New AI Chatbot Laws in 2026: What Your Business Needs to Know

78 AI chatbot bills across 27 states. A federal preemption deadline on March 11. Here's what actually applies to your business chatbot and how to stay compliant.

Cover Image for New AI Chatbot Laws in 2026: What Your Business Needs to Know

78 AI chatbot safety bills have been introduced across 27 US states in 2026. California's Companion Chatbots Act is already in effect. Oregon just passed its own chatbot safety bill on March 5. And the federal government has a March 11 deadline to publish its evaluation of which state AI laws it considers unconstitutional.

If you operate a chatbot on your website, you need to know which of these laws apply to you, what they require, and what you need to do about it.

This guide breaks down the 2026 chatbot regulatory landscape, separates the laws that affect business chatbots from those targeting companion AI, and provides a practical compliance checklist.

Update (June 17, 2026): Since this post was published, Colorado repealed its original AI Act (SB 24-205) and replaced it with a narrower disclosure law, SB 189 — signed May 14, 2026 and effective January 1, 2027, not June 30, 2026. The new law drops the impact-assessment regime and focuses on transparency and consumer rights for automated systems that influence consequential decisions. For the current rules and what they mean for your chatbot, see Colorado Repealed Its AI Act — What Replaces It. The Colorado entries below have been corrected; the rest reflects the landscape as of March 2026.

The Critical Distinction: Companion Chatbots vs. Business Chatbots

Before you panic about 78 bills, understand this: most of the high-profile chatbot legislation targets a specific category called "companion chatbots" -- AI systems designed to simulate friendship, emotional connection, or therapeutic communication with users.

California's SB 243, the most significant chatbot law currently in effect, explicitly excludes bots used for:

  • Customer service
  • Business operational purposes
  • Productivity and analysis
  • Internal research
  • Technical assistance

If your chatbot answers product questions, captures leads, or handles support tickets, it is a business chatbot, not a companion chatbot. That distinction matters because it determines which laws apply to you.

That said, several states have passed or proposed broader disclosure laws that apply to all AI-powered chatbots, including commercial ones. You cannot ignore the regulatory landscape just because your chatbot is not a companion app.

State Laws That Apply to Business Chatbots

Here is what is currently in effect or imminent across key states.

Disclosure Laws (Apply to Commercial Chatbots)

StateLawEffectiveKey Requirement
MaineChatbot Disclosure ActSep 2025Notify users they are not interacting with a human
ColoradoSB 189 (replaced SB 24-205)Jan 1, 2027Notice + consumer rights for automated decisions (not a blanket chatbot rule)
CaliforniaAB 489Jan 2026Prohibits AI from claiming healthcare licenses; requires disclosure in patient communications

Maine's law is the simplest and most broadly applicable: if you use an AI chatbot that interacts with consumers, you must tell them it is not a human. Colorado's original AI Act took a similar disclosure approach, but as noted above it has since been repealed and replaced by SB 189, which narrows the rules to automated systems that materially influence consequential decisions rather than every chatbot interaction.

Companion Chatbot Laws (Narrower Scope)

StateLawEffectiveApplies to Business Chatbots?
CaliforniaSB 243Jan 2026No -- explicitly excludes customer service and business bots
OregonSB 1546Pending governor signatureTargets companion chatbots; business chatbot scope TBD
UtahHB 4522026No -- targets AI mental health chatbots specifically
IllinoisWOPRA2026No -- restricts autonomous AI in clinical practice

These laws impose strict requirements -- suicide prevention protocols, minor protections, three-hour usage reminders, bans on engagement-maximizing design patterns -- but they apply to companion and therapeutic chatbots, not to a business FAQ bot on your website.

The important caveat: if your chatbot blurs the line between business tool and companion (for example, a chatbot that encourages extended personal conversations rather than resolving queries), you may fall under the broader definition. Keep your chatbot focused on its business purpose.

Federal Landscape: The Preemption Battle

The federal government is not writing its own chatbot law. Instead, it is trying to limit what states can do.

Executive Order (December 2025)

President Trump signed an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence" that sets up a potential collision between federal and state regulators:

  • Commerce Department evaluation (due March 11, 2026): The Secretary of Commerce must identify state AI laws that may be unconstitutional or that "burden interstate commerce." This evaluation could challenge state disclosure requirements.
  • FTC policy statement (due March 11, 2026): The FTC is directed to clarify how existing consumer protection law applies to AI chatbots.
  • AI Litigation Task Force: A new DOJ task force will challenge state AI laws deemed inconsistent with federal policy.

What Is Protected from Preemption

The executive order explicitly protects state laws related to:

  • Child safety
  • AI compute and data center infrastructure
  • State government procurement and use of AI

This means the companion chatbot laws focused on child safety (California SB 243, Oregon SB 1546) are likely safe from federal challenge. Commercial disclosure requirements like Maine's are the ones most at risk.

Federal Bills in Progress

BillStatusKey Provision
CHAT Act (S.2714 / H.R.7218)In committeeAge verification for companion chatbots; parental consent for minors; 60-minute popup reminders
GUARD Act (S.3062)In committeeWould ban minors from using AI companion chatbots entirely

Neither has passed, but both signal the direction of federal thinking: heavy focus on minors, less interest in regulating commercial chatbot interactions.

