Long before “AI disclosure” was a headline, California quietly made it law. SB 1001, in force since July 1, 2019, requires a bot to identify itself when it’s used to sell you something or sway your vote. As the EU AI Act’s Article 50 lands on August 2, 2026 with exactly the same instinct, SB 1001 is the established U.S. anchor of a rule that’s now going global: tell people when they’re talking to a machine.
What it prohibits
It is unlawful to use a bot to communicate or interact with a person in California, online, in order to (a) incentivize a sale or transaction of goods or services, or (b) influence a vote in an election, without clearly and conspicuously disclosing that the account is a bot. A “bot” is an automated online account where substantially all of the actions or posts are not the result of a person. The disclosure has to be designed so a reasonable person actually understands they’re dealing with automation.
Who it reaches
The duty applies on public-facing platforms with at least 10 million monthly U.S. visitors or users, and it lands on the party deploying the bot — not on the platform provider itself, which the statute expressly protects. So the question isn’t “does California regulate my website?” It’s “do I run a customer-facing bot, on a large platform, that nudges Californians toward a purchase or a vote?” If yes, you disclose.
How it’s enforced
There is no private right of action; enforcement runs through the Attorney General and California’s Unfair Competition Law. On paper the direct penalty is modest — but a UCL predicate is not nothing, and the reputational cost of an undisclosed sales bot in 2026 is considerably higher than it was in 2019.
Why it matters now: the Article 50 pairing
Here is the strategic point. On August 2, 2026, two things arrive at once: the EU AI Act’s Article 50 transparency duties (disclose AI interactions; label AI-generated content) and California’s own AI Transparency Act (CAITA). Both are the same idea SB 1001 pioneered — and California has newer bot laws (like SB 243 on companion chatbots) layering on top. A company that builds one clean “disclose the bot” capability satisfies SB 1001 today and is already most of the way to Article 50 and CAITA tomorrow. Miss it, and you’re solving the same problem three times under three deadlines.
What “clear and conspicuous” actually takes
A disclosure buried in a terms-of-service page does not count. The standard is a disclosure the user perceives at the point of interaction — a labeled chat header, an opening message, a persistent indicator — not a legal footnote discovered after the fact. The design question (where, when, how prominently) is the compliance question, which is why disclosure is a UX decision your product and legal teams should make together.
Do these three things now
1. Map every customer-facing bot that interacts with California users in a sales or electoral context. 2. Add a clear, conspicuous bot disclosure at the point of interaction — not in the fine print. 3. Reuse the pattern to front-run EU Article 50 and California CAITA, both landing August 2, 2026.
SB 1001 is old, narrow, and easy to overlook — and it’s the clearest early sign of where global AI transparency law is heading. Solve it once, deliberately, and the next two deadlines become a copy-paste instead of a scramble.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 22, 2026.
See how a Gap Assessment maps your exposure →Not sure which of these reach you?
Find out in 30 minutes.
The free AI Risk Exposure call maps your AI footprint to the obligations that actually apply — and the ones that don’t.
Book the call →