The FTC AI chatbot inquiry began on 11 September 2025. That day the US Federal Trade Commission sent orders to seven companies whose chatbots act as companions. The orders asked what the companies had done to test safety and to protect children and teens (TechCrunch). The inquiry gathers facts. It is not a disclosure rule. If your product has EU users, the binding chatbot duty comes from somewhere else: Article 50(1) of the EU AI Act, which has applied since 2 August 2026.
Teams keep mixing up these two regimes. The mix-up tends to show up at the worst moment, when a customer's security questionnaire asks about the FTC and the only thing the product team has is an EU disclosure banner. Or the reverse happens. This article sets the two side by side. It then shows which evidence covers both and which covers only one.
What the FTC asked, and of whom
The seven recipients
According to CNN's report via WRAL, the Commission opened an investigation into seven tech companies over potential harms their companion chatbots cause. TechCrunch named the recipients as Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap and xAI. The orders were issued under the FTC's Section 6(b) study authority. A 6(b) order requires a company to answer the Commission's questions. It does not accuse the company of breaking the law.
What the orders ask about
The Seattle Times summarised the goal: the FTC wants to know what steps, if any, companies took to evaluate how safe their chatbots are when they act as companions. The published coverage puts the questions into roughly five groups:
- how the companies monetise user engagement
- how characters and personas are developed and approved
- how negative effects are tested and monitored, both before and after deployment, with particular attention to children and teens
- how users and parents are told about the risks
- how personal information from conversations is used and shared
Only the fourth group is about disclosure. The other four concern product design, testing and data practices. For this article, that asymmetry is the key point.
What an inquiry is not
A 6(b) study does not create a rulemaking and does not set a compliance deadline. The companies that received orders have to respond. Nothing in the inquiry gives any other chatbot operator a new duty. What comes next is uncertain: a staff report, enforcement under existing law, or nothing. Watch the FTC's own press releases for that, not secondary coverage.
A second FTC signal: the July 2026 bias statement
Ten months later the agency took a different direction. Investing.com reported on 1 July 2026 that the FTC said AI companies which train their chatbots to avoid responses discriminating against specific groups of people may violate federal law.
That is a statement of enforcement posture. It is not a published rule. Before it changes how you tune a model's outputs, have US counsel read the primary text. A news summary is not enough. This statement also has nothing to do with the EU transparency duty. Article 50 governs whether people are told they are talking to AI. It does not govern what the AI says.
FTC inquiry vs EU Article 50(1): side by side
Article 50(1) of Regulation (EU) 2024/1689 requires providers to design AI systems that interact directly with natural persons so that those persons are informed they are dealing with an AI system. The exception is where this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. Article 50(5) requires the information to be given clearly, at the latest at the first interaction. Our chatbot disclosure requirement guide covers the exception test in detail.
| Dimension | FTC companion-chatbot inquiry | EU AI Act Article 50(1) |
|---|---|---|
| Legal nature | Information-gathering study (6(b) orders) | Binding obligation in a regulation |
| Who it binds | The seven order recipients | Every provider of a covered system placed on the EU market |
| Trigger | Chatbot acting as a companion | Any AI system interacting directly with people, companion or not |
| Core ask | Answers on testing, monetisation, minors, data, user information | Tell the person they are interacting with AI |
| Age focus | Central (children and teens) | None specific in 50(1) |
| Date that matters | Orders issued 11 September 2025 | Applies since 2 August 2026, with no transition period |
| What satisfies it | A complete response to the order | A notice that is clear and on time, or a documented "obvious" reasoning |
Most readers skim past one row: trigger. The FTC's inquiry is aimed at companions. Article 50(1) covers a plain customer-support bot as well. A B2B SaaS team with no companion features falls outside the FTC's focus and still inside Article 50(1).
Three product shapes, three answers
A US-only companion app
The EU duty does not reach it while no EU market is served. The FTC's question list is the more useful checklist here, and state law may add obligations. California's companion-chatbot statute, for example, sets its own disclosure and minor-user rules; see our SB 243 breakdown.
A SaaS support bot with EU users
Article 50(1) applies whenever the bot is not obviously an AI. The FTC inquiry does not name this kind of product. Decision rule: if the bot answers in natural language and could plausibly be taken for a human agent, show the notice before or in the first message. Do not bury it in the terms of service.
