Skip to main content
Back to blog

Four AI-disclosure regimes, one settings surface: EU AI Act, California SB 243, Utah, and Korea

The EU AI Act, California SB 243, the Utah AI Policy Act, and Korea's AI Basic Act all demand the same primitive — the person must know they are talking to an AI. How the four regimes differ, and how Devotel Orbit's tenant-owned disclosure toggles cover all four from one surface.

Orbit Editorial Team

Four AI-disclosure laws are now live across the jurisdictions a communications platform touches every day, and the surprise is how similar they are: the EU AI Act (Article 50), California SB 243, the Utah AI Policy Act, and Korea's AI Basic Act all reduce to one primitive — before your AI agent engages with a person, the person must know it is an AI. The differences are in what each regime adds on top of that primitive, and those differences are exactly where operators lose time. This post lays out the four regimes side by side, then shows how one settings surface in Devotel Orbit covers all four without maintaining four mechanisms. Which laws actually bind your traffic is a determination for your counsel — this is an engineering read of what the controls do.

The four regimes, side by side

RegimeIn force sinceCore dutyWhat's peculiar about it
EU AI Act, Article 502026-08-02Tell the person they are interacting with an AI; mark AI-generated content as machine-generated in a machine-readable way.The only regime here with a content-marking duty (generated audio and text must be machine-readably marked, not just announced). Sits inside an enforcement frame with fines in the tens of millions of euros or a percentage of global turnover.
California SB 243 ("Companion-AI" Act)2026-01-01Disclose the AI; for contacts who are minors, periodically remind them during long sessions that they are talking to an AI — and to consider taking a break.The only recurring-disclosure duty here: the reminder re-fires on a cadence during a session, and it only applies to a per-contact minor determination, not to every interaction.
Utah AI Policy ActIn force since 2024A business deploying a generative-AI interaction with a consumer must clearly disclose that the consumer is interacting with AI, not a human.The oldest regime here and the narrowest: disclosure, nothing else. No content marking, no minor cadence — get the notice in front of the person and the obligation is met.
Korea AI Basic ActLive since 2026-01-22Inform the user that they are interacting with an AI, across AI services presented to users in Korea.Applies across both text and voice surfaces, so the notice has to exist on every channel your agents run on — a chat-only notice does not cover the voice agent.

Two properties make these regimes cheap to operate together. First, they are additive: none of them forbids anything the others require, so the union of all four is a valid posture everywhere. Second, the union is small — one disclosure notice per interaction, content marking on AI output, plus a recurring reminder for flagged minors. That is why one settings surface handles them.

One surface, four regimes — how Orbit maps the toggles

In Orbit, the whole family lives under Settings → Compliance → AI Disclosure (or the /api/v1/compliance/ai-disclosure endpoint; documented in AI disclosure settings). The model:

  • `default_enabled` is the master switch. It carries the oldest regime — the Utah AI Policy Act's plain disclosure duty — and it must be on for any notice to render or any marking to stamp. When it is on, the chat notice is prepended to an agent's first reply (once per conversation) and the voice intro plays before an AI voice agent begins a call.
  • The two notice surfaces are shared across regimes. chat_notice_text covers the chat side for Utah, Korea, the EU, and SB 243 at once; voice_intro_text (or your pre-recorded voice_intro_audio_url) covers the voice side the same way. You write the notice once; every enabled regime reads it.
  • Three named toggles mark which regimes apply. eu_ai_act_enabled, kr_disclosure_enabled, and ca_minor_reminder_enabled are the EU, Korea, and California rules. Turning one on applies it to all of the workspace's AI interactions.
  • `marketing_disclosure_required` layers an explicit disclosure duty onto automated marketing outreach, independent of the jurisdiction toggles.

The one per-contact rule: SB 243's minor reminder

Every other rule is workspace-wide. The California minor reminder is the one exception, resolved per contact: it fires only for contacts explicitly flagged as a minor on their contact record, on the cadence you set in minor_break_reminder_minutes. Orbit does not infer minor status from a birth date, phone number, or address — the legal-age threshold varies by jurisdiction, so inferring would guess at exactly the point a regulator will audit. A contact with no flag is treated as an adult and gets no reminder; the per-contact flag is authoritative, and a stored birth date never sets or overrides it.

The reminder copy itself is fixed: "You've been chatting for a while — consider taking a break. Remember, you're talking to an AI assistant." The tenant-facing notice text is yours to write; the break reminder is regulator-mandated wording and stays in code.

