State Chatbot Laws Have Arrived. Here Is What Your Business Now Owes.

A patchwork map of state legal documents under a magnifying lens

For most of the AI boom, a business could put a chatbot on its website without thinking about a single law written specifically for chatbots. That’s now toast. Well over 100 chatbot-related bills have been introduced across more than 35 states. [2] Eleven states have passed laws aimed squarely at chatbots: California, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island, and Washington, with Hawaii expected to become the twelfth. [1]

If your business runs a chatbot that talks to consumers, some of these laws may already apply to you, and more take effect on a rolling schedule through 2027. Most target companion or conversational chatbots and carve out narrow, transactional customer-service bots, but the definitions vary by state, and California is already advancing a bill that would extend disclosure duties to customer service chatbots. [2] Here is what the patchwork legislation actually requires.

Disclosure is becoming mandatory.

The most common requirement across the new laws is AI-identity transparency: users must be told they are talking to software, not a person. [1]

Utah’s AI Policy Act took effect May 1, 2024 and, as amended, requires disclosure whenever a user directly asks whether they are interacting with AI, and during high-risk interactions involving health, financial, or biometric data. [2]

California’s SB 243, effective January 1, 2026, requires operators to disclose non-human status, implement mental health crisis protocols, and provide special protections for minors. [3]

California’s chatbot law was the first state AI law to include a private right of action: a user injured by a violation can recover the greater of actual damages or $1,000 per violation, plus attorney’s fees. [4] Oregon’s SB 1546, effective January 1, 2027, goes further. A user who can demonstrate a violation can seek $1,000 in statutory damages without proving any actual harm. [2] For a business whose chatbot talks to thousands of visitors, that converts a compliance gap into direct, per-user dollar exposure.

Professional services are getting their own rules.

Lawmakers are moving from broad AI frameworks toward targeted rules for specific use cases, with professional services and child safety at the center. [5]

Tennessee’s SB 1580, effective July 1, 2026, prohibits AI systems from presenting themselves as licensed mental health professionals. [3]

If you run a therapy practice, a medical office, or any licensed profession, the question of what your website chatbot is allowed to say is no longer hypothetical. It is statute.

The calendar keeps filling.

Colorado’s AI Act, with major provisions effective June 30, 2026, mandates reasonable care to prevent algorithmic discrimination in high-risk AI systems. [3]

New York’s AI Companion Models law has been in force since November 2025, requiring safety protocols to detect and address self-harm risk and recurring disclosures that the user is talking to AI. [3]

Washington’s Chatbot Disclosure Act takes effect January 1, 2027. [3]

Nebraska’s Conversational AI Safety Act and Idaho’s closely modeled law follow on July 1, 2027. [3] Each has its own definitions, thresholds, and duties. Because these laws apply based on where users are located, not where a business is headquartered, a business operating a single chatbot on the public internet can be exposed to several of them at once. [2]

What the patchwork actually demands from you.

Strip away the state-by-state variation and the new laws converge on a short list: disclose that your chatbot is AI, protect minors, respond appropriately to crisis expressions, and stay out of licensed-profession territory. [1] Meeting those duties in practice comes down to two operational capabilities: knowing exactly what your chatbot can say, and being able to prove what it did say. Neither can be met by a chatbot that generates answers freely at runtime, because a free-generating system cannot guarantee in advance what it will say to any given user.

This is the compliance case for Gated Truth Architecture. With Truebe, every answer the chatbot can give was drafted from your documents and approved by a human before going live. The system serves only approved answers, so what it can say is a known, finite, reviewable set. Every interaction is logged, and an audit trail records who approved each answer and when. If a visitor asks something outside the approved library, the system declines and logs the gap instead of improvising.

When a regulator, an insurer, or a plaintiff’s lawyer asks what your chatbot told people, you can answer with records instead of guesses.

The practical takeaway.

Chatbot regulation is now a mainstream compliance obligation. [1] Before your chatbot takes one more question from the public, you should be able to answer: What exactly can it say? Can you prove what it said? And who approved it?

Try the demo

[1] IAPP. "Chatbot laws: Coming to a state near you." July 2026. iapp.org.

[2] StackCyber. "State AI Chatbot Laws: Compliance Guide for Businesses." May 2026, updated June 2026. stackcyber.com.

[3] Orrick. "2026 State Chatbot Laws: Key Provisions and Regulatory Trends." April 2026. orrick.com.

[4] Cooley LLP. "AI Chatbots at the Crossroads: Navigating New Laws and Compliance Risks." October 2025. cooley.com.

[5] MultiState. "State AI Chatbot Regulation Tackles Disclosure and Safety in 2026." January 2026. multistate.ai.