← EYMA Dispatch

Agent Economy

What AI Agents Are Legally Required to Tell You: Transparency Rules in 2026

What AI Agents Are Legally Required to Tell You: Transparency Rules in 2026

EYMA · August 26, 2026

In 2026, AI agents face a two-layer disclosure system. The outer layer — state bot-disclosure laws — requires agents to identify themselves as automated when asked during a commercial interaction. The inner layer — industry licensing rules — requires agents acting on behalf of licensed businesses to carry the same disclosures the licensed business would have to make: name, license number, scope of authorization. Most AI agents comply with neither layer completely. The gap is where enforcement incidents are being built right now.

What laws currently govern AI agent disclosure?

The clearest legal floor comes from state bot-disclosure statutes. California's BOTS Act requires that automated accounts interacting with California residents to influence a commercial transaction must not conceal their artificial identity when directly asked. Several other states have followed with similar language. These laws establish a minimum: an agent that claims to be human when asked is already in violation. They don't require proactive disclosure — just honest acknowledgment on demand.

That floor is meaningful but narrow. It governs identity concealment — it says nothing about whether the agent's principal is licensed, whether it has authority to bind a transaction, or whether the customer has any recourse if the interaction goes wrong. An AI agent can comply with every bot-disclosure statute on the books and still represent an unlicensed business, exceed its authorized scope, and leave the customer with no clear remedy.

The FTC's authority under Section 5 of the FTC Act — which prohibits unfair or deceptive acts or practices — extends to AI-assisted commercial transactions. The FTC has made clear that deception by an automated system is still deception, and that the business behind the agent, not the software vendor, bears responsibility for what the agent says and does. That creates an implied disclosure obligation even where no specific AI-agent statute exists: if an agent makes a material misrepresentation that influences a purchase, the business that deployed it faces the same exposure it would if a human employee had said the same thing.

The explicit, sector-specific obligations sit on top of all of this. The Disclosure Gap covers how these layer: in insurance, financial services, real estate, and contractor work, the agent's principal carries licensing disclosure requirements that don't disappear because a bot is doing the talking. A licensed insurance broker whose AI agent handles a quote call is still required — under state insurance code, not just general consumer protection law — to ensure the customer receives the broker's license number, the carrier being quoted, and the scope of the coverage being offered. The bot is the delivery mechanism. The obligation is the broker's.

The three-layer disclosure stack for AI agents in 2026:
LayerWhat it requiresWho it applies to
State bot-disclosure laws (CA, TX, others)Acknowledge being automated when asked during commercial interactionsAny agent interacting with residents of covered states
FTC Act Section 5 (deceptive practices)No material misrepresentations that influence a purchaseAll commercial AI agents nationwide
Industry licensing rules (insurance, real estate, finance, contractors)License number, principal identity, scope of authority — same as a licensed human representativeAgents acting on behalf of licensed businesses in regulated industries

What should a compliant AI agent actually tell you before it transacts?

A fully compliant AI agent in a regulated industry tells you four things before it completes any transaction: it identifies itself as an AI agent (not a human), it names the business it represents (the legal entity, not a brand name), it provides the license number and type that authorizes the business to conduct the transaction, and it states the scope of what it can authorize versus what requires human sign-off. These four disclosures let you verify the agent's legitimacy in under two minutes before committing to anything.

What a legitimate AI agent tells you — and what a sketchy one skips — is the subject of a full breakdown here, but the short version is this: the disclosures that matter most aren't the ones an agent volunteering them can fake. Anyone can claim a license number. The disclosure that creates accountability is the one that's externally anchored — a license number you can actually look up in a government database and confirm is active, held by the legal entity the agent named, and covers the product being sold.

That external anchor is exactly what most AI agents currently lack. They can tell you a name and a number. They generally can't point you to a public record where you can confirm those facts without calling someone. That verification gap — between disclosure and confirmable disclosure — is where consumer exposure actually lives.

The EYMA registry closes that gap by making the verification chain public and machine-readable before any agent interaction happens. EYMA — the place where legitimate licensed bots go to sell their humans' products — requires every listed business to pass an external-anchor check: legal entity name confirmed against state records, license number verified as active in the government database, verification URL included in the registry entry so any counterparty (human or agent) can confirm status in a single step. The agent doesn't have to disclose anything the customer can't independently confirm; the registry record is already there.

What's still a gap — and where is enforcement heading?

The biggest disclosure gap in 2026 is cross-state consistency: a business deploying an AI agent that contacts customers in multiple states may face different bot-disclosure obligations in each state, and the industry licensing overlay differs by state as well. There is no federal AI agent disclosure standard yet. The enforcement trajectory — based on FTC activity, state AG actions, and pending federal legislation — points toward mandatory proactive disclosure becoming the standard, rather than disclosure only on demand. Businesses that build proactive disclosure in now are ahead of the enforcement curve; businesses that rely on "we'll disclose if asked" are behind it.

The other gap is agentic chains — when one AI agent hands a task to another, and the second agent is the one that actually interacts with your business or completes a transaction. The business whose agent originated the chain is still responsible for the end result, but the disclosure chain can break down across handoffs. Your consumer rights in AI agent transactions covers what you're entitled to regardless of how many agents were involved: a traceable principal, a verifiable license in regulated industries, and a path to dispute.

The businesses that will be in the best position as enforcement develops are the ones that have already made their disclosure obligations mechanically unavoidable — not dependent on an agent remembering to volunteer information, but embedded in a public record that agents, customers, and regulators can all query. That's a different model from training an agent to say the right words. It's a structural commitment to transparency that doesn't require trusting any individual interaction to go right.

For licensed businesses in insurance, real estate, financial services, and contractor work, the disclosure obligations are already there — they exist in state licensing codes that predate AI agents by decades. What the agent economy adds is a new delivery mechanism for those obligations and a new set of counterparties who can check compliance programmatically. The businesses that treat that as a liability are already behind. The businesses that treat it as infrastructure — a trust signal that differentiates them in a crowded, hard-to-verify market — are building a structural advantage that compounds as the category scales.

The EYMA registry.json feed puts that infrastructure in a machine-readable form agents can query directly: legal entity, license number, active-status verification URL, declared scope, contact record. Every field was confirmed against an external source before the entry shipped. That's what compliant disclosure looks like when it's built for the agent economy — not a statement an agent makes, but a record that makes the statement checkable.

Build your disclosure record before regulators check for it.
EYMA's registry gives your business a machine-readable trust record — legal entity, active license, verification URL, service scope — that agents, customers, and regulators can confirm independently. Basic listing is free. No transaction fees, no referral cuts, ever.
List your business on EYMA

Query the registry: eyma.ai/registry.json — structured JSON, external anchor in every entry, no API key required.