Quick answer: Many websites are not prepared. If AI interacts with customers or processes information collected through your website, your business may have disclosure, privacy, consumer-protection, security, and vendor-management responsibilities—even when a third-party plugin or CRM supplies the technology. Important EU transparency rules began applying on August 2, 2026. Here is where the exposure may hide, five steps to improve your AI readiness, and the questions to bring to your attorney.
At WordCamp US 2026 here in Phoenix, the sessions that drew the biggest crowds were about what AI can build. I’ve already written my honest take on whether AI can build a website. But the session that made the room go quiet wasn’t about what AI can build — it was about what AI can cost you.
AI regulation is developing quickly. The EU AI Act’s Article 50 transparency rules began applying on August 2, 2026, US states continue to adopt AI and automated-decision requirements, and existing privacy and consumer-protection laws still apply when businesses use AI. A business operating a website may remain responsible for customer-facing information and data practices even when a vendor supplies the technology.
A note before we start: I’m a web engineer, not a lawyer, and this article is education, not legal advice. Its purpose is to help you identify technical questions and have a better conversation with qualified counsel.
Who Pays When Your Website's AI Gets It Wrong?
In 2024, a Canadian tribunal answered this question so clearly that lawyers still quote it.
A passenger named Jake Moffatt asked Air Canada’s website chatbot about bereavement fares after his grandmother died. The chatbot confidently explained he could book a full-price ticket and apply for the discount afterward. That policy did not exist — the chatbot invented it. When Air Canada refused the refund, Moffatt took them to British Columbia’s Civil Resolution Tribunal.
Air Canada’s defense was remarkable: it argued the chatbot was “a separate legal entity that is responsible for its own actions.” The tribunal didn’t buy it. It found Air Canada responsible for all the information on its website — “whether the information comes from a static page or a chatbot” — ruled the company had committed negligent misrepresentation, and ordered it to pay about CA$812.
The amount was small; the warning is not. The decision is Canadian and does not bind US courts, but it illustrates a practical risk: a business may not be able to distance itself from inaccurate information delivered through a chatbot it placed on its own website.
Insurance coverage for an AI-related claim will depend on the policy, the allegations, applicable exclusions, and the circumstances of the loss. Ask your broker or carrier—in writing—how your current policies would respond if a chatbot, automated recommendation, or AI-assisted publication caused a customer loss.
Where Does AI Create Legal Exposure on a WordPress Site?
WordPress 6.9 introduced the Abilities API, which standardizes how WordPress functionality can be discovered and executed. When a site owner deliberately installs and configures the separate WordPress MCP Adapter, selected abilities can be exposed to authorized AI tools. This creates useful automation opportunities, but it also makes permissions, logging, data access, and human approval important design decisions. The Abilities API alone does not automatically connect a WordPress site to an AI agent.
There are four zones where the exposure concentrates.
1. Privacy and data residency — every AI plugin is a data pipeline
When a visitor types into your chat widget, fills out a form, or gets profiled by a personalization plugin, that data doesn’t stay on your server. It flows to the AI vendor — often to servers in another country — and every new AI connection your site makes sends more of it.
GDPR may apply to a US business when its processing relates to offering goods or services to people in the EU or monitoring their behavior there. A European visitor reaching your website does not automatically settle the issue. US state privacy laws also differ in scope and thresholds, so counsel should determine which regimes apply.
For each tool, ask: What personal or confidential data does it touch? Is sensitive information likely to appear? Where does the data go? How long is it retained? Is it used for training? Can it be deleted? Who are the vendor’s subprocessors? If you cannot answer those questions, your public notices and internal controls may not match reality.
2. Notices, consent, and legal basis: does the site match reality?
Many privacy policies and consent tools were configured before AI features were added. Cookie consent, chatbot notices, form disclosures, and a privacy policy serve different purposes and should not be treated as interchangeable. Some processing may require consent; other processing may rely on another legal basis. Counsel should help determine what applies.
