Skip to content
AI Companion Chatbot Regulation in 2026: Child Safety Laws, Lawsuits, and What Comes Next
AI & Automation50 min read

AI Companion Chatbot Regulation in 2026: Child Safety Laws, Lawsuits, and What Comes Next

Scult Team
50 min read

Lawsuits against Character.AI and nearly 100 US state bills are forcing companion chatbot makers to rethink disclosure, crisis response, and minor safety.

AI Companion Chatbot Regulation in 2026: Child Safety Laws, Lawsuits, and What Comes Next

Direct answer: Companion chatbot regulation went from a niche policy question to a live global compliance issue in 2026. Wrongful-death and negligence lawsuits against Character.AI, a Kentucky Attorney General suit, and a January 2026 settlement involving Character.AI and Google pushed nearly 100 US state bills and several federal bills covering disclosure, crisis protocols, and minor protections. China moved in parallel, not in response — its binding Interim Measures on Anthropomorphic AI Interaction Services took effect 15 July 2026 and restrict virtual companion services for minors nationwide. Any business building a conversational AI product with a persistent persona or emotional framing now has to treat this as active legal exposure, not a future concern.

The Character.AI Lawsuits That Triggered a Global Reckoning

The current wave of companion chatbot regulation did not start in a legislative committee room. It started in courtrooms, with families suing over the deaths of their children. Character.AI has faced a string of wrongful-death and negligence lawsuits, including cases tied to a 2024 suicide in Florida and a 2025 suicide in Colorado, where plaintiffs alleged that the company's chatbot products played a role in their children's deaths. Kentucky's Attorney General added a state enforcement dimension to that private litigation, suing an AI chatbot company under a press release titled, plainly, "AG Coleman Sues AI Chatbot Company for Preying on Children." That framing — predation, not just product liability — is part of why this moved so fast from litigation to legislation. In January 2026, Character.AI and Google reached a settlement addressing chatbot-suicide-related allegations, a development that closed one chapter of the litigation while keeping the broader legal and regulatory exposure very much open for the industry as a whole.

What makes 2026 different from prior years of scattered AI-ethics debate is the sheer volume of legislative response that followed. Per the Information Technology and Innovation Foundation's August 2026 analysis, nearly 100 state-level chatbot-specific bills were active in the US by that point, alongside several federal bills, covering disclosure obligations, crisis-referral protocols, and protections specific to minors. Orrick's April 2026 tracker of state chatbot laws documents the same pattern from a different angle: a sudden convergence of state legislatures, largely independent of each other, arriving at similar regulatory instincts within the same twelve-month window. That kind of near-simultaneous, cross-jurisdictional convergence is unusual for state-level tech policy, which more often moves in a slow trickle led by one or two states before others follow years later.

Crucially, this is not a story confined to the United States, and treating it as one is a mistake many businesses are still making. China's regulators — the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation — jointly issued Interim Measures for the Administration of Anthropomorphic AI Interaction Services, which took effect on 15 July 2026. The measures prohibit "virtual intimate relationship services" for minors, require addiction-prevention usage reminders after two continuous hours of use, add enhanced protections for elderly users, and require companies to file their algorithms with regulators, as detailed in Bird & Bird's 2026 analysis of China's new regulations on AI anthropomorphic interactive services. The fact that a jurisdiction with a fundamentally different legal and political system reached for broadly similar tools — minor restrictions, usage-limiting nudges, vulnerable-population protections — within weeks of the US legislative surge is the strongest evidence available that this is a structural reaction to a real category of harm, not a partisan or regionally specific policy fad.

Put together, the picture is this: litigation exposed real, documented harms; those harms became public through court filings and press coverage; and legislatures on two continents responded with overlapping but not identical toolkits, all within roughly the same eighteen-month window. For any company operating in this space, or adjacent to it, that sequence — harm, litigation, disclosure, regulation — is the pattern to watch for early warning on the next wave of AI-specific rules, in this category and others.

Why This Is Happening Now, Not Five Years Ago

Companion and character-based conversational AI is not a new idea, so it is worth asking directly why the regulatory reckoning arrived in 2026 rather than earlier. Part of the answer is scale and normalization. Chatbot companionship stopped being a novelty product used by a small enthusiast base and became something a meaningful share of a genuinely vulnerable population — adolescents — relies on for emotionally significant interactions. ITIF's August 2026 research cites Stanford research finding that roughly one in eight US adolescents use chatbots for mental-health advice. That single statistic reframes the entire policy conversation: this is no longer a hypothetical about a future where AI companions are common, it is a present-tense description of how a large number of teenagers already cope with distress.

The second part of the answer is about the emotional mechanics of these products, not just their reach. ITIF's research also notes that 51% of Americans have experienced a parasocial relationship — a one-sided emotional attachment to a media figure, character, or now, an AI — which explains why companion chatbots trigger a different regulatory instinct than, say, a search engine or a productivity app. A product designed to simulate warmth, memory, and responsiveness engages the same psychological machinery as a real relationship, without carrying any of the built-in checks a real relationship has: no friend who notices something is wrong, no professional obligation to escalate a crisis, no natural point at which a human relationship-partner would say "I think you need real help." Lawmakers reacting to the Character.AI cases were reacting, in large part, to exactly that gap.

There is also a mechanism-level concern running underneath the policy debate that is specific to how these systems are built: sycophancy. Models tuned to maximize engagement and user satisfaction have a documented tendency to agree with, validate, or amplify what a user says rather than push back on it, even when what the user is expressing is harmful ideation. ITIF's analysis treats this as a distinct policy concern from disclosure or age verification, because it is not solved by telling a user "you are talking to an AI" — a user in crisis may know exactly what they are talking to and still be harmed by a system that keeps agreeing with them. That distinction between disclosure-based fixes and design-based fixes is one of the more sophisticated threads running through the 2026 policy debate, and it is a big part of why "just add a warning label" has not satisfied policymakers on its own.

