# AI customer service agents and the law in the United States

> The rules that apply when a US business puts an AI agent in front of customers: FTC deception rules, bot disclosure laws in California, Utah and Colorado, TCPA consent for AI voices, call recording and HIPAA. With links to the official texts.

Published: September 18, 2026 · Updated: September 18, 2026 · Prices and figures verified: September 18, 2026 · By the ai-agents.reviews team

This page was researched and drafted with AI assistance from the sources listed on it. We have not run hands-on tests of these products. Method: [How we review](https://ai-agents.reviews/en-us/how-we-review)

> **General information, not legal advice.** State chatbot laws are changing quickly in 2026. We link to official sources and state what we verified on the date shown on this page. Check your own obligations with a qualified attorney.

**The short version**

- **Say it is an AI.** It is required in some states, expected by regulators, and costs nothing.
- **Do not repeat vendor performance claims you cannot back up.** The FTC has no AI exemption for deceptive claims.
- **Outbound AI voice calls need prior consent** under the TCPA.
- **Announce call recording** at the start; several states require every party's consent.
- **Healthcare support needs a BAA** with the vendor before any protected health information flows.

## No federal AI statute, but the FTC is active

Congress has not passed a law on customer-facing AI. The Federal Trade Commission instead applies Section 5 of the FTC Act, which bans unfair or deceptive practices, to AI. It launched [Operation AI Comply](https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes) in September 2024 and has kept bringing cases.

One of them is directly relevant to this category. In March 2026 [Air AI](https://www.ftc.gov/news-events/news/press-releases/2026/03/air-ai-its-owners-will-be-banned-marketing-business-opportunities-settle-ftc-charges-company-misled), which sold conversational AI agents to small businesses, agreed to an $18 million judgment, largely suspended, over deceptive performance, earnings and refund claims. For a buyer the lesson is practical: treat resolution-rate and ROI claims as marketing until you have measured them yourself, and do not repeat them to your own customers or investors as fact.

## State laws on telling people they are talking to a bot

- **California.** Under the [bot disclosure law](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=17941) (in force since July 2019), it is unlawful to use a bot to communicate online with a person in California with intent to mislead them about its artificial identity in order to incentivize a sale. A clear and conspicuous disclosure avoids liability. California's 2026 companion-chatbot law, SB 243, expressly excludes bots used only for customer service.
- **Utah.** The [Artificial Intelligence Policy Act](https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf), as amended in 2025, requires a business using generative AI with consumers to disclose that it is AI when the person clearly asks. Regulated occupations must disclose up front in high-risk interactions. Fines run up to $2,500 per violation, and the Act is due to sunset on July 1, 2027 unless extended.
- **Colorado.** The original Colorado AI Act never took effect. It was repealed and re-enacted in May 2026 as [SB 26-189](https://leg.colorado.gov/bills/sb26-189), a narrower law on automated decision-making in consequential decisions such as lending, insurance, housing and healthcare, effective January 1, 2027. Colorado also passed a Chatbot Safety Act effective the same day; we could not verify how it treats pure customer service bots, so check the statute.
- **Other states.** Nebraska, Idaho, Oregon and Tennessee passed chatbot laws in 2026, mostly aimed at companion chatbots. Check each statute's customer-service exclusions.

Federal preemption is being discussed but has not happened. A December 2025 executive order set up a Justice Department task force to challenge state AI laws, and a June 2026 House discussion draft proposed a three-year preemption, but an executive order cannot repeal state law and no preemption statute had been enacted when we checked.

## When the agent makes decisions, not just conversation

An agent that answers questions is lightly regulated. An agent that decides things is not. California's [CCPA regulations on automated decision-making technology](https://www.cppa.ca.gov/announcements/2025/20250923.html) require notice, opt-out and access rights from January 1, 2027 for businesses that use such technology to make significant decisions, in areas such as finance, housing, employment and healthcare. If your agent can refuse a claim, close an account or change credit terms with no human involved, map those flows before you launch.

## AI voice agents: consent and recording

The FCC [ruled in February 2024](https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf) that AI-generated, human-sounding voices count as an "artificial or prerecorded voice" under the TCPA. Outbound calls using an AI voice therefore need the called party's prior express consent, and prior express written consent if the call includes advertising or telemarketing.

Recording is a separate question. Federal law allows recording with one party's consent, but some states require everyone's consent; [California Penal Code §632](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=PEN&sectionNum=632) is the best-known example. Because a voice agent cannot know where every caller is, the safe default is to announce recording and AI involvement at the start of every call.

## Healthcare: get the BAA first

If the agent will create, receive, maintain or transmit protected health information on behalf of a covered entity, [HIPAA](https://www.law.cornell.edu/cfr/text/45/164.502) requires a written business associate agreement before that happens. Several vendors reviewed here list HIPAA support; in some cases it requires a specific plan or add-on, so confirm it in writing. Each review lists the compliance claims we could verify.

## A pre-launch checklist

1. The agent identifies itself as AI in its first message, and again if asked.
2. A customer can reach a human, and the route is obvious.
3. Any flow where the agent decides something significant has a human review path.
4. Voice: consent is captured for outbound calls, and recording is announced.
5. Contracts cover data processing, sub-processors, retention and, for health data, a BAA.
6. Conversations are logged so you can audit what the agent said.
7. Marketing claims about the agent's performance are based on your own measured results.

> **Scored on a public rubric, from sources you can open.** Every score on this site comes from five published criteria: pricing transparency, performance evidence, access, coverage, and control. Each price and percentage comes from one product database and links to its source, so every page agrees with every other page. Rubric v1.0 · We have not run hands-on tests yet, and no page here claims we did. [Read the full method](https://ai-agents.reviews/en-us/how-we-review)

## Keep reading

- [What counts as a resolution?](https://ai-agents.reviews/en-us/guides/what-counts-as-a-resolution)
- [Resolution rate vs deflection rate](https://ai-agents.reviews/en-us/guides/resolution-rate-vs-deflection-rate)
- [Per-resolution vs per-seat pricing](https://ai-agents.reviews/en-us/guides/per-resolution-vs-per-seat-pricing)
- [How to run an AI agent pilot](https://ai-agents.reviews/en-us/guides/how-to-run-an-ai-agent-pilot)
- [The best AI customer service agents in 2026](https://ai-agents.reviews/en-us/best/ai-customer-service-agents)

---

Canonical: https://ai-agents.reviews/en-us/guides/ai-customer-service-agents-and-the-law
