Does Iowa Conversational AI Services Act (SF 2417) require Transparency & Disclosure?

Iowa • enacted

Yes — 3 provisions

Requirements at a glance

This regulation imposes 10 specific requirements for Transparency & Disclosure across 3 provisions:

Conversational AI Artificiality Disclosure #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators — persons who develop and make a conversational AI service available to the public (§ 554J.1(4)); a conversational AI service is publicly accessible software whose primary purpose is simulating human conversation and interaction through text, audio, or visual communication, excluding R&D tools, features inside a program with a different primary purpose, narrow-and-discrete-topic systems, customer-service and commerce assistants sold to businesses, speaker/voice-assistant interfaces, and systems used solely for internal business purposes (§ 554J.1(2)); app stores and search engines are not operators merely for providing access (§ 554J.1(4))
high-impactupcoming
Two disclosure regimes sit side by side. The general one in § 554J.3 fires only on a reasonable-individual mistaken-for-human test, so a service that visibly presents as a bot may owe nothing. The minor-account-holder one in § 554J.2(1) has no such trigger: if the operator knows or is reasonably certain the account holder is under 18, the disclaimer is owed unconditionally. Both routes accept a persistent visible disclaimer, which is the cheap compliance path and is likely what most operators will build.

Requirements

RequirementDetails
Minor disclaimer, persistent optionClearly and conspicuously disclose to a minor account holder that they are interacting with artificial intelligence, by way of a persistent visible disclaimer (§ 554J.2(1)(a))
Minor disclaimer, interval optionAlternatively, provide both a disclaimer at the beginning of each interaction between the service and the minor account holder and a disclaimer at least once every three hours of continuous interaction (§ 554J.2(1)(b))
General consumer disclosureWhere a reasonable individual interacting with the service would believe they are interacting with a human, clearly and conspicuously disclose that the service is artificial intelligence, using either a persistent visible disclaimer or a disclaimer appearing after every three hours of continuous interaction (§ 554J.3)

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Anti-Anthropomorphism and Emotional Dependency Measures #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services (§ 554J.1(4)); the duty sits in § 554J.2, headed "minors — requirements", and two of its four enumerated examples are framed around a minor account holder, but the operative test is what a reasonable individual would believe
high-impactupcoming
This is the provision with no California analogue. SB 243 regulates the disclosure; Iowa regulates the persona. Barring statements that "simulate emotional dependence" or "simulate a romantic interaction" reaches model behaviour rather than interface copy, which means the compliance artifact is a system prompt, a fine-tune, or an output classifier — not a banner. It is drafted as a reasonable-measures standard, so the question at enforcement will be what the operator did to prevent the output, not whether the output ever occurred.

Requirements

RequirementDetails
Reasonable measures against human-impersonation outputInstitute reasonable measures to prevent the service from generating statements that would lead a reasonable individual to believe they are interacting with a human (§ 554J.2(4))
Sentience and humanity claimsIncluded in the bar: explicit claims that the service is sentient or human (§ 554J.2(4)(a))
Simulated emotional dependenceIncluded in the bar: statements that simulate emotional dependence on a minor account holder (§ 554J.2(4)(b))
Romantic or sexual framingIncluded in the bar: statements that simulate a romantic interaction or a sexual innuendo (§ 554J.2(4)(c))
Adult-minor romantic role-playIncluded in the bar: role-playing an adult-minor romantic relationship (§ 554J.2(4)(d))

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))

Licensed Mental Health Service Representation Bar #

Obligation:
Transparency
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services; the reference point is professional psychology or behavioral health services that would require licensure under Iowa Code chapter 154B (psychologists) or 154D (behavioral science practitioners) (§ 554J.5)
cross-domainupcoming
The scienter standard is the highest in the chapter — "knowingly and intentionally cause or program" — so an emergent therapeutic persona the operator did not design is outside this section, though it may still be caught by the reasonable-measures duty in § 554J.2(4). The bar is on representation, not on function: a service may in fact behave therapeutically as long as it does not lead a reasonable individual to believe it is a licensed practice.

Requirements

RequirementDetails
No licensed-practice representationDo not knowingly and intentionally cause or program a conversational AI service to make a representation that would lead a reasonable individual to believe the service is designed to provide professional psychology or behavioral health services requiring licensure under Iowa Code chapter 154B or 154D (§ 554J.5)
Runtime statements coveredThe bar reaches a "representation or statement", so programmed in-conversation output implying licensed psychology or behavioral health practice is covered, not only marketing or product description (§ 554J.5)

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))
Model developer carve-outA developer of an AI model is not liable solely because a third party used the model to create or train a conversational AI service (§ 554J.6(5))
View full regulation View obligation Obligation matrix