell-checking an AI draft is different from an AI holding a live sales conversation unsupervised. Match your disclosure to how much the AI is actually acting on its own, and when unsure, lean toward telling people. This is general information, not legal advice.
Is this legal advice?
No. This article is general information to help you think through when and how to disclose AI, and it deliberately describes laws in broad terms because the details change quickly and differ by country, state, and industry. It is not a substitute for advice from a qualified lawyer who knows your specific situation, and it should not be relied on as a compliance checklist. If disclosure carries real stakes for your business — regulated industry, outbound calling, large-scale messaging — get tailored legal advice before you rely on any general rule. Use this to ask better questions, not to answer the legal ones for yourself.

About the author

Farhad, founder of GHL Spark

Farhad

Founder, GHL Spark

Farhad is the founder of GHL Spark, where he builds and white-labels GoHighLevel SaaS platforms for agencies and SaaS operators. He writes about the parts of GoHighLevel that actually break in production — A2P registration, onboarding, support load and automation.

More from Farhad

Want this handled for you?

We set up, configure and white-label your GoHighLevel SaaS — so you can sell it instead of building it.

Fixed quote · No lock-in · Launch-ready in ~7 days