What This Means for Your Business Chatbot

If you run a chatbot on your website for customer support, sales, or lead generation, here is the practical summary:

You are likely subject to:

  • State disclosure laws requiring you to tell users they are interacting with AI (Maine is active now; Colorado's revised law, SB 189, applies January 1, 2027)
  • General consumer protection law (FTC Act) prohibiting deceptive practices -- an AI chatbot that pretends to be human is deceptive

You are likely not subject to:

  • Companion chatbot laws (SB 243, SB 1546) as long as your chatbot serves a business function
  • Minor-specific protections, unless your chatbot is designed for or likely to be used by children

You should prepare for:

  • More states passing disclosure laws in 2026-2027
  • Potential federal standards that could either simplify or complicate the patchwork
  • Increased FTC scrutiny of AI chatbots that make false or misleading claims

Compliance Checklist for Business Chatbot Operators

Here is what to do right now, regardless of which state your customers are in. These steps align with the direction of every current and proposed law.

1. Disclose That Your Chatbot Is AI

This is the single most universal requirement. Make it clear to users that they are interacting with an AI, not a human.

How to do it:

  • Name your chatbot something that signals AI (e.g., "AI Assistant," "Support Bot")
  • Include a disclosure message in the chatbot's greeting: "I'm an AI assistant trained on [Company]'s knowledge base. How can I help?"
  • Display an "AI" or "Bot" label in the chat interface

On Agentkit, you control the chatbot's name, avatar, and initial greeting message. Set these to make the AI nature clear. The widget itself can be configured with a custom welcome message that includes your disclosure.

2. Keep Your Chatbot Focused on Its Business Purpose

The more your chatbot stays within its defined scope -- answering product questions, capturing leads, handling support -- the less likely it is to fall under companion chatbot regulations.

Practical steps:

  • Use Q&A pairs to control responses to sensitive topics
  • Configure your chatbot's system prompt to redirect off-topic conversations back to business queries
  • Review conversation logs regularly for conversations that drift outside your intended scope

Agentkit's prompt engineering features let you define clear boundaries for what your chatbot should and should not discuss.

3. Implement Domain Restrictions

If your chatbot is embedded on your website, restrict it to your domain. This prevents your chatbot from being embedded on unauthorized sites where the context (and therefore the regulatory exposure) is different.

Agentkit includes domain restrictions on all plans. Set them in your chatbot's settings to ensure the widget only loads on your approved domains.

4. Log Conversations

Every proposed law includes some form of accountability. Conversation logs are your evidence of compliance and your early warning system for problems.

Track:

  • Total conversation volume
  • Topics discussed (are conversations staying on-topic?)
  • Any conversations involving sensitive content
  • User satisfaction signals

Agentkit provides conversation logs and analytics on all plans. Use them to audit your chatbot's behavior regularly.

5. Add Human Escalation

Multiple laws and regulatory frameworks emphasize the right of consumers to reach a human. Even if your state does not require it, offering escalation is good practice and reduces regulatory risk.

Options:

  • Include a "Talk to a human" button or trigger phrase
  • Configure your chatbot to suggest human contact for complex issues
  • Display business hours and contact information within the chat

6. Review Your Data Handling

AI chatbot conversations generate personal data. Depending on your jurisdiction, you may need to:

  • Disclose what data your chatbot collects (names, emails, chat transcripts)
  • Provide a mechanism for users to request deletion of their data
  • Ensure chat data is stored securely

If you use Agentkit's lead capture feature, the data collected (name, email, phone, custom fields) should be covered by your privacy policy.

State-by-State Quick Reference

If you do business in these states, here are your specific obligations:

StateWhat You Must DoDeadline
All statesDo not let your chatbot pretend to be human (FTC Act)Now
MaineNotify consumers they are interacting with AINow
CaliforniaDisclose AI in healthcare communications (AB 489)Now
ColoradoNotice + human review for automated decisions (SB 189, replaced SB 24-205)Jan 1, 2027
More statesMonitor -- 78 bills are pending across 27 statesOngoing

For businesses operating nationally, the safest approach is to comply with the strictest current standard (Maine's disclosure requirement) across all states. Adding a clear "This is an AI assistant" disclosure costs nothing and protects you everywhere.

The Bottom Line

The regulatory environment for AI chatbots is moving fast, but the core requirement is simple: be transparent. Tell users they are talking to AI. Keep your chatbot focused on business tasks. Log your conversations. Offer human escalation.

If you are running a business chatbot -- not a companion or therapeutic chatbot -- the current laws are manageable. The main risk is not the regulations themselves, but being caught off guard when your state passes a new disclosure requirement or the federal landscape shifts after March 11.

The businesses that treat compliance as a feature rather than a burden will be the ones that build user trust while their competitors scramble to catch up. A chatbot that clearly identifies itself as AI, stays on topic, and escalates to humans when needed is not just compliant. It is a better chatbot.

Build your chatbot for free →

No credit card required.

Empieza gratisNo se requiere tarjeta de crédito