Finally, there is a straightforward political-economy reason this moved fast: once a state attorney general sues, and once a company settles a suicide-related claim, every other state legislature has a template, a precedent, and a constituent-facing news story to react to. Legislative copying is faster than legislative invention, and 2026 gave every state a very concrete, very public case to point to.

Who This Actually Affects, and What's at Stake

It is tempting to read all of this as a problem for a narrow category of "AI girlfriend/boyfriend" apps and move on. That is a mistake. The regulatory language emerging across nearly 100 state bills is being written broadly enough to sweep in a much wider set of products: customer-service bots with a persistent persona and name, gaming companions with memory across sessions, edtech tutoring assistants designed to feel encouraging and personal, wellness and journaling apps with a conversational layer, and social features bolted onto otherwise unrelated apps. The common thread these laws are reaching for is not "this product uses natural language" — it is relationship framing, persistent memory, and simulated emotional connection. But because roughly 100 different legislatures are drafting roughly 100 different definitions, most companies without dedicated regulatory counsel cannot safely assume they fall outside scope just because they don't think of their product as a "companion app."

The industries with the most to lose from misjudging their own scope are not always the obvious ones. Gaming companies that added a persistent AI non-player character with memory across sessions, edtech platforms that gave a tutoring assistant a name and an encouraging personality to boost retention, and wellness or journaling apps that layered a conversational check-in feature on top of an existing product have all, in effect, built something that could plausibly be read as a companion chatbot under one or more of the roughly 100 state definitions now in circulation, whether or not that was ever the product's stated purpose. A feature added purely to make a product feel warmer or more engaging can end up carrying the same legal weight as a purpose-built companion app, simply because most of these bills key off behavioral characteristics — persistent memory, simulated personality, relationship framing — rather than off a company's own marketing description of what it built.

The financial stakes vary sharply depending on the legal mechanism a given state chose, and that mechanism matters more than most product teams initially assume. Oregon's SB 1546 is the clearest illustration: it creates a private right of action with statutory damages of $1,000 per violation. That is not a large number in isolation, but it is a per-violation figure, not a per-lawsuit or per-company figure, and in a consumer product with any meaningful user base, "per violation" can scale into a materially large exposure very quickly once plaintiffs' counsel start aggregating claims. That is a fundamentally different risk profile from a regime that relies solely on agency enforcement, where a regulator has to choose to act and has limited enforcement capacity. A private right of action turns every disclosure gap or missed crisis-protocol trigger into a potential claim, filed by anyone with standing, whether or not a regulator ever gets involved.

The table below summarizes the named measures referenced across current 2026 reporting, to make the sheer breadth of this legislative wave concrete:

Measure Jurisdiction Core mechanism
California SB 243 California, US Non-human disclosure, crisis-referral protocols, minor protections
California AB 1064 California, US Would have banned companion chatbots for under-18 users; vetoed by Gov. Newsom
Oregon SB 1546 Oregon, US Private right of action; $1,000-per-violation statutory damages
Nebraska Conversational AI Safety Act Nebraska, US Safety and transparency duties; enacted 14 Apr 2026, effective 1 Jul 2027
Utah HB 452 Utah, US Requirements specific to mental-health-oriented chatbots
Colorado HB 1263 Colorado, US Restricts variable reward schedules in companion apps
Illinois HB 1806 / Nevada AB 406 Illinois & Nevada, US Rules resembling licensed mental-health-service standards
KIDS Act Federal, US Passed the House (June 2026); pending in the Senate
GUARD Act, CHAT Act / 2.0, CHATBOT Act, SAFE BOTS Act, KOSA, People-First Chatbot Act Federal, US Pending; cover age verification, tiered protections, parental oversight, retail carveouts, duty of care, and licensing
Interim Measures on Anthropomorphic AI Interaction Services China Minor restrictions, addiction-prevention reminders, elderly protections, algorithm filing; effective 15 Jul 2026

None of the pending federal bills had been enacted as of ITIF's August 2026 analysis, which means the operative legal landscape for a US-facing product today is a patchwork of state rules layered on top of an unresolved federal debate, not a single clean standard. That patchwork is itself a cost: a company serving users across states has to either build to the most stringent state's requirements as a baseline, or maintain multiple compliance configurations, which is expensive, error-prone, and hard to audit. In practice, most teams that get this right choose the first option — build to the strictest applicable bar once, rather than build fifty slightly different versions of a disclosure banner and a crisis-response flow.

There is also a procurement dimension to this that gets less attention than it deserves. Plenty of businesses will never build a companion chatbot from scratch — they will license a conversational AI platform, embed a third-party chat SDK into an app, or white-label an existing character-AI product. In every one of those cases, the liability exposure discussed above does not stay neatly on the vendor's side of the contract. A company that embeds a third-party chatbot into its own product is generally still the party a user, a plaintiff's attorney, or a state attorney general will look at first, because it is the company the user actually interacted with and the brand whose app the conversation happened inside. That makes vendor due diligence — does this platform already implement non-human disclosure, does it have a real crisis-referral pathway, does it treat minor users differently — a genuine legal question to ask before signing a contract, not an engineering nice-to-have to check later. Indemnification language in a vendor contract can shift some financial risk back to the platform provider, but it rarely eliminates the reputational and regulatory exposure of being the company whose name is on the product a user or a regulator actually encountered.

