Yes, in a growing number of states, and the honest answer is “it depends on the state, the channel, and whether the lead asked” — which is a worse answer than a one-line yes, because it means a single chatbot script that’s fine in Florida can be a $2,500-per-violation problem in Salt Lake City. Utah already has a live disclosure law on the books. Colorado’s rewritten AI Act takes effect January 1, 2027 and names insurance specifically as a covered use case. The FCC settled the voice-call question back in February 2024. None of these rules talk to each other, none of them were written with a licensed health or life agent’s AI-texting setup in mind, and most agents running an AI follow-up bot today have never read any of them. This article maps exactly what each one requires, the one-line script that satisfies the strictest version of all of them at once, and what Ambrose’s reply-bot and channel-bridge spokes actually do about it if you’d rather not build the review step by hand.
Key takeaways
- Utah requires any business using generative AI in a consumer transaction to admit it's AI if a person asks (Utah Code 13-75-103(1), effective May 7, 2025) — but the stricter, proactive upfront-disclosure duty only applies to "regulated occupations" licensed by the Department of Commerce, and Utah insurance producers are licensed by a separate Insurance Department instead (Utah Code 31A-2-101).
- Colorado's rewritten AI Act (SB26-189) takes effect January 1, 2027 and requires "clear and conspicuous notice" at the point of interaction for AI used in a defined list of "consequential decisions" that explicitly names insurance (Colorado General Assembly, SB26-189 bill page).
- The FCC's February 2024 declaratory ruling already treats an AI-generated voice on a call as an "artificial" voice under the TCPA, triggering the same consent and identification rules as any prerecorded call (FCC, Declaratory Ruling FCC-24-17).
- Utah's penalties run up to $2,500 per violation administratively or in court, and up to $5,000 per violation for defying an order (Utah Code 13-75-105); TCPA violations run $500 to $1,500 per call under the federal private right of action (47 U.S.C. § 227(b)(3)).
- As of August 31, 2026, 26 jurisdictions have adopted the NAIC's AI Model Bulletin, which expects a written AI governance program, not a specific consumer-facing script (NAIC, Legal Adoption Map, Aug. 31, 2026).
The pain: a lead asks “am I talking to a real person?” and you don’t actually know the right answer
Picture the setup a lot of agencies already have running. A lead fills out a form after hours, an AI-drafted text goes out within a minute or two to get the conversation started, and a few back-and-forths later the lead types, “wait, is this a real person?” Somebody on your team glances at the thread, isn’t sure what the bot is supposed to say, and either ignores the question or has the bot deflect with something vague. It feels like a minor UX wrinkle. It is actually the exact moment Utah’s law is written around — and if the same bot also places a follow-up call using a synthetic voice, it’s the exact scenario the FCC settled nearly two years ago, with a federal statute’s private right of action sitting behind it.
Most agents didn’t choose to ignore this. There’s no single place that tells you the answer, because there isn’t a single federal disclosure law yet — just a federal voice-call ruling, two live-or-almost-live state laws with genuinely different triggers, and an NAIC bulletin that’s about something else entirely (insurer governance, not chatbot scripts). An agent licensed in three or four states is, in effect, subject to three or four different answers to the same question, and the states most actively legislating this — Utah, Colorado, California — are not necessarily the states where most health and life business gets written, so it’s easy to assume none of it applies and be wrong the one time it does.
The second version of this pain is subtler: you want to disclose, you just don’t know what counts as disclosure. Is a line buried in a website’s terms of service enough? Does a chat widget’s “AI Assistant” label in the header satisfy an upfront, verbal-equivalent duty? Nobody selling AI texting tools to agencies is answering that question for you, because most of them aren’t licensed to practice law and have no reason to tell you where their tool’s default behavior falls short.
Why it happens: three different rulebooks, built for three different problems
Utah built its law around the format of the interaction, not the industry. Utah Code 13-75-103, enacted by S.B. 226 in the 2025 General Session and effective May 7, 2025, splits the disclosure duty into two tiers. Subsection (1) is the baseline: “a supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction shall disclose to the individual that the individual is interacting with generative artificial intelligence and not a human, if the individual asks or otherwise prompts the supplier” — reactive, triggered only by the consumer’s own question (Utah S.B. 226, enrolled, Section 3). Subsection (2) is stricter and proactive — prominent disclosure before the interaction even starts — but it only binds “regulated occupations,” which Section 13-75-101(8) defines as an occupation “regulated by the Department of Commerce” that requires a license or state certification. Insurance producers are licensed under Title 31A, administered by Utah’s own Insurance Department (Utah Code 31A-2-101: “The Insurance Department shall administer the Insurance Code”) — a separate agency from the Department of Commerce. Read literally, that means an insurance agent texting a Utah lead through an AI assistant owes the reactive duty under (1), but not the proactive, prominent, upfront duty under (2) that a Utah-licensed therapist or accountant would owe. That’s a genuinely easy distinction to get backwards if you’ve only read a law-firm summary instead of the statute, which is why this article is citing the enrolled bill text directly rather than someone’s recap of it.
