September 5, 2026. Ask a compliance vendor which US states require an AI caller to announce itself and you will get a list that includes Colorado, effective June 30, 2026. Colorado's general disclosure duty is still printed in the statute with that date, but the legislature repealed and replaced the whole law in May 2026 with a version that contains no such duty from January 1, 2027, and a federal court order from April 2026 bars the Attorney General from even opening an investigation under either version. Most 2025 guides have not caught up. The wider truth, read from the statutes rather than the summaries, is that as of today no federal rule and no state law requires an ordinary private business to proactively announce "this is an AI" on a consented live sales call. What binds AI voice deployments is narrower, older and mostly about consent. Here is the map.
Federal: consent, not disclosure
The Telephone Consumer Protection Act, 47 U.S.C. 227(b)(1)(A), makes it unlawful to call a mobile number using an artificial or prerecorded voice without prior express consent, and 227(b)(3) gives recipients $500 per call, up to $1,500 for wilful violations. On February 8, 2024 the FCC's Declaratory Ruling confirmed that the TCPA's restrictions on artificial or prerecorded voice encompass current AI technologies that resemble human voices or generate call content using a prerecorded voice. So an AI voice call to a cell phone needs prior express consent, and prior express written consent if it is telemarketing; every artificial-voice message must identify the responsible business at the start and telemarketing messages must offer an opt-out. Two things the ruling does not do: it does not require a caller to say the voice is AI, and it says nothing about inbound. In August 2024 the FCC proposed exactly such an on-call disclosure, plus consent language covering AI-generated calls. No order adopting it appears on the FCC's site as of today, and the proposal itself states that the TCPA's requirements do not extend to technologies used to answer inbound calls. Treat on-call AI disclosure as proposed federal law, not enacted.
The states with a live duty for private businesses
- California, robocalls. Public Utilities Code 2874, amended by AB 2905 effective January 1, 2025: before an automatic dialing-announcing device plays a prerecorded message, a natural-voice announcement must state the nature of the call, the business name, address and phone, ask consent to hear the message, and inform the person if the prerecorded message uses an artificial voice, defined as one generated or significantly altered using AI. Penalty: up to $500 per violation and possible disconnection under Section 2876. It applies only to prerecorded robocalls, not to a live conversational agent.
- California, bots. Business and Professions Code 17940 to 17943 make it unlawful to use a bot to communicate online with intent to mislead about its artificial identity to induce a purchase or a vote, with a safe harbour for clear disclosure. "Online" means public websites and apps, so phone calls sit outside it.
- Utah. Utah Code Title 13, Chapter 77, effective May 7, 2025: a supplier using generative AI in a consumer transaction must disclose it is AI if the individual asks or otherwise prompts with a clear question. Proactive disclosure, verbally at the start of a verbal interaction, is required only for state-licensed regulated occupations in high-risk interactions involving health, financial or biometric data or medical, legal or financial advice. A bot that says at the outset and throughout that it is AI has a safe harbour, and using AI is no defence to any consumer-protection violation. Fines up to $2,500 per violation.
- Maine. 10 M.R.S. 1500-Y, effective September 24, 2025: no person may use an AI chatbot, defined to include textual or aural communications, in trade and commerce in a manner that may mislead or deceive a reasonable consumer into believing they are engaging with a human, unless the consumer is clearly and conspicuously notified otherwise. It is a deception standard with a disclosure cure, and "aural" puts voice inside it. Breach is an unfair trade practice; the Attorney General may seek up to $10,000 per intentional violation.
The states that do not reach an ordinary sales call
Colorado's story is above; the replacement law, SB 26-189, covers automated decision-making in consequential decisions and expressly excludes natural-language tools that answer questions or make recommendations, customer service triage and marketing. Texas's TRAIGA, effective January 1, 2026, imposes a clear disclosure duty before or at the time of interaction, but only on governmental agencies and health care providers, with no general private-business duty. New York's General Business Law Article 47 requires AI companion operators to notify users, verbally or in writing, at the start of an interaction and every three hours, with civil penalties of up to $15,000 per day, but it excludes systems used solely for customer service or product information. California's SB 243, effective January 1, 2026, imposes notice duties on companion chatbot operators and excludes bots used only for customer service or business operations. Washington's companion chatbot law takes effect January 1, 2027 and Nebraska's Conversational AI Safety Act on July 1, 2027; both exclude customer service tools, and Nebraska adds tools primarily marketed for commercial use by businesses. Florida's telemarketing statute, read in full, requires prior express written consent for automated or recorded sales calls and a true name immediately on contact, and never mentions AI. A pending California bill, AB 1609, would require businesses with more than $500 million in revenue to disclose customer service chatbots and route to a human within 15 minutes; it passed on August 31, 2026 and awaits the governor's decision by September 30.
