Skip to content

Risk Digest

Dead Internet Theory, Bot Disclosure, and the 50-State Patchwork

With bots generating a majority of web traffic and 14 state chatbot safety laws enacted in H1 2026, organizations face a patchwork of disclosure, safety, and professional-licensure obligations. This article maps each jurisdiction's standard so risk managers can determine which rules apply to their AI chatbots.

By Editorial TeamUpdated Jul 25, 2026Verified Jul 25, 2026
CONFIRMED
Jurisdiction
US Federal
Court
Federal Trade Commission
AI tool named
DoNotPay
Ruling date
Feb 1, 2025
Source document
View primary court order ↗
Last verified
Jul 25, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

The useful version of the dead internet theory is no longer the theatrical one. It does not require a hidden controller, a single coordinated campaign, or a claim that every online interaction is fake. The narrower legal problem is enough: when bot activity is large enough that ordinary users cannot reliably tell whether they are dealing with a person, disclosure stops being a platform-design preference and becomes legislative infrastructure.

That is why Cloudflare’s June 2026 traffic finding matters to lawyers. Fortune reported that bots generated 57.5% of webpage requests, crossing the human-traffic line more than a year earlier than Cloudflare’s CEO had previously predicted; the same article also reported HUMAN Security’s finding that agentic AI traffic grew 7,851% year over year.[1] Those figures do not prove every claim associated with the dead internet theory. They do make it harder to treat bot identity as a niche issue limited to spam comments and obvious scams.

There is a measurement caveat worth making before the compliance map begins. Cloudflare’s 57.5% figure and Thales/Imperva’s 53% figure come from different systems, and no single provider sees the entire web.[1] For legal risk work, however, the exact denominator is less important than the direction of travel. Once a substantial share of online interaction may be automated, the administrable question becomes: which rule requires the organization to tell the user what they are dealing with, when must that happen, and who can sue or enforce if it does not?

Digital bot traffic beneath a highlighted map of state regulatory activity

From Bot Traffic to Bot Disclosure

The first generation of U.S. bot-disclosure law was narrower than today’s chatbot-safety wave. California SB 1001, enacted in 2018, targeted deceptive bot communications used to incentivize purchases or influence voting behavior. Cooley’s analysis of the law describes penalties of up to $2,500 per violation under California’s Unfair Competition Law.[2] That statute was built for a recognizable problem: a bot pretending to be a human in order to push a transaction or political outcome.

The 2026 problem is wider. A customer-service assistant, a companion chatbot, a mental-health-like conversational tool, a homework helper, a legal-intake bot, and a sales agent may all be automated, but they do not raise the same statutory questions. Some rules focus on whether the bot is non-human. Others focus on whether a minor is using it. Others are aimed at companion design, crisis response, professional impersonation, or manipulation that keeps the user engaged.

The legislative pace is now the operational fact. The Future of Privacy Forum’s 2026 tracker identifies 98 chatbot-specific bills introduced across 34 states as of July 2026, and the Transparency Coalition’s mid-year report states that at least 14 state chatbot safety laws were enacted in H1 2026 across 13 states.[3][4] Those numbers are not a national standard. They are a warning that a single bot-disclosure sentence placed in a footer is unlikely to answer the right question in every state.

The Enacted-Law Map Is Not One Rule

The states most likely to create real memo work are not simply the states that have “AI laws.” They are the states where the trigger, user class, timing, safety obligation, and enforcement mechanism do not line up. California, Oregon, Washington, and Nebraska illustrate the spread: California’s SB 243 is described as the first companion-chatbot disclosure law and took effect January 1, 2026; Oregon SB 1546 takes effect in January 2027 and creates a private right of action with $1,000 statutory damages per violation; Washington HB 2225 takes effect in January 2027 and prohibits certain engagement-manipulation techniques for minors, including simulating emotional dependence; Nebraska LB 525 takes effect in July 2027 and imposes conversational AI safety requirements.[5][6][7]

Jurisdiction or groupObligation type to check firstEffective-date postureRisk point for a chatbot operator
California SB 243Companion-chatbot disclosureEffective January 1, 2026A companion-like product needs a California-specific disclosure analysis, not merely a generic bot label.
Oregon SB 1546Disclosure and statutory liability exposureEffective January 2027The private right of action and $1,000 statutory damages per violation change the litigation-risk calculation.
Washington HB 2225Minor-facing manipulation limitsEffective January 2027Engagement features that simulate emotional dependence require special review when minors can access the bot.
Nebraska LB 525Conversational AI safety requirementsEffective July 2027Safety protocols need to be tracked against a later effective date rather than treated as immediately live.
Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, New York, Rhode Island, South Carolina, and WyomingState-specific enacted-law obligationsH1 2026 enacted-law waveThe state name alone is not enough; the review must identify covered bot type, user class, disclosure cadence, safety duty, and enforcement model.