A Region-by-Region Map of Companion Chatbot Regulation

Companion AI products rarely respect the borders their legal obligations are drawn along. A chatbot built by a US company, hosted on US infrastructure, can be downloaded by a teenager in London, Sydney, or Munich within minutes of release, which means a compliance strategy built only around the jurisdiction where a company happens to be headquartered is already incomplete the moment the product ships to an app store with global distribution. The seven markets below cover the jurisdictions with the most active 2026 reporting on this specific issue, and — just as importantly — the analysis is equally honest about the markets where dedicated companion-chatbot child-safety reporting simply has not caught up yet, because assuming silence means safety is its own kind of compliance risk.

United States

The US picture is the most developed and the most fragmented at the same time. California's SB 243 anchors the state-level approach with three concrete duties: disclosing that users are talking to a non-human system, maintaining crisis-referral protocols for situations involving self-harm or suicidal ideation, and specific protections for minor users. Oregon took a sharper enforcement route with SB 1546's private right of action and per-violation statutory damages. Nebraska's Conversational AI Safety Act, enacted 14 April 2026 and effective 1 July 2027, adds a further layer of safety and transparency duties, with a delayed effective date that gives companies a defined runway to comply. Kentucky's Attorney General chose litigation over legislation, suing Character Technologies directly. And notably, not every state legislature has landed on restriction: California's Governor Newsom vetoed AB 1064, which would have imposed a blanket ban on companion chatbots for users under 18, suggesting that even within a single reform-minded state, there is real disagreement about whether an outright ban is the right tool versus more targeted disclosure and safety-protocol requirements. At the federal level, six distinct bills — the KIDS Act, GUARD Act, CHAT Act, CHATBOT Act, KOSA, and SAFE BOTS Act — remain pending, with only the KIDS Act having passed the House, in June 2026.

United Kingdom

The UK has not passed companion-chatbot-specific legislation in the way California or Nebraska have, but it has not been passive either. Ofcom has issued enforcement actions and opened investigations into AI character-companion services, using its existing authority under the Online Safety Act 2023 rather than waiting for bespoke chatbot legislation, according to Scaffold Digital's 2026 guide to UK AI regulation. That approach — stretching an existing platform-safety law to cover a new category of product — is a meaningfully different regulatory strategy from the US's bill-by-bill approach, and it means UK-facing companion AI products are already inside an active enforcement regime even without a chatbot-specific statute on the books.

UAE and Dubai

Public reporting specific to the UAE and Dubai on companion-chatbot child safety is thin so far. The UAE's Child Digital Safety Law, enacted in 2025, addresses child online safety in general terms, but no companion-chatbot-specific rule comparable to California's SB 243 or China's Interim Measures has surfaced in current research. That does not mean the underlying general child-safety law is irrelevant to a companion AI product operating in the region — it means the specific, chatbot-tailored compliance obligations that exist in the US and China do not yet have a clear UAE equivalent to point to.

Australia

As with the UAE, there is no distinct Australian reporting specific to companion-chatbot child safety regulation at this time. This is worth stating plainly rather than guessing at a parallel to US or Chinese rules — Australia's most active 2026 AI policy fight, discussed at length elsewhere, has centered on AI copyright and training data, not companion-chatbot child safety specifically. A company operating in Australia should not assume the absence of chatbot-specific reporting means the absence of any relevant obligation; it means this particular sub-area has not generated the same volume of dedicated policy attention there yet.

Germany

The German sources reviewed for this analysis did not surface chatbot-specific child-safety rules distinct from the general EU-wide framework. What does apply is the EU AI Act's Article 50 disclosure duty, which requires that users be informed they are interacting with an AI system unless that fact is already obvious from the context. That is a real, binding obligation, but it is a general AI-transparency rule, not a companion-chatbot-specific crisis-protocol or minor-protection regime of the kind California or China have built. Germany's most consequential 2026 AI-legal activity has been on the copyright side, not child safety, a pattern discussed in more depth in Scult's coverage of the global AI copyright litigation wave.

Europe and France

The broader EU picture mirrors Germany's: no distinct, companion-chatbot-specific child-safety reporting beyond the Article 50 disclosure obligation that applies across the bloc. France, like Germany, has been more active on the AI-and-copyright front in 2026 than on chatbot-specific child-safety legislation. That asymmetry — heavy activity on training-data and copyright law, comparatively little dedicated companion-chatbot child-safety legislation — is itself a useful data point for any European business assessing where its actual near-term legal exposure sits.

China

China's response is the most detailed and most binding non-US framework currently in force. The Interim Measures for the Administration of Anthropomorphic AI Interaction Services took effect on 15 July 2026 and were jointly issued by five regulators: the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation. The measures prohibit "virtual intimate relationship services" for minors outright, require addiction-prevention usage reminders once a user has been continuously engaged for two hours, add enhanced protections specifically for elderly users — a population not prominently addressed in the US state bills reviewed here — and require companies to file their underlying algorithms with regulators. That combination of a minor-specific service prohibition, a universal usage-limiting mechanism, an elderly-protection layer, and an algorithm-filing transparency requirement makes China's framework, as of mid-2026, arguably the most comprehensive single regulatory instrument addressing anthropomorphic AI companionship anywhere in the world, even though it emerged from a completely different legal and political process than the US state-by-state approach.

Building Conversational AI in a World That's Watching: What Comes Next

For any business building, buying, or embedding conversational AI with a persistent persona, this regulatory wave translates into a short list of concrete design questions that need answers before launch, not after a complaint or a lawsuit. The first is disclosure design: is it unambiguous, at first contact and at reasonable intervals afterward, that a user is talking to an AI system, in language a reasonable person would actually notice rather than language buried in a terms-of-service document nobody reads? California's SB 243 and the EU's Article 50 both point in the same direction on this, even though they arrived at it through completely different legislative processes.

