AI Disclosure laws - what you need to know
If you use AI to communicate with customers, there are a number of national and US state regulations you should be sure you're complying with.
Which laws require disclosure?
Broadly speaking, there are four main areas to be concerned with:
- The EU AI Act requires, "AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system." The possible penalties are severe - up to 3% of global annual revenue!
- Various US states have laws that are either pending or already in place, but they all require more or less the same thing: clear disclosure that the caller is speaking to an AI. Whether disclosure is required at the start of the call or only upon being asked varies by state.
- UDAP (Unfair and Deceptive Acts or Practices) laws generally predate AI and don't specifically mention it, but they can be very broad and some US states' attorneys general have used them to go after companies who try to disguise an AI as a human (e.g. fake typing noises). This is more of a concern for outbound sales and marketing calls than inbound support.
- Special cases: if your voice agent can process payments, FTC regulations require it to get clear verbal authorization first. If your agent can use information it received on the call to make legal or contractual decisions, Article 22 of the GDPR kicks in. These test cases go beyond automation and we would recommend you validate them manually.
What counts as adequate disclosure?
Most laws require the disclosure to be:
- Proactive - the AI must volunteer it, not wait to be asked
- Clear - "I'm a virtual assistant" or "this is an AI-powered call" is generally sufficient
- Early - typically within the first sentence or two of the call
By default, VoiceGremlin will consider the terms AI, virtual, or some variation of robot/chatbot to count as AI disclosure; it will not accept jargon like IVA or LLM. You can dictate different terms if needed for your jurisdiction; otherwise, a test like "Confirm that the Agent discloses its AI status" will work fine. However, as long as you're covering your bases for compliance, you might want to combine this with another disclosure test case:
Wiretapping and recording disclosure
Long before AI came into the picture, many countries and US states passed laws requiring that callers be explicitly notified if they are being recorded. Some of them are vague as to what constitutes "recording", so even if you don't retain audio you may want to disclose this anyway to cover the brief storage involved in processing audio streams.
Putting it all together
Usually, we suggest that you cover one test case with one call to get clear results, but this is an exception - a single test should work fine for both disclosures:
// In your CI pipeline
"Verify that the agent discloses its AI status and audio recording on the first message."
Why this matters for CI
If you are working on your IVA functionally - changing vendors, adding functionality like tool-calling, or just A/B testing different greetings, it is possible to remove the disclosure without realizing it. Once this happens, your company could be in violation of a wide variety of laws with serious penalties (did I mention the EU AI Act authorizes fines up to 3% of global revenue?) and the first person to notice it might be a regulator.
As we discuss in our article on writing effective tests, our recommendation is that this be the first automated test you should implement. Depending on your needs, it may be the only one. If that's the case, just use the disclosure test as your "Is it working?" health check.