Home  ›  Blog  ›  Risk and Compliance
Risk and Compliance

Do I Have to Tell Customers I Am Using AI?

Short answer

Usually no. No United States law requires labeling AI-drafted emails, captions, or web copy. Disclosure is legally required in narrower cases: fake reviews and testimonials, bots used to sell in California, and automated systems used in consequential decisions in states that regulate them. Disclose whenever a customer would otherwise believe they are talking to a person or looking at a real photograph.

Key Takeaways
  • There is no general federal AI labeling law, but Section 5 of the FTC Act still prohibits deception, and that covers anything a customer would be misled by.
  • The FTC rule on consumer reviews and testimonials, 16 CFR Part 465, took effect October 21, 2024 and expressly covers AI-generated fake reviews, so AI may help you reply to reviews but never write one.
  • California's Bot Disclosure Act requires a clear and conspicuous notice when a bot communicates online to incentivize a sale, and Wisconsin businesses that sell online reach California customers too.
  • Disclose when a customer would otherwise believe they are talking to a person or looking at a real photograph, and always pair the disclosure with a way to reach a human.
  • Never publish AI-generated images of property, food, or completed work that a customer could buy, because that is a deception claim regardless of AI labeling law.
  • A one-page internal AI policy naming approved tools, forbidden inputs, review requirements, and one sign-off person prevents most disclosure failures.

Do you have to tell customers you are using AI? In most everyday small business uses, no. No United States law requires you to put a label on an AI-drafted email, a social caption, or a first draft of your website copy. What the law does require is that you not deceive anyone, and that is where AI trips businesses up: you cannot publish AI-written reviews as if real customers wrote them, you cannot run a chatbot that pretends to be a human while it tries to sell something in California, and you cannot repeat a claim about your product just because a model produced it.

This guide covers where disclosure is legally required, where it is merely smart, and how to word it so it builds trust instead of setting off alarms. It is general information for business owners, not legal advice, and if you operate in a regulated field you should run your language past your attorney.

Is There a General Law That Says I Must Disclose AI Use?

There is no federal statute that says "label your AI." There is Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, and that is the rule that actually governs most of what a small business does with AI. The question regulators ask is not "did a machine write this" but "would a reasonable customer be misled."

A definition first, because the word gets used loosely. AI disclosure means telling a person that content they are reading, or an entity they are talking to, was generated or operated by software rather than a human. That is different from an AI policy, which is your internal rulebook for how your team uses these tools.

Under the deception standard, the practical test comes down to three questions:

  • Is anyone being told something false? An AI-written blog post about your roofing process is not false. An AI-written five-star review signed with an invented customer name is.
  • Does the person believe they are talking to a human? If your chat widget is named Sarah and answers in the first person with no indication it is software, you have created a belief you need to correct.
  • Would knowing change their decision? A customer who learns your newsletter was drafted with AI shrugs. A patient who learns the treatment summary they relied on was generated without a clinician reading it does not.

Where Is AI Disclosure Actually Required by Law?

Four situations carry real legal weight for a small business: fake reviews and testimonials, bots used to sell in California, automated systems used in consequential decisions in states that regulate them, and regulated professions with their own rules. Everything else is a judgment call.

Reviews, Testimonials, and Endorsements

This is the one most likely to bite a local business. The Federal Trade Commission's Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, took effect on October 21, 2024. It prohibits creating, buying, or selling reviews and testimonials that misrepresent that they came from someone who does not exist or who never actually used the product or service. The FTC's announcement specifically named AI-generated fake reviews as covered conduct. The rule carries civil penalties, and the maximum the FTC cited when it finalized the rule was $51,744 per violation.

Read that as a bright line: AI may help you reply to reviews. AI may never write a review. More on the practical side of that in our guide to using AI for reviews and reputation without sounding fake.

Chatbots That Try to Sell in California

California's Bot Disclosure Act, Business and Professions Code sections 17940 through 17943, has been operative since July 1, 2019. It makes it unlawful to use a bot to communicate with a person online, with intent to mislead about the bot's artificial identity, in order to incentivize a purchase or sale of goods or services (or to influence an election vote). The statute says the disclosure must be "clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot." Disclose properly and you are protected from liability under that chapter.

Wisconsin has no equivalent statute. But if you sell online, some of the people typing into your chat widget live in California, and one sentence solves the whole problem.

Automated Decisions About People

If software helps you decide who gets hired, housed, insured, or lent money, a growing set of state laws apply. Colorado passed the first comprehensive version, Senate Bill 24-205, in 2024. It was delayed repeatedly and then repealed and replaced: Governor Polis signed Senate Bill 26-189, "Automated Decision-Making Technology," on May 14, 2026. The replacement requires clear notice at the point of interaction with a covered system, plain-language explanations to consumers within 30 days of an adverse outcome, and a right to request human review, with the developer and deployer documentation duties phasing in later rather than immediately.