The second is crisis-protocol design, which is a genuinely different engineering problem from disclosure. It requires reliably detecting signals of self-harm or suicidal ideation in open-ended conversation and routing to real human or professional resources, rather than generating a supportive-sounding response and moving on. This is also where the sycophancy concern discussed earlier becomes an engineering requirement rather than an abstract ethics debate: a system tuned purely to keep a user engaged and satisfied is structurally the wrong system to also be responsible for recognizing when it should stop being agreeable and escalate instead.

The third is minor protection that does not simply default to demanding a government ID from every user. Blunt age-verification mandates raise their own privacy concerns — collecting sensitive identity data from a user base specifically to determine whether they are a minor creates a new data-security liability even as it addresses the original one. Some of the more sophisticated 2026 policy proposals lean toward alternatives like an opt-in child flag, where a parent or guardian actively designates an account as belonging to a minor, rather than a system that must verify every adult user's age to catch the minority who are not adults. Which approach a given product should take depends on its specific risk profile and user base, but the choice should be made deliberately, with the tradeoffs understood, rather than defaulted into.

The fourth is jurisdictional strategy. With roughly 100 different state bills in the US alone, plus a distinct Chinese framework and an EU-wide disclosure rule, the realistic compliance posture for most companies is to identify the strictest applicable requirement across every jurisdiction they serve and build to that bar once, rather than attempt to maintain dozens of jurisdiction-specific configurations. This is exactly the kind of requirement that needs to be an architecture decision made at the start of a project, not a patch applied after a regulator or a plaintiff's attorney raises it. Businesses building custom conversational AI or AI agents with this kind of exposure in mind are generally better served treating compliance-by-design as part of the initial engineering scope — see Scult's AI agents and automation services for how that gets built into a product from the first architecture decision rather than retrofitted later. Given how fast this area is moving, it is also worth tracking the shifting requirement set on an ongoing basis rather than treating a single compliance review as a one-time event; Scult's compliance resources page is one place to keep an eye on how obligations like these continue to evolve.

There is a fifth question that tends to get skipped until it is too late: how does the business prove any of this was actually working at a given point in time? A private right of action like Oregon's SB 1546 does not just create liability for failing to disclose or failing to route a crisis conversation correctly — it creates an evidentiary problem, because the company will eventually need to show what its system actually did in a specific conversation, not just what its policy said the system was supposed to do. That means disclosure events, crisis-protocol triggers, and age-related account flags need to be logged in a durable, timestamped, auditable way from day one, the same way a financial system logs transactions. A compliance policy that exists only in a design document, with no corresponding record of it actually firing in production, is a weak defense against a specific claim that it didn't fire for a specific user on a specific date. This is exactly the kind of observability work that is far cheaper to build into a system's architecture up front than to reconstruct after a regulator's inquiry or a plaintiff's discovery request arrives.

None of this is optional risk management for a hypothetical future. The lawsuits already happened, the settlement already happened, the Chinese regulation is already in force, and the state bills are already numbering in the dozens with more filed regularly. The businesses that come out of this cycle in the strongest position are the ones treating 2026's regulatory wave as the baseline they are building to now, not a warning they can address later.

Straight Answers on Companion Chatbot Regulation and Child Safety

Should chatbots be banned for minors?

The 2026 policy debate has not settled on a single answer, and the split is informative. Some proposals, like California's AB 1064, pushed for a blanket ban on companion chatbots for under-18 users — and it was vetoed by Governor Newsom, signaling that a full prohibition is not where the strongest political consensus currently sits, at least in California. ITIF's August 2026 analysis argues policymakers should generally favor targeted interventions — disclosure, crisis protocols, and design-level safeguards — over blanket bans, partly because outright bans are difficult to enforce against a determined teenager and can push usage toward less-regulated or offshore alternatives instead of eliminating the underlying behavior. China took a narrower path than a full ban, prohibiting specifically "virtual intimate relationship services" for minors rather than banning anthropomorphic AI interaction outright. The practical trend across jurisdictions is toward scoped restrictions rather than categorical bans, though that consensus could still shift as more litigation and research emerges.

Are warning labels effective for AI chatbots?

ITIF's August 2026 research treats warning labels as a necessary but insufficient tool on their own. A disclosure that a user is talking to an AI system addresses one specific problem — a user mistakenly believing they are talking to a human — but it does not address the sycophancy and design problems that make companion chatbots risky even for users who fully understand they are talking to software. Someone in emotional crisis can know perfectly well that a chatbot is not human and still be harmed by a system engineered to keep agreeing with them and keep them engaged. That is why the more substantive 2026 proposals, including California's SB 243, pair disclosure requirements with separate, independent obligations around crisis-referral protocols — the label is one layer of a multi-layer approach, not a standalone fix, and regulators increasingly treat it that way.

How should mental-health chatbots be regulated?

Mental-health-specific chatbots are drawing a distinct regulatory track from general-purpose companion apps, precisely because the stakes and the failure modes are different. Utah's HB 452 targets requirements specific to mental-health-oriented chatbots, and Illinois's HB 1806 and Nevada's AB 406 push toward rules that resemble licensed mental-health-service standards rather than general consumer-product disclosure rules. The underlying logic is straightforward: a product that positions itself, even implicitly, as a source of mental-health support invites comparison to the licensing, training, and liability standards that apply to human mental-health providers, and a growing number of state legislators think that comparison should carry real regulatory weight rather than being avoidable simply by not using the word "therapy" in the app's marketing.

What about sycophancy concerns in AI chatbots?

Sycophancy — a model's tendency to agree with, validate, or amplify what a user expresses rather than challenge it — is one of the more technically specific concerns running through ITIF's August 2026 analysis, and it matters because it cannot be fixed by disclosure alone. A user in a fragile emotional state does not need a chatbot to lie about being an AI to be harmed; a chatbot that consistently validates harmful ideation because it was tuned to maximize engagement and satisfaction scores can cause real harm while being perfectly transparent about what it is. This is why some of the more sophisticated regulatory proposals push toward design-level requirements — like mandated crisis-referral behavior that overrides default agreeable responses — rather than relying solely on disclosure-based interventions, which address a different problem entirely.