One trap is to assume the model vendor carries the duty. If you integrate a third-party model into your own AI system and offer it under your own name, Article 3(3) makes *you* the provider.
A companion bot that also generates images or voice
This is where the lanes stack. A companion bot served in the EU that also produces synthetic images or voice can touch three of Article 50's four paragraphs: 50(1) for the conversation, 50(2) for machine-readable marking of generated output, and 50(4) if that output amounts to a deepfake. It also matches everything the FTC asked about. This product needs the full evidence file below.
One evidence file, two audiences
These 10 records are the ones worth keeping per conversational surface. The table shows which regime each one answers to.
| # | Evidence item | FTC inquiry topics | Art. 50(1) |
|---|---|---|---|
| 1 | Inventory of every conversational surface, markets and launch date | ✓ | ✓ |
| 2 | Disclosure copy plus first-interaction screenshots | ✓ (user information) | ✓ |
| 3 | Age-assurance approach and minor-user handling | ✓ | — |
| 4 | Pre- and post-launch testing for harmful outputs | ✓ | — |
| 5 | Persona/character approval workflow | ✓ | — |
| 6 | Engagement monetisation model | ✓ | — |
| 7 | Conversation data flows: retention, training use, sharing | ✓ | — (GDPR instead) |
| 8 | Model-vendor record and provider/deployer role under Art. 3(3) | — | ✓ |
| 9 | Written "obvious to the user" reasoning where no notice is shown | — | ✓ |
| 10 | Re-verification log showing the notice still renders after each release | ✓ | ✓ |
Only 3 of the 10 items serve both audiences. Five map to the FTC's topics alone and two to Article 50 alone. A disclosure notice by itself covers a small part of what the FTC asked companion operators. A team that has "done the AI banner" has not done the FTC's homework. A team that answered an FTC-style questionnaire may still have no Article 50 role analysis on file.
The item that fails most often is #10. A redesign moves the chat launcher, the notice component is dropped from the new build, and nobody notices for weeks. Automated render checks after each deploy catch this early. A screenshot taken at launch cannot. DiscloseKit's verification step and hash-chained evidence log are built for that check. Neither is a certification, and neither shows that a given wording is legally sufficient.
What changes in November and December 2026
The one EU date inside this window is 2 December 2026. Under Regulation (EU) 2026/1744, the Digital Omnibus on AI, providers of generative AI systems placed on the market before 2 August 2026 have until then to meet Article 50(2) marking. That transition covers neither the chatbot notice in Article 50(1) nor deployers. The Omnibus's new Article 5 prohibitions also apply from 2 December 2026. The 2026 deadline overview sets out the full sequence.
On the US side, no FTC date is fixed for this window. If your team is waiting for the inquiry to "conclude" before acting on the EU notice, it is waiting on the wrong clock.
This article is operational guidance, not legal advice. Questions about US federal enforcement exposure or state-law scope need counsel admitted in that jurisdiction.
FAQ
Is there a chatbot disclosure requirement in 2026?
In the EU, yes. Article 50(1) of the AI Act has required providers to tell people they are interacting with an AI system since 2 August 2026, unless that is obvious. In the US, the FTC's inquiry adds no disclosure duty of its own. State laws such as California's SB 243 regulate companion chatbots, so check which states you serve.
Can AI chatbots be illegal?
A chatbot as such is not unlawful. Specific practices around it can be. In the EU, running a covered chatbot without the Article 50(1) notice breaches the regulation, and some AI practices are prohibited outright under Article 5. In the US, liability usually turns on existing consumer-protection or state law applied to what the product actually does. That analysis needs a lawyer.
How does the FTC regulate AI?
Mostly through powers it already has, not AI-specific rules. It uses studies such as the 6(b) companion-chatbot inquiry to gather facts, and it issues statements on how it reads existing law. The July 2026 bias statement is one example. Its own releases are the primary source; news coverage summarises them.
What shouldn't users share with an AI chatbot?
For product teams, the more useful question is what you tell users about where their messages go. The FTC asked companion operators how conversation data is used and shared. If you cannot answer that for your own bot (item 7 above), your users cannot make an informed choice about what to type.
