The short version
- Say it is a bot in the first message. California, Maine and (from 2027) Colorado require it in some form.
- Put a short notice above the chat input. Say the chat is recorded and which vendor processes it. It blunts California chat-wiretap claims.
- Get written opt-in before marketing texts and honor STOP or any plain-language opt-out right away.
- Follow Meta's own rules on WhatsApp and Messenger: opt-in first, a 24-hour reply window, and a clear route to a human.
- Treat the bot's answers as your own statements. Ground it in your current policies and prices, and test it before launch.
- Check the widget with a keyboard and a screen reader, and keep another way to reach you.
Tell people they are talking to a bot
There is no federal disclosure rule. State laws differ, but one opening line such as "I'm an automated assistant" covers the ones we checked.
- California. Under Business and Professions Code §17941 (SB 1001, operative July 1, 2019), it is unlawful to use a bot to communicate online with a person in California with intent to mislead them about its artificial identity. California's companion-chatbot law, SB 243, excludes bots used only for customer service.
- Maine. 10 M.R.S. §1500-DD covers any AI chatbot used in trade or commerce, including ordinary sales and support bots. If a reasonable consumer could think they are talking to a human, you must clearly say they are not. A violation is an unfair trade practice.
- Colorado. HB 26-1263, signed May 29, 2026, requires operators of public-facing conversational AI to disclose that the service is AI. Operator duties apply from January 1, 2027. The bill summary shows no customer-service exclusion; we did not read the enrolled text, so plan to disclose.
- New York and Utah. New York's companion-AI law excludes systems used solely for customer service or product information. Utah's generative-AI disclosure rule is scheduled for repeal on July 1, 2027; we could not verify whether 2026 bills changed it.
Meta's Messenger policy also requires automated chats to say so where the law requires it. And if you serve EU customers, Article 50 of the AI Act has applied since August 2, 2026, with no grace period for the chatbot disclosure duty.
No cookie-consent law, but chat-wiretap suits in California
The US has no cookie-consent law for loading a chat widget. The risk is different: plaintiffs sue website owners under California's Invasion of Privacy Act (Penal Code §631), claiming the third-party chat vendor intercepts the conversation. Statutory damages are $5,000 per violation, according to a law-firm summary.
In Gutierrez v. Converse (July 9, 2025), the Ninth Circuit sided with the website owner: evidence that the vendor could read messages was not proof that it did. We rely on a law-firm summary and did not read the opinion. The ruling is unpublished, so suits continue.
Show a notice before the chat starts that names the vendor and says conversations are recorded, and bar the vendor by contract from using transcripts for its own purposes.
Marketing messages: texts, WhatsApp and Messenger
- Text messages (TCPA). Marketing texts sent with an autodialer need the recipient's prior express written consent. Since April 11, 2025, you must honor an opt-out made by any reasonable method, such as STOP or a plain-language reply. The part that applies one opt-out to all unrelated message types is waived until January 31, 2027 by FCC order DA 26-12.
- WhatsApp. We found no FCC statement on whether the TCPA covers app-to-app messages, so treat Meta's rules as the standard. The WhatsApp Business Messaging Policy allows contact only if the person gave you their number and opted in. The bot can reply freely for 24 hours after the user's last message; after that, only approved templates. Automation needs a clear route to a human, and you must respect every opt-out.
- AI on WhatsApp. The Business Solution Terms bar general-purpose AI assistants offered as the main product. A business bot for support, bookings or sales is not the target. You may not train AI models on WhatsApp Business Solution data, except a model for your exclusive use.
- Messenger. A business has 24 hours to respond. The 7-day Human Agent tag is for manual replies by a person, not bot messages. We could not confirm the Instagram rules from Meta's documentation.
Our guide to WhatsApp chatbot rules has the details.
You answer for what the bot says
In Moffatt v. Air Canada (February 14, 2024), a British Columbia tribunal held the airline liable after its website chatbot gave wrong bereavement-fare advice. The award was CAD 812.02. This is a Canadian small-claims decision, not US law, and we found no US court ruling on the same point. In the US, Section 5 of the FTC Act and state unfair-practices laws lead to the same result.
