The Short Version
Yes, and at the start of the call rather than when someone asks.
The usual reasoning for disclosure is about trust, and that reasoning is sound. But there is a second reason practices tend not to know about: in at least one state, a licensed practice using generative AI in a call that collects health information is already expected to say so out loud at the beginning, and disclosing proactively is what earns the statutory safe harbour. The trust argument and the legal argument point the same way, which makes this an unusually easy decision.
This is not legal advice, and state law here is moving quickly. What follows is a description of two published statutes as read on 17 September 2026, and the operational case. Confirm your own position with your counsel, because the answer depends on where you practise.
The Law Is Narrower Than People Think, and Also Broader
Two statutes get cited in this conversation, and both are usually described wrongly.
California is narrower than its reputation. California Business and Professions Code section 17941, added by SB 1001 and operative from 1 July 2019, is widely summarised as “California requires bots to identify themselves.” It does not, quite. It makes it unlawful to use a bot to communicate with a person in California online with intent to mislead about the bot’s artificial identity, in order to deceive the person about the content of the communication and incentivise a sale or influence a vote. There is no liability if the operator discloses, and the disclosure must be “clear, conspicuous, and reasonably designed to inform.” A system that never pretends to be a person, in a practice with no intent to deceive anyone, sits outside the core prohibition even if it says nothing.
So “California makes me do it” is a weak argument. The problem is that practices then conclude nothing makes them do it, and that is where the second statute matters.
Utah is broader than its reputation. The Utah Artificial Intelligence Policy Act, as amended by SB 226 and in effect from 7 May 2025, was reported at the time as a narrowing, and for most businesses it was: the general duty became disclosure on request, triggered by a clear and unambiguous question about whether the interaction is with a human or with artificial intelligence.
But the amended Act keeps a stronger, proactive duty for a specific group. Providers in regulated occupations, meaning those requiring a state licence, must give prominent disclosure when delivering services in a high-risk artificial intelligence interaction, and the Act specifies the timing: verbally at the start of a verbal interaction, or in writing at the start of a written one. A high-risk interaction includes one involving the collection of sensitive personal information such as health data, or the provision of personalised advice a person could reasonably rely on for a significant personal decision.
Read that against a dental practice taking a patient call. Dentistry is licensed. The call collects health information. It is a verbal interaction. The Act’s repeal date was extended to 1 July 2027 by SB 332, so this is not a rule that is about to lapse.
The safe harbour is the practical part. Under the amended Act, an entity is not subject to enforcement for the disclosure provisions where the system clearly and conspicuously discloses that it is not human at the outset of, and during, the interaction. Proactive disclosure is not merely permitted. It is the thing that buys you protection.
Utah binds practices in Utah. Most states have no rule squarely on point today. But if you are choosing a default for a system you will run for years, the direction of travel across state legislatures is one way, and the cheapest posture is the one that already complies with the strictest rule you can find.
The Argument That Would Hold Even Without a Statute
Disclosure costs you almost nothing and buys three things.
It removes the moment of discovery. The damage in these calls is rarely the AI. It is the patient realising partway through that they were mistaken about what they were talking to. Disclosure at the top means there is nothing to discover, and the caller spends the call deciding whether the thing is useful rather than whether it is real.
It makes the request for a human legitimate. A caller who knows they are talking to a system asks for a person without embarrassment. A caller who is unsure hedges, repeats themselves, and gets frustrated. Disclosure is what makes the escape hatch usable, and the escape hatch is what keeps the difficult calls from going badly.
It protects the practice from the worst version of the story. “Our AI answered the phone” is a neutral sentence. “Their AI pretended to be a person” is a complaint, a review, and occasionally a regulator’s interest. The gap between those two sentences is one clause in a greeting.
Against that, the fear is that callers hang up. Practices that have run it generally find the opposite: the hang-ups come from hold music and voicemail, not from a system that answers in under a second and books the appointment.
What Good Disclosure Actually Sounds Like
Disclosure is not a disclaimer. The failure is a legalistic sentence that makes the caller brace.
It works when it is short, early and followed immediately by usefulness. Name the practice, say what the assistant is, and move straight to helping. The caller should hear that they have reached the right place and that something is about to get done. A greeting that spends eight seconds on a compliance statement before asking how it can help has technically disclosed and practically annoyed.
Two rules worth setting alongside it:
- Do not claim to be a person, ever, including when asked directly. “Am I talking to a real person?” has one acceptable answer, and the system should never be configured to deflect it.
- Disclose once, clearly, and do not keep apologising for it. Repeating it every turn is its own kind of bad experience.
We have worked scripts for both the greeting and the human-request path in building patient trust with an AI receptionist, and the evidence on how callers actually react in will patients be annoyed if AI answers.
What to Ask a Vendor
- Is the disclosure in the default greeting, and can it be removed? Ask to hear the greeting as it would ship, not as it could be configured.
- What happens when a caller asks directly whether they are speaking to a person? Ask them to demonstrate the call.
- Does the disclosure survive a transfer? If the system hands off to a human, the caller should be able to tell that something changed.
- Is it recorded anywhere? A transcript showing the disclosure was made is the evidence you would want later.
- Can it disclose differently by location? For a group operating across state lines, that is not a hypothetical.
Key Takeaways
- Disclose at the start of the call, not on request. Under Utah’s amended Act, proactive disclosure at the outset is what creates the safe harbour.
- California’s section 17941 is about intent to mislead in online commercial contexts, so “no law requires me to” is a misreading of a narrower statute rather than a description of the whole field.
- A dental practice is a licensed occupation and a patient call collects health data, which is the combination Utah’s Act treats as high risk.
- The operational case stands on its own: disclosure removes the moment of discovery and makes the request for a human legitimate.
- Never configure a system to claim it is a person when asked directly.
Frequently Asked Questions
Do we need this if we only use AI after hours? The interaction is the same interaction. A caller at 9pm does not know your staffing model.
Does saying it is AI make patients trust us less? The reverse is the more common finding, because the alternative is not a human receptionist. It is voicemail. Patients compare the AI to what actually happened before.
What if we operate in several states? Then you are choosing between configuring per state and adopting the strictest rule everywhere. Most groups take the second option because it is simpler to run and does not need revisiting each legislative session.
Is a disclosure in our privacy policy enough? The Utah timing language is about the start of the interaction, and California’s requires disclosure reasonably designed to inform the person it is communicating with. Neither reads like a document nobody opens.
Sources
All read 17 September 2026. Statutes change; check the current text before relying on any of this, and take your own legal advice.
- California Business and Professions Code section 17941, added by SB 1001, operative 1 July 2019. Bill text and codified section.
- Utah Artificial Intelligence Policy Act as amended by SB 226, in effect 7 May 2025, with the Act’s repeal date extended to 1 July 2027 by SB 332. Analysis of the amendments, including the regulated-occupation disclosure timing and the safe harbour, from Davis Wright Tremaine.
Related Posts
How AI Hands Difficult Calls to Your Team
The transfer is the part that breaks. Here is what has to be true for a handoff to work, what the vendors actually publish about theirs, and the failure nobody puts on a feature list.
Does Your Answering Service Actually Book?
Most services that promise scheduling are really taking a very tidy message. Here is the difference, and a five-minute test that tells you which one you are being sold.
What to Hand Over Before Go-Live
An AI receptionist enforces your rules; it does not invent them. Here is the handover pack that turns setup into a transcription job instead of a series of guesses.