AI Calling Compliance · Updated 16 July 2026

AI Caller Disclosure Laws: What You Must Tell People (2026)

No general United States law requires an AI voice agent to announce that it is an AI. The FCC proposed that rule and never adopted it. What federal law does require on an artificial-voice call is narrower and older: identify the business responsible for the call, and give a working callback number.

The precise position as of July 2026: 47 C.F.R. § 64.1200(b)(1) requires an artificial or prerecorded voice message to state clearly, at its beginning, the identity of the entity responsible for initiating the call, and § 64.1200(b)(2) requires a callback number during or after the message. Those rules reach AI voice calls because FCC Declaratory Ruling FCC 24-17(released 8 February 2024) held that AI-generated voices are “artificial” voices under the TCPA. The AI-identity requirement people expect — saying the words this call uses AI — sits in FCC 24-84, a Notice of Proposed Rulemaking released 8 August 2024. Its comment cycle closed on 25 October 2024. It has not been adopted, so it binds nobody.

AI-identity disclosure is mandatory elsewhere, and the map is jurisdictional rather than federal: Article 50(1) of the EU AI Act from 2 August 2026, California’s AB 3030 for health-care communications since 1 January 2025, California’s SB 243 for companion chatbots since 1 January 2026, and Utah’s AI Policy Act whenever a consumer asks. If you call into the EU, you disclose. If you call US consumers outside those niches, you identify the caller and the purpose — which is what the law asks for, and what a person on the other end deserves regardless.

Two questions that keep getting merged

A statement telling a person that they are interacting with an artificial intelligence system rather than a human. On calls it is distinct from caller identification: 47 C.F.R. § 64.1200(b)(1) compels an artificial-voice call to identify the business responsible for it, while a duty to disclose the AI identity itself arises only under specific instruments such as Article 50(1) of the EU AI Act.

Almost every confusion in this area comes from collapsing two separate duties into one. They have different sources, different triggers, and different answers.

  • Caller identification — who is calling and why. In force now, federally, for every artificial-voice call, under 47 C.F.R. § 64.1200(b). This is not an AI rule. It predates AI voice by decades and applies to a 1995 answering-machine recording identically.
  • AI-identity disclosure — that the voice is a machine. Not a general federal duty. Proposed in FCC 24-84 and still pending. Mandatory under the EU AI Act from 2 August 2026, and under a handful of US state statutes with narrow subject-matter scope.

The practical consequence is that a US-only B2B calling operation that identifies its caller correctly is already compliant with the federal disclosure regime today, while the same operation calling a prospect in Dublin on 3 August 2026 is not, unless it says it is an AI. Same script, same software, different obligation — because obligation follows the recipient.

What US federal law requires on the call today

The operative rule is 47 C.F.R. § 64.1200(b), and it has three prongs. FCC 24-17 is what pulls AI voices into it: adopted 2 February 2024 and released 8 February 2024, the unanimous Declaratory Ruling confirmed that the TCPA’s restrictions on an “artificial or prerecorded voice” encompass AI technologies that generate human voices, including voice cloning that mimics a specific real person. AI voice calls therefore inherit the whole artificial-voice regime, including prior express consent under 47 U.S.C. § 227(b)(1)(A).

  1. 1.Identity, at the beginning of the message. § 64.1200(b)(1) requires the call to “state clearly the identity of the business, individual, or other entity that is responsible for initiating the call.” Where a business is responsible, it must use the name it is registered under with the State Corporation Commission or comparable authority — not a campaign alias, not a brand nobody could look up.
  2. 2.A callback number, during or after the message. § 64.1200(b)(2) requires a clearly stated telephone number for that entity. It may not be the number of the autodialer that placed the call, and it may not be a 900 number or any number charged above local or long-distance transmission rates. A number that rings nowhere is a defect, not a formality.
  3. 3.An opt-out mechanism, within two seconds. For messages that include or introduce an advertisement or constitute telemarketing to a residential line, § 64.1200(b)(3) requires an automated, interactive voice- or keypress-activated opt-out mechanism, with brief instructions, provided within two seconds of the identification required by (b)(1). The two-second window is literal.

Read those together and the federal ask is unglamorous: say who is calling, say why, give a number that works, and let the person leave. An AI agent that opens with “Hi, this is Ana calling from Northgate Roofing — is now a bad time?” satisfies (b)(1) without ever using the word “AI.” Whether that is enough is a separate question from whether it is legal, and the two answers currently differ.