What it means for operators
For an outbound AI voice program the binding constraint in every state is TCPA consent, not disclosure. Without prior express written consent, an AI voice sales call to a mobile number is a $500 to $1,500 event per call before any state law is considered, and state statutes like Florida's add their own private actions. With consent in place, the disclosure duties that actually apply are narrow: California's natural-voice preamble if you are playing prerecorded messages through a dialler; Utah's answer-if-asked rule, which is satisfied for good by a bot that identifies itself at the start; and Maine's rule, which in practice means disclose whenever a reasonable person might think they are speaking to a human, which for a convincing voice model is always.
That points to one design choice that satisfies every live statute and the FCC's pending proposal at once: have the agent identify the business and say it is an automated assistant in its first sentence. It costs a second of talk time, it is Utah's safe harbour, it is Maine's cure, it is what California already requires for recorded messages, and it removes the argument in any future TCPA class action that the call was designed to deceive. The businesses that resist this are usually protecting a script that sounds human because it was meant to pass as human, which is precisely the design the deception-based statutes target.
Inbound is a different regime. The TCPA does not reach the technology that answers a call, the FCC has said so in its own proposal, and the state companion-bot laws exclude customer service. An AI receptionist that identifies itself and can hand off to a person is, on today's statutes, a low-exposure deployment in every state, which is why inbound intake is where we point clients first when we build AI voice agents for law firm intake or home services.
How to run an AI calling program across states
- Get prior express written consent that names automated and AI-generated calls before any outbound AI voice call to a mobile number.
- Identify the business and the automated nature in the first sentence. One line satisfies Utah, Maine, California's robocall preamble logic and the FCC proposal.
- Offer an opt-out and honour it across every channel, as the FCC rules require for telemarketing messages.
- Hand off to a human on request, which the pending California bill would mandate for large companies and which every regulator treats as good faith.
- Check the sector overlays. Utah's high-risk categories and Texas's health care duty bite on medical, financial and legal use cases.
- Re-read Colorado in 2027, when the replacement law starts and the injunction litigation may have moved.
Our earlier piece on whether AI cold calling is legal covers the FCC ruling in depth, and California's AI caller disclosure law covers the natural-voice preamble. The consent capture and the first-sentence disclosure are built into every compliant AI calling program we run, because they are the two things every statute on this map agrees about.
Frequently Asked Questions
Not yet. The FCC's February 8, 2024 ruling classifies AI-generated voices as artificial or prerecorded voice under the TCPA, which means prior express consent is required and the business must be identified at the start of the message, but it does not require the caller to disclose that the voice is AI. The FCC proposed such a disclosure in August 2024; no adopting order appears as of September 2026.
No. The general disclosure duty in C.R.S. 6-1-1704(1) is still printed with that date, but SB 26-189, signed May 14, 2026, repeals and re-enacts the law from January 1, 2027 without a general AI-interaction disclosure, excluding natural-language tools, customer service triage and marketing. A federal minute order of April 27, 2026 in X.AI v. Weiser also bars the Attorney General from initiating enforcement or investigation under the old law or its replacement until the litigation moves.
Under Utah Code Title 13, Chapter 77, effective May 7, 2025, a supplier using generative AI in a consumer transaction must disclose it is AI if the individual asks or clearly prompts. Proactive disclosure at the start of a verbal interaction is required only for regulated occupations in high-risk interactions involving health, financial or biometric data or medical, legal or financial advice. A bot that identifies itself as AI at the outset has a safe harbour. Fines run up to $2,500 per violation.
For ordinary private businesses: California's robocall preamble rule (PUC 2874, January 1, 2025), Utah's answer-if-asked rule (May 7, 2025) and Maine's deception standard for chatbots including aural communications (September 24, 2025). Texas's duty applies only to government agencies and health care providers. New York, California SB 243, Washington and Nebraska regulate companion chatbots and exclude customer service tools.
No. The FCC's own August 2024 proposal states that the TCPA's requirements do not extend to technologies used to answer inbound calls, and the state companion-chatbot laws exclude customer service tools. An inbound AI receptionist that identifies itself and can hand off to a person is a low-exposure deployment under current statutes.
Obtain prior express written consent that names automated and AI-generated calls, identify the business and state that the caller is an automated assistant in the first sentence, offer and honour an opt-out, and hand off to a human on request. That single opening line satisfies Utah's safe harbour, Maine's disclosure cure, California's robocall preamble logic and the FCC's pending proposal at once.