In several states, yes. California requires a disclaimer on AI messages about clinical information. Utah requires one in high-risk interactions by licensed professions. Texas requires one whenever AI is used in health care services. Federally, AI voices are "artificial" under the TCPA. The safe rule: disclose at the start of every AI call and text.
Takeaways
No single federal disclosure rule yet
The FCC proposed one in 2024. It had not been adopted as of August 2026.
State laws overlap and differ
California, Utah and Texas each cover different situations with different wording.
AI voices are "artificial voices." The FCC ruled in 2024 that TCPA consent rules apply to AI-generated voice calls.
Disclose everywhere
One plain sentence at the start of every AI call and text covers the strictest rules.
California: AB 3030 and SB 1001
AB 3030 (Health and Safety Code 1339.75) took effect January 1, 2025. It applies when a health facility, clinic, physician's office or group practice uses generative AI to create patient communications about clinical information.
What it requires depends on the format:
- Written messages (letters, email): a disclaimer at the start.
- Chat and video: a disclaimer shown throughout the interaction.
- Audio (phone calls, voicemail): a spoken disclaimer at the start and at the end.
- Every message: clear instructions on how to reach a human health care provider or staff member.
Two important limits:
- Provider review exemption. If a human licensed or certified health care provider reads and reviews the AI-generated message before it goes out, the disclaimer isn't required.
- Administrative matters are excluded. Scheduling, billing and similar business messages fall outside AB 3030.
SB 1001 (Business and Professions Code 17941) has been in force since July 1, 2019. It makes it unlawful to use a bot online to mislead someone about its artificial identity to drive a sale or influence a vote. A clear, conspicuous disclosure is a safe harbor. It matters most for marketing chat on your website.
Utah: SB 149 and SB 226
Utah's AI Policy Act (SB 149) took effect May 1, 2024. It required regulated occupations, which include licensed health professions, to "prominently disclose" generative AI use. For calls, that means spoken at the start. For electronic messaging, before the written exchange begins. Fines run up to $2,500 per violation.
SB 226 (effective May 7, 2025) narrowed the duty for regulated occupations to "high-risk" interactions. Those include collecting health, financial or biometric data, or giving advice people may rely on. Most patient calls touch health information, so assume they count. Other businesses must disclose only when someone clearly asks whether they're talking to AI.
SB 332 pushed the Act's repeal date to July 1, 2027. Watch for changes before then.
Texas: TRAIGA
The Texas Responsible Artificial Intelligence Governance Act (HB 149) took effect January 1, 2026. Under Business and Commerce Code 552.051(f), if an AI system "is used in relation to health care service or treatment," the provider must disclose it.
- When: no later than the date the service is first provided, or as soon as reasonably possible in an emergency.
- How: clear, conspicuous, plain language, with no dark patterns. A hyperlink is allowed.
- Enforcement: the Texas Attorney General. Penalties are $10,000 to $12,000 per curable violation and $80,000 to $200,000 per uncurable one.
Unlike AB 3030, TRAIGA isn't limited to clinical content. An AI reminder call about a health care service plausibly falls inside it.
Colorado: SB 26-189
Colorado's original AI Act (SB 24-205) included a general duty to tell consumers when they were interacting with an AI system. SB 26-189, signed May 14, 2026, repeals and reenacts that law as an automated decision-making law. According to an analysis by the law firm McDermott, it drops the general AI-interaction disclosure.
What remains applies only when automated decision-making technology is used in a "consequential decision," including health care. McDermott describes notice at the point of interaction and a plain-language explanation within 30 days of an adverse outcome. It applies to decisions made on or after January 1, 2027. A routine reminder call isn't a consequential decision. Coverage or eligibility determinations might be.
AI calls and texts with opt-out built in
Start free in the Rivvi workspace. Calls, texts and the website widget are on Team.
Federal: the FCC and the TCPA
FCC 24-17 (February 2024) is a declaratory ruling that AI-generated voices, including voice clones, are "artificial" voices under the TCPA. That means the TCPA's consent rules for artificial or prerecorded voice calls apply to AI calls. It doesn't create a disclosure duty by itself, but it puts AI calls squarely inside TCPA consent and opt-out rules. Our TCPA guide for healthcare covers those rules.
FCC 24-84 is a proposed rule from August 2024. It would define "AI-generated call," require disclosure when consent is collected, and require disclosure at the start of each AI-generated call. Comments closed in October 2024. As of August 2026, the FCC had not adopted a final rule. If it does, a start-of-call disclosure becomes a national requirement.
The practical rule: disclose everywhere
Tracking which law covers which call in which state is a losing game. A patient's phone number doesn't tell you where they are, and many practices serve patients across state lines.
The approach that satisfies the strictest version of each law:
- 1
Say it at the start of every AI call
One plain sentence, such as: 'This is an automated assistant using AI, calling for [Practice name].' Put it before any health discussion.
- 2
Say it again at the end of clinical calls
Repeat the AI disclaimer before hanging up when the call involved clinical information.
- 3
Label every AI text and chat
Start texts with who is sending and that it is automated. Keep a persistent AI label in website chat.
- 4
Always offer a human
Tell patients how to reach staff, and give them a live option. A warm transfer to the right person works best.
- 5
Answer truthfully when asked
If a patient asks whether they're talking to a person, the AI must say it is AI. Every time.
- 6
Write it into policy
Add the disclosure rule to your AI acceptable use policy so every campaign and vendor follows it.
How Rivvi handles it
Rivvi is a HIPAA-compliant AI workspace with an action layer for inbound and outbound AI calls, texts and a website chat widget. TCPA opt-out is honored on every outreach path. When a patient wants a person, Rivvi can warm-transfer them live to the right department or create a follow-up task for staff.
At Southeast Medical Group (August 2026), Rivvi reached 104,000+ patients with a 0.45% opt-out rate.
For the policy side, see our AI acceptable use policy template, which includes a patient-facing disclosure section.
Start in the workspace
Free for you and two colleagues, with a HIPAA BAA. Calls and texts are on Team.
Sources
- California AB 3030 bill text
- Medical Board of California: GenAI notification requirements
- California Business and Professions Code 17941 (SB 1001)
- Utah SB 149 (2024), enrolled
- Utah SB 226 (2025), enrolled
- Utah SB 332 (2025), enrolled
- Texas HB 149 (TRAIGA), enrolled text
- Colorado DRE: SB 26-189 summary
- McDermott: Colorado AI law in flux
- FCC 24-17 Declaratory Ruling (AI voices under the TCPA)
- Federal Register: FCC 24-84 NPRM on AI-generated calls