August 10, 2026

What Are the AI Disclosure Requirements for My Industry?

Decision map of the four triggers that create a legal AI disclosure duty, with the industries and jurisdictions each one applies to
Photo: Magic Teams AI / generated in the build

No law tells your industry to label AI work. Disclosure duties fire on triggers, not job titles: a licensed professional letting AI touch a client’s substantive matter, an AI system that talks to people unsupervised, AI touching an employment decision, or an AI claim you can’t back up. Most agencies and consultancies cross zero or one of those. Healthcare, legal, insurance, and financial advice cross several, and those rules are already in force.

That reframe matters, because the headlines make this sound like an emergency for everyone. It isn’t. States enacted 109 AI laws in the first half of 2026 and almost none of them say “tell people AI wrote this” (Tech Policy Press, July 2026).

One caveat before the map. This is plain language, not legal advice. Duties turn on your license, your state, and what the AI actually does, so run your final answer past counsel who knows your field.

Is there one AI disclosure law that covers my industry?

No. There’s no federal AI disclosure statute in the United States, and the federal picture got less settled through 2026, not more.

A December 11, 2025 executive order directed the Justice Department to challenge state AI laws, and DOJ stood up an AI Litigation Task Force on January 9, 2026 (Paul Hastings, 2026). No preemption statute passed. States kept legislating anyway.

You can watch that collision play out in Colorado. xAI sued the state in April 2026 over its 2024 AI Act, DOJ intervened, the court stayed the law’s start date, and Colorado’s legislature then repealed and replaced the whole thing (Norton Rose Fulbright, 2026).

So the question that actually pays off is narrower than “what does my industry require.” It’s which of four triggers your day-to-day work crosses.

What actually triggers an AI disclosure requirement?

Four things trigger a written-in-law duty to disclose. Everything else is a trust decision or somebody else’s obligation.

Cross none of them and no law makes you label anything. Disclosure becomes a trust choice at that point, which is a different and often more interesting decision.

Notice what’s missing from the four. “I used ChatGPT to draft a proposal” isn’t on the list. Neither is “our newsletter was written with AI and edited by a person.”

These laws police deception, unsupervised machines, and consequential decisions. They mostly don’t police authorship.

Which AI disclosure rules apply to my industry?

Here’s the map for the industries a $1M to $10M service business is most likely to sit in or sell to. Status is as of August 2026.

Industry What triggers disclosure Rule to read Status
Healthcare (CA) GenAI writes patient clinical communications without provider review CA AB 3030 In force since Jan 1, 2025
Healthcare (TX) AI used in diagnosis or treatment TRAIGA HB 149 and SB 1188 In force; HB 149 since Jan 1, 2026
Law AI output influences a significant decision, the client asks, or the engagement letter says so ABA Formal Op. 512 plus your judge’s standing order In force; court orders vary by judge
Investment advice How you describe AI in marketing, Form ADV, and client comms Advisers Act antifraud rules and the Marketing Rule 2026 SEC exam priority
Insurance Written AI governance program, documentation to the regulator on request NAIC Model AI Bulletin as adopted by your state 25 jurisdictions as of Aug 6, 2026
Any employer (IL) AI used in recruiting, hiring, promotion, discipline, discharge Illinois HB 3773 In force since Jan 1, 2026
Any employer (NYC) Automated employment decision tool screens candidates NYC Local Law 144 In force; bias audit plus 10 business days notice
Licensed occupations (UT) High-risk interaction, or a consumer clearly asks if it’s AI Utah AI Policy Act, as amended In force; sunsets July 1, 2027
Anyone with EU users Chatbot interaction or synthetic media EU AI Act Article 50 Applicable since Aug 2, 2026
GenAI providers over 1M monthly users AI-generated image, video, or audio CA AI Transparency Act (SB 942 / AB 853) In force since Aug 2, 2026
Everyone else (US) Deceptive or unsubstantiated AI claims FTC Act Section 5 Always on

Colorado is missing from that table on purpose. Its sweeping AI Act was repealed and replaced by SB 26-189, signed May 14, 2026, and the new framework doesn’t start until January 1, 2027 (Davis Wright Tremaine, 2026).

