California's SB 243 Forces AI Systems to Say What They Are
A new California statute requires chatbots, voice assistants, and customer-service agents to disclose their non-human status — with civil penalties up to $250,000 per violation for those that don't.
The question of whether users know they're talking to a machine just became a legal matter in California. SB 243 is now enacted — a statute that compels AI systems interacting with the public to clearly identify themselves as non-human. For every company deploying a customer-facing AI in the state, the compliance clock has started.
What the Law Actually Requires
The statute casts a wide net. Chatbots, voice assistants, and customer-service agents are all explicitly named — which covers the majority of AI touchpoints consumers encounter today. Providers must implement conspicuous notices in interfaces and outputs, making the non-human status of the AI evident during the interaction itself. A buried footer disclosure or a single onboarding screen almost certainly won't satisfy that standard. The requirement is ongoing and ambient — the AI's nature must be evident, not merely acknowledged once at sign-up.
The law also targets deceptive AI content more broadly, including deepfakes and synthetic media that could mislead users about the identity or nature of a speaker. That framing matters: SB 243 isn't just about chatbots forgetting to introduce themselves. It treats the systematic obscuring of AI identity as a harm in its own right, aligning disclosure requirements with the growing concern over synthetic personas used in fraud, manipulation, and influence operations.
The Penalty Structure Changes the Calculation
Regulatory mandates without enforcement mechanisms are suggestions. SB 243 is not that. Violations related to illegal or undisclosed AI content can incur civil penalties of up to $250,000 per incident. That per-incident framing is the detail operators need to take seriously. A company running an undisclosed AI agent across thousands of daily customer interactions isn't facing a single fine — it's potentially facing a penalty stack that compounds with every non-compliant exchange.
That exposure reframes the build-versus-comply decision for product and legal teams. The cost of retrofitting a disclosure layer into an existing deployment is almost certainly lower than the liability exposure of running one without it. Companies that have been treating AI disclosure as a nice-to-have UX consideration now have a dollar figure attached to the alternative.
What Operators Need to Think Through
The practical compliance challenge isn't philosophical — it's architectural. "Conspicuous notice" in a text-based chat interface looks different from conspicuous notice in a voice assistant interaction. A banner or label in a chat UI is straightforward. In a voice context, that likely means an explicit verbal disclosure at the start of an interaction, every time. Companies that have designed seamless, human-sounding voice agents will need to decide how to integrate that disclosure without degrading the experience they've built — or rebuild the experience around transparency from the start.
The scope of "deployed by companies in the state" will also face definitional pressure. Does a company headquartered outside California, serving California users, fall under SB 243? That question won't be answered cleanly until enforcement actions start drawing lines. Operators serving any significant California user base should assume the answer is yes until told otherwise.
Deepfake and synthetic media provisions add a second compliance surface beyond conversational AI. Any company producing AI-generated video, audio, or imagery where the synthetic nature could be unclear to a reasonable viewer is in scope — not just the chatbot team.
The Bigger Shift
SB 243 is not an isolated move. It reflects a regulatory posture that treats AI identity deception as a structural risk — not an edge case — and is willing to attach serious financial consequences to it. California has historically set the floor that becomes the national baseline. What's a state compliance requirement today tends to become the expectation everywhere within a product cycle or two.
The underlying shift is simpler than the legal language: regulators are no longer willing to let the question of AI identity remain ambiguous by design. For builders and operators, the era of leaving that ambiguity as a deliberate product choice — or simply never getting around to disclosure — is closing. SB 243 gives that shift a number: $250,000, per incident, to concentrate the mind.