The additional enacted-law states identified in the 2026 law-firm summaries and trackers include Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, New York, Rhode Island, South Carolina, and Wyoming.[5][6][7] For a risk manager, that list is the beginning of the assignment, not the conclusion. A state may regulate a companion chatbot differently from a transactional service bot; a minor-facing feature differently from an adult-only interaction; and a therapy-, law-, or medicine-like exchange differently from ordinary product support.

The recurring statutory buckets reported across the 2026 enacted-law materials are practical: non-human disclosure timing, heightened disclosure cadence for minors, self-harm detection and crisis-interruption protocols, professional-services impersonation bans, engagement-optimization limits, and enforcement mechanisms that range from attorney-general-only enforcement to private claims.[5][6][7] These buckets should not be collapsed into a single “AI chatbot disclosure” control. A design that satisfies a general disclosure rule may still be exposed if it markets itself as therapy, simulates dependency with a minor, or fails a crisis-interruption requirement.

Companion Bots Are a Different Category

A companion chatbot is not just a chatbot with a warmer tone. The regulatory concern is that the product may be designed for sustained emotional interaction rather than a bounded transaction. That distinction matters because the user may be a minor, lonely, distressed, or simply unaware that the system is optimizing a conversational experience without professional accountability.

California’s SB 243 is the cleanest early example because it is described in the 2026 summaries as a first-of-its-kind companion-chatbot disclosure law, effective January 1, 2026.[5][6] The legal question is therefore not merely whether the system is automated. It is whether the bot’s function and presentation put it into a companion category that triggers a more specific disclosure analysis.

Minor-Facing Design Needs Its Own Review

Washington’s HB 2225 shows why age access cannot be left as an afterthought. The law, effective January 2027, is described as prohibiting engagement-manipulation techniques for minor users, including simulating emotional dependence.[5][6] That is not the same issue as whether a disclosure appears at account creation. It asks whether the product’s conversational design uses a minor’s attachment to keep the interaction going.

This changes the diligence questions. Counsel cannot stop at “we do not target children” if minors can access the bot in practice. The review has to look at age gates, account settings, marketing channels, default prompts, recommender logic, retention nudges, and escalation paths. A bot that never says “I am human” can still raise a minor-safety issue if it is structured to prolong dependency-like engagement.

Professional Impersonation Is Not Hypothetical

The enforcement hook for professional-services claims is already visible at the federal level. In February 2025, the FTC finalized an order against DoNotPay, imposing $193,000 in monetary relief and prohibiting deceptive claims that its AI chatbot could act as a “robot lawyer.”[8] The case is not a state chatbot-disclosure statute, and it should not be treated as one. Its value is narrower and more important: regulators have already acted when an AI product crossed from assistance into claimed professional substitution.

That precedent should sit next to the state-law tracker when a bot gives legal, medical, or therapy-like responses. A disclosure that the user is speaking with AI may not cure marketing that implies licensed judgment, a professional relationship, or a substitute for regulated advice. The safer memo separates ordinary automation disclosure from professional-licensure risk, because the evidence, the statutes, and the remedies may come from different places.

A Practical Applicability Workflow

The fastest way to get this wrong is to ask, “Do chatbot laws require disclosure?” That question is too broad to be useful. The better workflow starts with the user, the interaction, and the state.

Decision flowchart for chatbot compliance review from user location to private right of action
  1. Identify the user’s location. State chatbot duties are not interchangeable, and a launch in California, Oregon, Washington, and New York may require different answers for the same interface.
  2. Classify the bot by function. A companion bot, transactional customer-service bot, educational assistant, legal-intake tool, or health-support assistant may trigger different statutory and professional-risk analyses.
  3. Determine whether minors can access it. Do not rely only on intended audience; review access controls, marketing, default settings, and actual product pathways.
  4. Check whether the bot touches legal, medical, therapy-like, crisis, or self-harm topics. These areas may create safety-protocol or professional-impersonation concerns beyond ordinary bot disclosure.
  5. Review engagement design. Features that encourage repeated interaction, simulate attachment, or deepen dependency need separate scrutiny in states with minor-focused manipulation limits.
  6. Map enforcement. A private right of action with statutory damages deserves a different launch-risk assessment than attorney-general-only enforcement.

Oregon is the example that should change the tone of an internal memo. Its SB 1546, effective January 2027, is reported to create a private right of action with $1,000 statutory damages per violation.[5][6] That does not mean every chatbot interaction in Oregon produces liability. It does mean the enforcement model belongs near the top of the analysis, because statutory damages can turn a disclosure defect into a scaled litigation issue.

Washington changes the workflow in a different way. If minors can use the bot, the reviewer must examine the design of the interaction, not only the words of the disclosure. A compliance file that contains screenshots of a non-human notice but no review of dependency-like engagement features may miss the point of a minor-manipulation prohibition.