Worth noting precisely, because it looks at first glance like it should sweep insurance back in: Utah’s statute defines a “high-risk artificial intelligence interaction” as one involving the collection of sensitive personal information, including health data, financial data, or biometric data, or the provision of personalized advice someone could reasonably rely on for a significant decision, including financial, legal, medical, or mental health advice (Utah S.B. 226, enrolled, Section 1, defining 13-75-101(5)). A chatbot helping a lead compare Medicare plans or estimate an ACA subsidy is arguably doing exactly that. But the high-risk trigger only matters for the proactive, prominent-disclosure duty in subsection (2) — and that subsection only binds “regulated occupations” in the first place. Since insurance isn’t one under Utah’s definition, the high-risk language doesn’t pull insurance back into the stricter tier; it’s a near-miss worth knowing about rather than an exemption to rely on blindly, especially if Utah’s legislature revisits the regulated-occupation definition in a future session.
Colorado built its law around the decision, not the format. The original 2024 version of Colorado’s AI Act, SB24-205, got delayed twice — first to June 30, 2026, then shelved entirely — before being repealed and reenacted as SB26-189, which takes a narrower “automated decision-making technology” (ADMT) approach with an operative date of January 1, 2027 (Colorado General Assembly, SB26-189 bill page). Instead of regulating “generative AI” as a category, it regulates AI used in a “consequential decision” — and the statute’s own list of consequential-decision domains names insurance outright, alongside education, employment, housing, financial or lending services, health care, and essential government services. The obligation that falls out of that: a deployer using a covered ADMT to help decide something consequential for a Colorado consumer has to give “clear and conspicuous notice to consumers at the point of interaction,” plus, within 30 days of an adverse outcome, a plain-language description of the system’s role in it. Notice that this isn’t about whether your chatbot is “generative AI” in the conversational sense Utah cares about — it’s about whether the output is doing something that shapes a consequential decision, which an AI tool helping triage, pre-qualify, or route a Medicare or ACA lead plausibly is.
The FCC settled the voice-call question in 2024, and it’s older and more binding than either state law. On February 8, 2024, the FCC unanimously adopted a Declaratory Ruling clarifying that the Telephone Consumer Protection Act’s restrictions on “artificial or prerecorded voice” already cover AI-generated voices — it wasn’t writing a new rule, it was confirming the existing one reaches the new technology (FCC, Declaratory Ruling FCC-24-17, released Feb. 8, 2024). Practically, that means a call using an AI voice clone or synthetic voice agent needs the called party’s prior express consent before it goes out, the same as any other prerecorded or artificial-voice call under the TCPA — and the TCPA has real teeth behind it through its private right of action.
Three rulebooks, three different triggers — the format, the decision, and the channel — and none of them cross-reference each other.
Mike MooreThe NAIC’s AI Model Bulletin is a fourth thing entirely, and it’s easy to conflate with the first three. Adopted by the NAIC’s Executive Committee and Plenary on December 4, 2023, the bulletin sets expectations for how a licensed insurer governs its own use of AI systems — a written AI program, documented testing and monitoring, human oversight, and vendor accountability that a state insurance department can ask to review during an exam or investigation. As of August 31, 2026, 26 jurisdictions — 25 states plus the District of Columbia — have adopted some version of it (NAIC, Legal Adoption Map: AI Model Bulletin, status as of Aug. 31, 2026). It’s a governance standard aimed mostly at carriers, not a script requirement for an individual agent’s chat widget, but it’s the piece that matters if your state’s insurance department ever asks how your agency supervises the AI tools it uses — which is a different question from what your bot says to a lead, and agents regularly mix the two up.
