The short version
- Disclosure duties attach to where the customer is, not where your server is. California's bot statute reaches any person using a bot to communicate with "another person in California online"; Maine's reaches any chatbot used in trade or commerce with a Maine consumer.
- Labelling the bot buys you nothing on accuracy. The disclosure statutes address deception about identity. What the bot then says is judged under the same rules as anything else your business publishes.
- In Moffatt v. Air Canada (2024 BCCRT 149) the tribunal called the argument that a chatbot is "a separate legal entity that is responsible for its own actions" a remarkable submission, and held the airline responsible for all the information on its website however it was delivered.
- A bot can form a contract. E-SIGN, 15 U.S.C. § 7001(h), preserves the validity of records created by electronic agents "so long as the action of any such electronic agent is legally attributable to the person to be bound" — and it is your agent.
A support bot on a marketing site raises two problems that have nothing to do with each other. One is a labelling rule: must the customer be told they are not speaking to a person? The other is an attribution rule: when the bot says something wrong, whose statement is it? Businesses spend their compliance attention on the first. Every reported loss so far has come from the second.
The disclosure rule follows the customer, not the server
California's bot statute, in force since July 2019, makes it unlawful for any person to use a bot "to communicate or interact with another person in California online, with the intent to mislead the other person about its artificial identity for the purpose of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction or to influence a vote in an election". The connecting factor is the customer's location. Hosting in Ohio and incorporating in Delaware changes nothing.
It is also narrower than its reputation. It needs intent to mislead about artificial identity and a purpose of deceiving about content and a commercial or electoral objective. A bot plainly labelled as a bot falls outside it, because the section says a person is not liable if they disclose that it is a bot. The ten-million-visitor figure people quote at each other comes from the definition of "online platform", which the prohibition never uses — that definition does work only in the carve-out for platform service providers, not in the rule itself. Size is not a defence.
How hard each regime pushes on the label
No rule on point
Only if you meant to deceive
On the customer's request
By design, first message
Maine took the intent requirement out. Title 10, section 1500-DD prohibits using an AI chatbot in trade or commerce "in a manner that may mislead or deceive a reasonable consumer into believing that the consumer is engaging with a human being unless the consumer is notified in a clear and conspicuous manner that the consumer is not engaging with a human being", and a breach is a breach of the Maine Unfair Trade Practices Act. Utah's Artificial Intelligence Policy Act, as amended in 2025, sets a lighter default — disclose when a consumer clearly and unambiguously asks — but requires it up front for high-risk interactions: those gathering sensitive financial, health or biometric data, or giving personalised advice a person might reasonably act on.
Article 50(1) of the EU AI Act has applied since 2 August 2026. It requires that systems intended to interact directly with people be designed so that people are informed they are dealing with an AI system, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". Note who carries it: that obligation sits on the provider of the system, not on the shop that bought it. If you licensed the bot, the design duty is your vendor's — which makes it a question about your SaaS agreement rather than about your website.
A linked policy page is not a disclosure
Every one of these rules asks where the notice sits, not whether it exists somewhere. California requires the disclosure to be "clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot". Maine requires notification "in a clear and conspicuous manner". The EU requires the information "at the latest at the time of the first interaction". A sentence in your privacy policy satisfies none of them — the person the rule protects never opened it.
- In the widget, before the first reply. Header text inside the chat panel, present when it opens — not appended after the customer has already asked.
- Not in the persona. A human first name and a headshot is the fact pattern these statutes were written about. If you want a name, pair it with a visible machine label.
- On the handover, both ways. If a human takes over, say so; if the human hands back, say that too. A conversation that silently changes hands is the version a regulator finds interesting.
- In voice, audibly. Maine's definition covers programs simulating conversation "through textual or aural communications". A phone agent needs a spoken disclosure.
"The bot said it" has already failed as a defence
The reference point is Moffatt v. Air Canada, a 2024 decision of British Columbia's Civil Resolution Tribunal. A customer asked the airline's chatbot about bereavement fares. The bot told him he could book at full price and apply for the reduced fare within ninety days. That was wrong; the airline's own policy page said the opposite. Air Canada argued that the chatbot was, in the tribunal's summary, "a separate legal entity that is responsible for its own actions". The tribunal called this a remarkable submission and rejected it: "It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot."
The detail worth carrying away is the one about the link. The bot's answer contained a hyperlink to the correct policy page. It did not save the airline. "There is no reason," the tribunal said, "why Mr. Moffatt should know that one section of Air Canada's webpage is accurate, and another is not." The claim succeeded in negligent misrepresentation — no contract needed, just a duty of care arising from the commercial relationship, an inaccurate statement, and reasonable reliance. The award was around C$650. The precedent is worth considerably more than that.
Some legislatures have written the point into statute. Utah's Act removes the argument directly: a supplier cannot escape a consumer-protection violation on the basis that the offending statement came from generative AI. That is the same conclusion the tribunal reached, converted into a rule that does not need litigating.
Labelling and accuracy are independent axes
Was it labelled a bot
What the bot said
Accurate
Wrong
Labelled
Nothing to answer for
The disclosure statutes are satisfied and there is no misstatement to attribute.
Labelled and still liable
Misrepresentation and consumer-protection exposure are untouched by the label. This is where most operators actually sit.
Unlabelled
Technical exposure only
A disclosure breach with no reliance and no loss. Regulator interest, not damages.
Both at once
The disclosure breach becomes the unfair-practice predicate, and the wrong answer supplies the damage.
Can it form a contract, or only a misrepresentation?
