Playbook
Does Your Agency's AI Have to Admit It's Not Human?
A patchwork of new state laws now requires AI to admit what it is. Most of them exempt your chatbot. Two of them don't.
Most of the new 2026 "AI chatbot" laws don't touch your insurance agency's AI tools. California, Washington, and Oregon all just passed laws regulating "companion chatbots," and all three explicitly exempt customer service bots678. But two older, less-discussed laws already do reach a sales or service bot: California's B.O.T. Act covers any online bot used to incentivize a sale1, and Utah's AI Policy Act covers any channel, phone included, the moment a consumer asks whether they're talking to a person4. Neither one requires much to comply. Both carry real penalties if you ignore them.
The day this stopped being hypothetical
You turned on an AI receptionist, or added a chat widget to your quote page, sometime in the last year. Missed calls were costing you appointments, and a bot that answers at 9 p.m. on a Tuesday beats voicemail every time. It's working. Then a headline crosses your feed about a state passing an "AI chatbot law," or a producer in your Facebook group asks whether their voice AI needs to say it's a robot, and now you're wondering if the thing you built to catch more leads just became a compliance problem you didn't sign up for.
That worry is reasonable, and it's also mostly, but not entirely, unfounded. 2026 really has been a busy year for state AI disclosure legislation. Five separate laws, across four states, now say something about a machine having to admit it isn't a person. If you stop reading after the headline, every one of them sounds like it could apply to you. Read the actual bill text, the part almost no coverage of these laws quotes directly, and a much narrower picture shows up: three of the five were written specifically for companion and relationship chatbots and say so in plain language, carving your customer service bot out by name. The other two were written more broadly, and one of them has a wrinkle specific to licensed professions that almost nobody selling you an AI receptionist has bothered to check.
This guide walks through what each law actually says, sourced from the enrolled bill text and the statute itself rather than a vendor's summary of a summary, which laws reach an insurance agency's AI tools today, which don't, what it costs if you get the two that do apply wrong, and the five-second fix that makes the whole question moot going forward.
One more reason this is worth your actual attention rather than a skim: most of the "AI compliance for licensed professionals" advice floating around right now was written with doctors, lawyers, accountants, and financial advisors in mind, because those are the professions state legislatures reach for first when they draft a bill about regulated occupations. Insurance producers are licensed in every state where they sell, but the agency that licenses them usually isn't the same one that licenses those other professions, and that single administrative fact turns out to change which rules actually apply to you. A generic checklist built for a medical practice's chatbot will tell you more than the law requires in some places and miss the actual trigger in others. This guide is built specifically around what an insurance producer's license looks like, not a stand-in for it.
This is not legal advice
This guide describes what these statutes say, sourced directly from the enrolled bill text and official code sections, checked this week. It isn't a substitute for your own attorney reviewing your specific setup, your states of licensure, and your actual AI vendor's disclosure behavior. Where a rule is genuinely unsettled or untested in court, this guide says so rather than guessing.
The 2026 wave, and why it probably isn't about you
Start with the laws generating the most headlines, because ruling them out first is what makes the rest of this guide short instead of terrifying. California's Senate Bill 243, Washington's House Bill 2225, and Oregon's Senate Bill 1546 all passed within about six months of each other in 2026, and all three regulate the same narrow thing: chatbots built to simulate an ongoing personal relationship with a user. Lawmakers call the category a "companion chatbot," and the legislative record behind each bill is explicit about why. Washington's bill states the purpose directly in its own findings section: these systems can "sustain prolonged, personalized, and emotionally adaptive conversations" and the concern driving the law is what that does to a user, particularly a minor, who starts treating the bot as a substitute for human connection7.