The FCC’s AI-disclosure rule is still a proposal

On 7 August 2024 the FCC adopted, and on 8 August 2024 released, FCC 24-84 — a Notice of Proposed Rulemaking and Notice of Inquiry captioned Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts, CG Docket No. 23-362. In its own words, the Commission proposed “to define AI-generated calls and propose new rules that would require callers disclose to consumers when they receive an AI-generated call.” It further proposed that consent forms specify that consent to artificial and prerecorded calls extends to AI-generated calls.

Comments were due 10 October 2024 and reply comments 25 October 2024. Both dates passed. As of July 2026 the Commission has adopted no final rule in the docket, and the current FCC’s deregulatory posture makes the timing of one genuinely uncertain rather than imminent.

This distinction is worth holding precisely, because a large amount of vendor marketing gets it backwards. A Notice of Proposed Rulemaking is a question, not a rule. FCC 24-84 creates no obligation, carries no penalty, and cannot be violated. Any page telling you the FCC requires an AI disclosure at the start of your calls is describing a proposal as though it were law. The honest planning assumption is different and more useful: the disclosure is likely enough to arrive that scripting for it now costs little, and building an operation that would break if it arrived is a bet with no upside.

US state law: narrow, subject-matter-specific, and often misquoted

State AI-disclosure duties are real but far narrower than their reputation. The table below is the set that matters for voice, with what each actually reaches.

LawIn forceReaches phone calls?
California B.O.T. Act
SB 1001 · Bus. & Prof. Code §§ 17940–17943
1 July 2019No — limited to communicating “online”
California AB 3030
Health & Safety Code ch. 2.13, § 1339.75 et seq.
1 January 2025Yes — verbal disclaimer at the start and end of audio, for GenAI patient clinical communications
Utah AI Policy Act
SB 149 (2024), am. SB 226 (2025) · Utah Code §§ 13-75-101 to -106
1 May 2024; amendments 7 May 2025Yes — on request, and proactively in high-risk interactions
California SB 243
Companion chatbots
1 January 2026Only for companion chatbots — not outbound sales calling
Colorado AI Act
SB 24-205 → repealed & reenacted by SB 26-189
Never took effect; successor applies 1 January 2027Not today

California’s SB 1001 is the most over-cited statute in this field. It is routinely quoted as though it forces AI callers to identify themselves. It does not reach calls at all. § 17941(a) is limited to using a bot to communicate onlinewith intent to mislead about its artificial identity in order to incentivize a sale or influence a vote; a “bot” is defined as an automated online account. The 10-million-visitor threshold that gets quoted as a limit on this duty is not one: it defines “online platform” (§ 17940(c)), a term the statute uses only to exempt service providers (§ 17942). The § 17941(a) duty binds any person using a bot online, at any scale — it simply does not reach phone calls, because a call is not “online” under § 17940(b). What the statute genuinely does lack is a private right of action, leaving enforcement to the Attorney General. Where disclosure is made, it must be “clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot.”

Utah is the live one for ordinary commercial calling. The AI Policy Act, as amended by SB 226 effective 7 May 2025, requires disclosure of generative-AI use when a person clearly and unambiguously asks whether they are dealing with a human or a machine. SB 226 narrowed the original 2024 duty: proactive disclosure is now confined to “high-risk” interactions — collecting health, financial, or biometric data, or giving advice a person may rely on for financial, legal, or medical decisions — where it must come at the start of the interaction, and verbally if the interaction is verbal. Civil penalties run to $2,500 per violation. The operational read is blunt: if a prospect asks your AI agent “am I talking to a real person?”, a Utah-facing agent that dodges is in breach.

Colorado deserves a correction rather than a row. SB 24-205 contained the disclosure duty that trackers still cite — that a deployer of an AI system intended to interact with consumers must disclose the AI to each consumer. It never became enforceable. Its start date moved from 1 February 2026 to 30 June 2026, and on 14 May 2026 Governor Polis signed SB 26-189, which repealed and reenacted the framework around notice, disclosure, and consumer rights, effective 1 January 2027. Compliance content that lists Colorado as a current AI-disclosure state is describing a law that never applied.

The EU AI Act: Article 50(1) and the 2 August 2026 date

Article 50(1) of Regulation (EU) 2024/1689 is the clearest AI-caller disclosure obligation in force anywhere. Providers must ensure that AI systems intended to interact directly with natural persons are designed so those persons are informed they are interacting with an AI system — unless that is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and context of use. It applies from 2 August 2026.

The “obvious” carve-out does no work for outbound voice. A modern synthetic voice on an unsolicited sales call is engineered to be indistinguishable from a person; if it were obvious, the product would be failing. Treating the exception as available for a good voice agent inverts it.