| Rule | What triggers it | Who it binds | Effective date |
|---|---|---|---|
| Utah Code 13-75-103(1) | The consumer directly asks if it's AI | Any "supplier" in a consumer transaction, insurance included | May 7, 2025 |
| Utah Code 13-75-103(2) | Any interaction, proactive and prominent | "Regulated occupations" licensed by Dept. of Commerce only — not insurance | May 7, 2025 |
| Colorado SB26-189 | AI materially influences a "consequential decision" | Deployers of covered ADMT, including insurance coverage, pricing, or claims | January 1, 2027 |
| TCPA, per FCC ruling FCC-24-17 | Placing a call using an AI-generated voice | Any caller, insurance included — same as any artificial/prerecorded voice rule | Feb. 8, 2024 (ruling date; TCPA itself predates it) |
What it costs: per-violation, not per-incident

The number that should actually worry a multi-state agency is “per violation,” not the dollar figure itself. Utah’s statute gives its Division of Consumer Protection the power to impose an administrative fine of up to $2,500 for each violation, and separately lets a court impose a fine of up to $2,500 per violation in an enforcement action it brings, plus attorney fees, court costs, and investigative fees awarded to the division if it wins (Utah Code 13-75-105(4)-(6)). If a person or agency then violates an order already issued over that conduct, the civil penalty jumps to up to $5,000 per violation (Utah Code 13-75-105(7)(a)). Run an AI texting sequence against a thousand-lead list with a script that never discloses AI use, and “per violation” is doing a lot of work in that sentence — it is not obviously capped at one fine for the whole campaign.
Per-violation exposure, not a flat fine
Maximum penalty per individual violation under each statute (not an aggregate cap)
Sources: Utah Code 13-75-105 (S.B. 226, 2025); 47 U.S.C. § 227(b)(3). Fetched October 2026. Figures are per individual violation, not an aggregate or campaign-level cap.
Run the Utah figures against a realistic lead list to see why “per violation” is the operative phrase. An agency running an AI text sequence that never discloses AI use against a thousand-contact list isn’t automatically looking at one $2,500 fine for the whole campaign — read literally, each contact that violated the statute is its own violation, which is how a sloppy script scales from a four-figure problem to something far larger before a single letter from the Division of Consumer Protection arrives. That’s a hypothetical built from the statute’s own per-violation structure, not a claim that any specific enforcement action has happened at that scale — but it’s the math worth doing before assuming a fine “wouldn’t really add up to much.”
The TCPA side is the one with an actual enforcement track record behind it. Because the FCC’s 2024 ruling treats an AI-generated voice as an “artificial” voice under the statute, a call placed without the called party’s prior express consent exposes the caller to a private right of action: the called party can sue for actual monetary loss or $500 in statutory damages per violation, whichever is greater, and a court can increase that award up to three times — $1,500 per violation — if the violation was willful or knowing (47 U.S.C. § 227(b)(3)). That’s per call. A voicebot calling a list of 500 leads without documented consent isn’t one violation if something goes wrong; depending on the facts, it can be read as up to 500.
How to fix it: the state-by-state rules and the one script that clears all of them
Nothing below requires a membership, a developer, or anything beyond a text editor. This is the complete manual method, not a preview of a paid version.
Step 1: Know which rule actually governs your setup

| Your setup | Governing rule | What it requires |
|---|---|---|
| AI chat or text, lead based in Utah | Utah Code 13-75-103(1) | Must truthfully confirm it's AI if the lead asks — reactive duty, no proactive script required for insurance specifically |
| AI chat or text, lead based in Colorado, used to triage or pre-qualify (a "consequential decision") | Colorado SB26-189, effective Jan. 1, 2027 | Clear and conspicuous notice at the point of interaction that it's an AI system |
| AI-generated voice on an outbound or follow-up call, any state | TCPA, per FCC Declaratory Ruling FCC-24-17 | Prior express consent before the call, same as any artificial or prerecorded voice call |
| How your agency governs and supervises any AI tool touching clients | NAIC AI Model Bulletin (adopted in 26 jurisdictions as of Aug. 31, 2026) | Written AI governance policy a regulator could request — not a consumer-facing script |
For Colorado specifically, the harder judgment call is deciding whether your bot is making a “consequential decision” at all. A chatbot that only books an appointment or answers an FAQ about office hours is doing something closer to scheduling than deciding. A bot that pre-qualifies a lead, recommends a specific plan type, or tells someone they likely do or don’t qualify for a subsidy is shaping an outcome that affects the person’s access to or cost of insurance — squarely inside the statute’s own list of consequential-decision domains. When a tool sits in that gray area, the safer read is to treat it as covered rather than find out otherwise after January 1, 2027.
The practical read: if you only sell in a handful of states and none of them are Utah or Colorado, you’re not off the hook — you’re just not yet bound by a state-specific chatbot law. You’re still bound by the federal TCPA rule the moment a synthetic voice touches a phone call, and you’re still the one who has to answer honestly if any lead, anywhere, asks whether they’re talking to a bot, because several more states have similar bills moving through committee this session and a script built state-by-state is a script you’ll be rewriting every few months.
