← All Reports
AI Compliance June 21, 2026 12 min read

The August 2, 2026 AI Chatbot Disclosure Deadline: A Practical SMB Compliance Playbook

California SB 942 and the EU AI Act both take effect August 2, 2026, with fines up to $2,500 per undisclosed AI conversation and €35M EU penalties. Free, this-week compliance steps for small businesses running chatbots.

If your small business has a chatbot, an AI receptionist, an SMS auto-responder, or a website form that pipes into a generative-AI assistant — you have 42 days to add one sentence to it. If you don't, you face fines up to $2,500 per undisclosed conversation in California, a $1,000 private right of action per affected user, and up to €35 million or 7% of global revenue if you sell into the EU (KIBO AI — EU AI Act Article 50; National Law Review — SB 243 Private Right of Action).

The fix is one honest sentence. The risk is that you don't know it applies to you.

What changes on August 2, 2026

Two regulations come into force simultaneously, deliberately aligned:

EU AI Act — Article 50 Transparency Rules

  • Effective date: August 2, 2026 — national enforcement begins this day (KIBO AI).
  • Who: Any organization deploying a chatbot, AI copilot, or generative-AI tool that interacts with EU residents. Geography of the business is irrelevant — if EU residents can use the bot, you're in scope.
  • Requirement: Users must be clearly informed they are interacting with an AI, not a human. Deepfakes and AI-generated content must be labelled.
  • Penalty ceiling: €35 million or 7% of global annual revenue, whichever is higher (CES Intelligence — EU AI Act Enforcement).

California SB 942 — AI Transparency Act

  • Effective date: August 2, 2026 — California explicitly moved its date to match the EU.
  • Who: Any business operating a chatbot used to communicate with California residents.
  • Requirement: "Clear and conspicuous disclosure" that the user is interacting with a bot.

California SB 243 — Already enforceable since January 1, 2026

This one is already live and most SMBs have not heard of it. SB 243 imposes a $2,500 civil penalty per undisclosed AI conversation plus a $1,000 private right of action per affected user — meaning any California resident who chats with your undisclosed AI can personally sue you (National Law Review).

Add to this: 14 U.S. states already require chatbot disclosure, and the FTC has stated that deceiving customers about whether they are talking to a bot is already illegal nationwide under existing consumer protection authority.

Who is actually exposed (probably you)

The misconception is that this law targets "AI companies." It doesn't. It targets the businesses that deploy AI to talk to customers. If any of the following describe your operation, you are within scope:

  • You have a website chat widget powered by ChatGPT, Claude, Gemini, Intercom Fin, Drift, or any of the 200+ GenAI chat vendors.
  • You run an SMS auto-responder that uses AI to draft replies (HighLevel, ManyChat, Twilio Studio + LLM, Smith.ai).
  • You have an AI phone receptionist (Loman, Goodcall, SoundHound, Air.ai, Bland.ai).
  • Your email inbox uses an AI to draft or auto-send responses to prospects.
  • Your CRM has any "AI assistant" feature that messages customers on your behalf.
  • You use AI to power a Facebook Messenger, Instagram DM, or WhatsApp Business bot.

If you checked any box and operate in California, sell to EU residents, or are in any of the 14 disclosure states — you have a compliance gap right now.

The 4-step compliance audit (free, do this week)

Step 1: Inventory every customer-facing AI surface

Open a spreadsheet. Walk every customer touchpoint: website, SMS, email, phone, social DMs, in-app chat. For each, note: (a) is AI involved in drafting the response, (b) does it auto-send or does a human approve, (c) is the user told upfront. This takes one hour for most SMBs.

Step 2: Add the disclosure to every yes-AI surface

The language doesn't have to be elaborate. The legally accepted baseline:

"You're chatting with an AI assistant. If you need a human, just type 'agent' or call (xxx) xxx-xxxx."

For chat widgets: put it in the opening message AND the placeholder text. For SMS: include it in the first message of any new conversation. For phone bots: have it said in the opening greeting. For social DMs: put it in the auto-reply trigger.

Step 3: Document your compliance trail

Screenshot every disclosure as it appears to the user. Save with the date. If you are ever sued under SB 243's private right of action, the entire defense is "we disclosed, here's proof." Without screenshots, you have no proof.

Step 4: Add an escalation path

SB 243 and the EU AI Act both require that users can reach a human when they want one. "Type 'agent'" or "press 0" or "reply STOP" — any clear off-ramp. Build it in now; it's also good UX.

The math: cost of compliance vs. cost of one lawsuit

ItemCostTime
Internal audit + disclosure rollout$0 (DIY)2–4 hours
One SB 243 private lawsuit (single plaintiff)$1,000 + legal fees3–9 months
One SB 243 class action (100 plaintiffs)$100,000+ + legal fees12–24 months
Single SB 243 civil penalty (1 conversation)$2,500
EU AI Act max penalty€35M or 7% revenue

The compliance fix is hours of work. The downside is unbounded. Every week you delay is a week of accumulating undisclosed conversations, each potentially $2,500.

Common excuses and why they fail

"My bot only handles internal employees." SB 243 covers any AI communication with a California resident, including your employees if they are CA residents. Disclose anyway.

"My bot is just FAQ canned responses." If a generative AI is involved in shaping any response, you're in scope. Pure deterministic decision trees (literally hardcoded if/then) are not in scope, but virtually no modern chatbot is purely deterministic.

"We're a B2B business, this doesn't apply." SB 942 and the EU AI Act don't carve out B2B. Any human interacting with your bot is a "user." Procurement managers count.

"We disclose in our Terms of Service." Both SB 942 and SB 243 specify clear and conspicuous disclosure — buried in a 40-page ToS does not qualify. The disclosure must be at the point of interaction.

42 days. One sentence. Decide today.

Audit your AI surfaces this week. Add the disclosure to every one of them. Screenshot the proof. Add a human escalation path. Total cost: zero dollars. Total time: an afternoon.

If you'd rather have a documented compliance memo with vendor-specific disclosure copy, screenshots, and an attorney-reviewable audit trail — that's exactly what the Standard Sprint package delivers in 24 hours.

Need this implemented?

Get a decision-grade memo on this — by tomorrow.

Send a brief by 5pm. Get a board-ready memo in 24 hours. Powered by Council Mode — 20+ AI models cross-checked on every recommendation.

Standard Sprint — $1,750 / 24hr Same-Day Rush — $2,550 / 12hr ⚡ Monthly Research Desk — $5,000/mo

See all strategy packages →