Quick answer: The four regimes that require a "you are interacting with an AI" notice share that one notice shape. Orbit stores your disclosure posture for all four in a single singleton settings row — one master switch (default_enabled) activates the notices, and one per-regime toggle marks which of the four regimes your workspace applies. You configure it once under Settings → Compliance → AI Disclosure, or over GET/PUT /api/v1/compliance/ai-disclosure, and every AI voice and chat agent in the workspace reads the same row. This is a tenant-owned control: you (with qualified counsel) decide which regimes apply to your traffic; the platform stores and delivers what you set, it does not mandate disclosure.
This post is the consolidated walk-through of the four-regime surface. The EU AI Act deep dive already published on this blog covers the European regime's two duties in detail; here the mapping spans the EU, Korea, California SB 243, and the Utah AI Policy Act in one loop. As with that post, this is an engineering read, not legal advice.
The regime-to-toggle map
Four regimes currently in force share the same disclosure shape — the person must be told they are interacting with an AI — so the settings surface encodes each with one toggle:
| Regime | In force | Toggle key | Enable it when |
|---|---|---|---|
| EU AI Act, Article 50 | Applies from 2026-08-02 | eu_ai_act_enabled | Your AI agents interact with people in the EU. Imposes both the interaction notice and machine-readable marking of AI-generated content. |
| Korea AI Basic Act | Live since 2026-01-22 | kr_disclosure_enabled | Your AI agents interact with people in Korea. |
| California SB 243 | Live since 2026-01-01 | ca_minor_reminder_enabled + minor_break_reminder_minutes | You flag contacts as minors. Adds a recurring "you're talking to an AI — consider taking a break" reminder during long sessions. |
| Utah AI Policy Act | In force since 2024 | default_enabled (the master switch itself) | Your AI agents interact with people in Utah. |
The per-regime toggles mark which regimes apply; they do not activate the notice by themselves. `default_enabled` is the master switch — it must be on for any notice to render or any AI-generated content marking to stamp. A workspace with eu_ai_act_enabled on but default_enabled off renders no notice. The AI-disclosure settings doc documents each field; the EU AI Act page maps the transparency obligation to the banner in detail.
No geo-detection — jurisdiction is your call
There is no automatic geo-detection behind any of these toggles. When you enable a regime, Orbit applies it workspace-wide to every AI interaction; the platform does not infer a contact's jurisdiction from their phone number, address, or IP. If your traffic touches the EU, turn the EU rule on for the whole workspace rather than trying to scope it to EU contacts — Orbit cannot tell you which contacts those are.
The one exception to workspace-wide application is California SB 243's minor reminder: it fires only for contacts you have explicitly flagged as a minor. Minor status is never inferred from a birth date or any other signal — your flag is the only trigger, which keeps the reminder out of adult sessions by construction.
How to configure it
Two paths write to the same singleton row:
- Dashboard — Settings → Compliance → AI Disclosure. Edit the
chat notice text and voice intro copy, turn on the jurisdiction rules that apply to your traffic, and set Enabled by default.
- API —
GET /api/v1/compliance/ai-disclosurereturns the current
row ({ "settings": null } until first configured); PUT /api/v1/compliance/ai-disclosure accepts a partial update — only the keys you send change. Both calls require the owner or admin role.
The row carries, in full: default_enabled (master switch), chat_notice_text and voice_intro_text (1–2000 characters each), voice_intro_audio_url (an HTTPS URL that overrides synthesis of the voice intro when set; send null explicitly to clear it), eu_ai_act_enabled, kr_disclosure_enabled, ca_minor_reminder_enabled, minor_break_reminder_minutes (integer, 1–1440), and marketing_disclosure_required.
The text a contact sees comes from that same row: chat_notice_text is prepended to an AI agent's first chat reply once per conversation, and voice_intro_text (or your pre-recorded voice_intro_audio_url) plays before an AI voice agent connects. Ready-made wording per channel lives in opt-in disclosure templates; the agent identity governance surface is the inventory that tells you which agents exist and will carry the notice.
The pre-publishing verification checklist
Saving settings takes effect immediately — the next agent turn reads the new values — but the right time to set this up is before an agent goes live. An unconfigured row means no notice renders at all, so before you flip any agent from draft to active:
GET /api/v1/compliance/ai-disclosureand confirm the row is not
null.
- Confirm
default_enabledistrueand the jurisdiction toggles your
traffic touches are on.
- Read
chat_notice_textandvoice_intro_textexactly as a contact
will see and hear them.
- Run a live check — start a chat session and confirm the notice shows
on the first reply; place a test call and confirm the intro plays before the agent speaks.
At runtime the same endpoint remains your verification surface: diff the row before a go-live review instead of assuming it still matches what legal approved.
Honest scope notes
Boundaries worth knowing up front, so nothing here surprises you at go-live:
- Workspace-wide scope. Each regime toggle applies to every AI
interaction in the workspace — there is no per-contact geographic scoping.
- Immediate effect. A PUT takes effect on the next agent turn; you
do not republish or redeploy agents when the posture changes.
- Validation, not silent corruption. An invalid payload returns a
422 naming the field that failed rather than storing a partial write.
- Auditable. Every write is recorded in the audit log with the acting
user's identity and the previous and new values of every changed field; review changes under the audit action compliance.ai_disclosure_updated.
Related reading
the field-by-field settings surface this post walks.
the regime framing and per-regulation posture matrix.
the agent inventory that confirms which agents carry the notice.
ready-made disclosure copy per channel.
For the EU-only deep dive — Article 50's two duties, the marking requirement, the enforcement timeline — read EU AI Act 2026 — what it means for communications platforms. This post is the consolidated multi-regime walk-through; that one is the European regime's detail pass.
A closing reminder of the frame: everything here is a tenant-owned toggle. Orbit supplies the control surface and delivers what you set; whether a regime applies to your traffic, and whether disclosure is required for you, is your counsel's call.