AI Chatbot Disclosure Requirements: EU and US Rules 2026

Bryce DeCora Avatar

TL;DR

  • Article 50 of the EU AI Act became enforceable on 2 August 2026. The Digital Omnibus delayed the high-risk rules to December 2027. It did not delay this one.
  • It applies if your bot messages anyone in the EU, no matter where your company sits.
  • US agencies are not exempt. California, Maine, New Jersey, Utah, Colorado, and the FTC Act already impose AI chatbot disclosure requirements on commercial bots.
  • For a text bot, one rule matters: the person has to know they’re talking to AI, no later than the first message.
  • There is no required wording. “Hi, this is Sarah, Vertex Realty’s AI assistant” is enough. “Virtual assistant” is not.
  • Most of the fix is one line in your GoHighLevel or HubSpot workflow template, not in CloseBot.
  • EU fines reach €15M or 3% of global turnover. For SMEs, it’s whichever is lower, not higher.

Your AI Bot Now Has to Introduce Itself. Here’s Exactly What It Has to Say

A lead in Dublin fills out your form at 11:07pm. Your automation fires, a text goes out, and by the time you open your laptop the next morning she’s qualified, booked, and sitting on Thursday’s calendar.

It’s not a rare anymore for those who are accustomed to using CloseBot for sales. 1.1 million appointments booked through CloseBot shows this is the new normal. World governments see that and are beginning to put regulations in place.

As of four days ago, that same conversation carries a compliance problem, because at no point did anyone tell this lead she was texting a machine. The AI chatbot disclosure requirements in Article 50 of the EU AI Act became enforceable on 2 August 2026, and if you’re reading this from the US thinking it doesn’t reach you, California, Maine, and New Jersey got there first (more on that below).

The good news, and I want to say this before anything else: for most of you this is a one-line fix in a message template, and it probably won’t cost you a single booking. But it does have to actually get done, and the deadline has already passed.

“Wait, wasn’t the AI Act delayed?”

Half the agency world thinks it was, so let’s clear this up first.

In June, EU legislators agreed to the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744. It pushed back the high-risk obligations, the heavy conformity-assessment regime, by more than a year.

DateWhat happened
2 Feb 2025Prohibited practices (Article 5) and AI literacy (Article 4) applied
2 Aug 2025Penalties and governance applied
2 Aug 2026Article 50 transparency became enforceable. National regulators got investigation powers.
2 Dec 2026Grace period ends for machine-readable marking on pre-existing generative systems
2 Dec 2027High-risk obligations (deferred from Aug 2026)
2 Aug 2028High-risk AI embedded in regulated products

If you relaxed in June because the AI Act “got pushed,” you relaxed about a different section of the law than the one that governs your chatbot.

conversational ai article 50

Does this actually apply to me?

Article 2 of the AI Act reaches companies outside the EU in two ways. It covers providers (like marketing agencies) placing AI systems on the EU market “irrespective of whether those providers are established or located within the Union or in a third country,” and it covers providers and deployers located in a third country “where the output produced by the AI system is used in the Union.”

That second clause is the one that catches agencies. Strip the legalese and you get a rule that’s easy to hold onto:

It follows the person, not the company.

Four scenarios:

  • You’re a US agency with US clients, and a lead fills out a form while visiting Lisbon. In scope for that conversation. Your server location, your incorporation, your client’s location. None of it saves you. The output landed on a person in the EU.
  • You’re a US agency with a client in Germany. In scope.
  • You’re an agency in Ireland, Spain, or Poland. In scope, obviously.
  • You have genuinely zero EU contacts. Out of scope for the EU AI Act, right up until one EU lead comes through, which for anyone running paid traffic is a matter of when. But out of scope here does not mean unregulated, because California, Maine, New Jersey, Utah, Colorado, and the FTC Act may still reach you. That’s the next section.

Most US agencies reading this are in the second category without knowing it, because they’ve never audited where their contacts actually are.

Do US chatbot laws apply even if you never touch an EU lead?

Yes. California, Maine, New Jersey, Utah, Colorado, and the FTC Act all impose AI chatbot disclosure requirements on commercial bots, independent of the EU AI Act. Maine’s has been enforceable since September 2025 and New Jersey’s names real estate explicitly. The same one-line disclosure satisfies all of them.

The EU has the biggest number attached to it, so it gets the headlines. But it was not first, and for a US agency it is usually not the nearer risk.