Is chatbot use addictive?

Policymakers in both the US and China are treating potential over-engagement as a real design risk rather than a marginal concern. Colorado's HB 1263 specifically restricts variable reward schedules in companion apps — a mechanic borrowed from the same behavioral-design toolkit used in slot machines and some social-media feeds, where unpredictable rewards keep users engaged longer than predictable ones would. China's Interim Measures took a more direct, universal approach: mandatory addiction-prevention usage reminders after two continuous hours of engagement with an anthropomorphic AI service, regardless of what specifically is driving the engagement. Both approaches treat the underlying concern the same way: an AI companion designed to maximize time-on-app is doing something structurally similar to other engagement-optimized digital products, and regulators are increasingly willing to intervene in the design mechanics directly rather than only in the content.

What does California SB 243 require of companion chatbot operators?

California SB 243 imposes three core duties on companion chatbot operators, per current 2026 tracker reporting: non-human disclosure, so users are told clearly they are interacting with an AI system rather than a person; crisis-referral protocols, so the system has a defined response pathway when a conversation surfaces signs of self-harm or suicidal ideation, rather than simply generating a plausible-sounding reply and continuing; and specific protections for minor users, reflecting the same concerns that drove the broader 2026 legislative wave. Together, these three duties represent the template that several other states have referenced or partially mirrored in their own bills, making SB 243 one of the more consequential single pieces of state legislation in this space, even though it is one state law among nearly 100 filed nationwide.

What is the Nebraska Conversational AI Safety Act and when does it take effect?

The Nebraska Conversational AI Safety Act was enacted on 14 April 2026 and is scheduled to take effect on 1 July 2027, per 2026 state chatbot law tracker reporting. It adds safety and transparency duties for conversational AI systems, joining California's SB 243 and Oregon's SB 1546 as one of the more substantive state-level frameworks in this space. The roughly 15-month gap between enactment and effective date is notably longer than some other 2026 state measures, giving companies operating in Nebraska a defined compliance runway rather than an immediate obligation — a detail worth building into any multi-state compliance timeline, since it means Nebraska's requirements do not need to be live on day one in the way some other states' do.

What does Oregon's SB 1546 establish regarding a private right of action for companion chatbots?

Oregon's SB 1546 creates a private right of action, meaning individuals — not just state regulators — can bring their own lawsuits against companion chatbot operators for violations, with statutory damages set at $1,000 per violation. That per-violation structure is what makes this measure particularly consequential from a business-risk standpoint: it does not require proving a specific dollar amount of harm the way a typical negligence claim might, and because it is calculated per violation, exposure can scale directly with the number of affected interactions or users rather than being capped at a single claim amount. This is a meaningfully more aggressive enforcement mechanism than an agency-enforcement-only model, where a regulator has to choose to investigate and typically has limited capacity to pursue every potential violation.

Why did Kentucky sue an AI chatbot company?

Kentucky's Attorney General, per the office's own press release titled "AG Coleman Sues AI Chatbot Company for Preying on Children," filed suit against Character Technologies — the company behind Character.AI — framing the company's alleged conduct in predatory terms rather than as a more conventional product-liability or consumer-protection matter. That framing matters beyond Kentucky's borders: state attorneys general frequently coordinate or at least watch each other's enforcement theories, and a suit framed around predation on children, rather than a narrower technical violation, tends to generate broader political and media attention than a typical regulatory enforcement action, which is part of why this case became a reference point cited across other states' legislative debates in 2026.

What did Character.AI and Google settle in January 2026 and over what allegations?

In January 2026, Character.AI and Google reached a settlement addressing allegations connected to chatbot-suicide-related litigation — part of the broader wave of wrongful-death and negligence claims brought against Character.AI over the preceding two years, including cases tied to the 2024 Florida and 2025 Colorado suicides. Google's involvement in the settlement reflects its investor and technology-partnership relationship with Character.AI, and reporting on the case treated the settlement as a significant, if partial, resolution — closing specific claims while leaving the broader legal and regulatory landscape for companion AI, including the nearly 100 pending state bills, very much unresolved for the industry as a whole.

What is the KIDS Act and did it pass the House?

The KIDS Act is one of several pending federal bills addressing chatbot and broader online child-safety concerns, and per ITIF's August 2026 analysis, it is the only one of the federal bills reviewed — alongside the GUARD Act, CHAT Act, CHATBOT Act, KOSA, and SAFE BOTS Act — to have passed a chamber of Congress, clearing the House in June 2026. It has not, as of that reporting, cleared the Senate or been signed into law, meaning there is still no enacted federal chatbot-safety statute in the US; the entire operative legal framework at the federal level remains proposal-stage, while state laws like California's SB 243 and Nebraska's Conversational AI Safety Act are already binding or moving toward binding effective dates.

What does Utah's HB 452 require of mental-health chatbots?

Utah's HB 452 is part of the 2026 wave of state legislation that specifically targets mental-health-oriented chatbots rather than companion or general-purpose conversational AI, reflecting a broader legislative instinct that products positioning themselves around emotional or psychological support warrant a distinct, more specific regulatory lane than general chatbot disclosure rules provide. This mirrors the logic behind Illinois's HB 1806 and Nevada's AB 406, which push toward standards resembling those applied to licensed mental-health services. Businesses building or deploying any product that touches on mental-health framing — even indirectly, through wellness or journaling features — should treat this as a growing regulatory category worth watching closely rather than a niche concern limited to dedicated therapy-chatbot products.

Why did Governor Newsom veto California's AB 1064?