California’s Transparency Act is in the table but rarely applies. It binds generative AI providers above a million monthly users and covers image, video and audio rather than text.

What must healthcare practices disclose?

If a practice uses generative AI to write patient communications about clinical information, California requires a disclaimer plus clear instructions for reaching a human provider.

AB 3030 has been in force since January 1, 2025 and covers health facilities, clinics, physician offices, and group practices. The disclaimer has to appear at the start of written messages, throughout a chat or video interaction, and verbally at the beginning and end of an audio interaction.

Enforcement runs through the medical boards and health facility licensing (Morgan Lewis, 2024).

Two carve-outs do most of the work. Administrative messages like scheduling, reminders, and billing are exempt. So is any AI-drafted clinical communication that a licensed provider reads and reviews before it goes out.

That second exemption is the whole design principle. Keep a clinician in the loop and the labeling duty falls away.

Texas went the other direction. Under TRAIGA, effective January 1, 2026, a provider using AI in diagnosis or treatment must give the patient a clear, plain-language disclosure no later than the date of service, or as soon as reasonably possible in an emergency (Holland & Knight, 2025). Human review doesn’t excuse it.

The Attorney General enforces. Civil penalties run $10,000 to $200,000 per curable violation and $2,000 to $40,000 a day for continuing ones, with a 60-day cure period for some conduct (Ashurst Perkins Coie, 2025).

Texas SB 1188 separately requires a physician to review any AI-produced record before it enters the chart (Texas Medical Liability Trust).

Same clinic, same tool, different duties by state. That pattern repeats in every industry below.

What must law firms disclose?

Lawyers face two duties, and the court one is stricter and messier than the client one.

On the client side, ABA Formal Opinion 512 says lawyers “must disclose their GAI practices if asked by a client how they conducted their work,” or if the engagement agreement or outside counsel guidelines require it. Consultation is also required when a tool’s output “will influence a significant decision in the representation” (ABA Formal Opinion 512, July 2024).

The opinion also requires informed consent before you put client confidential information into a self-learning tool, and it says boilerplate in an engagement letter isn’t informed consent.

On the court side there’s no national rule. Individual judges have issued standing orders ranging from certifying that a human verified every AI-generated citation, to disclosure on the first page of a filing, to outright bans on using generative AI in research (Drug & Device Law, April 2026).

The stakes here are documented and growing. The AI Hallucination Cases database, which only counts decisions where a court found or clearly implied reliance on fabricated material, listed 1,868 cases worldwide including 1,297 in the United States as of August 8, 2026 (Damien Charlotin, HEC Paris).

The practical rule for a small firm: check the specific judge’s standing order before every filing, and keep a verification log for anything AI touched.

What about accountants, financial advisers, and insurers?

These three land in the same bucket for a different reason. Their disclosure duty is mostly about how you describe and govern AI, not whether you use it.

For investment advisers, “AI washing” means overstating how you use AI. The SEC brought its first two cases in March 2024 against Delphia and Global Predictions, settled for $400,000 in combined penalties (Morgan Lewis, 2024).

AI washing stayed on the 2026 examination priorities list (Goodwin, 2025). The exposure runs through the Marketing Rule and your Form ADV, which have to describe the extent and limits of AI use accurately.

For insurance, the NAIC Model Bulletin on the Use of AI Systems by Insurers requires a written AI systems program with senior accountability, model validation, vendor oversight, and documentation available to the regulator on request.

It was adopted December 4, 2023, and NAIC’s own tracker shows 25 jurisdictions had adopted it as of August 6, 2026, with California, Colorado, New York, and Texas running their own insurance-specific AI guidance instead (NAIC adoption map). That’s a governance duty aimed at your regulator rather than a consumer label.

For accountants and other licensed practitioners in Utah, the AI Policy Act sets a two-tier rule. After the 2025 SB 226 amendments, a general business only has to answer when a consumer clearly and unambiguously asks whether they’re dealing with AI.

A regulated occupation has a higher bar, though the amendments narrowed it. Prominent disclosure at the outset is required in a high-risk interaction, meaning one that both collects sensitive personal data and gives personalized advice a person could reasonably rely on for a significant decision.