None of that describes an insurance agency's AI receptionist or chat widget, and the statutes say so in their own definitions, not as an interpretation someone has to argue for you.
| Law | What it targets | Customer service exclusion | Effective |
|---|---|---|---|
| California SB 243 | A chatbot "capable of meeting a user's social needs" | Explicitly excludes bots used "only for customer service, a business' operational purposes"6 | January 1, 2026 |
| Washington HB 2225 | A bot that "sustains a relationship across multiple interactions" | Excludes bots used only for "customer service" that don't sustain a relationship7 | January 1, 2027 |
| Oregon SB 1546 | A system simulating a "sustained, human-like platonic, intimate or romantic relationship" | Excludes software operating "solely for the purpose of customer service or support"8 | January 1, 20279 |
Read that middle column again. Every one of these laws had to draw a line somewhere, and every one of them drew it in the same place: a bot that answers a coverage question, books an appointment, or takes a lead is a customer service tool, not a companion, and it's explicitly carved out. If a vendor tells you your AI receptionist needs a special "SB 243 compliance package," ask them to point to the specific clause. There isn't one that reaches you.
The two laws that already reach a sales bot
Set the companion chatbot wave aside. Two other, older laws were written broadly enough to catch an ordinary sales or service bot, and if your agency runs any kind of AI receptionist or website chat tool today, one or both of these already governs it.
California's B.O.T. Act
California passed the nation's first bot disclosure law back in 2018, and it took effect July 1, 20191. It's easy to miss now because it predates the current AI news cycle by seven years, but the operative language covers exactly the kind of bot an insurance agency runs today. The statute makes it "unlawful for any person to use a bot to communicate or interact with another person in California online, with the intent to mislead the other person about its artificial identity for the purpose of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction"1.
A "bot" under the statute is "an automated online account where all or substantially all of the actions or posts of that account are not the result of a person"2, which is a plain description of a chat widget answering quote questions on your website. If that widget is helping move a California visitor toward requesting a quote or booking a call, and it doesn't tell them it's a bot, it's operating in the exact space this statute was written for. The fix the law asks for is narrow: "a disclosure that is clear, conspicuous, and reasonably designed to inform" the person they're talking to a bot1. Do that, and you're compliant. The law only reaches online, public-facing interactions, not phone calls, so a voice-only AI receptionist sits outside its scope entirely.
Utah's Artificial Intelligence Policy Act
Utah passed its own AI law in 2024, and it took effect May 1, 20244, which makes it the older of the two rules that actually reaches an insurance sales bot and the one built to cover more ground. Where California's law is online-only, Utah's covers "text, audio, or visual communication"4, meaning it applies to your phone-based AI receptionist as plainly as it applies to a website chat widget. Where California's law requires proof of an intent to deceive, Utah's base rule is simpler: "A person who uses, prompts, or otherwise causes generative artificial intelligence to interact with a person... shall clearly and conspicuously disclose to the person with whom the generative artificial intelligence interacts, if asked or prompted by the person, that the person is interacting with generative artificial intelligence and not a human"4.
In plain terms: if a Utah resident asks your AI receptionist or chat widget whether they're talking to a person, Utah law says you have to tell them the truth, clearly. That's the whole base rule, and it applies to any business, insurance agencies included.
Worth checking on your own tools this week
Call your own AI receptionist and ask it directly, "Are you a real person?" Then open your website chat widget and ask the same thing. If either one dodges the question, deflects, or claims to be human, that's a real, fixable gap, independent of which state your caller happens to be in. If you want a broader read on where your site stands on AI-facing signals generally, the free Audit checks it in about a minute. Run a free Audit.
The Utah nuance nobody explains to agents
Here's where most coverage of Utah's law, aimed at doctors and lawyers, stops short of what an insurance agent actually needs to know. Utah's statute doesn't stop at the base "disclose if asked" rule. It adds a second, heavier duty for a specific category: "A person who provides the services of a regulated occupation shall prominently disclose when a person is interacting with a generative artificial intelligence in the provision of regulated services," and that disclosure has to be proactive, not triggered by a question, spoken "at the start of an oral exchange or conversation" and sent "through electronic messaging before a written exchange"4.
