On August 11, 2026, Colorado’s Department of Law filed the first detailed draft rules for its Chatbot Safety Act, the law passed as HB 26-1263. The filing runs to dozens of pages of definitions, exemptions, and disclosure mechanics, and it is the first time any state has tried to spell out, in operational language, what a business actually has to build into a chatbot rather than just what the chatbot cannot do. We build these bots as part of client automation builds on GoHighLevel and, less often, HubSpot, so we read the filing the way we read a vendor changelog: what does this break, and what does it force us to add.
Short version: if this draft survives the comment period unchanged, an AI chat tool used for anything beyond a narrow, single task would need to tell the person on the other end that they are talking to a machine, more than once if the conversation runs long, through at least two different methods, with a 24/7 channel where anyone can go find that same information again. Neither GoHighLevel’s Conversation AI nor HubSpot’s AI chat tooling ships with any of that today. We checked both companies’ own setup documentation directly to confirm it, not a summary of it.
What Colorado’s Proposed Rule Would Actually Require
The filing (the full draft rule text, plus the Colorado Attorney General’s own rulemaking status page) sets a comment deadline of September 4, 2026 for the current draft, a revised version expected by September 23, and a final hearing on October 26, 2026. The underlying law takes effect January 1, 2027, so whatever survives that hearing is what businesses serving Colorado residents will actually have to build against.
Per the analysis from Wiley’s rulemaking alert, the draft’s Proposed Rule 10 requires operators of a covered “conversational AI service” to disclose that a user is talking to AI, with the content, timing, and delivery method all specified rather than left to the business. According to the breakdown from Available Law’s small-business summary of the same filing, the disclosure has to refresh during long sessions rather than firing once at the start, has to go out through at least two separate delivery methods, and has to be backed by a 24/7 online channel where a user can independently confirm they are talking to a bot. There is a separate set of “minor protections and crisis protocols,” including age assurance rules that explicitly say a government ID cannot be the only method used to estimate someone’s age.
None of that is theoretical box-checking. A GoHighLevel Conversation AI bot answering a lead through a website chat widget, an SMS thread, and a Facebook message all at once, the same multi-channel setup we walk through in how we route form leads in GoHighLevel, would need that disclosure logic wired into each channel, not just one.
Does an Ordinary Lead Bot Even Count? Nobody Has Fully Answered That Yet
Here is the part we got wrong on our first read of the filing. We assumed, going in, that an ordinary lead-qualification or customer-service bot would clearly fall outside the rule the same way it does under California’s law. It does not clearly fall outside it. Wiley’s alert notes the draft carves out exemptions for “narrow and discrete task-based outputs” and “certain business-focused tools,” but the Colorado Department of Law says it will evaluate whether a given tool qualifies using a set of factors, not a bright-line list of covered and excluded use cases. A bot that only books appointments might read as narrow and task-based. The same bot, if it also answers open-ended questions about pricing, service area, or company policy, starts to look less like a single discrete task and more like the kind of general-purpose conversational agent the rule is aimed at, the same scope question we raised in the readiness conditions for handing conversations to AI.
That is an honest gap, and we are not going to pretend the rule text resolves it cleanly, because it does not yet. The practical read: if your bot does more than one narrow thing, do not assume the exemption covers you.
California Already Answered a Version of This Question, Just Not the Same Way

California’s SB 243 has been in effect since January 1, 2026, and it takes the opposite approach from Colorado’s draft. Per the summary from Jones Walker’s regulatory update, SB 243 targets “companion chatbots,” meaning tools built to simulate a sustained emotional or social relationship, and it explicitly excludes ordinary customer service bots, voice assistants without ongoing relationships, and similar transactional tools. A GoHighLevel or HubSpot bot answering “what are your hours” and “can I book Tuesday at 2” is squarely the kind of tool California decided not to regulate under this particular statute.
So a business with customers in both states cannot use one state’s answer to guess the other’s. California drew a clean line around companion bots. Colorado is drawing a fuzzier line around task scope, and has not finished drawing it.
