Every few months a California business owner reads a headline about AI regulation and concludes that automated marketing communication is now legally risky. Usually it is not. California's bot law is narrower and more sensible than the coverage implies, and complying with it takes roughly one sentence.
Here is the plain-English version, and where it does and does not apply across a marketing stack. General information, not legal advice.
What the law says
SB 1001, the B.O.T. Act, took effect July 1, 2019 and lives at California Business and Professions Code §§ 17940–17943.
The core prohibition: it is unlawful to use a bot to communicate or interact with a person in California with the intent to mislead the person about its artificial identity, in order to knowingly deceive them about the content of the communication for the purpose of incentivizing a purchase or sale of goods or services in a commercial transaction, or influencing a vote.
The safe harbor: no violation if the bot discloses that it is a bot, and the disclosure is clear, conspicuous, and reasonably designed to inform the person.
Three things worth noticing
Intent to mislead is an element. The statute targets deception, not automation. An automated system that identifies itself honestly is not what it was written about.
It is tied to commercial transactions and elections. Not a general prohibition on automated interaction.
Disclosure is a complete safe harbor. No filing, no registration, no approval process. Disclose clearly and you are within the exception.
So the question is never "can we use this in California." It is "is our disclosure clear and conspicuous."
Where it applies in a marketing stack
Website chat. The most obvious case. If your site has a conversational assistant, disclose it in the opening message, not buried in a terms link.
Automated SMS conversations. If your system holds a back-and-forth text conversation, disclose. A one-way confirmation text is not the same thing as a conversational bot, but if it responds and converses, treat it as in scope.
Phone answering. Disclose in the greeting or immediately when asked. If a caller asks whether they are speaking with a person, the answer is a direct no followed by continuing to help — not a deflection.
Where it is less relevant. Automated bidding, audience targeting, content generation, and internal analytics do not involve a bot communicating with a person as its artificial identity. The statute is about the conversation, not the infrastructure.
What clear and conspicuous looks like
Good: a short statement in the opening — in the chat window's first message, in the phone greeting, at the start of an automated text thread. Early enough that the person has not invested anything in the conversation before learning it.
Also good: an immediate honest answer when asked directly.
Not good:
- Disclosure buried in the fourth sentence of a long greeting most people talk over
- A human first name presented with no clarification, ever
- Disclosure only in your website terms of service
- Evasion when asked, "I'm here to help you today!" in response to "are you a real person?" is the clearest possible bad fact
The related rules people conflate with it
Four separate regimes that all need their own answer, and none of which SB 1001 addresses:
Call recording. Penal Code § 632 requires all-party consent for confidential communications. Entirely separate. Complying with the bot law does nothing for this.
Data privacy. What you do with recordings, transcripts, and customer data after the interaction is governed by California's privacy framework.
Text messaging consent. Largely federal, with its own consent and opt-out requirements.
Automated employment decisions. Separate rules apply if you use automated tools in hiring.
If you are building a marketing automation stack in California, all four need attention alongside SB 1001.
The five-minute audit
Run this today on your own business, from a device and number nobody recognizes:
1. Open your website chat. Is the automated nature disclosed in the first message, clearly?
2. Call your main number. Is there a recording notice before you say anything substantive? Ask "am I talking to a real person?" and note exactly what comes back.
3. Call your after-hours number. Same tests.
4. Call every advertising tracking number. Same tests. This is where the gaps are, because those numbers are usually configured by whoever set up the ad campaign rather than whoever configured the phone system.
5. Trigger an automated text sequence. Is it disclosed if it is conversational?
Any path that fails is a configuration change measured in minutes. The reason to do it now is that it is trivial today and awkward to explain later.
Why building to the California standard is efficient
California was first. It is not alone anymore. Colorado, Utah, Maine, and New Jersey all regulate commercial chatbot disclosure in some form, and the FTC's general prohibition on deceptive practices applies nationwide.
That means one disclosure configuration, deployed everywhere, keeps you clean across the states that regulate it and costs you nothing in the states that do not. Businesses that maintain a permissive configuration for most states and a special one for California create exactly the kind of drift where somebody eventually deploys the wrong one.
The honest bottom line
This is not an obstacle to marketing automation in California. It is a requirement to be honest about it, which is what you should be doing regardless, a customer who discovers on their own that they were misled is a customer you have lost, and a customer told plainly almost never cares.
Configure it, audit every path, document what you did, and get back to the work that makes money.