If a chat widget sends conversations to a model provider while the site mentions only analytics cookies, the website may not adequately describe its actual data flows. Review the language at the point of collection as well as the privacy policy, cookie configuration, retention practices, and vendor terms.
3. The EU AI Act — you're a "deployer," even if you never wrote a line of the model
The EU AI Act distinguishes among providers, deployers, and other actors, and their obligations are not identical. A business using an AI system under its authority may be a deployer, but the Act’s scope, definitions, exceptions, and territorial rules still need to be assessed for the specific use.
Article 50 began applying on August 2, 2026. Under the European Commission’s guidance:
- Providers of covered systems that directly interact with people must design them so users are informed they are interacting with AI, unless that is already obvious.
- Deployers must disclose the operation of covered emotion-recognition and biometric-categorization systems to affected people.
- Deployers must clearly label qualifying deepfakes and certain AI-generated or manipulated text published to inform the public about matters of public interest, subject to defined exceptions.
If you operate an AI chatbot, confirm that the provider supplies an adequate disclosure and make sure your implementation does not hide, remove, or contradict it. Independently of the precise legal allocation, clearly labeling a customer-facing bot is a sensible trust and risk-management practice. If you publish AI-generated text to inform the public on matters of public interest (health, politics, safety, environment), it has to be disclosed as AI-generated — unless a human did real editorial review and takes responsibility for it. Qualifying AI-generated or manipulated image, audio, and video content that constitutes a deepfake must be disclosed, with special rules and exceptions for artistic, creative, satirical, fictional, and similar works. Not every AI-assisted marketing image is automatically a regulated deepfake.
Article 50 penalties can reach €15 million or 3% of worldwide annual turnover, with proportionality considerations for smaller businesses. That headline figure should not be presented as the automatic penalty for every missing website label; enforcement depends on the violation and applicable rules.
(You may also hear about the EU’s Digital Services Act requiring recommendation engines to disclose their main ranking factors. That one is aimed at platforms and marketplaces, not the average business site — but if your site personalizes what visitors see, treat it as the direction the law is heading.)
The rule that protects you isn’t “will anyone be able to tell?” It’s this: you disclose, so that you — not the AI, and not a detection tool — are the authoritative source for what’s on your website. That’s the consumer trust these laws exist to protect.
4. US laws: a growing state-by-state patchwork
There’s no single American AI law. There’s a patchwork, and it’s growing every legislative session. Utah requires businesses using generative AI with consumers to disclose it when asked — and proactively in sensitive contexts. California has a stack of them: bot-disclosure rules for sales chatbots, a companion-chatbot law that took effect in 2026, an AI transparency law for large AI providers, and new automated-decision-making rules phasing in through 2027. The FTC’s authority over deceptive practices covers everyone, in every state.
The part business owners miss: consumer-protection laws may apply beyond the state where your business is located. Which laws apply can depend on where your customers live, whom your business targets, and whether you meet specific legal thresholds. An attorney can help determine which state requirements your website must follow. You can’t geofence your way out of a patchwork — which is why the practical strategy is to meet the strictest common denominator: disclose.
What About Your Contact Form and CRM?
This is the section I most want you to remember, because it applies to businesses that are certain they “don’t use AI.”
Look at your contact form. Where do submissions go? For most businesses we work with, they flow into a CRM or follow-up tool — HubSpot, Zoho, Salesforce, Jobber, or a dozen others. Now check what that tool advertises on its homepage: AI lead scoring. AI-drafted replies. AI enrichment that builds a profile of the person who contacted you.
If a visitor’s form submission enters a system that applies AI to it, the website’s data map should include that downstream processing. Your business may have responsibilities as a customer of the service, a data controller, a deployer, or another regulated actor depending on the law and configuration. Do not assume that one label applies in every jurisdiction. Ask the vendor in writing: Which enabled AI features process our customers’ data? What information is used? Is it retained or used for model training? Where is processing performed? Which subprocessors receive it? Can features be disabled separately? What contractual assistance is available if a person exercises a privacy right or a regulator asks questions?
