Hermes AI LabsHERMESAI LABSBook a call
Trust & Compliance6 min read

AI Voice Agents & the Law: Recording Consent, GDPR, HIPAA & the EU AI Act for Spas (2026)

The Hermes AI Labs Team

Running an AI receptionist legally comes down to three things: tell callers they're speaking with an AI, get proper consent to record, and protect the data you capture. The specifics vary by country and — in the US — by state, but the safe default everywhere is the same: disclose the AI and the recording at the very start of every call, and handle caller data under a clear, consented purpose.

Key takeaways

  • Three rules govern an AI receptionist: disclose the AI, consent to record, and protect the data.
  • The EU AI Act (from 2 August 2026) requires any voice AI to tell people they're talking to a machine at the first interaction — fines reach €15M or 3% of global revenue.
  • In the US, two-party-consent states require recording disclosure, and California's AB 2905 mandates AI-voice disclosure with a $500-per-call penalty.
  • Injectable and laser med spas are usually HIPAA-covered entities, so any vendor touching call data should sign a Business Associate Agreement (BAA).
  • The universal safe default: a short spoken disclosure at the start of every call ('You're speaking with an AI assistant, and this call may be recorded'), plus consented, purpose-limited data handling.
On this page

The single biggest reason a spa owner hesitates on an AI receptionist isn't the price or the technology — it's a quieter worry: is this even allowed? You're putting an AI on your phone line, recording calls, and capturing clients' names, numbers, and treatment interests. That's a reasonable thing to get right before you flip it on.

The good news is that compliance here is very manageable, and it comes down to three plain ideas: disclose the AI, consent to record, and protect the data. Below is how each works across the markets a spa is most likely to operate in — the US, UK, Canada, Australia, France, and Switzerland.

Not legal advice. This is a practical overview for spa owners, current as of 2026. Laws change and specifics vary by jurisdiction and business; confirm your own obligations with a qualified advisor before going live.

Rule 1 — Disclose that it's an AI

This is the newest and fastest-moving area, and 2026 is the year it became law in the EU.

European Union (and anyone serving EU clients). From 2 August 2026, the EU AI Act's Article 50 requires that any AI system built to interact with people — chatbots and voice assistants included — makes clear the person is dealing with a machine, no later than the first interaction. It has to be easy to notice. Penalties for ignoring it reach up to €15 million or 3% of global turnover. For a clinic in France, or one in Switzerland serving EU clients, this is now the baseline.

United States. California's AB 2905 (effective 2025) requires disclosure when an AI or artificial voice is used on a call, with a $500-per-call penalty for non-compliance, and the FCC has moved toward mandatory AI disclosure at the start of AI-generated calls. Expect more states to follow.

Everywhere else, disclosure isn't always legally mandated yet — but it is unambiguously best practice, and it's good business. A simple, warm line at the top of the call ("Hi, you've reached [Clinic], I'm the AI assistant — how can I help?") removes the "I was tricked by a robot" risk entirely and, in our experience, callers simply feel like they reached a helpful front desk that answered right away.

Recording calls is where the oldest and most location-specific rules live.

United States: one-party vs two-party consent. Most states are "one-party" (one person on the call — you — can consent). But a set of two-party (all-party) consent states require everyone on the call to agree to recording, including California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, Vermont, and Washington. In those states your AI must disclose the recording before any substantive conversation. Because callers can be anywhere, the clean policy is: disclose the recording on every call, regardless of location.

United Kingdom & EU. Recording is governed by GDPR (and PECR in the UK). You need a lawful basis and a clear, up-front notice of the recording and its purpose.

Canada (PIPEDA). You must inform the customer you're recording, state the purpose, and obtain consent — which can be implied if they continue the call knowing it's recorded and why. Quebec's Law 25 adds further requirements.

Australia. Recording is regulated by a patchwork of federal and state surveillance-devices laws; disclosure and consent are the safe course.

Switzerland. Recording personal conversations without consent can engage both data-protection and criminal provisions; disclose and obtain consent.

The through-line: a short spoken recording disclosure at the very start of the call satisfies the strictest of these regimes and keeps you safe everywhere.

Rule 3 — Protect the data you capture

An AI receptionist collects personal data — names, numbers, and often treatment interests, which can be health data. That triggers data-protection duties.