LawIn forceWhat triggers it
California SB 1001 (B.O.T. Act)1 Jul 2019Using a bot in a commercial transaction with intent to mislead about its artificial identity. Clear and conspicuous disclosure is an explicit safe harbor.
Maine Chatbot Disclosure Act24 Sep 2025The broadest of the set. Any chatbot in trade or commerce where a reasonable consumer could not tell the difference.
New JerseyIn forceBot communication in the sale or advertising of merchandise or real estate. Disclosure required at the start of the interaction.
Utah SB 226In forceGenerative AI in consumer transactions: disclose if the consumer asks. Healthcare, finance, and legal: disclose prominently at the start.
ColoradoIn forceHigh-risk AI in consequential decisions covering employment, finance, healthcare, housing, insurance, and legal services.
FTC ActNationwideThe deception baseline. Applies to every US chatbot in every state.

Two of these deserve a closer look if you run agency campaigns.

New Jersey names real estate explicitly. If you or your clients run lead-gen for realtors, investors, or property services, that is the statute describing your exact use case.

Maine is enforced under its Unfair Trade Practices Act, which carries a limited private right of action. Most compliance risk in this space is regulator-driven, and regulators are slow and under-resourced. A private right of action means a plaintiff’s lawyer can bring the claim instead, and they are neither.

Here is the part that should make this easy. Every one of these laws, plus Article 50, is satisfied by the same thing: telling the person, clearly, at the start, that they are talking to AI. There is no version of this where you write different openers for different states. You write one good disclosure and it covers the entire map.

Good news: text-only means one rule instead of four

Article 50 has four transparency obligations stacked inside it, and most coverage treats them as one giant blob. For a text-based lead qualification bot, three of the four don’t apply at all. Worth walking through, because it shrinks the problem dramatically.

Article 50(2): machine-readable marking of synthetic content. This is the watermarking rule, and it’s aimed at systems generating synthetic content for publication and distribution. The prevailing reading is that a conversational exchange with one lead engages 50(1), not 50(2). It isn’t a fully settled question, but note where the obligation sits even if it did apply: on providers of the generative system, not on the agency running a bot. Either way it isn’t your build.

Article 50(3): emotion recognition and biometric categorization. CloseBot does neither. Not applicable.

Article 50(4): deepfakes. Requires generated image, audio, or video. A text bot produces none. Not applicable.

Article 50(4): AI-generated text on matters of public interest. This one trips people up because it mentions text. But the trigger is text published to inform the public on a matter of public interest. A sales SMS to one lead about a kitchen remodel is not that. Not applicable.

There’s no voice component here either, which sidesteps the entire voice-agent disclosure debate playing out elsewhere.

So for a CloseBot deployment, Article 50(1) is essentially your whole compliance surface.

AI chatbot disclosure requirements: the three tests your wording must pass

No law prescribes exact disclosure wording. Article 50 requires only that the person be informed they are interacting with an AI system, clearly, no later than the first message. Any sentence passing three tests complies:

  • it uses the word AI or automated
  • it attaches to this conversation
  • it arrives no later than the first message

Article 50(1) requires that the person be informed that they are interacting with an AI system. Article 50(5) adds that the information must be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” and must conform to accessibility requirements.

That’s it. You do not have to write “an AI will be responding to your inquiry.” You can, and it would comply. It’s just clunkier than it needs to be and reads like a legal notice bolted onto your opener.

What your disclosure does have to do is pass three tests.

1. It has to be clear. The words “AI” or “automated” need to appear. This is where most attempts fail, and they fail on a specific word: virtual assistant. That term has meant a human being in another country for twenty years. Same for “smart assistant” and “digital assistant.” Both describe plenty of software that isn’t AI, and neither tells a lead what they need to know. The European Commission’s guidelines on transparency obligations, adopted 20 July 2026, read the “it was obvious” exemption narrowly, so a term your lead might reasonably read as human won’t carry you.

2. It has to attach to this conversation. A line on your About page saying your company uses AI does nothing for the person receiving a text. The Commission is explicit that disclosure buried in terms and conditions, privacy policies, or fine print doesn’t count. It has to be perceivable in the interaction itself, without special tools.

3. It has to arrive no later than the first message.

Here’s what that looks like in your actual channel:

Fails:

  • “Hi, this is Sarah from Vertex Realty. Is now a good time to chat?”
  • “You’re chatting with our smart assistant.”
  • AI mentioned only in the privacy policy you linked in the footer.

Passes:

  • “Hey Sarah here. I’m Vertex Realty’s automated assistant. Is now a good time to chat?”
  • “Quick heads up: I’m an AI assistant. I’m super smart, but a team member can jump in any time if you’d rather.”
ai assistant messaging for eu ai act

One more thing on timing. Once at the start is the baseline; you don’t need to repeat it every message. But if you’re running 30/60/90-day reactivation and a bot re-opens a conversation months later, treat that as a fresh first interaction and disclose again. A lead who forgot they ever filled out your form is, functionally, meeting your bot for the first time.

Where does the disclosure actually go?

It depends on who speaks first. If your CRM sends the opening message after a form fill, the disclosure belongs in that workflow template. If the lead messages you first, it belongs in your bot’s global instructions. If they open your web chat widget, it belongs in the widget’s welcome message. Most agencies only need the first one.

Here’s the part that surprises people. In the most common setup, CloseBot never sends the first message, so the disclosure doesn’t belong in CloseBot at all. That’s not a bad thing. That’s just how AI systems work. Read more about database reactivation setup and the first outbound message here.

CloseBot has no forms and doesn’t initiate outbound. A lead fills out your form, your GoHighLevel or HubSpot workflow sends the first text, and CloseBot takes over from the reply onward. Which means the disclosure obligation lands on you, in your CRM.

Three scenarios, three different places the wording lives:

Who speaks firstFirst AI interaction isWhere the disclosure goes
You do (form fill triggers outbound SMS or email)Your own workflow messageYour GHL/HubSpot message template
The lead does (inbound SMS, Messenger, Instagram DM, WhatsApp)CloseBot’s first replyJob Flow Settings → global instructions
The lead opens your web chat widgetThe widget greetingChat Widget → Chat Settings → Welcome Message

Scenario one is the big one, and it’s a CRM change, not a CloseBot change. Open the workflow that sends your first touch, edit the template, add three words. Done. If you’re running the same opener across thirty sub-accounts, that’s thirty edits, and there’s no shortcut, but each one takes about fifteen seconds.

Scenario two is where CloseBot matters. When a lead texts your tracking number or DMs your Facebook page cold, CloseBot’s reply is the first AI interaction. Put the disclosure in your Job Flow Settings global instructions rather than in a single node, so it applies no matter which node the conversation opens on. Use Source Filters to check which channels can actually receive inbound traffic. That’s your list of exposed entry points.

Scenario three is the widget. Put it in the Welcome Message, and consider reinforcing it in the Header Title so it survives scrollback rather than disappearing above the fold once the conversation gets going.

Now a point worth sitting with: two of these three are deterministic. Your GHL template is static text and the widget Welcome Message is static config. Neither depends on a language model deciding to comply. Only scenario two routes through instructions the model has to follow. So that’s the one to actually verify. Run it through the testing portal, open a fresh inbound conversation, and confirm the disclosure shows up in the first reply every time before you publish.

This is also the practical argument for a purpose-built platform over native CRM AI or a stack you assembled yourself in n8n: you can only guarantee an opening line if you control the opening line, and you can only prove it if you can test it before it ships.

What about putting it on the form?

A form notice counts, but it cannot be your only disclosure if you have leads that do not hit the form (ex. inbound messages). Article 50(5) requires disclosure “at the latest” at first interaction, so telling people on the form is explicitly allowed. It just misses every lead who never fills one out: inbound DMs, database reactivation, purchased lists, and anyone replying on someone else’s behalf.

A line on the form telling people an AI assistant will follow up is a legitimate way to satisfy the rule, and worth adding. It just shouldn’t be your only line of defense, because form-only disclosure has holes:

  • Inbound leads never touch the form. Someone who DMs your Instagram or texts your tracking number saw nothing.
  • Database reactivation. You’re texting leads who filled out a form in 2023, before that notice existed. They were never told.
  • Purchased or imported lists. No form, no disclosure.
  • The replier isn’t always the submitter. A spouse, a business partner, or an office manager picks up the phone and answers your text.
  • Time gaps. Form on Monday, first text on Thursday. Whether that still counts as the same “first interaction” is exactly the kind of question you don’t want to be arguing after a complaint.

If you do want to rely on the form’s consent box instead of the first message, put it as visible text next to the submit button, not inside the consent checkbox and not in the linked terms. The Commission specifically rejects disclosure buried in T&Cs, and a checkbox nobody reads is functionally the same thing. Something like: “By submitting, you agree we may follow up by text. Our AI assistant handles initial replies.”

three scenarios

Can my bot still be designed to feel human?

Yes, as long as you disclose. Sounding natural is legal. Concealing that you’re AI is not. Response delays and occasional typos are conversion tooling, and nothing in Article 50 requires a bot to sound robotic. What it requires is that the bot be identified.

I’d rather address this directly than let you find it on your own.

CloseBot’s Persona settings include Response Delay and Frequency AI Typos. The second one deliberately introduces occasional misspellings followed by corrections. Both exist to make replies feel less machine-generated.