Step 2: Write one disclosure line that satisfies the strictest version of every rule
Rather than maintaining a different script per state, write to Colorado’s “point of interaction” standard, since it’s the strictest trigger of the three (upfront, not reactive) and layer in the voice-specific consent language for calls:
For chat or text, at the very first message:
“Hi, this is an AI assistant for [Agency Name]. I can help you get started, answer quick questions, or connect you with a licensed agent — just ask, and I’ll always tell you straight whether you’re talking with AI or a person.”
For an AI-generated voice call, at the start of the call, before anything else:
“Hi, this is an AI assistant calling on behalf of [Agency Name] about the information you requested. If you’d rather speak with a licensed agent directly, just say so.”
Both lines do three things at once: they satisfy Colorado’s point-of-interaction notice requirement before it’s even legally required, they automatically satisfy Utah’s reactive if-asked duty because the answer is already given, and the voice version doubles as the kind of up-front identification that keeps a consent-based TCPA call defensible instead of ambiguous. Build it into the first message of every sequence and the first line of every script, and the “wait, am I talking to a real person?” moment from the opening of this article never happens, because the lead already knows.
A disclaimer buried in a privacy policy is not disclosure
Colorado's standard is "clear and conspicuous notice... at the point of interaction," and Utah's proactive standard (for the occupations it covers) requires disclosure delivered verbally at the start of a verbal interaction or in writing before a written one. A sentence in a website's terms of service, a tiny "AI" badge a lead has to notice on their own, or a disclosure mentioned three messages into a thread doesn't meet either bar. Put it first, in the message itself.
Step 3: Get consent before an AI voice ever dials out
If any part of your follow-up stack places outbound calls using a synthetic or AI-cloned voice, confirm you have the same prior express consent you’d need for a prerecorded message before the FCC’s 2024 ruling existed — a checked box, a signed form, or a clearly disclosed opt-in that names the specific number being called, not an assumption that a lead who filled out a web form implicitly agreed to an AI phone call. This is the exact gap the FCC’s ruling closed: tools marketed as “AI voice agents” aren’t a new unregulated category just because the voice isn’t a recording of a specific human being.
Step 4: Keep a record of what every lead was actually told
Save the exact script version that was live on the date each lead was contacted, not just the current one. If a complaint or inquiry comes in six months later, “here’s exactly what the bot said and when” is a materially stronger position than “we’re pretty sure it said something like that.” A simple dated folder of script versions, or a CRM note logging which template fired on which date, does this with zero additional tooling.
A test you can run this week
Open your AI texting or chat tool right now and type "are you a real person?" as if you were a lead. Read exactly what comes back. If it dodges the question, changes the subject, or answers something adjacent instead of a straight yes-or-no, that's the gap to fix today — before a real lead finds it first.
Everything above works whether you ever touch Ambrose or join anything. It’s four scripts and a filing habit, not a purchase.
How Ambrose’s reply-bot and channel-bridge spokes build the disclosure in instead of hoping someone remembers it
The manual version works, and it also depends entirely on every teammate who edits a bot template remembering to leave the disclosure line in. That’s the exact failure mode Ambrose’s review-first design is built around. The reply-bot spoke, documented as drafting AI-generated responses across email, SMS, and chat channels, defaults to a per-team “needs-review” setting rather than auto-send — Ambrose’s own documentation puts it as “Auto-send vs needs-review is a per-team toggle. Default = needs-review” — and pairs every draft with a confidence score and a “why this draft” trace so whoever approves it can actually see the reasoning, not just the output (Ambrose docs, spoke-reply-bot, fetched October 2026). Its three tools are reply_draft (generates the candidate response), reply_send (dispatches an approved draft through channel-bridge), and reply_book_appointment (schedules the follow-up meeting).
The channel-bridge spoke is the actual outbound dispatcher underneath it — “the single place messages actually leave your account,” exposing bridge_send_email and bridge_send_sms, and it runs in drafts mode by default too, holding messages for review until auto-send is deliberately turned on at the agent or team level (Ambrose docs, spoke-channel-bridge, fetched October 2026). Outbound message bodies route through the PHI Gateway automatically whenever the destination isn’t on the agency’s BAA allowlist, which matters here specifically because a lead’s question about whether they’re “talking to a real person” often arrives in the same thread where they’ve also shared a health condition or a Medicare number.
