- Three jurisdictions use three different triggers. The EU wants disclosure before the conversation starts, Utah wants it when the customer asks, California only bans deception intended to push a sale.
- The EU AI Act's transparency article applied from 2 August 2026, so the proactive duty is live now rather than pending.
- Utah offers an explicit safe harbour: a bot that says what it is at the outset and throughout is protected from enforcement under that section.
- One design satisfies all three regimes, which is to disclose plainly at the start of every conversation and answer honestly if asked again.
- Your AI written product descriptions are almost certainly not covered by any of this. The duties attach to conversations and to public interest content, not to shop copy.
A chat widget sits in the corner of your shop answering questions at two in the morning. It is polite, it is fast, and it has a name you chose. Somewhere in a settings panel you decided whether it introduces itself as software.
That decision is now regulated in several places at once, by rules that were written separately and do not agree on the trigger. The good news is that the disagreement resolves into a single practical answer. The rest of this piece is how to get there, and which of your AI surfaces the rules never touch.
Which AI in your shop is even in scope?
Far less than most owners assume. The obligations attach to systems that talk to people and to content that is passed off as a record of the real world. A model that writes your product page is generally neither.
The chat widget and the phone agent are squarely in scope: they interact with a person directly. Generated images used to depict something that looks real carry their own labelling duty. Product descriptions, email drafts you review before sending and replies you approve are, in the ordinary case, out of scope entirely.
What does the EU actually require now?
That people are told they are dealing with a machine, before or at the moment of first contact. Article 50 of the AI Act requires providers to design systems that interact directly with people so that those people are informed they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well informed person.
The timing and manner are specified rather than left open. Information must reach the person at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and it has to meet accessibility requirements. A disclosure buried in a terms page does not satisfy a rule written around first contact.
Two further limbs matter to a shop. Providers of generative systems must mark outputs in a machine readable format so they can be detected as artificially generated, which is a duty on the tool you bought rather than on you, and which we looked at from the merchant side in the invisible marks now travelling inside AI text. Deployers of systems producing image, audio or video content that resembles real people or events must disclose that the content is artificially generated.
The date matters because it has passed. Transparency under Article 50 applied from 2 August 2026, a deadline that did not move when other parts of the timetable were pushed back, as we set out in the AI Act read as a decision tree and a timeline.
Is there really a duty on text you publish?
Yes, but it is narrower than the panic suggests and it probably misses your shop. The text limb applies to content published to inform the public on matters of public interest.
A product description is not that. A shipping policy is not that. A blog post about your own products is a commercial communication rather than public interest reporting. The provision is aimed at synthetic news and civic content, which is why it carries an exemption where the text underwent human review and a person or organisation holds editorial responsibility for its publication.
That exemption is worth noticing even if you think you are out of scope, because it describes good practice regardless. A named human who read it and takes responsibility for it is the standard that keeps you out of trouble in every regime discussed here.
What do the American rules say?
Something quite different, and the differences are the reason a single global policy is easier than a per market one. The table below sets the three regimes side by side.
| Where | What triggers the duty | Applies to | Status |
|---|---|---|---|
| European Union, AI Act Article 50 | First interaction, proactively, unless obvious | Systems interacting with people, plus synthetic media | In force since 2 August 2026 |
| Utah, consumer transactions | Only when the customer clearly asks whether AI is being used | Suppliers using generative AI in a consumer transaction | In force since 7 May 2025 |
| Utah, regulated occupations | Prominently and up front, for high risk interactions | Licensed occupations, spoken at the start or written before it | In force since 7 May 2025 |
| California, existing bot law | Only where a bot deceives in order to incentivise a sale or influence a vote | Automated accounts communicating online | In force since 1 July 2019 |
| California, proposed AB 410 | Proactive disclosure at first contact, plus honest answers when asked | Bots a reasonable person could believe are human | Held in committee, not law |
Utah's approach is the most interesting for a small business because it is the most forgiving and the most explicit. Its statute, enacted by Senate Bill 226 and effective from 7 May 2025, requires a supplier using generative AI in a consumer transaction to disclose that fact if the individual asks or otherwise prompts about whether AI is being used, with the added condition that the question must be a clear and unambiguous request to determine whether the interaction is with a human.
The tighter rule sits one section along, for licensed occupations. There the disclosure must be prominent, and must be given verbally at the start of a verbal interaction or in writing before a written one, where the use amounts to a high risk interaction. Utah defines that to include collecting health, financial or biometric data, or providing advice that could reasonably be relied on for significant personal decisions.
California's operative law is narrower still. Its bot disclosure section makes it unlawful to use a bot to communicate with a person in California with intent to mislead about its artificial identity, for the purpose of knowingly deceiving about the content of the communication in order to incentivise a purchase or sale. Disclosure is a complete answer to it. An honest bot that never pretends to be human is outside the prohibition.
Utah writes a safe harbour into the statute. A person is not subject to enforcement under that section if the system clearly and conspicuously discloses, at the outset of the interaction and throughout it, that it is generative AI, that it is not human, or that it is an AI assistant. Being permanently honest is the documented way to stop worrying about the trigger.
So what should the widget actually say?
Say it plainly, at the start, and keep it visible. That single design satisfies the EU's proactive rule, clears Utah's reactive rule by never letting the question arise, sits inside Utah's safe harbour, and stays outside California's prohibition because nothing is being concealed.