The responsibility to understand and follow the regulations that apply sits with your business: not with the CRM vendor, and not with your web agency. What we can do — what I’m doing right now — is flag it and tell you plainly: look into it.
The practical consequences: your privacy policy needs to describe what actually happens to a submission, your consent language needs to cover it, and if the AI makes decisions about people (like scoring which leads get a callback), the new automated-decision rules may eventually apply to you. Ask your CRM provider two questions in writing: which AI features are processing my customers’ data, and where is that processing happening?
How Do You Make Your Website Legally Ready for AI?
Here’s the checklist we now walk through with our own clients.
Step 1: Talk to a lawyer. Not after something happens — now, while it’s a planning conversation instead of a crisis one. Bring the question list from the next section and the inventory from Step 2.
Step 2: Build an AI and data-flow inventory. You can’t audit — or disclose — what you don’t know is running. Go through your plugins, embedded widgets, form destinations, and admin connections, and write down every place AI touches your website or its data. It can be a simple table:
Step 3: Update your privacy policy — and disclose. Every row of that inventory should be reflected in your privacy policy: what’s collected, what the AI does with it, where it goes. Then add the visible disclosures. A few copy-paste starting points:
For a chatbot: “You’re chatting with our AI assistant. It can make mistakes — please confirm anything important with our human team.” For AI-assisted articles: “This article was drafted with AI assistance and reviewed, fact-checked, and edited by [author name].” For AI marketing images, keep it light: “Image created with AI — our designer takes credit for the good ideas.” And the simplest rule we can give you: if you’re not sure whether something needs to be disclosed, disclose it. A disclosure you didn’t strictly need is free. A missing one isn’t.
Step 4: Limit and control each AI function: Keep chatbot functions, content generation, personalization, CRM processing, and agent actions separately documented and configurable. Apply least-privilege access, separate service accounts, approval before consequential actions, activity logging where lawful, and a tested way to disable access quickly.
Step 5: Re-audit on a defined schedule. This is the step people skip. AI tools update their own behavior: a routine plugin update can quietly add an AI feature, and your CRM can switch on new AI processing with a release note nobody reads.
One reframe before you treat this list as a chore: compliance is a trust signal. A clear “here’s where we use AI and here’s what we do with your data” reads as confidence, not confession. It’s the same trust math as accessibility — which is why we treat it like our ADA compliance work — and it’s what search engines’ E-E-A-T standards and AI answer engines increasingly reward: sites that are the authoritative source about themselves.
Operational Safeguards for Customer-Facing AI
Legal language alone will not prevent an Air Canada-style failure. Pair notices with operational controls:
- Give customers an obvious route to a human and make the alternative accessible by keyboard and assistive technology.
- Define topics the AI is not authorized to answer, such as binding prices, guarantees, refunds, medical advice, or legal conclusions.
- Test responses against current policies before launch and after material updates.
- Provide a correction and incident-escalation process, including an emergency shutoff.
- Review permissions, logs, recurring failures, and vendor changes; do not give an agent broader WordPress access than it needs.
- Apply heightened review to employment, housing, credit, insurance, healthcare, legal, financial, biometric, and child-directed uses.
What Should You Ask Your Vendors?
- Which AI features are enabled for our account, and which are optional?
- What data is sent to each model provider or subprocessor?
- Is our data retained or used to train or improve models, and can that use be disabled?
- Where is the data processed and stored, and for how long?
- How can we delete, export, or correct data?
- What security, audit-log, incident-notification, and access-control features are available?
- How will you notify us before materially changing a model, subprocessor, or data practice?
- What do the contract and data-processing agreement say about responsibility, regulatory assistance, and indemnification?
What Should You Ask Your Lawyer?
