data center
A growing number of states now require companies to tell you when a machine is on the other side. But the laws don't agree with each other.

In March, a woman posted a video of a call she made to a hotel that left her frustrated. The booking "agent," a warm Southern voice named "Jolene," chatted with her, with background noise convincing enough to sound like she was a real person in a call center or a hotel lobby. She wasn't. When asked directly to speak with a human, Jolene insisted at first that she was a "live agent". The video hit millions of views.

There's a social media trend of people cornering customer-service and sales bots that won't admit their nature are until pressured. In one case, the agent caved when asked its birthday. And in the U.S., they don't have to admit it. At least not everywhere, and not consistently. Unlike Europe, a market that decided people have a right to know when they're talking to AI and recently wrote it into law, making disclosure mandatory or face a hefty fine.

A growing number of states now require companies to tell you when a machine is on the other side. But the laws don't agree with each other. Each covers different businesses based on who they target, and differs on when and how the disclosure has to happen. The playbook will only get harder to decipher as more AI bills move through state legislatures.

The protection depends on where you take the call

"There's a lot more law here than meets the eye," says Cameron Powell, a partner at DeepLaw, a firm that advises companies on innovation ventures like AI.

But ask him which state actually protects you, and the answer depends entirely on your zip code. "Maine's the one that actually has teeth," he told International Business Times.

Anyone using a bot to engage in trade or commerce with a consumer has to clearly disclose that the person isn't talking to a human whenever the bot could mislead them into thinking otherwise.

Violations run through the state's Unfair Trade Practices Act, which means an ordinary person can sue without waiting on an attorney general to act. "That's what we call a private right of action," Powell says. Win, and the company pays your legal fees too, which he adds is what actually gets companies to the negotiating table instead of ignoring a complaint.

Then there's Utah, which the Houston-based attorney confirms a bot only has to admit what it is if the customer thinks to ask first. "Now, who thinks to ask that of a person they think is real?" Powell explains.

"In Utah there's no prohibition at all. It can lie to you all it wants. They can take your grandma's money, as long as you haven't asked 'are you a bot?' and it said 'no, I'm a real person.'"

A rule that only kicks in when the customer gets suspicious, protecting those who think to ask and nobody else, making certain demographics, like the elderly, that much more vulnerable.

California has two separate bot statutes, and Powell says neither was built for what matters here. "One was written just to be online; it had no connection to telephones," he says. "The other was written for the answering machine, basically." Neither reaches a live voice agent having a real conversation.

"California has completely failed to deal with what's arguably the biggest risk of deception: a machine that sounds like a person and talks back," Powell argues.

California's law is also narrower because a company has to have intended to mislead, and to have intended a specific outcome from that deception. Both, he argues, are notoriously hard to prove in court.

New Jersey requires disclosure upfront, but only when a bot is selling merchandise or real estate. Everything outside those two categories isn't covered. These types of holes and design flaws are scattered throughout the country.

Underneath all of it sits the FTC, which can treat an undisclosed bot as deceptive even in states with no bot law at all. But only in a commercial context, and only if the technology's presence would actually change what a customer does. It is a mechanism, not a guarantee, and Powell says it has rarely been tested. "The FTC has never seriously tried to enforce anything against these unidentified bots.

Why the market may close what the law leaves open

If the law can't offer consistent protection, the pressure to disclose may end up coming from the market itself. It wouldn't be the first time.

In 2018, the EU enforced the General Data Protection Regulation, a move designed to safeguard European consumers that is now used as a global standard. Software companies were required to prioritize privacy in the building phase of their products, including encryption, access controls, and automated data deletion. Faced with a choice between building one privacy system that met the EU's stricter standards or a separate product for Europe alone, most chose the cost-effective route and standardized worldwide, giving you the right to delete your browsing history and limit what a website can collect about you.

A Columbia law professor called this the Brussels Effect: the EU's ability to set a rule for its own market that ends up governing everyone else's.

That same pattern is already playing out with AI. When the EU's Article 50 forced popular AI tools to redesign how they operate, most companies didn't build a separate version for Europe. They standardized the change everywhere. Anthropic's Claude made headlines doing exactly that, watermarking its output worldwide rather than only for EU users. The same past instinct to standardize rather than build a separate tool.

Michael Keany, CEO of the ad agency Redscout, thinks the industry is already moving into a new stage because of that pressure. "AI round one was about operating efficiencies and everybody loving LLMs for research," he says. "Round two is about authenticity and trust, and some economic returns."

Essentially, the first stage rewarded whoever automated the most, fastest, with the least friction. The second stage is starting to reward whoever can show a customer nothing was hidden from them.

But not everyone is convinced the market pulls in that direction. Powell's read on where some companies go next isn't a new business plan at all, but a decision about where not to operate.

"A lot of companies may say, look, we're not going to call Maine or Colorado or California at all," he says. "They're just going to prey on the states that don't protect their citizens as well."

There is more protection on the books for consumers. But right now, whether any of it reaches you comes down to which market and, in the U.S., which state you picked up the phone.