What Washington Law Requires Before Your Business Turns On an AI Tool
A readiness check for Seattle and Washington businesses: the recording-consent, health-data, breach-notice and regulator rules that apply the moment an AI tool starts listening to calls or holding customer data.
In this guide
Before you switch on an AI tool that records calls, reads customer messages, or stores personal data, Washington law already applies — and three rules decide most first deployments: you need every participant's consent to record a conversation, you need opt-in consent before collecting consumer health data, and you have 30 days to report a breach. Handle them before go-live, not after a complaint.
This guide is for an owner, operations lead, or finance lead at a Seattle or Washington business weighing its first AI tool — an AI notetaker, a voice "receptionist," a chatbot, or a vendor that processes customer records. This is a readiness method, not legal advice; confirm the specifics with your own counsel. The point is to know which questions decide the project before you sign the order form.
Do you need everyone's permission to record a call in Washington?
Yes. Washington is an all-party consent state. RCW 9.73.030 makes it unlawful to record a private conversation or communication "without first obtaining the consent of all the participants." Consent can be a spoken announcement, but only if that announcement is itself recorded as part of the conversation.
See what an AI assessment settles about scope and boundaries before you deploy
This is the rule most first AI deployments trip on, because the common ones listen: AI notetakers and meeting summarizers, AI voice agents that answer the phone, and call-center transcription or quality-scoring tools. To use any of them lawfully in Washington, the tool has to play and capture a recorded notice at the start of every session; a silent background recorder does not meet the rule. The consequences are concrete. A recording made without that consent is inadmissible in any Washington court, and the person recorded can sue for actual damages or liquidated damages of $100 a day up to $1,000, plus attorney fees, under RCW 9.73.060. That changes a buying question into a configuration question: can this vendor turn on a recorded consent prompt, and who owns the greeting and voicemail scripts that carry it?
When does the My Health My Data Act reach a business that isn't a clinic?
Further than most owners expect. Washington's My Health My Data Act defines "consumer health data" broadly in RCW 19.373.010 — conditions, treatments, medications, biometric and genetic data, precise location near health services, and, importantly, data that is derived or inferred from non-health information. A fitness or wellness feature, an intake form that asks about allergies or accommodations, or a model that infers a health condition can all put a non-clinical business inside the Act.
When it applies, the Act requires opt-in consent before you collect consumer health data, a separate written authorization before you sell it, a prominent privacy policy, and no geofencing around health care facilities, as the Washington Attorney General summarizes. Being small does not exempt you; it only moved your deadline. Regulated entities had to comply by March 31, 2024 and small businesses by June 30, 2024, and a "small business" here still handles consumer health data of up to 100,000 consumers a year. Two scope points change the answer in practice: data about your own staff acting in an employment context is not "consumer" data under this Act, and a violation is a per se violation of the state Consumer Protection Act — enforceable by the Attorney General and through a private lawsuit.
What happens if the AI vendor has a breach?
You notify — not the vendor. Under Washington's data-breach law, RCW 19.255.010, a business that owns the data must tell affected Washington residents without unreasonable delay and no more than 30 days after discovering a breach, and must also notify the Attorney General within 30 days whenever more than 500 residents are affected. Sending customer records to a new AI vendor does not move that clock to the vendor; it is still your name on the notice.
So the vendor contract is where this gets handled before go-live, not after an incident. Require the vendor to tell you promptly when it suspects a breach, so you can meet the 30-day clock. Send the fewest fields the tool actually needs, because data you never transmitted cannot leak from the vendor. And write down what customer data leaves your systems, so a later incident has a known scope instead of a guess.
Does your industry's regulator already have rules for AI?
Often, yes, and they survive the switch to AI. Washington's insurance regulator issued Technical Assistance Advisory 2024-02, adopting the national model bulletin, which reminds insurers that consumer-affecting decisions "made or supported by" AI systems must still follow insurance law — including the rules against unfair discrimination — and expects a documented AI governance program the office can request during an investigation or examination (Office of the Insurance Commissioner). Insurers can read the detail on the insurance operations page, but the principle generalizes to every regulated field: a decision your regulator governs — pricing, underwriting, credit, eligibility, licensed advice — is still your regulated decision when a model helps make it.