Both, and the routes are different. Moffatt was decided in tort — the customer never had a contract at the bereavement fare. Contract formation is governed in the United States by the Uniform Electronic Transactions Act, adopted in almost every state. Section 14 provides that a contract may be formed by the interaction of an electronic agent and an individual, and that a contract between two electronic agents is good "even if no individual was aware of or reviewed the electronic agents' actions or the resulting terms and agreements". The federal E-SIGN Act adds the hinge in 15 U.S.C. § 7001(h): such a record keeps its legal effect "so long as the action of any such electronic agent is legally attributable to the person to be bound".
Attribution is where the argument is, and it is a weak place to stand. Under UETA an electronic record is attributable to a person "if it was the act of the person" — and a bot you chose, configured, connected to your catalogue and published on your own domain is your act. The realistic defences are narrower and structural: that a price quoted in chat was an invitation to treat rather than an offer, that the order was subject to your acceptance, and that the customer knew the figure was an error. All three depend on your terms of service actually saying so and your checkout actually working that way.
Put the clause where it has to live
The website terms of use template carries the accuracy, order-acceptance and pricing-error provisions the chatbot questions turn on, so you can see what your current page is missing rather than guessing.
What the terms of use can and cannot do
A chatbot clause is worth writing, provided you are honest about its range. It can define what the bot is authorised to do, reserve acceptance of orders to a later confirmation, and set a precedence rule so that published policy pages govern where they conflict with anything said in chat. It cannot make an unincorporated disclaimer bind a consumer who never saw it, and it cannot remove statutory consumer rights in the customer's own jurisdiction.
Two supporting documents matter as much. The transcript is personal data and usually leaves for a vendor, so the privacy policy has to name that processing and the retention period. And the vendor contract decides whether you can pass the loss on — accuracy warranties in bot suppliers' agreements are usually thin. Which legal pages a site actually needs covers how these fit together.
Controls, cheapest first
What each control actually buys
- An afternoon
Label it, first message
Clears California, Maine and Utah in one change, and moves the EU duty onto the provider where it belongs.
- Low
Ground it in your own pages
Answers drawn from published policy text, refusing where there is no source. Removes the invented-policy failure entirely.
- Moderate
Fence the money topics
Refunds, fares, eligibility and pricing route to a human or to a link. These are the answers people rely on and then sue about.
- Ongoing
Log and retain transcripts
Without the log you cannot prove what was said, and the customer's screenshot becomes the only evidence.
None of these is a legal control. They are the operational reasons the legal question never arises.
Before the bot goes live
- Open the widget as a customer would and confirm the machine label is visible before you type anything.
- Ask the three questions most likely to cost you money — refunds, eligibility, price — and read the answers against your published pages.
- Confirm the handover to a human is announced, and the handover back.
- Check the vendor agreement for an accuracy warranty and an indemnity. Assume there is neither until you find them.
The uncomfortable part is how ordinary this is. Nothing in Moffatt turned on the technology. The tribunal applied a tort older than the internet to a company that had published two contradictory statements and expected the customer to reconcile them. The label on the widget is a compliance task you can finish this week. Making sure the bot cannot say something your published pages do not say is the actual work, and no statute will tell you when you have finished it. AI clauses in client contracts covers the mirror image, where the AI use is yours and the exposure is your client's.
Sources
- California Business and Professions Code § 17941 (bot disclosure)
- 10 M.R.S. § 1500-DD — required disclosure of AI chatbot use — Maine Legislature
- Utah scales back reach of generative AI consumer protection law — Davis Polk
- EU AI Act Article 50 — transparency obligations
- 15 U.S.C. § 7001(h) (E-SIGN, electronic agents) — Cornell LII
- UETA § 14 as enacted — Minn. Stat. § 325L.14 (automated transactions)
- Moffatt v. Air Canada, 2024 BCCRT 149 — case note, McCarthy Tétrault
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Do I legally have to say my chatbot is AI?
It depends where your customer is. Maine requires clear and conspicuous notice whenever a reasonable consumer might think they are talking to a person. Utah requires it on request, and up front for high-risk interactions. California only prohibits bots used with intent to mislead about their artificial identity for commercial or electoral purposes. Labelling the bot satisfies all three at once.
Is my business responsible for wrong information a chatbot gives?
Treat it as yes. In Moffatt v. Air Canada the tribunal held that a company is responsible for all the information on its website, whether it comes from a static page or a chatbot, and rejected the argument that the bot was a separate legal entity. The claim succeeded in negligent misrepresentation, which needs a duty of care, an inaccurate statement and reasonable reliance — not a contract.
Does a disclaimer in my terms of use protect me?
Only partly, and only if it was properly incorporated. A disclaimer can help establish that a quoted price was not an offer and that orders are subject to your acceptance. It does not reliably exclude liability for misstatements to consumers, because most consumer-protection regimes treat that exclusion as unenforceable. A term the customer never saw before contracting is weaker still.
Can a chatbot form a binding contract on my behalf?
Yes, in principle. Under the Uniform Electronic Transactions Act a contract may be formed by the interaction of an electronic agent and an individual, and the federal E-SIGN Act preserves the validity of records created by electronic agents where the agent's action is legally attributable to the person to be bound. A bot you configured and published on your own domain is normally attributable to you.
Where does the disclosure have to appear?
Inside the conversation, at the start. California requires a disclosure that is clear, conspicuous and reasonably designed to inform the people the bot interacts with. Maine requires clear and conspicuous notification. The EU AI Act requires the information at the latest at the time of the first interaction. A line buried in a privacy policy or a linked page does not meet any of those standards.