Nebraska adds a timing problem. LB 525 is reported as effective July 2027, with conversational AI safety requirements.[5][6] For product counsel, that means the issue is not only whether the launch is lawful today. It is whether the roadmap, procurement terms, logging, escalation procedures, and release calendar can support a state-specific safety duty when it comes online.

What the Tracker Should Actually Track

A 50-state chatbot tracker that merely lists bill numbers will not hold up under launch pressure. The useful version has fields that answer the questions someone will ask before the product ships.

Tracker fieldWhy it matters
Primary-source link and last-verified dateThe 98-bill figure is a moving July 2026 snapshot, so stale secondary summaries are a known risk.
Status and effective dateCalifornia is already effective; Oregon and Washington are January 2027; Nebraska is July 2027.
Covered bot typeCompanion, transactional, professional-services, and general conversational bots may not be treated the same way.
Covered user classMinor-facing obligations can turn on access and design, not only the product’s stated audience.
Triggering interactionSome rules focus on deception, others on companion use, crisis topics, professional claims, or engagement manipulation.
Disclosure cadence and placementA one-time notice, recurring notice, and context-specific interruption are different controls.
Safety protocolSelf-harm detection, crisis interruption, and escalation procedures require operational ownership.
Professional-services restrictionLegal, medical, and therapy-like claims need review even where ordinary bot disclosure is satisfied.
Enforcement mechanismPrivate claims, statutory damages, and regulator-only enforcement create different risk tolerances.

The effective-date field deserves more attention than it usually gets. A product that launches in Q3 2026 may already need to comply with California’s companion-chatbot disclosure rule, may need a January 2027 plan for Oregon and Washington, and may need a July 2027 implementation path for Nebraska.[5][6][7] Treating all enacted laws as either “live” or “future” obscures the sequencing that product, engineering, and support teams actually need.

The covered-bot field is just as important. A bank’s balance-inquiry assistant, a retailer’s return-status bot, a social companion app, and a legal-help chatbot may all use generative AI. The same disclosure banner will not answer whether the system is covered as a companion bot, whether minors are protected users, whether self-harm escalation is required, or whether the product implies professional judgment.

The enforcement field is where legal risk becomes concrete. Oregon’s reported private right of action and $1,000 statutory damages per violation should not be buried in a notes column.[5][6] A state with regulator-only enforcement may still matter, but it produces a different risk conversation from a state that gives users a direct claim.

The Federal Layer Is Helpful but Not a Substitute

Federal activity helps identify risk themes, but it does not replace the state-by-state analysis. The FTC’s DoNotPay order is useful because it shows a regulator treating “robot lawyer” marketing as deceptive, with monetary relief and claim restrictions attached.[8] That is a professional-impersonation warning, not a comprehensive chatbot-disclosure code.

The same distinction applies to federal inquiries and proposed federal frameworks. They may influence norms around safety, monetization, and minor protections, but a product team still needs to know whether California requires a companion disclosure now, whether Oregon creates private litigation exposure in January 2027, whether Washington restricts specific minor-facing engagement techniques, and whether Nebraska’s later safety requirements affect the roadmap.

The Current Boundary

As of Q3 2026, the dead internet theory’s legal implications for AI bots are best understood in their narrow, verifiable form: bot activity has become large enough that states are building rules around identification, safety, manipulation, and professional accountability. The 98-bill, 34-state figure is a moving snapshot as of July 2026, not a final map.[3] H2 2026 may change the enacted-law list, the effective-date calendar, and the enforcement mix.

No single national disclosure playbook is safe unless it is backed by a living jurisdiction tracker with primary-source links, last-verified dates, covered-bot classifications, user-class fields, safety duties, professional-services notes, and enforcement mechanisms. The operational question is no longer whether users should be told when they are speaking to a bot. It is which law requires the telling, at what moment, for which user, and with what consequence if the organization gets it wrong.

References

  1. Dead internet theory is coming true as bots and AI agents now generate the majority of web traffic, Fortune, July 23, 2026.
  2. California Regulates Online Bots, Cooley LLP.
  3. 2026 Chatbot Legislation Tracker, Future of Privacy Forum.
  4. Watershed Year for Chatbot Safety Measures: 14 New State Laws Enacted So Far in 2026, Transparency Coalition, July 15, 2026.
  5. Not Human, Not Optional: The New Wave of State AI Chatbot Laws, Eversheds Sutherland, March 2026.
  6. 2026 State Chatbot Laws: Key Provisions and Regulatory Trends, Orrick, April 2026.
  7. AI Chatbots Face Rising Legal and Legislative Scrutiny, Kelley Drye, January 2026.
  8. FTC Finalizes Order with DoNotPay, Prohibits Deceptive AI Lawyer Claims, Imposes Monetary Relief Requirements, Federal Trade Commission, February 2025.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →