Untitled UI logotext
Solutions
Legal Infrastructure
Regulatory Risk Intelligence
ProductTechnologyPricing
Resources

Learn

AI Regulatory OS
What Is Regulatory Intelligence
Regulatory Horizon Scanning
Regulatory Change Monitoring
Intelligence vs Compliance
Regulatory
Platforms
Regulatory Data
Sources
Use cases
Programmatic Ai Compliance

Insights

Podcasts
Blog
News & Insights

Knowledge

Knowledge Base
Glossary
Governance at the Speed of AI
A jointly authored research paper introducing a three-layer architecture for embedding compliance directly into the AI system lifecycle.
Read the Full Research Paper
About US
Developers
Explore
Arrow to go next
All posts

You Have to Tell People It’s a Robot.

THE SHORT VERSION
SOC 2 assures controls within its defined scope; it is not a legal-compliance certification for every AI interaction. Whether an AI agent must identify itself, how it may be used, and how its conversation data may be handled can depend on the user’s jurisdiction, the product’s function, the context of the interaction, and the applicable law. AI disclosure, consumer protection, privacy, and communications laws can create separate obligations. One generic notice may not address all of them.

1. What Kentucky’s Character.AI Case Shows

On January 8, 2026, Kentucky Attorney General Russell Coleman announced a lawsuit against Character Technologies, Inc., the company behind Character.AI. The state’s complaint alleges violations of the Kentucky Consumer Protection Act, the Kentucky Consumer Data Protection Act, and other laws in connection with the platform’s operation and its alleged treatment of children’s data and safety.

The case matters because it illustrates a broader enforcement reality: regulators may use established consumer-protection and privacy laws to examine AI products. The allegations concern more than whether a user was told they were interacting with AI; they include claims about safety, representations, age-related safeguards, and data practices. Teams should therefore treat AI transparency as one part of a wider compliance assessment—not as a standalone shield.

‍

2. Why SOC 2 Does Not Answer This Alone

SOC 2 is valuable. It reports on controls relevant to one or more AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. The report’s scope, system description, criteria selected, and controls tested matter.

But SOC 2 is not a determination that a particular AI interaction is lawful in every jurisdiction. It will not, by itself, establish whether a specific disclosure was required, whether a particular automated-decision use is permitted, or whether a notice-and-consent flow satisfies applicable consumer-protection, privacy, or communications laws.

‍

3. State Rules Have Different Scopes and Triggers

US state requirements are evolving quickly. The critical implementation question is not simply “Do we show an AI banner?” It is: which law applies to this product, this user, this use case, and this moment—and what exactly does that law require?

The examples below are illustrative, not an exhaustive 50-state survey. They should be validated against current primary sources and applied with counsel to the facts of the product.

‍

Jurisdiction Example requirement Scope / trigger Implementation takeaway
California SB 243 regulates defined “companion chatbots” and imposes specified disclosures and safeguards. Applies to covered companion-chatbot operators; remedies and obligations have statutory conditions. Do not treat it as a universal rule for every chatbot. Confirm whether the product meets the statutory definition and whether the user and interaction are in scope.
Utah Utah law includes disclosure provisions for certain generative-AI interactions and mental-health chatbots. Requirements vary by context, including consumer transactions, regulated services, and mental-health chatbot use. Map the conversation’s purpose and the service provider’s regulatory status; a prompt-based disclosure rule is different from an always-on notice.
Colorado Colorado’s AI Act focuses on high-risk AI systems and consequential decisions. Employment, housing, education, healthcare, insurance, legal services, and other defined consequential decisions can trigger duties. Assess whether the system makes, or is a substantial factor in making, consequential decisions—not merely whether it can converse.
Washington Washington’s AI companion-chatbot law takes effect January 1, 2027. Covered operators must disclose at the beginning of an interaction and at least every three hours; additional, more frequent notices apply for known minors or chatbots directed to minors. Build configurable notice timing, age-aware controls, evidence logging, and jurisdictional rules before the effective date.

‍

A practical baseline can be broad and user-friendly—clear disclosure that the user is interacting with AI—but legal analysis still has to be specific. A broad notice can reduce confusion; it does not replace a review of whether a statute has additional wording, timing, age, product-definition, or recordkeeping requirements.

‍

4. Conversation Data Is a Separate Workstream

AI identity disclosure and conversation-data handling raise different questions. A company may need to assess whether it collects, records, replays, shares, retains, or routes conversation content to analytics providers, model vendors, quality-assurance tools, or other service providers. Relevant rules can arise under privacy, consumer-protection, and communications laws, and the outcome can be highly fact- and jurisdiction-dependent.

This area has generated litigation involving website chat and session technologies, including claims under state wiretap statutes. That litigation does not establish that every vendor data flow is unlawful. It does mean teams should document the data path, contractual roles, notices, consent mechanisms, retention, and applicable exemptions—and obtain legal advice for the jurisdictions in which they operate.

‍

5. What SOC 2 Can—and Cannot—Establish

‍

SOC 2 question What it can help evidence What requires separate legal analysis
Is the system secure? Controls designed to protect systems and information from unauthorized access, based on the report’s scope. Whether a user-facing AI disclosure is required by a particular statute.
Is the system available? Controls supporting availability and resilience, when availability is in scope. Whether a covered interaction received a required notice at the required time.
Is processing reliable? Controls supporting complete, valid, accurate, timely, and authorized processing, when processing integrity is in scope. Whether an AI system is being used in a legally restricted consequential-decision context.
Is data handled according to scope? Relevant confidentiality and privacy controls, where included in the examination. Whether a specific collection, sharing, recording, or consent practice complies with applicable law.

‍

The takeaway is not to replace SOC 2. It is to pair security assurance with a legal and operational process that can evaluate the specific interaction at issue.

‍

6. Start With a One-Week Assessment

A focused one-week assessment can identify priority gaps. Remediation timing will depend on the product architecture, jurisdictions, vendor data flows, user populations, and legal requirements.

  1. Map every AI interaction surface, including customer-facing tools, employee tools, pilots, voice channels, and embedded experiences.
  2. Identify the relevant facts for each interaction: user location, user type, age signals, topic, product function, and whether the system informs a consequential decision.
  3. Separate AI-identity disclosures from privacy, recording, data-sharing, and consent assessments.
  4. Diagram every raw-transcript data path, including model providers, analytics, observability, QA, support, storage, and subprocessors.
  5. Convert requirements into release tests and evidence: notice version, display time, user jurisdiction signal, consent state, vendor path, and exception handling.
  6. Create an escalation path for legal review when a use case, jurisdiction, or data flow falls outside the configured rule set.

‍

7. SOC 2 Is Still Worth It

SOC 2 remains a meaningful buyer signal and a useful discipline for security and control maturity. The limitation is simply one of scope: it does not substitute for legal interpretation or prove that every AI action is permitted under every applicable law.

‍

Carver Agents

‍Carver is designed to help teams identify applicable legal requirements, operationalize jurisdiction-aware checks, and retain evidence for AI interactions. It does not provide legal advice or guarantee compliance.

‍

Frequently Asked Questions

Does SOC 2 cover AI disclosure laws?

Not by itself. SOC 2 evaluates controls against the Trust Services Criteria selected for the examination and within the report’s defined scope. It is not a jurisdiction-specific legal-compliance certification for AI disclosure, consumer protection, communications, or privacy laws.

‍

Which states require AI chatbot disclosures?

The answer depends on the statutory definition, product type, interaction, user, and effective date. California, Utah, and Washington have enacted laws containing AI or chatbot disclosure requirements in specified contexts; Colorado’s AI Act addresses high-risk AI systems and consequential decisions. Use current primary sources and counsel to assess a particular use case.

‍

Is AI disclosure the same as consent for conversation-data handling?

No. A notice that a user is interacting with AI and a consent or notice related to collection, recording, sharing, or vendor processing address different issues. The applicable requirements depend on the law and facts, including jurisdiction, technology, data flow, and consent design.