The four-step method from this article
- You write the disclosure line into every template by hand
- Every teammate who edits a script has to remember to keep it
- You manually log which script version was live on which date
- Works today, in any texting tool, at zero cost
The same disclosure, built into a reviewed draft
- reply_draft generates the response; a human approves before reply_send fires it
- needs-review is the default, not an opt-in setting you have to remember
- Every scrub event and send is logged with a timestamp for later review
- Non-BAA destinations route through the PHI Gateway automatically
Be precise about what this is and isn’t. Neither spoke knows, on its own, that Colorado requires upfront notice while Utah’s is reactive — that judgment, and writing the actual disclosure line into the template, is still yours to make, the same as it is in the manual version. What the needs-review default removes is the mechanical failure mode: a teammate editing a script at 11pm and accidentally deleting the one sentence that matters, with nobody catching it until a lead asks the wrong question to the wrong bot in the wrong state.
What you get by joining
One Ambrose seat comes with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, founding rate locked in while the membership stays active. That includes weekly Zoom calls with open Q&A and build-with-you sessions, 30-plus hours of recorded training, pre-built AI templates and bot deployments, Meta Ads and marketing training built for this industry specifically, and a free annual in-person member workshop — plus an explicit no-recruiting rule, so a question about getting your disclosure line right doesn’t turn into someone else’s downline pitch.
Ambrose usage is separate from the $97 seat
The membership includes one Ambrose seat; usage inside Ambrose runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise. See the full Spokes catalog for what reply-bot and channel-bridge sit alongside.
Know which rule actually applies
Utah's reactive duty, Colorado's upfront duty, and the federal voice rule aren't the same rule.
One script, not fifty
Write to the strictest standard and it clears the rest automatically.
Consent before an AI voice ever dials
The FCC already treats a synthetic voice as an artificial voice under the TCPA.
Keep a dated record
Know exactly what every lead was told, and when.
A reviewed draft, not a blind auto-send
reply-bot and channel-bridge both default to human review before anything fires.
A logged audit trail
PHI Gateway routing and scrub-event logging back up what you can show a regulator.
Stop guessing which disclosure rule applies
The manual script above works whether you ever join anything or not. If you'd rather have it built into a reviewed draft on your own follow-up stack, with someone watching your screen while you set it up, one Ambrose seat comes with the Tech Savvy membership.
Join Tech Savvy — $97/monthThe close
A lead who asks whether they’re talking to AI deserves a straight answer, and getting there is one sentence written into a template, not a legal overhaul. Write it to the strictest standard you’re subject to, put it first instead of burying it, get documented consent before any synthetic voice dials out, and keep a dated record of what every version actually said. If you’d rather have that built into a reviewed draft instead of a template everyone has to remember to protect, that’s the kind of thing we work through on a Tuesday call in the Tech Savvy community — $97 a month, cancel anytime, and nobody will pitch you a downline: https://techsavvyinsurance.com/.
Before you change your AI disclosure scripts
Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. Whether a specific script, call flow, or state law applies to your exact setup is a judgment call you and, where appropriate, your own counsel need to make. You are responsible for your own licensure and for complying with all applicable CMS, HIPAA, TCPA, state, and carrier requirements. When Medicare marketing is involved, your TPMO disclaimer obligations and CMS's marketing rules still apply on top of everything in this article. Never paste a client's protected health information into a general-purpose AI tool without a Business Associate Agreement in place — that's exactly the gap Ambrose's PHI Rail is built to close. AI outputs may contain errors — always verify. Results may vary.
Frequently asked questions
Sources
- Utah S.B. 226 (2025), enrolled — enacts Utah Code 13-75-101 through 13-75-106 — le.utah.gov
- Utah Code 31A-2-101 — General duties (The Insurance Department) — le.utah.gov
- Colorado General Assembly — SB26-189 bill page — leg.colorado.gov
- FCC — Declaratory Ruling FCC-24-17, AI-Generated Voices in Robocalls (released Feb. 8, 2024) — fcc.gov
- 47 U.S.C. § 227(b)(3) — Telephone Consumer Protection Act, private right of action — law.cornell.edu
- NAIC — Legal Adoption Map: Model Bulletin, Use of Artificial Intelligence Systems by Insurers (status as of Aug. 31, 2026) — content.naic.org
- Ambrose docs — spoke-reply-bot — app.hiambrose.com
- Ambrose docs — spoke-channel-bridge — app.hiambrose.com
- Ambrose docs — PHI Rail architecture — app.hiambrose.com
Ready to put this into practice?
Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.
Join Tech Savvy — $97/month