Understanding California's Bolstering Online Transparency Act (SB 1001)

California's Bolstering Online Transparency Act (SB 1001), effective July 1, 2019, is often misunderstood. It's not a blanket law requiring all chatbots to announce themselves. Instead, it targets a specific type of online deception: the intentional misleading of individuals through bot interactions. The crucial difference lies in the intent and the specific actions prohibited, not merely the presence of a bot.

The Act, codified at Cal. Bus. & Prof. Code §§ 17940–17943, prohibits a person from using a bot to communicate or interact with another person in California online with the intent to mislead that person about its artificial nature or its status as a bot. This three-pronged requirement—a bot, interaction in California, and intent to mislead about its identity—must all be met for the prohibition to apply.

The law offers a clear path to avoid liability: disclosure. If a bot clearly and conspicuously discloses that it is a bot, it operates outside the scope of the prohibition. This disclosure acts as a shield, preventing the bot operator from being found in violation of the Act. Therefore, the operative question for any developer or company deploying automated systems online that interact with Californians is not *if* they are using a bot, but rather *how* they are ensuring that bot is not being used with the intent to deceive about its nature.

Consider the distinction: A customer service chatbot that clearly states, "You are now chatting with our AI assistant," is compliant. Conversely, a bot designed to pose as a human to spread misinformation or manipulate a user into a transaction, without any disclosure, would fall under the Act's prohibition if it interacts with someone in California and the intent to mislead is present.

Diagram illustrating the three conditions required for SB 1001 prohibition: bot use, California interaction, and intent to mislead.

Intent to Mislead: The Core of the Law

The critical element that distinguishes a violation under SB 1001 is the intent to mislead. This is not about accidental misrepresentation or a user's assumption that they are speaking with a human. The law requires a deliberate effort to deceive the user about the bot's artificial nature or its status as an automated system. This intent is the linchpin. Without it, the act of using a bot in California, even without disclosure, does not constitute a violation.

The statute defines 'bot' broadly as a software application that runs automated tasks (scripts) over the internet. This includes anything from simple automated scripts to sophisticated AI-driven chatbots. The key is the automation and the interaction with a person online within California's jurisdiction.

The disclosure requirement is not prescriptive about the exact wording or placement, beyond being 'clear and conspicuous.' This leaves room for interpretation, but the intent is to ensure that a reasonable person interacting with the bot would understand they are not communicating with a human. This could be a banner at the top of a chat window, an opening statement from the bot, or a persistent indicator throughout the interaction.

Who is Affected and What are the Penalties?

Any entity, whether a business, an individual, or an organization, that operates a bot interacting with individuals in California can be subject to SB 1001. The law does not exempt small businesses or non-profits. The 'intent to mislead' clause is what filters the practical application. If your bot is designed for legitimate purposes and either does not interact with Californians, or does so with clear disclosure, you are likely not in violation.

The enforcement mechanism for SB 1001 is through the California Consumer Privacy Act (CCPA) enforcement provisions. Violations can lead to civil penalties. Specifically, a violation is considered an unlawful, unfair, or fraudulent business act or practice. The CCPA allows for statutory damages of $100 to $750 per violation, or actual damages, whichever is greater, in a private right of action. The California Attorney General can also seek statutory damages of $2,500 per violation, or up to $7,500 for intentional violations.

The law is designed to foster transparency and protect consumers from deceptive practices facilitated by automation. It recognizes the increasing prevalence of bots in online communication and seeks to ensure that individuals are aware when they are interacting with non-human entities, particularly when that interaction could lead to a transaction or influence their decisions.

Distinguishing SB 1001 from SB 942

It is important to distinguish SB 1001 from other legislative efforts in California concerning AI and online transparency. For instance, SB 942, the California AI Transparency Act (enacted in 2024), addresses generative AI and watermarking. SB 942 applies to 'covered providers'—entities that create publicly accessible generative AI systems with over one million monthly users in California. It mandates disclosure of AI-generated content and requires covered providers to build and operate a free public service for detecting whether a system produced a given file. This is a distinct regulatory focus, concentrating on the output of generative AI and its provenance, rather than the interactive deception targeted by SB 1001.

SB 1001 predates the widespread public awareness of advanced generative AI like LLMs, focusing instead on the more general category of bots and their potential for direct user deception. While both laws aim to increase transparency, they do so in different domains and with different mechanisms. SB 1001 is about the *interaction* and the *identity* of the communicator, while SB 942 is about the *origin* and *attribution* of AI-generated content.

Practical Implications for Developers and Businesses

For developers and businesses deploying bots that interact with users online, SB 1001 necessitates a clear assessment of their bot's purpose and its operational context within California. If a bot's function could be construed as intending to mislead users about its identity, implementing clear and conspicuous disclosures is paramount. This means ensuring that users in California know they are interacting with an automated system.

The 'clear and conspicuous' standard suggests that disclosures should be easily noticeable and understandable. A small, hidden disclaimer buried in terms of service is unlikely to suffice. Proactive disclosure at the beginning of an interaction or a persistent, visible indicator is the safer approach. Businesses should audit their existing bot deployments and update them to comply with this disclosure requirement if there is any risk of violating the 'intent to mislead' clause.

The law serves as a reminder that as automation becomes more integrated into daily online life, transparency about its role is increasingly important. While SB 1001 is specific in its focus on deceptive intent, it underscores a broader regulatory trend towards ensuring users understand the nature of their digital interactions.