The FTC also polices claims about the bot itself. On February 11, 2025 it finalized an order against DoNotPay over untested "AI lawyer" claims. Ground answers in your live policies and prices, test before launch, and do not rely on a "the bot may be wrong" disclaimer. Our guide on writing a bot knowledge base shows how.
Transcripts, privacy and EU or UK customers
Our research did not cover US state consumer-privacy laws, so check those separately. Three habits are sensible anyway: set a transcript retention period, make sure you can export or delete one person's chats, and forbid the vendor from reusing transcripts, including for AI training.
If you serve customers in the EU, check the GDPR. You need a documented retention period, the ability to hand over a person's transcripts within one month of a request, and a data processing agreement with the vendor. Load the widget on click or behind your consent banner so it sets no cookies first. For transfers, check the vendor's EU-US Data Privacy Framework certification and keep standard contractual clauses as a fallback; we could confirm the framework's current status only from secondary sources.
Automated decisions
Colorado's SB 26-189, signed May 14, 2026, regulates automated decision-making technology in consequential decisions only, not ordinary chatbots; the compliance date is January 1, 2027, according to a law-firm summary. If a conversation could end in a decision that matters to the person, such as credit, route it to a human. See when not to use a chatbot.
Accessibility
The Justice Department's web accessibility guidance (March 18, 2022) says the ADA covers the online goods and services of businesses open to the public. There is no regulation with detailed technical standards for private websites, and no official source we found addresses chat widgets. Use WCAG as the yardstick; private lawsuits are the practical risk. Make the widget work with a keyboard and a screen reader, and keep another contact route.
Before you switch the bot on
- Make the first message say it is a bot, and repeat it when a person hands the chat back to the bot.
- Add a notice above the chat input: that it is recorded, which vendor processes it, and a link to your privacy policy.
- Get and log an explicit opt-in that names your business and the channel before any SMS, WhatsApp or direct-message marketing.
- Make opting out one reply away, and apply it at once in the bot and in your CRM.
- Offer a route to a human in every channel: in-chat handover, phone or email.
- Ground the bot in your current policies and prices, test it, and schedule regular transcript reviews.
- Set a transcript retention period and confirm you can export or delete one person's chats.
- Forbid vendor reuse of transcripts by contract. Add a data processing agreement if you serve EU or UK customers.
- Test the widget with a keyboard and a screen reader.
Frequently asked questions
Does US law require a chatbot to say it is a bot?
No federal law does. California bans using a bot to mislead someone about its artificial identity, Maine requires a clear disclosure for any chatbot used in commerce if a consumer could think it is human, and Colorado's disclosure duty for public-facing conversational AI applies from January 1, 2027. One opening line covers all three.
Do I need a cookie banner for a chat widget in the United States?
There is no US cookie-consent law for chat widgets. The practical risk is California chat-wiretap suits under Penal Code §631. Show a short notice before the chat starts. If you serve EU visitors, do not let the widget set cookies before they click it.
Does the TCPA apply to WhatsApp messages?
We found no FCC statement on app-to-app messages, so we cannot say. Treat SMS as the regulated channel, where marketing texts need prior express written consent. On WhatsApp, Meta's own policy requires an opt-in either way.
Is my business liable if the chatbot gives a customer wrong information?
Plan as if it is. A Canadian tribunal held Air Canada liable for its chatbot's wrong fare advice in 2024. That is not US law, and we found no US court ruling on the point, but the FTC Act and state unfair-practices laws apply to what you tell customers. Keep the bot's sources current and test its answers.
Keep reading
- What is the difference between a chatbot and an AI agent?guide
- Rule-based or AI chatbot: which should you build?guide
- How is chatbot software priced?guide
- What counts as a conversation in chatbot pricing?guide
- Best chatbot buildersbest list
Researched and drafted with AI assistance from the sources listed on this page. We have not built or tested bots on these platforms yet. Method: How we review