That sounds, at first read, exactly like the rule an insurance producer would fall under. Producers are licensed. The work is regulated. Except the statute defines "regulated occupation" narrowly, as "an occupation regulated by the Department of Commerce that requires a person to obtain a license or state certification to practice the occupation"4. Insurance producers in Utah aren't licensed by the Department of Commerce. They're licensed by the Utah Insurance Department, a separate agency whose Producer Licensing Division handles applicant exams, background checks, and license issuance for the industry5.
Read narrowly, that means an insurance producer's AI receptionist likely sits under Utah's base disclose-if-asked duty, the same one that applies to any ordinary business, rather than the heightened proactive duty written for Department of Commerce professions like nursing, medicine, and pharmacy. It's a genuinely fine distinction, and it's the kind of thing a general "AI compliance" checklist written for doctors and lawyers gets wrong by assuming every licensed occupation is treated the same. It isn't.
Nursing, medicine, pharmacy, and similar
- Meets Utah's "regulated occupation" definition directly4
- Must proactively disclose AI use, unprompted, before the exchange starts
- Verbal disclosure required at the start of every call
- Written disclosure required before every chat exchange
Heightened dutyDisclose without being asked
Licensed by the Utah Insurance Department, not Commerce
- Falls outside the statute's "regulated occupation" definition45
- Base duty still applies: disclose clearly if a consumer asks
- No proactive, unprompted disclosure required by this statute
- Still the safest practice to disclose proactively anyway
Base dutyDisclose if asked, and be ready to
Notice what that last line in the right-hand column says, because it's the most important sentence in this section. Just because Utah's statute doesn't require proactive disclosure from an insurance producer doesn't mean proactive disclosure is a bad idea. It means the legal floor is lower than the practical ceiling ought to be. A caller who has to ask whether they're talking to a machine, and gets a straight answer only because they happened to ask, is a caller who now wonders what else your agency didn't volunteer. Meeting the letter of the base duty and skipping the spirit of it is a strange place to save five seconds.
What getting this wrong actually costs
Two different enforcement systems apply to the two laws that reach you, and neither is severe on paper, but both are real and both compound per violation, meaning per call or per chat session, not per agency.
| Law | Who enforces it | Maximum penalty |
|---|---|---|
| California B.O.T. Act | Attorney General, district attorneys, certain city attorneys, via the Unfair Competition Law | Up to $2,500 per violation, plus equitable remedies3. No private right of action under the chapter itself. |
| Utah AI Policy Act, base duty | Utah Division of Consumer Protection, and the state in court | Up to $2,500 per violation administratively, another $2,500 per violation and disgorgement in a court action, plus attorney fees4 |
| Utah AI Policy Act, violating an order | Utah Attorney General, on behalf of the division | Up to $5,000 per violation4 |
Put a number on what "per violation" means for a working agency. If your AI receptionist takes forty calls a week and the disclosure question comes up in even a handful of them because your script quietly dodges it, that's not one violation waiting to happen, it's a pattern an investigator building a case would have no trouble documenting. The dollar figures above are individually modest. The exposure isn't the size of one fine. It's that a bad script runs the same mistake on every call, and every call is a separate count.
Make it concrete with a scenario a lot of independent Medicare and ACA agents will recognize. Say you're licensed in six states, including California and Utah, and you run one AI receptionist across your whole book because building six separate scripts never made sense. Your receptionist takes calls from all six states through the same phone number and the same underlying script. If that script is written to avoid ever admitting it's a bot, even when directly asked, you're not exposed in one state. You're exposed everywhere Utah residents call in, because the base disclosure duty travels with the caller, not with your office address. A single script decision, made once when the AI receptionist was set up, is now running the same compliance gap on every relevant call, week after week, without anyone having to do anything wrong on purpose.