Both halves have to be present. Disclosing clearly at the outset and throughout the interaction creates a safe harbor (Davis Polk, 2025).

Confidentiality duties sit alongside all of this and often bite harder than disclosure does. We covered that side in safe AI for law firms and accountants.

Does AI in hiring create a disclosure duty in my industry?

Yes, and this trigger is industry-agnostic. It catches marketing agencies and construction firms exactly as hard as it catches hospitals.

Illinois HB 3773 took effect January 1, 2026. It amends the Human Rights Act to bar discriminatory AI in employment and requires employers to notify employees and applicants whenever AI is used in recruitment, hiring, promotion, renewal, selection for training, discharge, discipline, or tenure (National Law Review, 2025).

The Illinois Department of Human Rights withdrew its proposed implementing rules and hasn’t republished them, so the detailed timing and format guidance is still pending. The statutory notice duty is in force regardless (Reinhart, 2026).

New York City got there first. Local Law 144 requires an independent bias audit within one year of using an automated employment decision tool, a public summary of the results, and notice at least 10 business days before the tool is used on a candidate (NYC DCWP).

Penalties there run $500 for a first violation and $500 to $1,500 for each later one, and every day of missed notice counts separately.

Colorado joins this list on January 1, 2027. SB 26-189 will require a pre-use notice before automated decision-making technology materially influences a consequential decision, plus an explanation within 30 days of an adverse outcome (Davis Wright Tremaine, 2026).

If you run an AI resume screener and hire in any of those places, you have a duty regardless of what business you’re in.

What if I’m a marketing agency, ecommerce brand, or general service business?

Then in most cases you have no AI labeling duty at all, and two real obligations.

The first is the FTC. Section 5 bans unfair and deceptive practices, and the agency’s Operation AI Comply sweep made the point that there’s no AI exemption from existing law. Those cases targeted fake AI-generated reviews, an “AI lawyer” service, and inflated AI money-making claims (FTC, 2024).

Nobody got charged for using AI. They got charged for lying about it.

The second is bots. California’s B.O.T. Act makes it unlawful to use a bot to communicate with a Californian to incentivize a sale without disclosing the bot, though the duty attaches to public-facing sites and apps above 10 million monthly US visitors (CA SB 1001).

That threshold puts most small businesses outside the letter of the statute, though the deception principle behind it still reaches you through the FTC. Companion chatbot rules were the most active state category in the first half of 2026, with 14 laws enacted (Tech Policy Press, 2026).

If you’re weighing the trust side rather than the legal side, we worked through that in should I tell clients my agency uses AI.

Do EU customers change the answer?

Yes, and this one turned on recently. The EU AI Act’s Article 50 transparency obligations became applicable on August 2, 2026.

Two triggers matter for a service business. If you deploy an AI system that interacts directly with people, they have to be informed they’re dealing with AI before or at the very start of the conversation. And AI-generated or manipulated content, including deepfakes, has to be disclosed or machine-readably marked (EU AI Act Article 50).

There’s an exception when the AI nature is obvious to a reasonably observant person, but the Commission reads it narrowly, limited to cases where almost no doubt remains (European Commission FAQ).

One timing detail is worth knowing. The Article 50(2) marking obligation for generative systems already on the market before August 2, 2026 was pushed to December 2, 2026 under the digital omnibus provisional agreement. The rest of Article 50 wasn’t delayed, and penalties reach 15 million euros or 3% of worldwide turnover (Cooley, August 2026).

A founder-reviewed email is not a chatbot. An always-on AI reply agent handling EU inbound is. We mapped that distinction in do AI email disclosure laws apply to my business.

Worked example: an agency that crosses four triggers

Take a 28-person marketing agency headquartered in Chicago. It uses an AI screener for inbound applicants, runs an AI chat widget on client sites, writes patient-facing email campaigns for a California dermatology group, and has two clients in Germany.

The agency’s own industry has no AI disclosure law. It still ends up with four duties.

The healthcare one is the instructive case. AB 3030 binds the dermatology practice, not the agency. But the agency built the campaign, so the disclaimer and the human-review step have to exist in the workflow the agency delivers, or the client is exposed and the agency is the reason.

