Hey. If you have used AI to draft a reply to a Google review, tidy up a testimonial, write an ad headline or answer a customer text, this one is for you. The rules on all four are no longer vague. One is federal and already carries fines. Several are state laws with dates on the calendar. None of them come with a small-business pass.
Here is what an owner can and cannot do, cited to the source, with a checklist at the end. I am not a lawyer. This is one operator reading the rules so you do not have to start from zero.
Reviews: the federal rule already in force
In August 2024 the FTC finalized its rule on fake reviews and testimonials, and it is the piece of AI law every small business is already living under. The FTC's own summary lists what it bans. Reviews that misrepresent who wrote them, "such as AI-generated fake reviews." Paying or rewarding anyone for a review that has to be positive or negative. Reviews from owners, managers or employees that do not clearly disclose the connection. A website you control posing as an independent review site. Threats or false accusations used to get a negative review taken down. Buying fake followers or views. The rule lets the FTC seek civil penalties against knowing violators.
What you can still do is most of what matters. You can ask real customers for reviews. You can use AI to draft your replies to reviews, as long as the reply is honest and you stand behind it. You can use AI to clean up a testimonial a real customer gave you, as long as the substance is theirs and they approve the final version.
What you cannot do: have AI write a review and post it as a customer. Offer a discount for a five-star rating. Let your office manager leave a review without saying she works there. Each of those is a knowing violation, and "the tool wrote it" is not a defense.
Marketing claims: "AI-powered" has to be true
On August 27 the FTC finalized orders against Cox Media Group and two marketing firms. Cox Media Group pays $880,000, and MindSift and 1010 Digital Works pay $25,000 each. They sold advertisers an "AI-powered" service that supposedly listened to smart-device conversations and targeted ads by location. The FTC found the service "wasn't based on voice data, and consumers hadn't opted into this service." The money goes back to Cox Media Group's advertising customers.
Two lessons. First, if a vendor pitches you AI targeting that sounds like magic, ask how it works before you pay. Second, the same standard applies to your own copy. If your website says "AI-powered scheduling" and a person does the scheduling, that is a claim you cannot back up. Say what the thing actually does.
Customer messages: tell them it is a bot
This is the area moving fastest, and it is state law, not federal. Squire Patton Boggs' midyear state AI law update counts twelve states with companion chatbot laws: California, New Hampshire and New York already in force, and Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon and Washington enacted this year. Colorado, Connecticut, Oregon and Washington take effect January 1, 2027, and Georgia, Idaho, Iowa and Nebraska follow on July 1, 2027. Hawaii's has been enforceable since the governor signed it on July 13, 2026. California signed SB 1119 on September 10, adding usage limits, self-harm protocols and independent audits, operative July 1, 2027, and the governor has until the end of September to act on SB 1000, which changes how disclosures on AI-generated content get verified.
Colorado is the one I read closely, because it is home. The Attorney General's proposed rules for the Chatbot Safety Act require a chatbot to "disclose to all users that they are interacting with AI and not a human," estimate user age, protect minors, run suicide and self-harm response protocols and file an annual report. The law takes effect January 1, 2027, the rulemaking hearing is October 26, 2026, and the draft names no small-business exemption.
The practical read: companion chatbot laws are aimed at apps built to be a friend. A booking bot or a voice agent that answers your phone is not that. But "tell the customer it is AI" is cheap, it is the direction every state is heading, and it costs you nothing in bookings. Every voice agent Apex builds inside its Customer service department opens by saying it is an AI assistant for the business. Do the same for any chat widget or text-back bot you run, and give the customer a way to reach a person.
Hiring: you own the tool's bias
If you use AI to screen resumes, the first of Connecticut's AI employment rules start October 1, 2026. From that date an employer "cannot shield itself from liability for a discrimination claim by asserting that it relied on an AI tool," and layoff notices under the state WARN Act must disclose whether the layoffs relate to AI. Courts may treat documented anti-bias testing as a mitigating factor. Written notice to applicants before an AI-influenced decision arrives October 1, 2027. Colorado's proposed rules go further: an adverse decision in employment, education, financial services, housing or insurance made with an automated tool must be disclosed within 30 days, with a path to human reconsideration.
Why this lands on you, not a regulator
You might expect Washington to sort this out. Not this year. NPR reported that most lawmakers left town this week until after the November election, short on time and short on consensus about whether AI regulation is even Congress's job. The Associated Press reported that Trump called the regulatory push a "conspiracy" and Speaker Johnson said "the reflex of legislative bodies is to cover things up with red tape and hyper regulation." Sen. Hawley's investigation into OpenAI asks the question the courts will eventually answer: "Who is held liable when AI goes rogue?"
Until then the answer for a small business is: you. And most of your peers are not ready. GTIA surveyed 520 SMB decision-makers and found 84% report positive business impact from AI, but only 44% have an acceptable-use policy, 40% have training and accountability rules, and 39% have data-security rules.
Related: what the AI CEOs agreed at the White House, and a plain AI operating plan by department for what to hand off first.
The compliance checklist
- No AI-written reviews, ever. Not on Google, not on your site, not "as a placeholder."
- No incentives tied to a rating. Ask for a review. Never pay for a sentiment.
- Insiders disclose. Staff and family who review you say so in the review.
- Testimonials are customer-approved. AI can polish, the customer signs off, the substance stays theirs.
- Every AI claim in your marketing is provable. If you say AI does it, AI does it.
- Every bot says it is a bot. Voice, chat and text, in the first message.
- A person is one step away. Any customer who asks for a human gets one.
- Hiring tools are tested and documented. Keep the paper trail. It is your defense.
- Write a one-page acceptable-use policy. What staff may paste into AI tools, what they may not, and who checks outputs before they go out.
None of this slows down a well-built automation. It is the difference between a review bot that drafts honest replies for you to approve and one that manufactures praise. The first is a Marketing asset. The second is a fine waiting to happen. If you want the rules baked into the build instead of bolted on later, that is what we do.