PricingGet Started
Back to home

Compliance capabilities (EU AI Act · CA SB 243 · NY GBL §1700)

Last updated: 2026-08-18

In one sentence

For three AI-conversation regulations already in force, ChatX ships disclosure, honest identity, crisis intervention and annual-report counting as product switches plus exportable evidence — compliance becomes a procurement advantage instead of a launch blocker.

This page is not legal advice; disclosure obligations rest with the service operator (deployer). We provide the tooling and the evidence surfaces.

The regulatory map

EU AI Act Art. 50 (applies from 2026-08-02): users must be informed at first interaction that they are interacting with AI; fines up to €15M or 3% of global turnover.

California SB 243 (effective 2026-01-01): companion chatbots must disclose AI identity, publish a crisis-intervention protocol, report crisis-referral numbers annually from 2027, and users get a private right of action.

New York GBL §1700 family: disclosure and safety duties for AI companion services.

Capability 1: system-level disclosure

When enabled, the first AI outbound message of every conversation is prefixed with a disclosure line (support-team tone, not legalese), auto-selected across nine languages by the customer's language, fully overridable by the operator.

It covers every AI outbound path: all three reply pipelines plus proactive outreach (disclosure at first touch); sent once per conversation with a durable mark that survives restarts; cloned voice never speaks the line — the first text reply carries it.

Capability 2: honest-identity mode

When enabled, a direct "are you an AI?" gets an honest answer: identity-denial constraints are skipped and the outbound guard allows truthful self-identification, while every other persona trait stays intact.

Disclosure and honest identity are independent switches — most B2B deployments enable disclosure and opt into honest identity as needed (the law requires non-deception, not per-message confession).

Capability 3: crisis detection → intervention → resources

Built-in crisis detection (severity tiers, idiom-safe), safe-reply override (red-line outputs are fully replaced), hotline-resource assurance (severe conversations always surface referral resources once), and proactive messages are suppressed inside crisis windows.

The whole chain is guarded by always-on automated evaluation gates (detection recall, response override, resource assurance, proactive suppression) that re-run on every code change — a continuously tested safety capability, not a one-off audit.

Capability 4: annual-report evidence

Crisis-referral counts persist to disk (daily buckets, by referral kind) with a read-only admin endpoint for export — the numbers SB 243 requires annually from 2027 are always at hand.

Disclosure execution is equally auditable: disclosed-conversation counts and the live switch states are returned by the same endpoint — one surface for troubleshooting and contract-exhibit data.

Capability 5: crisis-protocol template page

A bilingual crisis-intervention protocol template is provided (see /compliance/crisis-protocol on this site); operators replace the [to be completed] placeholders and publish it to satisfy SB 243's publication duty. The in-product membership page links to the operator's own URL.

Responsibility split & defaults

The legal duties of disclosure, publication and annual reporting rest with the service operator (deployer); as the tool vendor we ship the switches, multilingual copy, counting and export, with documented deployment and verification steps.

All compliance switches default to OFF: existing deployments are untouched until the operator explicitly enables them per local regulation (config group compliance.*, effective immediately).

How to verify (for procurement & legal)

With disclosure on: the first AI reply of any new conversation carries the line exactly once per conversation; the admin endpoint echoes switch states, disclosed-conversation counts and referral counts.

The evaluation-gate inventory, engineering mapping and responsibility split are detailed in the ChatX Compliance Capability document, referenceable in sales contracts; start from the download page for a demo or trial.

Service provider: BOUNDLESS · @WJKJ2026 · hello@bd2026.cc