HIPAA (US med spas specifically). This one catches a lot of owners off guard: a med spa becomes a HIPAA-covered entity when it provides healthcare services such as injectables or laser and handles protected health informationeven if you're cash-pay. HIPAA applies to how you handle the information, not how you get paid. The practical consequence for an AI receptionist: any vendor that handles PHI on your behalf must sign a Business Associate Agreement (BAA) and apply appropriate safeguards. If a vendor won't sign a BAA, that's your answer.

GDPR (UK/EU), nFADP (Switzerland), PIPEDA (Canada), Privacy Act (Australia). All require broadly the same discipline: a lawful basis and clear purpose for the data, data minimisation (collect only what the booking needs), sensible retention (don't keep recordings forever), security (encryption, access control), and the ability to honour data-subject rights (access, correction, deletion). Switzerland's nFADP has been in force since 1 September 2023 and is closely aligned with GDPR, so if you meet GDPR you're most of the way there for Suisse-romande clinics.

Treatment interest counts as sensitive information in most of these regimes, so treat call data with the same care as a client's chart.

The universal safe-default checklist

You don't need to memorise every statute. If you do these, you're in good shape across all six markets:

  • Disclose the AI at the first interaction ("You're speaking with an AI assistant").
  • Disclose recording before any substantive conversation, on every call.
  • Collect only what the booking requires, and say what it's for.
  • Set a sensible retention period and delete on schedule.
  • Secure the data (encryption in transit and at rest, restricted access).
  • Sign a BAA with your vendor if you're a HIPAA-covered med spa.
  • Be able to honour deletion/access requests (GDPR/nFADP/PIPEDA/Privacy Act).
  • Keep a human escalation path for clinical questions, complaints, and emergencies.
  • Don't let the AI improvise on medical or legal specifics — scope it, and hand those to a person.

What to ask any AI-receptionist vendor

Turn the checklist into purchase questions:

  1. How does the agent disclose that it's an AI, and can we word it ourselves?
  2. How and when does it disclose call recording?
  3. Where is call data stored, how is it secured, and how long is it retained?
  4. Will you sign a BAA? (If you're a HIPAA-covered med spa and they say no, walk away.)
  5. Can we honour a client's data-deletion request end to end?
  6. What happens on a call it shouldn't handle — does it escalate to a human?

A vendor who answers these crisply is one who has built for clinics, not just for demos. A vendor who gets cagey is telling you something.

Why this is actually a selling point

Here's the reframe: compliance isn't a tax on running an AI receptionist — it's part of why it beats the alternatives. A voicemail box has no disclosure and no consent trail. A rushed front desk scribbling a card number on a sticky note is a bigger data risk than an encrypted, access-controlled system with a defined retention policy. Done right, an AI agent is often the most compliant way your phone has ever been answered — and being able to tell a nervous first-time client "yes, this is handled properly and privately" is a trust advantage, not a burden.

At Hermes AI Labs we build the disclosure, consent, and data handling in from the first call — because on a client relationship worth thousands over its lifetime, getting the trust layer right is the whole point. If you want to see exactly how we'd configure it for your clinic and your jurisdiction, book a 15-minute call and we'll walk through it.

Frequently asked questions

Do I have to tell callers they're talking to an AI?

Increasingly, yes. From 2 August 2026 the EU AI Act requires any chatbot or voice assistant to disclose it's a machine at the first interaction. In the US, California's AB 2905 requires AI-voice disclosure, and the FCC has moved toward mandatory disclosure on AI calls. Even where it isn't strictly required yet, disclosing is best practice and builds trust.

Is an AI answering service HIPAA compliant?

It can be, but compliance is about how the service is configured, not a label. If your med spa is a HIPAA-covered entity (most injectable and laser practices are), any vendor that handles protected health information on your behalf should sign a Business Associate Agreement (BAA) and apply the required safeguards. Ask a vendor directly whether they'll sign a BAA.

What are two-party consent states?

They're US states where all parties on a call must consent to it being recorded — including California, Florida, Illinois, Washington, Pennsylvania, and others. In those states your AI must disclose the recording before any substantive conversation. The simplest policy is to disclose on every call regardless of the caller's location.

Does GDPR apply to my clinic's recorded calls?

If you operate in the UK or EU (or handle EU residents' data), yes. A recorded call containing a caller's name, number, and treatment interest is personal data, so you need a lawful basis, a clear purpose, appropriate retention, and the ability to honour data-subject rights. Switzerland's nFADP and Canada's PIPEDA impose similar duties.

Keep reading