Most Walworth County businesses are not covered. But if you use an AI resume screener, that is exactly the category these laws describe, so keep an eye on it.

Regulated Professions

Medical, dental, legal, financial, and insurance practices have their own disclosure and supervision expectations, and several states have added rules about AI-generated communications with patients. If you run a dental office in Elkhorn or a financial practice in Delavan, ask your professional association and your carrier before you automate anything that touches a patient record or a recommendation.

What Should I Disclose Even When the Law Does Not Require It?

Disclose the two things customers would feel misled about if they found out later: when they are talking to software instead of a person, and when a real-looking image, voice, or person is synthetic. Almost everything else is production work nobody needs a footnote for.

Here is the split we use with clients:

  • Disclose: chat widgets and phone answering systems that use AI; AI-generated images that look like real photos of your property, food, staff, or completed work; AI-generated voices in ads or voicemail greetings; automated replies sent outside business hours; any AI system that screens or scores a person.
  • No disclosure needed: AI helping draft a blog post, email, or caption that a human edits and approves; AI summarizing your own meeting notes; AI categorizing your bookkeeping; AI translating your menu; AI cleaning up or resizing your own photos.
  • Never do it at all: AI-written reviews or testimonials, AI-invented statistics or credentials, AI-generated before and after photos of work you did not do, or a synthetic voice or likeness of a real person without their written permission.
Hard line: The fastest way to turn an AI question into a legal problem is a photo. If you post an AI-generated image of a lakefront patio, a finished roof, or a plated dinner that does not exist, and a customer books based on it, that is a deception claim regardless of what any AI-labeling law says. Use your own photos for anything a customer could buy.

How Do I Word an AI Disclosure Without Scaring People?

Keep it short, put it where the interaction happens, and pair it with the human escape hatch. Customers do not object to AI, they object to being stuck with it. A disclosure that also tells them how to reach a person reads as service, not as a warning label.

Language you can copy and adapt:

  • Chat widget opener: "Hi, I am an automated assistant for Lakeside Landscaping. I can answer questions about services, pricing, and scheduling. Type the word person at any time and I will pass you to Dana."
  • After-hours auto reply: "Thanks for writing. This reply is automated. A member of our team reads every message and will respond by 10 a.m. on the next business day."
  • Phone system: "You have reached the automated scheduling line. Say front desk at any time to reach a person."
  • Website footer or About page line: "We use AI tools to help draft content and answer routine questions. A person on our team reviews and approves everything we publish."
  • Image credit: "Illustration generated with AI." Put it in the caption, not buried in the terms of service.

Three things to avoid. Do not give the bot a human first name and a headshot. Do not write "powered by advanced artificial intelligence technology," which says nothing useful to anyone. Do not bury the disclosure in a policy page nobody opens, because the FTC standard is clear and conspicuous, which means at the point of interaction.

What Does This Look Like for a Lake Geneva Business?

Picture a dental office in Elkhorn with two dentists, a hygienist team, and one very busy front desk. They want AI to handle after-hours questions, draft recall reminders, and help respond to Google reviews. Here is where each piece landed after a disclosure review.

  • The website chat widget got a disclosure and a name change. It had been called Ask Ashley. It is now the Automated Scheduling Assistant, it opens with one sentence saying it is automated, and it hands off to a person on request or after two failed answers.
  • Recall reminders got no disclosure. They are template messages the office manager approves each month. AI drafted the wording once. Nobody is misled.
  • Review responses got no AI label but a strict rule. AI drafts, the office manager edits and posts under her own name, and no reply ever references clinical details.
  • The chatbot got a hard content boundary. It answers hours, insurance accepted, location, and appointment availability. It refuses anything clinical and says so: "I cannot answer questions about symptoms or treatment. I can get you to our team." That is disclosure doing real work.
  • The intake form summarizer got a patient-facing notice. Because it touches health information, the practice added a line to the intake page and confirmed the vendor terms with their attorney before turning it on.

Total time to write and approve all of it: about two hours. The escape hatch cut complaints immediately, because the previous version pretended to be a person named Ashley and patients got angry when Ashley could not look up their appointment.

What Should Go in My Written AI Policy?

A one-page internal policy prevents most disclosure problems, because the failures come from a well-meaning employee, not from a strategy meeting. The National Institute of Standards and Technology's AI Risk Management Framework organizes this work into four functions (Govern, Map, Measure, and Manage), and for a small business the Govern function mostly means writing down who is allowed to do what.