That’s the pattern worth internalizing. In a service business, your binding rules usually arrive through your clients’ industries rather than your own.

Personal insight

When Magic Teams AI installs an email or support layer, disclosure config is a build decision, not a policy document. We ask three questions before writing a single automation: does a named human approve before send, does this system ever talk to an outsider unsupervised, and whose license is on the line if it’s wrong. Those answers decide where a disclaimer gets hard-coded into the workflow and where one would just be noise.

How do I find the rules that apply to me?

You can get a defensible answer in about two hours. Work down this list, then take it to counsel instead of starting from a blank page.

Most businesses finish this and find one or two real duties, not twenty. The unsupervised-bot line and the hiring line catch the most people by surprise.

The design lesson underneath the audit is simple. These rules were mostly written to catch machines acting alone, so a system where a named human approves anything consequential never trips most of them. That’s why we treat human approval as an architecture choice rather than a compliance afterthought.

Which dates should I have on my calendar?

Most of these only matter if you sell into a specific place. Know them anyway, before you build something you’d have to redo.

The wildcard sits outside the timeline. The DOJ task force and the states will either narrow this patchwork or leave it as is, and Colorado shows the fight is real rather than theoretical (Paul Hastings, 2026). Neither outcome is a reason to stall a project you’d otherwise ship.

Key takeaways

  • There’s no general AI disclosure law by industry. Duties fire on four triggers: licensed work, unsupervised bots, employment decisions, and AI claims.
  • Healthcare has the most specific rules. California requires a disclaimer on unreviewed GenAI clinical communications; Texas requires disclosure of AI in diagnosis or treatment even when a human reviews it.
  • Lawyers answer to ABA Opinion 512 with clients and to an inconsistent set of individual judges in court, where 1,297 US decisions have already addressed fabricated AI material.
  • AI in hiring creates a notice duty in Illinois and New York City today, and in Colorado from January 1, 2027, no matter what industry you’re in.
  • Service businesses usually inherit their strictest rules from clients’ industries rather than their own, and human approval before anything consequential makes most of these duties moot.

Frequently asked questions

Do I legally have to disclose that my business used AI to write something?

In most industries, no. There’s no general US law requiring you to disclose AI as a drafting or analysis tool, so using ChatGPT on a client proposal triggers nothing by itself. The exceptions are licensed contexts: a lawyer whose AI output influences a significant decision in a representation, a Utah-regulated professional in a high-risk interaction, or a healthcare provider in California or Texas. Your own client contracts or a procurement policy may add a duty the law doesn’t, so check your agreements.

What happens if I don’t disclose when I’m required to?

It depends on the rule. Texas TRAIGA carries civil penalties of $10,000 to $200,000 per curable violation, plus daily penalties for continuing conduct, enforced by the Attorney General. California AB 3030 routes through your licensing board. FTC matters end in consent orders, refunds, and injunctive terms. NYC Local Law 144 runs $500 to $1,500 per violation with each day counting separately. EU Article 50 penalties reach 15 million euros or 3% of worldwide turnover.

Do AI disclosure rules apply to internal AI use?

Mostly no, with one large exception. Internal drafting, research, and summarizing generally trigger nothing. But AI used in employment decisions is internal by nature and does trigger notice duties in Illinois and New York City today, and Colorado in 2027. Confidentiality rules still govern what data you feed into any tool.

If my client is in a regulated industry, whose problem is compliance?

Legally it’s usually the licensed entity’s problem. Practically it becomes yours, because they’ll expect the deliverable you built to meet their rules. Write the disclosure and human-review steps into the workflow you hand over, and put the allocation of responsibility in the contract.

Is a general federal AI disclosure law coming?

Nothing has passed. The December 2025 executive order and the DOJ’s AI Litigation Task Force aim to constrain state AI laws rather than create a federal disclosure standard, and as of August 2026 no preemption statute exists. Planning around the state patchwork remains the realistic approach.

Working out which triggers your setup crosses, and how to build the system so it crosses as few as possible, is a conversation worth having before you automate anything customer-facing. Magic Teams AI runs exactly that mapping at the start of every one-week install, and we still send the final call to your counsel, because the answer depends on your license and your states.