One more framing point. Washington has no single comprehensive consumer-privacy statute like the ones several other states passed; instead these specific rules apply, which is why privacy analysts treat My Health My Data as sector-specific but broad in practice. A vendor's generic "we comply with California's law" answer does not settle the Washington question.
A four-question check before you switch it on
Here is a decision method you can run in one short meeting before any AI tool goes live. It is a readiness checklist, not a compliance certification, and it points to the rule and the owner rather than giving a legal opinion on your facts.
| Ask this about the tool | If yes, the Washington rule in play | What to verify before go-live | Who owns it |
|---|---|---|---|
| Does it record, transcribe, or listen to live conversations (calls, meetings, voicemail)? | All-party consent to record (RCW 9.73.030); a spoken notice counts only if the notice is itself recorded | The vendor can play and log a recorded consent notice every session; greetings and voicemail are updated | Whoever owns the phone or meeting system |
| Could it collect or infer anything about health — conditions, medications, biometrics, or location near a health facility — even from non-health data? | My Health My Data Act: opt-in consent to collect, written authorization to sell, posted privacy policy | Whether any field or inference is consumer health data; a consent step before collection; no sale or sharing without authorization | Whoever owns the customer record and privacy policy |
| Will you send customers' personal information to a new vendor to process or store? | Breach notification (RCW 19.255.010): 30 days to notify residents and the Attorney General; the AG when over 500 residents are affected | The contract requires prompt breach notice to you; the fields you actually send are minimized and written down | Finance or IT, and whoever signs the contract |
| Will it help make a decision a regulator governs (pricing, underwriting, credit, eligibility, licensed advice)? | Your regulator's rules still apply — for insurers, the OIC advisory and its unfair-discrimination rules | A named human owner for the decision; documentation of how the model is used and tested; your regulator's current guidance | The compliance owner for that decision |
Worked example (hypothetical): a Seattle accounting firm turns on an AI meeting assistant that records and summarizes client calls. Row one applies at once — the firm configures the tool to play and record a consent notice on every call and updates its voicemail greeting. Row two is unlikely but worth a check: ordinary tax and bookkeeping facts are not consumer health data, though a client's medical-expense detail could be, so the firm notes that its summaries should not capture it. Row three applies because call audio and transcripts now sit with a vendor, so the engagement partner confirms the contract's breach-notice terms and limits what syncs. Row four is a reminder that the CPA's professional-responsibility duties do not transfer to the model. The whole review takes a meeting, and it happens before the tool is live.
Quick answers
Is Washington a one-party or all-party consent state for recording?
All-party. Under RCW 9.73.030 everyone in a private conversation must consent before it is recorded, and a spoken notice only counts if the notice itself is recorded.
Does the My Health My Data Act apply to businesses that aren't health care providers?
It can. The Act defines consumer health data broadly, including data inferred from non-health information, so a non-clinical business that collects or infers health details can fall under it.
How fast must we report a breach at an AI vendor?
Within 30 days of discovering it, you must notify affected Washington residents and, when more than 500 residents are affected, the Attorney General. Using a vendor does not shift that duty to the vendor.
Does handing a decision to AI move the legal responsibility to the software?
No. A regulated decision stays your responsibility; Washington's insurance regulator, for one, expects insurers to document and stand behind AI-supported decisions.
Sources
- RCW 9.73.030 · app.leg.wa.gov
- inadmissible in any Washington court · app.leg.wa.gov
- RCW 9.73.060 · app.leg.wa.gov
- RCW 19.373.010 · app.leg.wa.gov
- Washington Attorney General · atg.wa.gov
- RCW 19.255.010 · app.leg.wa.gov
- Office of the Insurance Commissioner · insurance.wa.gov
- why privacy analysts treat My Health My Data as sector-specific but broad in practice · iapp.org
How we research and review these guides
Put the ideas to work in your business.
We provide AI consulting and implementation. Bring us the process that is slowing your team down and the systems involved. We can assess the problem with you and discuss a practical implementation.
Discuss your project →Still exploring? Read the AI transformation decision guide →