If you run a website with a chatbot, use AI in hiring, or serve customers in the EU, 2026 is the year AI compliance stopped being optional. The regulatory landscape moved fast this year, and it's genuinely confusing — different rules apply depending on which states or countries your customers are in, not where your business is based.
The US Picture: A Genuine Patchwork
As of mid-2026, more than a dozen US states have enacted chatbot-specific laws, with well over 100 related bills introduced across more than 35 states. California's SB 243 took effect on 1 January 2026 and applies using a "market reach" test — if your chatbot is accessible to and used by California residents, it applies to you regardless of where your business is headquartered. Washington's Chatbot Disclosure Act follows a similar model, effective 1 January 2027, and gives individuals the right to sue providers directly for statutory damages rather than relying solely on state attorney general enforcement.
The pattern across nearly every state law is the same: disclose clearly that users are interacting with AI, not a human; protect minors with age-aware safeguards; and have a protocol for responding if a user shows signs of a mental health crisis during the interaction.
The EU AI Act Is Now Being Enforced
Article 50 of the EU AI Act requires businesses to inform users when they're interacting with an AI system, and enforcement began on 2 August 2026. This applies to any business serving EU customers — including US-based companies — with no small-business carve-out. If even one user in Germany, France, or any other EU member state interacts with your chatbot, Article 50 applies to you, regardless of where you're incorporated.
What "Disclosure" Actually Needs to Look Like
Regulators and the FTC have been consistent on this point: disclosure has to be clear and conspicuous. Burying "powered by AI" in your terms of service or a footer link doesn't meet the standard under any of the frameworks currently in force. The disclosure should appear at the start of the interaction, in plain language, before the chatbot collects any personal information from the user.
The Federal Backstop You Can't Opt Out Of
Even in states without a specific chatbot law, the FTC maintains enforcement authority under Section 5 of the FTC Act. A chatbot that deceives consumers about its nature is a federal violation regardless of state law — which is part of why most compliance guidance now recommends implementing clear AI disclosure everywhere you operate, not just in the states that have passed specific legislation.
Minor Safety Is the Fastest-Growing Requirement
A growing share of new state laws focus specifically on protections for users under 18 — age-aware design, restrictions on addictive engagement patterns, and specific prohibitions on generating sexual content involving minors. If your chatbot or AI tool could plausibly be used by anyone under 18, this is the area where new obligations are appearing fastest.
Why This Matters Even If You Didn't Build the Chatbot Yourself
Many small businesses license a chatbot rather than build one, which can create a blind spot: you may have limited visibility into exactly how the underlying AI model behaves, but you're still the business the disclosure obligation falls on. It's worth confirming directly with your chatbot vendor what disclosure and safety features are built in versus what you're expected to configure yourself.
Frequently Asked Questions
Does this apply to a simple FAQ chatbot with no AI behind it?
Most current laws are aimed at AI-driven conversational systems specifically — a rules-based FAQ widget with no generative AI is generally outside scope, but the line can be blurry with modern tools, so it's worth checking your specific vendor's technology.
My business is US-only — do I need to worry about the EU AI Act?
Only if EU residents can access and use your chatbot. If your website is genuinely geo-restricted to exclude EU traffic, Article 50 doesn't apply; if it's openly accessible, it likely does.
Is there a single set of rules I can follow to cover every state?
Not currently — the safest practical approach is implementing the strictest applicable standard (clear upfront disclosure, minor safeguards, and a crisis-response protocol) across your whole chatbot, rather than trying to vary compliance by visitor location.
Read next: Does Your Business Have to Tell Customers They're Talking to a Bot?
Where to Go From Here
Because this area is genuinely fast-moving — new state laws have been passing at a pace of roughly one every few weeks throughout 2026 — we keep the AI Compliance guides updated as the legal landscape shifts, with separate editions for the specific frameworks that matter most depending on where your customers are.
Get AI Compliance for Small Business (US Edition) →
📖 Also available on Amazon: Kindle | Paperback
This article is for educational and informational purposes only and does not constitute legal advice. State and international AI law is changing rapidly. Always verify current requirements for your specific jurisdiction and seek professional legal advice.