Your AI SDR Is a Bot Under California Law. Did It Say So?
California has had a bot-disclosure statute since 2019, written for astroturfing and political manipulation. The commercial branch of it — communicating to incentivize a sale — now describes the entire AI sales-agent category, which was built with human first names, human-sounding voices and no disclosure at all.
A 2019 Statute Aimed at 2026 Products
The law was written when a bot meant a scripted social-media account, and for several years it was discussed almost entirely in the election context. What changed is not the statute but the product category underneath it. The current generation of sales agents holds a genuine conversation, adapts to objections, and is deliberately designed to read as a person — with a human first name, a written voice, and in the voice channel, disfluencies and backchannel sounds added specifically to pass as human.
That last design decision is worth pausing on, because it is the one that converts a compliance question into an intent question. Filler words and breathing sounds have no function other than to make the listener believe a person is speaking. A product team that added them wrote the evidence for the intent element into the release notes.
Which of Your Surfaces Are In Scope
- AI SDR sequences. Email and social outreach where the persona, the replies and the follow-ups are model-generated.
- Outbound voice agents. Qualification calls, appointment setting and renewal outreach placed by a synthetic caller.
- Web chat that qualifies. A widget that gathers budget and timeline and books a demo is incentivizing a sale, whatever the team calls it.
- Support bots with upsell objectives. Deflection is not commercial; a retention offer during a cancellation flow is.
- Review and community accounts. Model-written participation in a public forum that steers toward a product is the original mischief the statute names.
- In-app assistants that recommend paid upgrades. The commercial purpose is explicit in the product spec.
The surface teams most often miss is the cancellation flow, because it is owned by retention rather than by marketing and nobody classified it as sales. It is also the flow where a disclosure failure is most likely to surface in a complaint, since it already attracts auto-renewal and negative-option scrutiny of its own.
What Disclosure Has to Achieve
The statutory standard is a disclosure that is clear, conspicuous and reasonably designed to inform the person that they are interacting with a bot. Reasonably designed is the operative phrase, and it is a design test rather than a drafting one: the question is whether an ordinary person in that conversation would come away knowing.
That has concrete implications. Modality matters — a visual banner does not disclose anything in a voice call. Timing matters — a person who has already given a budget figure to what they believed was a human has been deceived regardless of what appears later. Persistence matters in long sessions, because a disclosure in turn one is thin cover for turn forty. And persona design matters most of all: a disclosure that says "I'm an AI assistant" sitting under a headshot and the name Rachel is doing two contradictory things at once, and a complaint will quote the second one.
The Adjacent Exposure Is the Expensive Part
Read on its own, the bot statute looks low-stakes: no private right of action, no published enforcement wave, a complete safe harbour available for the cost of one sentence. That reading misses how statutes without private rights of action get enforced in California. Unfair-competition claims borrow violations of other laws as their predicate, and a deception element that the plaintiff does not have to construct from scratch is worth a great deal to a complaint.
Three adjacent regimes commonly arrive with it. Recording and wiretapping consent, where an AI voice agent that transcribes is recording in a two-party-consent state. Autodialer and telemarketing rules, where synthetic voice outreach has its own consent framework and statutory damages. And deceptive-practice enforcement, where federal regulators have been active against overstated AI claims and against AI used to deceive. The disclosure costs one sentence. Its absence is a free element in every one of those cases.
An Implementation Checklist
- Inventory every conversational surface where a model generates the words a customer reads or hears.
- Mark which have a commercial objective, including retention and upsell flows.
- Make disclosure a default property of the agent framework, not a per-campaign setting.
- Disclose in the first turn, in the same modality, and keep an ambient indicator visible in long sessions.
- Align persona design with the disclosure — avoid manufactured human cues whose only purpose is to conceal.
- Log the disclosure as an event with the transcript, so it can be produced per conversation.
- Pair it with the recording-consent and opt-out language the channel separately requires.
- Review agent prompts for instructions to deny being an AI, and remove them.
The last item has produced real incidents. A system prompt that tells an agent to insist it is human when asked is a written instruction to deceive, discoverable in a repository, and it defeats any argument that a disclosure elsewhere in the flow was made in good faith.
Questions Revenue and Legal Teams Ask
Won't disclosure destroy our conversion rate?
It moves it, and the direction is less obvious than teams assume. The measurable effects reported by operators cluster in two places: a modest drop in initial engagement, and a meaningful drop in the hostile reaction that occurs when a prospect discovers mid-conversation that they were misled. The second matters commercially because that discovery tends to happen at the handoff to a human, which is the highest-value moment in the funnel. If you want the number for your own funnel rather than an anecdote, run the disclosure as an A/B test measured to booked meetings rather than to reply rate — reply rate rewards ambiguity and booked meetings do not. Run it before a complaint forces the change, so you retain the option of designing the wording.
We only sell B2B. Does a consumer-protection framing reach us?
The bot statute speaks about a person in California and a commercial transaction, not about a consumer relationship, so a B2B framing does not remove you from it. Unfair-competition claims in California are available to business plaintiffs and to competitors as well as to consumers, and a competitor complaint is an underrated risk in a category where every vendor knows exactly how every other vendor's agent behaves. The one place B2B genuinely changes the analysis is telemarketing rules, whose consent frameworks distinguish business and residential lines. That distinction does not carry over to the disclosure question.
Our agent is human-supervised. Is it still a bot?
It depends on how much of the output a person actually authors. The definition turns on an automated account whose actions or posts are not the result of a person, so a genuine human-in-the-loop model where a person reviews and sends each message sits outside it. The pattern that does not qualify is the common one: a person monitors a dashboard, intervenes on exceptions, and the overwhelming majority of messages go out untouched. If your supervision ratio is one reviewer to hundreds of concurrent conversations, the messages are the result of the model. Measure the intervention rate before relying on the supervision argument, because it is the number that decides it.
How should a multi-state, multi-country deployment handle this?
Disclose everywhere by default and vary only the wording. Building a jurisdiction-detection layer that decides whether to be honest is expensive, fragile, embarrassing when it leaks into a repository, and wrong whenever the rules change or a user travels. The maintenance argument is the strongest one: a default-on disclosure needs no per-jurisdiction review when a new state law passes, and there have been several. A conditional one requires legal review on every change, forever, and its failure mode is silent.
What should we do first if we have deployed agents with no disclosure?
Turn disclosure on before you write a policy about it. The exposure accrues per conversation, so the first fix is the switch, not the documentation. Then work backwards: export the list of California-touching conversations to date, check whether any prompt instructed the agent to deny being an AI, and preserve what you have rather than deleting it once you know there is an issue. Then rewrite the personas. The temptation is to run the legal review first and change the product after; the arithmetic runs the other way, because every day of review is another day of conversations added to the set.
Read Your Own System Prompt
Search every agent prompt in your repository for instructions about how to answer "are you a real person". Whatever you find is the most quotable document your company owns, and it was written by someone optimising a conversion metric.
Fix that line, then turn disclosure on by default, then measure the funnel. In that order — the first two are free and the third is the only one that needs a debate.