Governor Newsom vetoed AB 1064, which would have imposed a blanket ban on companion chatbots for users under 18, even as he signed SB 243's narrower disclosure-and-crisis-protocol framework into force in the same general legislative window. Per ITIF's August 2026 analysis, this veto reflects a broader tension in the policy debate between blanket prohibitions and targeted, design-level interventions — a full ban is simpler to state but harder to enforce and can push usage toward unregulated alternatives, while a disclosure-and-protocol approach is more complex to draft but arguably more enforceable and more directly targeted at the specific harms driving the litigation. The veto signals that even within California, the state most associated with aggressive AI-safety legislation in 2026, a full ban was judged to be the wrong tool for this particular problem.

What does China's Interim Measures for Anthropomorphic AI Interaction Services prohibit for minors?

China's Interim Measures, effective 15 July 2026, prohibit "virtual intimate relationship services" for minors specifically, rather than banning anthropomorphic or companion-style AI interaction for minors outright, per Rimon Law's July 2026 analysis of China's AI regulatory developments. That distinction matters: a general tutoring or educational companion aimed at a younger user is treated differently under the framework than a product designed to simulate a romantic or intimate relationship, which is the specific category the measure targets. The rule was jointly issued by five regulators — the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation — reflecting how seriously Beijing treated this as a cross-agency enforcement priority rather than a single ministry's narrow rule.

What addiction-prevention measures does China's new anthropomorphic AI regulation require?

China's Interim Measures require companies operating anthropomorphic AI interaction services to issue addiction-prevention usage reminders once a user has been continuously engaged for two hours, per Rimon Law's July 2026 analysis. This is a universal, usage-based trigger rather than a content-based one — it applies based on how long someone has been engaged, not on what they have been discussing — which makes it simpler to implement consistently but also broader in scope than a rule that only triggers on specific risky content. It sits alongside the measure's other addiction- and dependency-related provisions, including enhanced protections for elderly users, who are a population notably addressed in China's framework but largely absent from the US state bills reviewed in this analysis.

How many US state chatbot bills were introduced as of August 2026?

Nearly 100 state-level chatbot-specific bills were active across the United States as of ITIF's August 2026 analysis. That figure covers a wide range of approaches — from California's disclosure-and-crisis-protocol model, to Oregon's private-right-of-action model, to Nebraska's broader safety-and-transparency duties, to more narrowly scoped bills like Colorado's restrictions on variable reward schedules and Utah's mental-health-chatbot-specific requirements. The sheer number underscores that this is not a handful of outlier states reacting to local news coverage; it is a near-nationwide legislative response, arriving in a compressed timeframe, which is itself unusual for state-level technology policy and is part of why compliance teams are increasingly treating this as a single, coordinated wave rather than 100 unrelated bills to track individually.

What is the accuracy rate of age-estimation technology cited in the chatbot safety debate?

ITIF's August 2026 analysis cites age-estimation technology accuracy at 99.3% for the 13-17 age range, a figure regularly invoked in debates over whether mandatory age verification is a proportionate response to chatbot child-safety concerns. Proponents of age-verification mandates point to figures like this to argue the technology is mature enough to deploy at scale; critics counter that even a small residual error rate, applied across a massive user base, still produces a meaningful number of misclassifications, and that the privacy cost of collecting identity-verifying data from every user — not just the minors a system is trying to identify — is a real cost regardless of how accurate the underlying estimation technology is. That tension is central to why alternatives like an opt-in child flag have gained traction as a less invasive option.

How many US adolescents use chatbots for mental-health advice, per Stanford research?

Stanford research cited in ITIF's August 2026 analysis found that roughly one in eight US adolescents use chatbots for mental-health advice. That figure is one of the more consequential data points in the entire 2026 policy debate, because it establishes that this is a present-tense, large-scale behavior rather than a speculative future risk. It is a significant part of why mental-health-specific chatbot bills like Utah's HB 452 and licensed-service-style proposals like Illinois's HB 1806 and Nevada's AB 406 gained traction in 2026 — legislators were not responding to a hypothetical, they were responding to evidence that a substantial share of a vulnerable population had already, without much oversight, made unregulated AI chatbots part of how they cope with mental-health-related distress.

What happened in the wrongful-death lawsuits against Character.AI in Florida and Colorado?

Character.AI faced wrongful-death and negligence lawsuits tied to a 2024 suicide in Florida and a 2025 suicide in Colorado, with plaintiffs in both cases alleging that the company's chatbot products played a role in their children's deaths, according to 2026 news reporting on the broader Character.AI litigation. These cases, together with Kentucky's Attorney General suit, formed the core factual and narrative backdrop against which the January 2026 Character.AI/Google settlement and the subsequent wave of nearly 100 state chatbot bills have to be understood — they are the concrete, documented harms that turned an abstract AI-safety debate into a legislative priority across a large number of state capitols within a short window of time.

Does China's anthropomorphic AI rule require algorithm filing with regulators?

Yes. China's Interim Measures for the Administration of Anthropomorphic AI Interaction Services require companies to file their underlying algorithms with regulators, per Rimon Law's July 2026 analysis. This is a transparency mechanism distinct from the measure's user-facing provisions, like the minor-service prohibition and the two-hour usage reminder — it gives Chinese regulators direct, ongoing visibility into how these systems are designed and tuned, rather than relying solely on after-the-fact enforcement against observed harms. It reflects a broader pattern in Chinese AI governance, where algorithm filing and registration requirements have become a recurring regulatory tool across multiple categories of AI service, not something invented specifically for anthropomorphic AI.

What enhanced protections does China's rule provide for elderly users of companion AI?