Walk in with your AI inventory and these questions, and a one-hour consultation will actually produce answers:
Which AI disclosure laws apply to my business — based on where my customers are, not just where I am? Does my privacy policy accurately cover every tool in my AI inventory and where each one sends data? Do my contracts with vendors (CRM, chat, forms) address AI processing of my customers’ data, and do I need data-processing agreements with any of them? Would my business insurance cover a claim like the Air Canada case if my chatbot or AI content misleads someone? Is my industry one where AI disclosure rules are stricter (health, legal, financial, anything regulated)? If my chatbot gives a customer wrong information, what’s my exposure — and can my terms of service reasonably limit it? And do I meet any of the thresholds where the bigger frameworks — the EU AI Act, California’s automated-decision rules — apply to me directly?
The decision is Canadian and does not bind US courts, but it offers a clear warning: a business may not be able to distance itself from inaccurate information delivered through a chatbot it placed on its own website.
FAQs
In the EU, yes for specific cases: AI text published to inform the public on matters of public interest must be disclosed (human editorial review changes this), and realistic AI images, audio, and video need labels. In the US, there’s no blanket federal rule — but state laws and FTC deception standards are filling the gap fast. The practical answer: if content is AI-generated and a reasonable visitor would care, disclose it.
If EU visitors can use your chatbot: yes, since August 2, 2026, unless it’s already obvious. Several US states require it in specific situations (sales bots in California, consumer interactions in Utah when asked). The disclosure costs you one sentence; the ambiguity can cost you an Air Canada moment. Label the bot.
Say what the AI is, what it does with the visitor’s data, and where a human fits in — in plain English, at the point of interaction, not buried in page 9 of a policy. Example: “You’re chatting with our AI assistant. Conversations are processed by [vendor] to generate answers. It can make mistakes — confirm important details with our team.” Match every statement with a corresponding section in your privacy policy.
Not every AI-assisted marketing image must be labeled under every law. Requirements can change when content qualifies as a deepfake, depicts a real person or event, appears in political or regulated advertising, or otherwise risks deception. Have counsel assess higher-risk uses, and do not make a broad claim that no US law requires a label.
It can. For a business without an EU establishment, GDPR may apply when processing relates to offering goods or services to people in the EU or monitoring their behavior there. Mere accessibility of a US website from Europe does not automatically answer the question. Map the processing and ask counsel to assess territorial scope.
In 2024, British Columbia’s Civil Resolution Tribunal held Air Canada responsible for negligent misrepresentation after its website chatbot supplied inaccurate bereavement-fare information. The Canadian decision is not binding precedent for US courts, but it demonstrates why businesses should control, test, and monitor customer-facing AI.
First, verify that’s actually true: check where your form submissions go, because an AI-powered CRM on the receiving end puts you back in scope. If your site is truly AI-free, you have a marketing opportunity instead of a compliance task — a line in your policy like “We are real people. Every word on this site was written by humans.” is a differentiator more businesses will envy every year.
AI-generated content is not inherently illegal to publish. The legal risk comes from how it’s used: undisclosed where disclosure is required, deceptive about being human, wrong in ways that mislead customers (see: Air Canada), or fed by data pipelines your privacy policy doesn’t cover. Used transparently and reviewed by a human, AI content is just content.
Final Takeaway
Making a website AI-ready is not only about adding a label. It means knowing which tools are active, mapping the data they receive, limiting their permissions, reviewing vendor terms, testing customer-facing outputs, maintaining a human escalation path, and documenting who is responsible. A web team can inventory and configure the technology; qualified counsel should determine which laws apply and approve the legal language.
I can’t tell you what the law requires for your business — that’s your attorney’s job. What I can do is build the document your attorney will ask for first: a dated inventory of every AI-connected tool on your WordPress site, what data it moves, and where it goes. Let’s talk — the conversation is free, and so is the honest answer.
Not sure where AI is already touching your WordPress website?
OlivSEO can perform a technical AI inventory covering plugins, forms, CRM connections, data flows, permissions, and visible disclosures—then organize the findings for review with your attorney.