What works in practice is short. An opening line naming the assistant as an assistant, a persistent label near the input rather than only in the first bubble, and a truthful answer if somebody types "are you a real person". The persistent part matters because conversations get long and people arrive mid thread from a link.
Two things to avoid. Giving the bot a human first name and a photograph of a person pushes directly against every regime here, and it is the specific pattern California's law was written about. And do not rely on the customer inferring it from stilted writing, because current systems no longer write badly enough for that to be the disclosure.
The handover deserves a sentence too. When the assistant escalates to you, say so, because a customer who thinks they are still talking to software will not tell you the thing they were saving for a human. The reverse case is worse: a customer convinced they reached a person, who acts on a commitment the machine had no authority to make. That is not a hypothetical risk, as we found in the tribunal that held a business to what its bot promised.
Are you the provider or the deployer?
The deployer, almost certainly, and the distinction decides which of these duties are yours to discharge. Article 50 splits its obligations between the two roles, and merchants keep reading duties that belong to their vendor.
A provider develops the system and puts it on the market. That is the company whose chat product you licensed, or whose model sits behind it. A deployer uses the system under its own authority, which is you, running it on your shop for your customers.
The split runs like this. The duty to design a system so that people are told they are dealing with generative artificial intelligence sits on the provider. So does the duty to mark synthetic output in a machine readable format. The duties to disclose that image, audio or video content is artificially generated, and to disclose generated text where the public interest limb bites, sit on the deployer.
What that means when you are choosing a tool is that one of these is a purchasing question and the others are yours to operate. Ask the vendor whether the assistant discloses itself by default and whether that behaviour can be switched off, because a product that lets you disable disclosure is handing you a compliance decision dressed as a settings toggle. Then own the rest, because no vendor can label your product photography for you.
What is the actual penalty?
Smaller than the headline figures for a business your size, and the structure is worth knowing rather than fearing. The AI Act sets its heaviest fines for prohibited practices, not for transparency failures.
Breaches of the transparency obligations fall into the middle band, which the Act sets at up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. For small and medium enterprises, including start ups, the Act flips that comparison so the cap becomes whichever of the two is lower. For a shop turning over a few hundred thousand, 3 percent of turnover is the operative number, not the millions.
Utah routes its enforcement through consumer protection rather than a bespoke AI penalty, treating a breach as a violation administered by its Division of Consumer Protection. California's existing bot statute is enforced as an unlawful practice, and its pending bill proposes a thousand dollars per violation pursued by the attorney general or local prosecutors.
None of these regimes is hunting small shops with honest chat widgets. The exposure that actually costs money is the adjacent one: a customer who was misled, a complaint to a regulator about the substance rather than the label, and a business with no record of what it disclosed or when.
Does a phone agent change the answer?
It raises the stakes rather than changing the rule. Voice removes the visual cues people rely on, and the systems now sound convincing enough that the old tell of an unnatural pause has largely gone.
Utah is explicit for regulated occupations that a spoken disclosure belongs at the start of the interaction, which is a sensible standard to adopt everywhere. On a call there is no persistent label available, so the opening sentence carries the whole burden, and a caller who joins a transferred call has missed it entirely.
There is also a recording question layered underneath, which varies by jurisdiction and is not covered by any of the AI rules discussed here. If your phone agent transcribes, the consent notice and the AI notice are two separate statements and both belong in the opening. The operational side of running one of these well is a separate problem we went through in what an AI phone agent is really judged on.
What about images and video?
Generated media carries its own duty when it depicts something that could be taken for real. This is where a shop is more exposed than it realises, because product imagery has drifted toward generated backgrounds, generated models and generated room scenes.
The EU duty on deployers covers artificially generated or manipulated image, audio or video content resembling real persons, objects, places or events that would falsely appear authentic. A synthetic model wearing your garment is exactly that shape, and the platforms have begun attaching their own consequences to it, with Instagram limiting the reach of profiles fronted by an AI generated person. An obviously stylised illustration is not. The practical test is whether a customer scrolling quickly would take the image for a photograph of a real thing, and if the answer is yes then a label costs you nothing and settles the question. Most shops already caption their lifestyle imagery, so this is a wording change rather than a new workflow.
Separately from any AI rule, consumer protection law has always required that imagery not mislead about what the customer receives. A generated photograph showing a colour your product does not come in is a misdescription whether or not it is labelled, which is the line we drew in what a generated product image can honestly claim.
The practical position
If you sell to anyone in Europe and run a chat or voice assistant, the proactive duty applies to you today and the cost of compliance is one sentence. If you sell only in the United States, the rules are looser now and moving in the European direction, with California's pending Assembly Bill 410 drafted around proactive disclosure and a penalty of a thousand dollars per violation attached to it.
Nothing here asks you to apologise for using AI, and none of these statutes treats generative artificial intelligence as something to hide. Disclosure is a factual statement, and the evidence from businesses that have done it is that customers mind far less than owners expect, provided the route to a human is real and short. What they mind is discovering it late, or being told a name and a photograph that turn out to belong to nobody.
The version to avoid is the one where a customer works it out for themselves after twenty minutes. That is the outcome every one of these laws is aimed at, and it is also just bad service, since the customer who feels tricked tells other people about it. Writing your position down once, in the same place you record what your staff may and may not do with these tools, turns it from a running judgement call into a settled one. Ours sits on our AI policy page, and yours can be shorter than you think.