They exist because an instant, perfectly-punctuated wall of text reads as spam and gets ignored. A three-second pause and an occasional typo make a message feel like it came from a person at a desk, and leads reply to it. That’s conversion design, and once you’ve disclosed, it stays entirely legitimate.

Where it goes wrong is if the humanization becomes the disclosure strategy, if the plan is that the lead never figures it out.

And there’s a sharper edge. If a lead asks “wait, is this a real person?” and your bot says yes, you’ve moved out of Article 50 and into Article 5, which prohibits deceptive techniques that materially distort someone’s behavior. That tier carries fines up to €35M or 7% of global turnover, versus 3% for a transparency breach. The Commission’s guidance on prohibited practices specifically flags chatbots presenting misleading information, “particularly if the AI nature of the interaction has not been disclosed.”

So put a truthfulness rule in your Job Flow Settings global instructions, in plain language:

If the contact asks whether they are speaking to a real person, a human, or a bot, always confirm honestly that you are an AI assistant. Never claim to be human. Offer to connect them with a team member.

Then go test it. Open the testing portal and ask your own bot, in a few different phrasings, whether it’s a real person. If it dodges, hedges, or plays along, fix it before that conversation happens with a real lead who has a real complaint form available to them.

Always leave a door to a human

Configure your Agent Node Exits, via @@@-mentions in your instructions or automatic tag and list rules, so any lead can reach a person on request. The Agent Node makes this a routing decision rather than a rebuild.

This isn’t strictly required by Article 50, but it does two useful things. It defuses the frustration that turns an annoyed lead into a complainant. And it lines up with GDPR Article 22, which gives people the right not to be subject to purely automated decisions that significantly affect them, where the expectation is meaningful human review rather than a rubber stamp.

The one that bites later: when qualification becomes high-risk

Everything above concerns limited-risk AI. There’s a line you can cross without noticing, and it’s worth knowing where it is before you sign the client.

Annex III of the AI Act classifies AI used for recruitment and employment decisions as high-risk: screening applicants, ranking candidates, filtering CVs, evaluating people for roles. The same applies to creditworthiness assessment. If you take on a staffing client and point your qualification bot at job applicants, or a lending client and have it pre-qualify borrowers, you’ve moved into a regime with conformity assessments, risk management systems, technical documentation, and logging obligations.

That deadline is 2 December 2027. Not urgent, but the architecture decisions get made now.

One trap specifically for agencies running white-label: under Article 25, putting your own name or trademark on a high-risk AI system makes you its provider, with the full provider obligation set. That rule only applies to high-risk systems, so it doesn’t touch a standard qualification bot today. But “white-labeled bot” plus “recruiting client” is exactly the combination that triggers it.

The practical guidance: keep bots on scheduling, information gathering, and routing. Keep the actual scoring or screening decision with a human. That’s a cleaner architecture anyway.

risk assessment conversational ai eu ai act

GDPR didn’t go anywhere

AI Act compliance is not GDPR compliance. They’re separate regimes and you need both.

Short version: pick a lawful basis under Article 6 for the processing and write it down in your record of processing activities. Watch Article 22 where automated decisions have significant effects. Set a retention policy. And remember that conversation transcripts are personal data, the entire chat history, not just the phone number.

We publish our security and compliance posture in our Trust Center and our privacy policy, so you can point clients at documentation rather than assurances.

Penalties, who’s actually knocking, and how you prove it

Article 50 breaches carry fines up to €15M or 3% of worldwide annual turnover, whichever is higher. Article 5 breaches, the “my bot claimed to be human” scenario, go to €35M or 7%.

One detail almost nobody knows, and it matters if you’re a twelve-person agency: for SMEs and startups, the AI Act applies whichever of the two figures is lower, not higher. The €35M headline is aimed at companies where 7% of turnover exceeds it. You are not the target of that number.

eu ai act fines

Enforcement is decentralized: national market surveillance authorities in each member state, not Brussels. Which means two things. Intensity will vary a lot by country. And it’s complaint-driven. Since 2 August, anyone can file a complaint with their national authority, and the authority is obliged to consider it. The realistic trigger isn’t a sweep. It’s one annoyed lead.

Which brings up the question worth ending on: if that happens, how do you prove you disclosed?

Your timestamped transcript is the evidence. A complaint is about one specific conversation, and the artifact that resolves it is that conversation, showing the disclosure in message one with a timestamp attached. Text bots are self-documenting in a way voice agents simply aren’t. Every word is already written down. That’s a genuine structural advantage and you should take the comfort from it.