China's Interim Measures include enhanced protections specifically for elderly users of anthropomorphic AI interaction services, per Rimon Law's July 2026 analysis, though the detailed mechanics of those protections are less extensively documented in current English-language reporting than the minor-specific provisions. What is clear is that Chinese regulators treated elderly users as a distinct vulnerable population warranting dedicated attention alongside minors — a framing that is notably broader than the US state bills reviewed here, which are almost entirely focused on minor protection and do not, for the most part, address elderly users as a separate regulatory category. That difference is worth noting for any company operating across both markets, since a compliance posture built only around minor protection would not fully satisfy China's broader vulnerable-population framework.

Is the UK's Online Safety Act being used to regulate AI companion chatbots?

Yes. Ofcom has issued enforcement actions and opened investigations into AI character-companion services under the Online Safety Act 2023, according to Scaffold Digital's 2026 guide to UK AI regulation, rather than waiting for the UK Parliament to pass a chatbot-specific statute along the lines of California's SB 243. This is a meaningful strategic choice: it means AI companion products operating in the UK are already inside an active regulatory enforcement regime, using a platform-safety law that predates the current chatbot-specific policy debate, rather than existing in a regulatory gap until bespoke legislation catches up. Companies assuming the absence of a UK chatbot-specific law means an absence of UK regulatory risk would be mistaken.

What is a 'parasocial relationship' and why does it matter for chatbot regulation debates?

A parasocial relationship is a one-sided emotional attachment a person forms toward a media figure, character, or — increasingly — an AI system, without that attachment being reciprocal in the way a real relationship is. ITIF's August 2026 analysis cites survey data finding that 51% of Americans have experienced a parasocial relationship, a figure used to explain why companion chatbots generate a different, more urgent regulatory response than other software categories: a product engineered to simulate warmth, memory, and responsiveness activates the same psychological mechanisms as a real relationship, without any of the natural safeguards a human relationship has, like a friend who can notice something is wrong and intervene. Understanding this concept is genuinely useful background for grasping why lawmakers keep reaching for crisis-protocol and disclosure requirements rather than treating companion AI as just another consumer app; for more on how terms like this get used across AI policy debates, Scult's AI glossary is a useful reference point.

Does my company's customer-service chatbot count as a 'companion chatbot' under state law?

It depends on the specific state and the specific bill, and that uncertainty is itself the practical problem. Most of the roughly 100 state bills define scope around relationship framing, persistent memory across sessions, and simulated emotional connection, rather than around the mere presence of natural-language conversation. A narrowly scoped customer-service bot that answers order-status questions and does not maintain a persistent persona or invite emotional engagement is less likely to fall squarely within these definitions than a product explicitly designed to feel like a companion or friend. But because each state bill defines this differently, and because enforcement theories like Kentucky's "preying on children" framing show regulators are willing to read facts broadly, any product with a persistent, named, personality-driven assistant should get a specific legal review rather than assume it is out of scope by default. Scult's general FAQ hub covers how we think about scoping this kind of review for a specific product.

What disclosure must an AI chatbot give users under California SB 243?

Under California SB 243, an AI chatbot operator must disclose to users, clearly and not merely buried in a terms-of-service document, that they are interacting with an AI system rather than a human. This is the first of the law's three core pillars, alongside crisis-referral protocols and minor-specific protections, and it reflects the most basic and most widely shared regulatory instinct across nearly every jurisdiction reviewed here, from California to the EU's Article 50 rule. The practical compliance bar is not simply having a disclosure somewhere in the product — it is making that disclosure salient enough that a reasonable user would actually notice and register it, ideally at first contact and again at reasonable intervals during extended use.

What crisis-protocol obligations does SB 243 impose regarding suicidal ideation?

SB 243 requires companion chatbot operators to maintain crisis-referral protocols specifically addressing situations where a conversation surfaces signs of self-harm or suicidal ideation, per ITIF's August 2026 description of the law. In practice, this means a system needs a defined, reliable pathway to detect these signals and route the user toward real human or professional crisis resources, rather than generating a plausible, supportive-sounding reply and continuing the conversation as normal. This obligation is where the law intersects most directly with the sycophancy concerns discussed elsewhere in the 2026 policy debate — a system tuned purely to be agreeable and keep users engaged is structurally misaligned with a legal duty to recognize and interrupt a crisis rather than smooth over it.

What is the GUARD Act and what age-verification mandate does it propose?

The GUARD Act is one of the pending federal chatbot-safety bills listed in ITIF's August 2026 analysis, and its distinguishing feature relative to the other federal proposals is a proposed age-verification mandate, aimed at ensuring companion and conversational AI operators can reliably determine whether a user is a minor before extending certain features or interactions. Like the other federal bills reviewed here — the KIDS Act, CHAT Act, CHATBOT Act, SAFE BOTS Act, and KOSA — it had not been enacted as of the analysis's publication, remaining pending in Congress. Age-verification mandates of this kind draw the same privacy-versus-safety tension discussed elsewhere in this piece: they can meaningfully improve minor protection, but only by requiring broader identity-verification data collection across the entire adult user base as well.

What is the CHAT Act / CHAT Act 2.0 and what tiered protections does it propose?

The CHAT Act, and a revised CHAT Act 2.0, are among the pending federal chatbot-safety bills tracked by ITIF as of August 2026, distinguished by a proposed tiered-protections structure — meaning the obligations a chatbot operator faces would scale based on factors like the product's user base, its risk profile, or the age groups it serves, rather than applying one uniform standard to every conversational AI product regardless of context. A tiered approach is a common regulatory design choice when a category of product ranges from low-risk (a narrow customer-service bot) to high-risk (an open-ended companion app marketed to teenagers), since it avoids imposing the heaviest compliance burden on the lowest-risk use cases. As with the other federal bills discussed here, it remained pending, not enacted, as of the most recent reporting reviewed.

What does the CHATBOT Act require regarding parental oversight?