No geo-detection, by design

A jurisdiction toggle is a workspace-wide opt-in, never a per-contact lookup. Orbit does not resolve a contact's country from their phone-number prefix, address, IP, or current location, so it never switches a rule on or off per interaction. If your traffic touches the EU, enable the EU rule for the whole workspace. The safe default runs the same direction everywhere: an off rule never adds a disclosure, disclosures are only ever added, and nothing is silently removed.

Fail-closed reads and the audit trail

Because these are compliance flags, the read path is built to fail closed: if the settings row ever fails shape validation at read time (schema drift), the lookup throws instead of silently coercing a mandated disclosure to "off," and the voice gateway refuses to start the agent flow. Every settings change lands in the audit log with the acting user's identity and the previous and new values of each changed field, and a PUT takes effect on the next agent turn — there is no republish step. The resolved posture also ships in each agent's AI-disclosure ledger export, so the "what was live when" question has a signed answer, and the conformity dossier compiles the per-agent evidence pack for an auditor or a buyer's procurement review.

A four-call configuration sequence

Everything below is API-shaped; the dashboard edits the same row.

  1. Flip the master switch — PUT /api/v1/compliance/ai-disclosure with { "default_enabled": true }.
  2. Set the notice copy once — chat_notice_text and voice_intro_text (1–2000 chars each), or point voice_intro_audio_url at a pre-recorded intro if you want your own recording instead of synthesized speech.
  3. Enable the regimes your traffic touches — eu_ai_act_enabled, kr_disclosure_enabled, and if you flag minor contacts, ca_minor_reminder_enabled with a minor_break_reminder_minutes cadence between 1 and 1440.
  4. Verify on a live interaction before any agent ships — start a chat and confirm the notice appears on the first reply; place a test call and confirm the intro plays before the agent speaks; confirm agent-sent messages carry metadata.ai_generated: true. Re-run the check whenever anyone edits the notice copy or the toggles.

What remains yours

The toggles mark which regimes you have decided apply; they do not make that determination. Three responsibilities stay with the tenant, and none of them is a formality. First, the legal call: which of the four regimes binds your traffic, and whether any other regime applies that this surface does not cover. Second, the notice text: a vague notice ("an automated system may assist you") is the tenant's gap, not the platform's — the duty is that the person is informed, and you write the words. Third, the minor flag: SB 243's reminder only fires for contacts you have flagged, so if you serve audiences that include minors, the flagging workflow upstream of the toggle is yours to build and keep accurate.

Frequently asked questions

Do I need four separate disclosure mechanisms for four regimes?

No. The four regimes share one notice primitive, so one settings surface covers them: a master disclosure switch, one chat notice and one voice intro used by every regime, and named toggles for the EU, Korea, and California rules. The per-contact piece — the SB 243 minor cadence — is the one rule with its own behavior, and it rides on the same row with its own interval setting.

Which toggle covers the Utah AI Policy Act?

The master switch. Utah's Act has been in force since 2024 and requires exactly one thing — the consumer must know they are dealing with AI — so it maps to default_enabled without a named jurisdiction toggle. With the master switch on and notice text set, the Utah disclosure duty is met alongside whatever named regime rules you also enable.

Does Orbit detect my contacts' jurisdictions and switch rules per contact?

No — every jurisdiction rule is a workspace-wide opt-in. Orbit deliberately does not infer a contact's country from phone prefix, address, or geolocation, so it never switches a rule on or off per interaction. The single per-contact datum in the whole model is the explicit minor flag that gates the SB 243 reminder. You enable each regime you operate in for the whole workspace.

What exactly does the California SB 243 toggle change for a minor contact?

It adds a recurring disclosure on top of the base notice. For a contact flagged as a minor, once a session has run longer than your configured interval, the agent injects "You've been chatting for a while — consider taking a break. Remember, you're talking to an AI assistant." and repeats it on that cadence while the session continues. The interval is configurable between 1 and 1440 minutes; the reminder wording is fixed, because it is regulator-mandated copy.

If a regime applies that these toggles do not cover, what then?

The surface covers the four regimes above plus the marketing-disclosure switch. If your counsel identifies a regime outside that set, contact trust@devotel.io so the gap is tracked as a product requirement rather than worked around in copy.

The full field reference — defaults, the endpoint contract, and the audit action — is in AI disclosure settings, and the EU regime's framing continues in EU AI Act Article 50 transparency for AI agents.

Four AI-disclosure regimes, one settings surface: EU AI Act, California SB 243, Utah, and Korea — Orbit by Devotel