  1. Approved tools. Name the specific tools your team may use (for example ChatGPT, Claude, Gemini, or Microsoft Copilot on your business account) and say that personal free accounts are not approved for company work.
  2. What never goes into a prompt. Customer payment data, health information, employee records, anything under an NDA. Our post on whether it is safe to put customer data into AI tools covers the settings behind this.
  3. What always gets human review. Anything published publicly, anything that quotes a number or a price, anything sent to more than ten people.
  4. Who signs off. One named person per channel. Not "the team."
  5. The disclosure standard. Copy your chat, phone, and image language straight into the policy so nobody has to invent it under pressure.
  6. The prohibited list. No AI-written reviews or testimonials. No synthetic photos of work or property. No AI-generated credentials, awards, or statistics. No AI voice or likeness of a real person without written permission.

Do This This Week

  1. Open your website on a phone and interact with your own chat widget. Write down whether a stranger would know it is software from the first message.
  2. Add one sentence of disclosure plus a human handoff instruction to that widget and to your after-hours auto reply.
  3. Audit your last 20 published images. Flag any that are AI-generated or heavily AI-edited and that show something a customer could buy. Replace them with real photos.
  4. Search your Google Business Profile, website, and social accounts for any review or testimonial you cannot trace to a named real customer. Remove it.
  5. Write the one-page AI policy using the six items above. One page, this week, not next quarter.
  6. Send it to your team with the two rules that matter most: no AI-written reviews, and nothing gets published that a person has not read.
  7. If you are in a regulated field or you use AI in hiring, put a 20-minute call with your attorney on the calendar before you expand anything.

Where to Go From Here

The decision is simpler than the legal landscape makes it look. Disclose when someone would otherwise believe they are talking to a person or looking at a real photograph. Never fabricate a review, a credential, or a customer. Keep a human name on anything you publish. Do those three things and you are ahead of most businesses in Walworth County, and comfortably inside what the FTC, California, and the emerging state laws are actually aiming at.

If you want a second set of eyes on where AI already touches your customer conversations, our AI Opportunity Audit maps every automated touchpoint in your business and flags the ones that need a disclosure line. If you are earlier than that, the free Local Visibility Audit on our homepage will at least tell you what customers see when they search for you. Either way, write the one-page policy first. It costs nothing and it prevents the expensive version of this conversation.

Sources and Further Reading

  1. 16 CFR Part 465: Trade Regulation Rule on the Use of Consumer Reviews and Testimonials (Final Rule). Federal Trade Commission, August 2024.
  2. 16 CFR Part 465: Rule on the Use of Consumer Reviews and Testimonials. Electronic Code of Federal Regulations, current.
  3. California Business and Professions Code, Division 7, Part 3, Chapter 6: Bots. California Legislative Information, operative July 2019.
  4. SB24-205 Consumer Protections for Artificial Intelligence. Colorado General Assembly, 2024.
  5. SB26-189 Automated Decision-Making Technology. Colorado General Assembly, signed May 2026.
  6. AI Risk Management Framework. National Institute of Standards and Technology, 2023.
  7. Prohibited and Restricted Content, Maps User Generated Content Policy. Google, current.
Questions

Frequently Asked

Do I legally have to label AI-written blog posts or social captions?

No United States law requires it. A blog post or caption that a person reviews, edits, and stands behind is your content regardless of what drafted it. The legal risk is not the tool, it is the claim: if the draft contains a statistic, credential, price, or promise you cannot back up, that is deceptive whether a human or a model wrote it. Read every published word before it goes out.

Does my website chatbot have to say it is a bot?

In California, yes, if it communicates with a person online with intent to mislead about its artificial identity in order to incentivize a purchase or sale. Wisconsin has no such statute, but online customers cross state lines, and one sentence removes the question entirely. Open with a plain line saying the assistant is automated, and tell people how to reach a person.

Can I use AI to write my own customer reviews or testimonials?

No. The FTC rule on consumer reviews and testimonials, effective October 21, 2024, prohibits creating reviews that misrepresent that they came from someone who does not exist or who never used the product, and the FTC named AI-generated fake reviews specifically. Penalties are civil and assessed per violation. Use AI to draft your replies to real reviews, never to manufacture the reviews themselves.

Do I have to tell job applicants I use AI to screen resumes?

It depends on where you and the applicant are. Several states now regulate automated systems used in consequential decisions such as employment, with requirements for notice at the point of interaction, an explanation after an adverse outcome, and a right to human review. Colorado's replacement law, Senate Bill 26-189, signed in May 2026, is the current template. Ask your attorney before you screen with software.

No Cost · No Obligation

See Exactly Where You Stand Online

Get a free Lake Geneva Local Visibility Audit. We will show you where you stand on Google, AI search, listings, reviews, and social, plus what to fix first.