The date survived the 2026 Digital Omnibus, and the detail matters because “the AI Act got delayed” became a widespread half-truth. What the Omnibus deferred is the high-risk regime — to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I — plus a four-month grace period, to 2 December 2026, for the Article 50(2) machine-readable marking duty as applied to systems already on the market before 2 August 2026. The Article 50(1) interaction disclosure was not deferred. The single most broadly applicable transparency duty in the Act lands on schedule.

Penalties are set by Article 99(4): for non-compliance with Article 50, administrative fines up to €15,000,000 or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups the cap is the lower of those two figures. The obligation attaches to the recipient’s location, not the caller’s: a US agency dialing an EU prospect is inside the AI Act’s reach.

When you must disclose: the short decision list

Four questions resolve nearly every outbound calling case. Any single yes means the AI identity is disclosed.

  1. 1.Is the person in the EU, on or after 2 August 2026? Disclose — though the duty is not formally yours. Article 50(1) binds the provider, which must design the system so people are informed they are interacting with an AI; an agency running a campaign is a deployer, and no paragraph of Article 50 imposes an interaction-disclosure duty on deployers of a voice agent. That allocates the responsibility rather than removing it — the disclosure is what the system is required to deliver, and scripting around it defeats the provider’s compliance instead of escaping your own.
  2. 2.Did they ask? If a person asks clearly and unambiguously whether they are speaking to AI, answer honestly. Utah compels it. Lying about it is where a merely unregulated call becomes a deceptive one, and the FTC Act and state UDAP statutes do not need an AI-specific rule to reach deception.
  3. 3.Is the subject matter regulated? Health-care clinical communications in California require a verbal disclaimer at the start and end of an audio interaction under AB 3030, plus instructions for reaching a human. Financial, legal, and medical advice triggers Utah’s high-risk disclosure at the outset. Regulated-occupation calling is the one area where the duty is proactive rather than on-request.
  4. 4.Would the person feel deceived on learning the truth? Not a legal test. It is the one that predicts complaints, carrier blocks, and the enforcement that arrives before the rule does.

One asymmetry decides the design. Disclosing when you did not have to costs a sentence. Not disclosing when you had to costs up to €15,000,000 or 3% of worldwide turnover in the EU, $2,500 per violation in Utah, and — because AI calls are artificial-voice calls after FCC 24-17 — leaves the underlying TCPA exposure of $500 to $1,500 per call intact regardless.

Where Veera stands

Veera does not inject an AI-identity disclosure into calls automatically. Stating otherwise would be a false claim about the product, and this page is not going to make one. The opening of a Veera call is scripted by the operator running the campaign, which means what the AI says about itself — including whether it says it is an AI — is the operator’s decision and the operator’s legal responsibility. Consent posture and disclosure scripting are yours to set.

Veera’s posture is that a call identifies who is calling and why. That is not a differentiator; it is what § 64.1200(b)(1) demands of any artificial-voice call, and an agent that opens without it is defective rather than clever.

The compliance control Veera does enforce automatically is TCPA quiet hours, checked on every voice call against the recipient’s local time, timezone-aware, and not skippable per campaign — a call outside the window is rejected before the number is dialed. Veera also honors CAN-SPAM one-click unsubscribe with suppression checked before every send, and honors GDPR Article 17 erasure requests. None of that is a certification, and none of it is a legal opinion about your program.

Scope, stated plainly. Voice calling is the channel that is live today. SMS and WhatsApp outreach are being activated and email outreach is building; in-call WhatsApp document delivery — sending a brochure or quote during a live call — is the one send path already running alongside voice. Veera syncs into the CRM an agency already runs, GoHighLevel or HubSpot, rather than replacing it: calls, outcomes, and transcripts land on the contact record there. Veera is free to start.

Frequently asked questions

Do you have to tell someone they are talking to an AI?

It depends on where the person is and what the call is about. As of July 2026 no general United States rule requires it on a phone call. Federal law requires an artificial-voice call to identify the business responsible for it and to give a callback number under 47 C.F.R. § 64.1200(b)(1)–(2), but it does not require the caller to say the words “this is an AI.” The FCC proposed exactly that requirement in Notice of Proposed Rulemaking FCC 24-84 (CG Docket No. 23-362, released 8 August 2024); the comment cycle closed on 25 October 2024 and the proposal has not been adopted, so it binds nobody. AI-identity disclosure is mandatory in narrower places instead: the EU AI Act’s Article 50(1) from 2 August 2026, California’s health-care law AB 3030 since 1 January 2025, California’s companion-chatbot law SB 243 since 1 January 2026, and Utah’s AI Policy Act whenever a consumer asks.

Does the FCC require AI callers to disclose that they are AI?