There's a second, quieter cost that doesn't show up in a penalty table: the retrofit. An agency that builds an AI receptionist with a script that dodges the "are you human" question, then later has to rewrite that script for every state it's licensed in once someone raises the question, is paying twice for the same feature. Building the disclosure in once, at launch, costs a sentence. Retrofitting it across a live system after a complaint, a client's attorney, or a state investigator asks about it costs a rebuild, and it costs it at the worst possible moment.
What's coming next
The pattern across 2026 is unmistakable even after narrowing out the laws that don't apply to you: more states are legislating in this space every session, and the rules keep getting more specific about timing, channel, and enforcement rather than less. Washington's law requires the companion disclosure not just at the start of an interaction but again "at least every three hours during continued interaction"7. Oregon went further and attached teeth: a private right of action letting an individual sue for the greater of actual damages or $1,000 in statutory damages per violation, plus attorney fees8, a mechanism California's older law doesn't have.
A different and separate mechanism is arriving on the same timeline. Colorado's legislature repealed its original 2024 AI Act and replaced it with Senate Bill 26-189, signed in May 2026, and the rebuilt law is set to take effect January 1, 202710. It doesn't regulate chatbot disclosure at all. It targets "automated decision-making technology" used in "consequential decisions," explicitly naming insurance among the covered sectors10, meaning it would matter if your agency or a carrier partner starts using an algorithm to help decide who qualifies for a rate or a product, not because a bot answers your phone. It's worth watching if that's a direction your agency is headed. It's a different question than the one this guide answers.
None of this is likely to be the last word. A state that regulates companion chatbots today can amend the definition tomorrow, and a legislature that's already passed one AI bill this session is a legislature that's shown it will pass another. The honest read is that the customer-service exclusion holding across California, Washington, and Oregon right now is doing real work for you, and it's worth knowing it's there rather than assuming every AI bill that makes the news applies to your agency by default.
How to build the disclosure in, once
You don't need a lawyer on retainer to handle the part of this that's actually within your control. The fix costs one sentence and about ten minutes of setup, and it makes the whole state-by-state question irrelevant because you're meeting the strictest version of the rule everywhere, all the time.
- Write one disclosure line and use it on every channel. Something like, "Hi, this is an AI assistant for [agency name], here to help with your question," works for a phone receptionist, and a chat-widget equivalent, "You're chatting with an AI assistant," pinned visibly at the top of the widget, covers the website side.
- Say it at the start, not just on request. Utah's base duty only requires disclosure if asked, but building the proactive version in by default means you're never one unlucky question away from a gap, and it costs nothing extra to say it first instead of waiting.
- Make sure the bot can't contradict its own disclosure. Test it directly: ask your AI receptionist and your chat widget, point blank, "Are you a real person?" A well-built system repeats the disclosure. A poorly prompted one sometimes plays along with the question instead, which is precisely the failure mode these laws exist to catch.
- Keep the disclosure visible for the whole interaction on chat, not just the opener. A banner that appears for two seconds and then scrolls away doesn't meet a "clear and conspicuous" standard nearly as well as one that stays pinned to the top of the widget for the entire session.
- Log it. If your AI platform can timestamp that the disclosure fired on every call and every chat session, keep that log. It's the difference between "we believe our system always discloses" and being able to show it did, on the specific call someone asks about.
The mistake we see most
An agency's AI vendor writes a receptionist script optimized purely to sound human, on the theory that sounding human converts better. Sometimes it even instructs the bot to deflect if a caller asks whether it's real, treating the question as an objection to talk past rather than answer. That's the exact scenario Utah's law addresses directly, and it's also, separately, a bad idea on the merits. A caller who catches an evasive bot trusts your agency less than one who got a straight answer.
None of the five steps above requires software you don't already have, and most AI receptionist and chat platforms let you edit the opening script yourself in a few minutes. If you'd rather have someone else own it end to end, that's the next section.