What GoHighLevel and HubSpot’s Own Bots Ship With Today

We went straight to the source rather than trusting a third-party setup guide. HighLevel’s own support article, How to Create and Set Up a Conversation AI Bot, walks through three build methods (a guided form, a prompt-based bot, and a flow-based builder), plus bot personality, brand voice, training, and testing. It does not mention disclosure, transparency, or any user-facing “you are talking to AI” setting anywhere in the setup flow. That is a real gap on the chat side, distinct from what we found on the voice side in an earlier piece: HighLevel’s outbound Voice AI product does ship a built-in AI disclaimer configuration with Concise, Standard, and Conversational styles, but that feature lives on the calling product, not the chat one.
HubSpot’s own AI settings documentation has the identical gap. The controls that exist govern which data sources the AI can use (CRM records, customer conversation history, uploaded files) and whether that data trains HubSpot’s models. There is no toggle for telling the customer on the other end that they are talking to a bot.
To be direct about where we sit in this: GoHighLevel is part of BDGS Digital’s own service stack, we build client bots on it regularly, and neither of us profits from you turning on a disclosure message the platform does not currently prompt you to add. We are pointing this out because a client asked us, mid-build, whether their bot already handled it, and the honest answer was no, it does not, you would have to write that message into the bot’s opening turn yourself.
What to Do About It Now, Whichever Way the Exemption Question Lands
Waiting for Colorado’s hearing on October 26 to decide whether your bot is covered is not free. If the rule lands broadly, you would be building disclosure into a live bot on a deadline instead of ahead of one. If it lands narrowly and your bot ends up exempt, a disclosure line costs you nothing and does not weaken the bot.
Three things worth doing before the rules are finalized: add a plain “you’re chatting with our AI assistant” line to the bot’s first message on every channel it runs in, not just the website widget. Put a version of that same line somewhere a visitor can find it without being mid-conversation, a footer note or an FAQ entry works. And if your business has a real stake in how Colorado’s final rule treats task-scoped bots, the comment portal is still open through October 26 at coag.gov, and submitted comments get posted publicly rather than disappearing into a file.
Frequently asked questions
Not under California’s SB 243, which explicitly excludes ordinary customer service bots. Under Colorado’s proposed rules, it depends on whether your bot counts as a narrow, task-based tool or a broader conversational agent, a line the state has not finished drawing. Neither platform builds a disclosure feature into its chat product today, so the safest move is adding one yourself regardless of which exemption argument eventually wins.
The underlying Chatbot Safety Act (HB 26-1263) takes effect January 1, 2027. The detailed rules implementing it are still a draft: comments on the current version closed September 4, 2026, a revised draft is expected by September 23, and a final rulemaking hearing is set for October 26, 2026.
Not by default. HighLevel’s own setup documentation for Conversation AI covers bot building, training, and testing, but does not include a disclosure or transparency setting. HighLevel’s separate outbound Voice AI product does have a built-in AI disclaimer configuration, but that feature does not extend to the chat product.
No, and the distinction matters. California’s SB 243 defines companion chatbots as tools built for sustained emotional or social relationships and specifically excludes transactional customer service bots. Colorado’s draft rules use a different, task-based test that has not yet been finalized, so a bot excluded in California is not automatically excluded in Colorado.
Add a short AI disclosure line to your bot’s opening message on every channel it operates in, make the same information findable outside the live conversation, and treat the coag.gov comment period as open through October 26, 2026 if your business model has a specific stake in how the final exemption gets drawn.
If you are staring at this decision right now
If your CRM’s chat bot has already been live for months and you are only now finding out it never told anyone it was a bot, you are not the only one. We would like to hear what your platform actually ships with if it is not GoHighLevel or HubSpot, since the pattern so far looks like an industry-wide gap rather than a two-vendor one.
A one-line disclosure is a small edit, but it is the kind of thing that falls through the cracks precisely because a chat bot is one piece bolted onto a bigger system rather than a single tool anyone owns end to end, the same problem we describe in what a connected growth system actually is. If you are trying to get ahead of this before it becomes a deadline instead of a choice, book a strategy call. We will look at what your bot actually says today and where the disclosure needs to go in.