No. The FCC proposed that rule and has not finalized it. Notice of Proposed Rulemaking FCC 24-84, adopted 7 August 2024 and released 8 August 2024 in CG Docket No. 23-362, proposes to define an “AI-generated call” and to require callers to disclose at the beginning of the call that AI-generated technology is being used. Comments closed 10 October 2024 and reply comments 25 October 2024. No final rule has been adopted as of July 2026, so the proposed disclosure is not law. What the FCC did settle is a different question: Declaratory Ruling FCC 24-17, adopted 2 February 2024 and released 8 February 2024, held that AI-generated voices are “artificial” voices under the Telephone Consumer Protection Act, 47 U.S.C. § 227. That ruling switched on the consent and identification rules that already existed. It did not create an AI-identity script.

What must an AI voice call disclose under current federal law?

Three things, all from 47 C.F.R. § 64.1200(b), which reaches AI voice calls because FCC 24-17 classified AI-generated voices as artificial voices. First, § 64.1200(b)(1) requires the message to state clearly, at its beginning, the identity of the business, individual, or other entity responsible for initiating the call — and where a business is responsible, the name it is registered under. Second, § 64.1200(b)(2) requires the message to state clearly, during or after it, a telephone number for that entity, which may not be the autodialer’s number and may not be a 900 number or any number charged above normal transmission rates. Third, § 64.1200(b)(3) requires an automated, interactive voice- or keypress-activated opt-out mechanism within two seconds of that identification for telemarketing messages delivered to residential lines. The practical shape is: say who is calling, say why, give a working callback number, and let the person opt out.

Does California’s bot-disclosure law apply to AI phone calls?

No. California’s B.O.T. Act — SB 1001, codified at Cal. Bus. & Prof. Code §§ 17940–17943 and effective 1 July 2019 — reaches only communication “online.” Section 17941(a) makes it unlawful to use a bot to communicate online with a person in California with intent to mislead about the bot’s artificial identity in order to incentivize a sale or influence a vote. A telephone call is not an online communication, so SB 1001 does not govern it. The 10-million-visitor threshold that gets quoted as a limit on this duty is not one: it defines “online platform” (§ 17940(c)), a term the statute uses only to exempt service providers (§ 17942). The § 17941(a) duty binds any person using a bot online, at any scale — it simply does not reach phone calls, because a call is not “online” under § 17940(b), and a “bot” is defined as an automated online account. What the statute genuinely does lack is a private right of action, leaving enforcement to the Attorney General. The California AI-disclosure rules that do reach voice are elsewhere — AB 3030 for health-care communications and SB 243 for companion chatbots.

When does the EU AI Act require you to disclose an AI caller?

From 2 August 2026. Article 50(1) of Regulation (EU) 2024/1689 requires providers to design AI systems intended to interact directly with natural persons so that those persons are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect natural person given the circumstances and context of use. A synthetic voice on an outbound sales call is not obvious in that sense, so the disclosure applies. The Digital Omnibus agreement reached in 2026 deferred the AI Act’s high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and gave the Article 50(2) machine-readable marking duty a grace period to 2 December 2026 for systems already on the market — but it left the Article 50(1) interaction disclosure on its original 2 August 2026 date. Article 99(4) sets fines for Article 50 breaches at up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Does Veera disclose that its calls are AI?

Not automatically, and claiming otherwise would be false. The opening of a Veera call is scripted by the operator running the campaign, so what the AI says about itself — including whether it states that it is an AI — is the operator’s decision and the operator’s legal responsibility. Veera’s posture is that a call should identify who is calling and why, which is what 47 C.F.R. § 64.1200(b)(1) requires of an artificial-voice call regardless. The compliance control Veera does enforce automatically is TCPA quiet hours: checked on every voice call against the recipient’s local time, timezone-aware, and not skippable per campaign. Veera also honors CAN-SPAM one-click unsubscribe with suppression checked before every send, and honors GDPR Article 17 erasure requests. None of that is a certification, and none of it is legal advice about your program.

This page is part of Veera’s AI calling compliance guide, a reference for the rules that govern automated outreach. Legal citations are to 47 U.S.C. § 227, 47 C.F.R. § 64.1200(b), FCC Declaratory Ruling FCC 24-17 (8 February 2024), FCC Notice of Proposed Rulemaking FCC 24-84 in CG Docket No. 23-362 (8 August 2024), Regulation (EU) 2024/1689 Articles 50 and 99, Cal. Bus. & Prof. Code §§ 17940–17943, Cal. Health & Safety Code § 1339.75 et seq., Utah Code §§ 13-75-101 to 13-75-106, and Colorado SB 26-189, each verified against the primary source on 16 July 2026. This is not legal advice. See also: What is an AI Business Aide? and State of Outbound Business AI 2026.