How we build it in from day one
Every AI receptionist and chat widget we ship for an agency states, at the start of the interaction, on every channel, that the caller or visitor is talking to an AI system. We don't treat it as a compliance add-on priced separately or a checkbox you have to remember to ask for. It's baked into the default prompt on every build, the same way we bake in HIPAA-conscious handling for anything that touches a client's health information, because both are the kind of thing that should be true by construction rather than by request.
Digital Foundation includes the AI chat widget starting at the Starter tier, and the 24/7 AI receptionist from the Pro tier up11. Both ship with the disclosure line already written into the default script, tested against the "are you a real person" question specifically, and consistent whether the person asking is in Sioux Falls or San Diego, so you're never relying on a caller's zip code to decide whether your bot tells the truth. If your setup is more custom, multiple offices, multiple brands, or a build that needs to route disclosure differently by state for reasons specific to your book of business, that's the kind of thing we scope on a call rather than force into a fixed tier.
You can absolutely do this yourself
Every step in the previous section is something you can implement in your existing AI receptionist or chat platform this week, without buying anything from us. Plenty of agencies read a guide like this and handle it in an afternoon, and that's a perfectly good outcome. This section exists for the agencies that would rather it just already be true on day one.
What you get
Handle this correctly and what changes is small and specific: your AI receptionist and chat widget stop being a compliance question you have to revisit every time a new state law makes the news, because you're already meeting the strictest applicable standard by default. Callers get a straight answer instead of a dodge, which, separately from any statute, tends to make them trust the rest of the conversation more, not less. And the two laws that actually reach an insurance agency's AI tools today, California's B.O.T. Act and Utah's base disclosure duty, both ask for something genuinely modest: say what the thing is, clearly, where a person can see or hear it.
What this doesn't do is make every future AI law irrelevant to you. Legislatures are still actively writing in this space, the customer-service exclusion holding today across three states could narrow tomorrow, and Colorado's incoming rule on automated decision-making is worth tracking separately if your agency moves toward AI-assisted underwriting or eligibility decisions. We won't promise you a rule that never changes. We will keep the disclosure line correct on everything we build, and we'll flag it here if the picture shifts.
Questions agents ask
Does my insurance agency's AI receptionist have to tell callers it's not human?
It depends on where the caller is and what your AI receptionist actually does. Under Utah's Artificial Intelligence Policy Act, anyone using generative AI to interact with a consumer must disclose that fact if the consumer asks, and Utah residents can ask at any point in the call. California's B.O.T. Act only covers online bots, not phone calls, so a voice receptionist alone doesn't trigger it. No state currently requires a proactive, unprompted disclosure from an insurance producer specifically, because Utah's heightened proactive duty applies only to occupations licensed by the Department of Commerce, and insurance producers are licensed by the Utah Insurance Department instead.
Does my website's AI chat widget have to disclose it's a bot?
If a California resident could interact with it, very likely yes. California's B.O.T. Act makes it unlawful to use an online bot to communicate with someone with the intent to mislead them about its artificial identity in order to incentivize a purchase or sale, and an insurance quote or lead-capture widget sits squarely inside that description. The disclosure has to be clear, conspicuous, and reasonably designed to be seen, not buried in a terms-of-service link.
Do the new 2026 companion chatbot laws in California, Washington, and Oregon apply to my insurance agency's AI tools?
Almost certainly not. All three laws, California's SB 243, Washington's HB 2225, and Oregon's SB 1546, define their target narrowly as bots built to sustain an ongoing social, emotional, or romantic relationship with a user, and all three explicitly exclude bots used only for customer service or business operations. An AI receptionist booking an appointment or a chat widget answering coverage questions is a customer service bot by definition, not a companion chatbot.
What happens if I don't disclose and a caller or website visitor complains?
It varies by state and by law. Utah's Division of Consumer Protection can impose an administrative fine of up to $2,500 per violation, and a court enforcing the statute can add another $2,500 per violation plus disgorgement and attorney fees, with violations of a resulting order carrying civil penalties up to $5,000 each. California's B.O.T. Act is enforced by the Attorney General and local prosecutors under the state's Unfair Competition Law, which caps civil penalties at $2,500 per violation. Oregon's companion chatbot law, notably, gives consumers a private right of action with statutory damages of $1,000 per violation, though that law doesn't reach a customer service bot in the first place.
