New state AI-disclosure laws take effect this summer. Here's why 'sounding human' just became a compliance liability, and how to evaluate voice AI now.
The Rule Change Landing This Summer
Starting mid-2026, a wave of state-level AI-disclosure laws takes effect, following the paths California, Utah, and Colorado already cleared. The core requirement is simple: if a caller is talking to an AI, you have to tell them. This extends the FCC's earlier ban on AI-generated voices in robocalls into the territory that actually matters for local service businesses: everyday inbound customer service and dispatch calls.
Regulators have been explicit about where this goes next. The robocall ban was about outbound spam. The new guidance signals that AI phone agents used by ordinary businesses, the receptionist that answers when someone calls your HVAC shop at 7am with no heat, are squarely in scope. Buyers are already re-scoping RFPs around it. If you are evaluating voice AI right now, 'does your AI disclose itself?' belongs at the top of the list, not the bottom.
The Arms Race Just Became a Liability
Here is the uncomfortable part for the whole category. For two years, the entire voice-AI industry optimized for one metric: indistinguishability. The pitch was always some version of 'your customers won't be able to tell it's a bot.' Vendors demoed the strategic 'um,' the fake keyboard clatter, the breath sounds engineered to pass as human.
That was always a strange thing to be proud of, and now it is a legal exposure. If your competitive advantage is that callers cannot tell they are being recorded and processed by an AI, you have built your product on the exact behavior these laws exist to stop. The better the impersonation, the clearer the violation.
Think about the parallel to TCPA. Nobody worried about text-message consent until the class-action bar made non-compliance expensive. Disclosure law is heading the same direction. The business that deploys a non-disclosing agent, not just the vendor who sold it, carries the risk. That is the 'did I just buy a liability?' problem, and it is the same instinct that made Your AI Receptionist Could Be Your Biggest Security Risk the most-read thing we have published. The threat model has simply moved from the breach to the regulator.
Disclosure Actually Converts Better
Now the counterintuitive part, and this is the piece most people get wrong. The assumption behind the impersonation arms race was that disclosure kills conversion. Tell people it's a bot and they hang up. In practice, the opposite tends to happen once you design for it.
When an AI opens with something like 'Hi, this is the automated assistant for Rodriguez Plumbing, I can get you scheduled right now,' it resets the caller's expectations in a useful way. People stop trying to trap it with small talk. They speak in clearer, more complete sentences. They are more willing to spell an address or repeat a card number because they know they are talking to a system. The awkward valley, where a caller half-suspects they are being fooled and gets guarded, disappears.
Disclosure also does something for trust that no amount of realism can. A homeowner who learns after the fact that the 'nice woman' who took their emergency call was a bot feels manipulated. A homeowner who was told upfront and still got their job booked in ninety seconds feels efficiently served. One of those relationships survives to a second call.
The winning move is not a more convincing human. It is transparent AI that discloses itself, captures consent cleanly, and still books the job. That is a product design goal, not a marketing concession.
The Evaluation Checklist
We wrote before, in Why Vendor Invoice Processing Needs a Reality Check, that if your automation cannot tell you when it is uncertain, it is not automation, it is a liability. The same honesty test applies to voice. Here is what to actually verify before you sign, phrased as questions a vendor should be able to answer without squirming.
- Disclosure, on by default. Does the agent identify itself as AI at the start of every call, in plain language, without you having to configure it? Can you customize the wording to name your business, and is there a log proving the disclosure fired on each call?
- Consent logging. When the agent records the call or captures payment and personal details, does it request and store consent as a timestamped, per-call record? You want a defensible artifact, not a checkbox buried in a settings page. If a regulator or a customer asks 'did you have consent,' you need to answer with data.
- Audit trail. Can you pull a complete, tamper-evident record of what the AI said, what it heard, what it decided, and when? Disclosure law is enforced on evidence. An agent that cannot reconstruct a specific call from six weeks ago is an agent you cannot defend.
- Opt-to-human. When a caller says 'I want a real person,' does the system route them cleanly to a human, every time, without a loop? This is both a compliance safeguard and a trust signal. Regulators care about it, and so do your best customers on their worst day.
- Data residency and retention. Where do the voice recordings and transcripts live, who processes them, and how long are they kept? Indefinite retention of full call transcripts is its own exposure, a point worth weighing alongside the cost math we ran in The Hidden Costs of Poor Invoice Management.
If a vendor treats these as edge cases or roadmap items, that tells you where their engineering effort went, and it was not here.
What To Do Before The Deadline
Do not wait for your state's effective date to become your enforcement date. Pull up your current or prospective voice agent this week and place a test call. Listen for whether it discloses itself unprompted. Ask your vendor for a sample consent log and a sample audit record, actual exports, not a slide. If they cannot produce them, you have your answer.
The firms that bet everything on 'you can't tell it's a bot' are about to be on the wrong side of both the law and their customers. The firms that treated disclosure as a feature are about to look like they saw it coming.
We built Reeve's call handling to disclose itself, log consent, and hand off to a human on request, because we thought transparent AI would win on trust before it was ever required by law. If you are re-scoping how you evaluate voice AI this summer, start with the checklist above and hold every vendor, including us, to it.