‍

What does Kentucky’s Character.AI lawsuit show?

Kentucky’s complaint alleges violations of consumer-protection, data-protection, and other laws involving Character.AI. It demonstrates that AI products can be assessed under established legal frameworks, including where no single AI-specific statute controls the entire case.

‍

Can a company remediate AI disclosure risk in a week?

A week can be enough to complete a targeted assessment and prioritize gaps. Implementing the necessary product, privacy, vendor, legal, and evidence controls may take longer.

‍

Does Carver replace counsel or a SOC 2 audit?

No. Carver is designed to support compliance operations and evidence workflows. It does not replace legal advice, an independent SOC 2 examination, or the organization’s accountability for compliance decisions.

‍

What happens when a new state passes an AI disclosure law?

Carver adds it to the jurisdiction map as it's enacted, so your product and legal teams see the new trigger before it becomes a filing, not after.

‍

Can Carver catch a compliance gap before it becomes a lawsuit?

That's the core idea. Carver checks each agent action against the law that governs it, jurisdiction, statute, case law, right now, so a missing disclosure line or an unconsented vendor hop gets flagged before a user, or a plaintiff's lawyer, notices.

‍

Sources and further reading

  • Kentucky Attorney General, announcement of action against Character Technologies (Jan. 8, 2026): https://www.kentucky.gov/Pages/Activity-stream.aspx?n=AttorneyGeneral&prId=1857
  • Kentucky Attorney General, filed complaint materials: https://www.ag.ky.gov/Press%20Release%20Attachments/CTI%20Complaint%20Motion%20and%20Order%20Filed.pdf
  • California SB 243 legislative analysis (private right of action and remedies): https://trackbill.com/s3/bills/CA/2025/SB/243/analyses/assembly-judiciary.pdf
  • Utah Code § 13-72a-203, disclosure requirements for mental health chatbots: https://le.utah.gov/xcode/Title13/Chapter72A/13-72a-S203.html
  • Utah Code, Generative Artificial Intelligence—Consumer Protection chapter: https://le.utah.gov/xcode/Title13/Chapter77/C13-77_2025050820250508.pdf
  • Washington RCW Chapter 19.440, AI companion chatbots: https://app.leg.wa.gov/RCW/default.aspx?cite=19.440&full=true
  • Washington House Bill Report ESSB 5984: https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bill%20Reports/House/5984-S.E%20HBR%20TEDV%2026.pdf
  • AICPA, 2017 Trust Services Criteria with revised points of focus: https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
  • Example discussion of chat-feature wiretap litigation: https://www.insideclassactions.com/2023/05/09/a-closer-look-courts-reject-california-wiretap-claims-based-on-website-chat-features/

Legal notice: This article is for general informational purposes only and does not constitute legal advice. Requirements vary by facts and jurisdiction and may change. Consult qualified counsel regarding your organization’s obligations.

‍

Carver is building regulatory data infrastructure to support the agent through its lifecycle so that all actions are legal. More at https://carveragents.ai

‍

Carver Agents Logo
Location

United States
447 Broadway,
2nd Floor Suite #563,
New York 10013

LinkedIn iconYoutube logo X.xom iconsubstack icon Listen to Carver Conversations on Moltbook
  • AI Regulatory OS
  • Regulatory Intelligence
  • Regulatory Sources
  • Regulatory Platforms
  • Horizon Scanning
  • Regulatory Monitoring
  • Intelligence vs Compliance
  • Pricing
  • Podcasts
  • Knowledge Base
  • Resources
  • Glossary
  • Use cases
  • Developers
  • Home
  • Legal Infrastructure
  • Regulatory Risk Intelligence
  • Product
  • Technology
  • About Us
  • mail
    hello@carveragents.ai
  • Github
    github.com/carveragents
SOC compliance

Copyright © 2026 Carver Agents | All Rights Reserved | Privacy Policy | Data Policy | Terms of Service | Privacy Rights
Language