Two caveats:

  • Retention has to outlive the complaint window. Your evidence exists only as long as the transcript does, and GDPR pushes you toward deletion. Make that a deliberate decision rather than a default you never chose.
  • In outbound-first flows, the record lives in your client’s CRM, not yours. The disclosing message was sent by their GoHighLevel workflow. But the agency is who gets asked about it. If you’re managing sub-accounts you may lose access to the account long before the complaint window closes, so keep your own copy of the templates and a sample of conversations.

What to actually do this week

Six steps, and they cover every AI chatbot disclosure requirement discussed above, on both sides of the Atlantic.

  1. Pull a list of your contacts and find out whether any are in the EU. Most agencies have never checked, though the US state laws mean you should do this regardless.
  2. If yes, open the workflow that sends your first outbound message and add “AI assistant” to the opener.
  3. Add the disclosure to your Job Flow Settings global instructions for inbound conversations.
  4. Add it to your Chat Widget Welcome Message.
  5. Add the truthfulness rule, then test it in the testing portal by asking your bot if it’s human.
  6. Add a line to your form, next to the submit button.

That’s an afternoon, and for most of you it’s less. This is a settings change, not a rebuild. And if the disclosure is written the way I’d write it, your leads won’t even slow down. In our own conversations, telling someone up front that they’re talking to AI has never been what loses the appointment. Being caught not telling them would be.

This is practical guidance from a conversational AI platform, not legal advice. If you’re operating at scale in the EU or serving regulated verticals, have counsel review your setup.

Frequently asked questions

Do I have to say “an AI will be responding”?

No. Article 50 doesn’t prescribe any specific wording. It requires that the person be informed they’re interacting with an AI system, clearly, no later than the first message. “Hi, this is Sarah, Vertex Realty’s AI assistant” satisfies it completely and reads better than a formal disclaimer.

Does the disclosure go on my form or in the first message?

You can have a clear disclosure in your form only, if these leads ALWAYS come in through your form. The law allows disclosing earlier than first interaction, but make sure you also consider leads that don’t touch your form disclosure. Inbound DMs, reactivation campaigns, and imported lists all reach people who never saw your form.

Which US states have AI chatbot disclosure requirements?

California (SB 1001), Maine, New Jersey, Utah, and Colorado all regulate commercial chatbot disclosure, and the FTC Act sets a deception baseline nationwide. Maine’s is the broadest, covering any chatbot in trade or commerce where a reasonable consumer could not tell the difference. New Jersey’s covers the sale or advertising of merchandise and real estate.

Do I have to disclose in every message, or just the first?

Just the first, in normal circumstances. The one exception worth handling is long-gap reactivation: if a bot re-opens a conversation 60 or 90 days later, treat it as a fresh first interaction and disclose again.

My bot only talks to US leads. Am I safe?

Safe from the EU AI Act, not safe generally. California, Maine, New Jersey, Utah, and Colorado all have AI chatbot disclosure requirements covering commercial bots, and the FTC Act applies nationwide. Maine’s has been enforceable since September 2025 and New Jersey’s names real estate specifically. The same disclosure line satisfies all of them plus the EU, so there’s no reason to scope it to EU contacts.

Can my bot still have a human name like Sarah?

Yes. Nothing requires you to call your bot BOT-9000. A human name is fine as long as the AI status is disclosed alongside it. “Sarah, our AI assistant” is a normal and compliant introduction.

What happens if a lead asks whether they’re talking to a bot?

It has to tell the truth. A bot that claims to be human moves you from Article 50, at 3% of turnover, to Article 5’s deception prohibition at 7%. Add an explicit truthfulness rule to your global instructions and test it before you publish.

Does a bot I launched last year get grandfathered in?

No. The obligations apply from 2 August 2026 to all in-scope systems regardless of when they were deployed. The only transitional relief is a separate four-month extension for machine-readable marking of synthetic content, which doesn’t apply to conversational text.

Am I the provider or the deployer?

If you’re an agency running bots for clients, you’re almost certainly a deployer, and your legal entity holds that responsibility even where contractors or freelancers did the build. The distinction gets sharper only if you move into high-risk territory, where putting your own brand on the system can make you the provider under Article 25.

Doesn’t the December 2027 delay cover me?

No. That deferral applies to high-risk obligations, which is a different chapter of the Act. Transparency was explicitly excluded from the delay and has been enforceable since 2 August 2026.

How do I prove I disclosed if someone complains?

The timestamped conversation transcript, showing the disclosure in the first message. Complaints target specific conversations, so the transcript is exactly the right artifact. Just make sure your retention period outlives the realistic complaint window, and keep your own copy where the first message was sent from a client’s CRM rather than yours.