I'm licensed in more than one state. Which state's rule applies to my AI receptionist?
Potentially several at once. California's law turns on where the person you're communicating with is located, not where your agency is based, so an online chat widget serving California residents is in scope no matter where your office sits. Utah's law works the same way for Utah residents. If your book of business spans multiple states, the safest and cheapest approach is to build one disclosure that meets the strictest applicable rule and use it everywhere, rather than trying to geofence your script by caller location.
Is a line of text at the top of my chat widget enough, or does my AI receptionist need to say something out loud?
For a website chat bot under California's law, a clear, conspicuous, persistent visual notice is what the statute asks for. For a phone-based AI receptionist reaching a Utah resident, the disclosure needs to be spoken and available on request during the call itself, since a written notice nobody hears on a phone call doesn't satisfy a verbal, on-request disclosure duty. Match the format to the channel.
Does Colorado's new AI law affect how my agency uses AI?
Probably not for a standard AI receptionist or chat widget. Colorado's revised AI Act, signed in May 2026 and set to take effect January 1, 2027, targets automated decision-making technology used to make consequential decisions, things like eligibility, pricing, or underwriting outcomes, not a bot that answers questions or books appointments. It's worth watching if your agency starts using AI to help decide who qualifies for something, but it's a different mechanism than the disclosure laws this guide covers.
Will Strategic AI Architects build the disclosure in, or do I have to write the script myself?
We build it in. Every AI receptionist and chat widget we ship states plainly, at the start of the interaction, that the caller or visitor is talking to an AI system, on every channel, in every state, by default. We treat it as a five-second, zero-cost line to include rather than a feature to configure state by state, because that's the cheapest version of getting this right for an agency that doesn't want to think about it again.
Sources
- California Business and Professions Code §17941 (the B.O.T. Act), operative bot disclosure requirement, effective July 1, 2019. leginfo.legislature.ca.gov.
- California Business and Professions Code §17940, definitions for "bot" and "online platform." leginfo.legislature.ca.gov.
- California Business and Professions Code §17206, Unfair Competition Law civil penalty of up to $2,500 per violation. leginfo.legislature.ca.gov.
- Utah S.B. 149 (2024), Artificial Intelligence Amendments, enacting Utah Code §13-2-12, effective May 1, 2024. Enrolled bill text. le.utah.gov.
- Utah Insurance Department, Producers licensing division. insurance.utah.gov.
- California S.B. 243 (2025), companion chatbot law, enacting definitions and disclosure requirements including the customer-service exclusion, approved October 13, 2025. leginfo.legislature.ca.gov.
- Washington Engrossed Substitute House Bill 2225 (2026), AI companion chatbot regulation, effective January 1, 2027. Enrolled bill text. lawfilesext.leg.wa.gov.
- Oregon Enrolled Senate Bill 1546 (2026), artificial intelligence companion regulation and private right of action. olis.oregonlegislature.gov.
- Mayer Brown. "Oregon and Washington Join California in Enacting Companion Chatbot Laws," April 2026, on Oregon SB 1546's January 1, 2027 effective date. mayerbrown.com.
- Norton Rose Fulbright. "Colorado enacts revised AI law," on Senate Bill 26-189, signed May 14, 2026, effective January 1, 2027, covering consequential decisions including insurance. nortonrosefulbright.com.
- Strategic AI Architects. "Digital Foundation," tier pricing and AI chat widget / AI receptionist inclusion by tier, verified this week. strategicaiarchitects.com.
Talk it through
Want a second pair of eyes on it?
Free 30 minutes. Bring what you found, or bring nothing and we will look together at how AI engines read your site and which fixes move first.
See how we build AI tools that disclose themselves by default
Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.