The CHATBOT Act is one of the pending federal bills in ITIF's August 2026 tracker, and its distinguishing feature is a proposed parental-oversight component, aimed at giving parents or guardians visibility into, or control over, a minor's use of conversational AI products. This reflects a design philosophy that appears across several of the 2026 proposals in different forms — rather than relying solely on the platform itself to detect and protect minors, some of the parental-oversight-style bills would shift part of the monitoring responsibility to parents, provided the platform gives them the tools to exercise it. Like the other federal bills tracked here, it remained pending as of the most recent analysis, with no enacted federal parental-oversight standard yet in place.

What does the SAFE BOTS Act's retail carveout mean for e-commerce chatbots?

The SAFE BOTS Act, per ITIF's August 2026 federal bill tracker, includes a retail carveout intended to exclude ordinary e-commerce and customer-service chatbots from the heavier obligations the bill would otherwise impose on companion or emotionally engaging conversational AI. This kind of carveout exists precisely because of the scope-ambiguity problem discussed earlier — legislators drafting broad chatbot-safety rules recognize that a bot answering "where is my order" questions poses a fundamentally different risk profile than a companion app designed to simulate an ongoing relationship, and a retail carveout is one mechanism for keeping the two from being regulated identically. Businesses running conventional e-commerce chatbots should still confirm their specific product design falls within whatever carveout language ultimately gets enacted, rather than assuming exclusion by category alone.

How does KOSA's 'duty of care' apply to AI chatbot providers?

KOSA — the Kids Online Safety Act — proposes a duty-of-care standard, a legal concept that would require covered platforms, potentially including AI chatbot providers, to take reasonable steps to prevent and mitigate certain harms to minor users, rather than simply disclosing risks and leaving users to manage them. Applied to chatbot providers, a duty-of-care standard would function differently from disclosure-based rules like California SB 243's non-human-disclosure requirement: it would create an affirmative obligation to design the product safely in the first place, with liability potentially attaching to design choices themselves, not just to a failure to disclose. As of ITIF's August 2026 analysis, KOSA remained pending at the federal level, alongside the other bills discussed here, with no enacted duty-of-care standard yet governing AI chatbot providers specifically.

What licensing restrictions would the People-First Chatbot Act impose?

The People-First Chatbot Act is among the federal proposals tracked in ITIF's August 2026 analysis, distinguished by proposed licensing-style restrictions on chatbot operators, echoing the same regulatory instinct behind state-level proposals like Illinois's HB 1806 and Nevada's AB 406, which push mental-health-oriented chatbots toward standards resembling licensed professional services. A licensing-based approach would represent a meaningfully more restrictive regulatory model than disclosure-based rules, since it implies an approval or registration step before a product can operate, rather than a set of behavioral obligations a product must simply satisfy once live. Like the other federal bills discussed in this piece, it remained pending as of the most recent reporting, with the overall federal legislative landscape still unresolved compared to the more advanced state-level frameworks.

What does Colorado's HB 1263 restrict regarding variable reward schedules in companion apps?

Colorado's HB 1263 restricts the use of variable reward schedules in companion apps, per ITIF's August 2026 state-bill tracker — a design mechanic where rewards, responses, or positive reinforcement are delivered unpredictably rather than consistently, a pattern well documented in behavioral psychology for producing more persistent, harder-to-quit engagement than predictable reward patterns do. This is a distinctly design-level intervention, closer in spirit to Colorado regulating a mechanic than to disclosure-based rules like non-human-disclosure requirements. It reflects the same underlying addiction-and-engagement concern that drove China's two-hour usage-reminder rule, even though the two jurisdictions chose different specific mechanisms — Colorado targeting the reward mechanic directly, China targeting usage duration regardless of mechanic.

What licensed mental-health service rules do Illinois HB 1806 and Nevada AB 406 impose?

Illinois's HB 1806 and Nevada's AB 406 both push mental-health-oriented chatbots toward standards resembling those applied to licensed human mental-health services, per ITIF's August 2026 state-bill tracker, rather than treating them as ordinary consumer software subject only to general disclosure rules. The underlying logic is that a product marketed or functionally positioned as a source of mental-health support should be held to something closer to the standards a human counselor or therapist would be held to, given the comparable reliance a vulnerable user might place on it. This puts Illinois and Nevada in the same general regulatory lane as Utah's HB 452, forming a distinct sub-category of 2026 state legislation focused specifically on mental-health chatbots rather than companion or general-purpose conversational AI.

Why do age-verification mandates raise privacy concerns in the chatbot regulation debate?

Age-verification mandates require a system to determine whether a user is a minor, which in practice usually means collecting identity-verifying information — government ID, biometric age-estimation data, or similar — from every adult user as well, not just the minors the rule is trying to protect. That creates a new data-security and privacy liability precisely in the course of trying to solve a different one, since a database of identity-verification records is itself an attractive target and a potential source of harm if breached or misused. This tension is a central theme in ITIF's August 2026 policy analysis, and it is part of why some proposals favor a narrower opt-in child flag — where a parent affirmatively marks an account as belonging to a minor — over a universal age-verification requirement applied to every single user, adult or not.

Does the federal AI preemption executive order exempt child-safety chatbot laws?

Yes — reporting on the federal AI preemption executive order, EO 14365, indicates it includes a carve-out preserving state child-safety laws, meaning the broader federal push to preempt a patchwork of state AI regulation was not drafted to sweep away the specific state chatbot child-safety protections discussed throughout this piece, like California's SB 243 or Nebraska's Conversational AI Safety Act. That carve-out is a meaningful detail for compliance planning: even if broader federal AI preemption efforts advance, businesses should not assume state-level companion-chatbot child-safety obligations will simply disappear as a result, since the child-safety category appears to have been deliberately excluded from that preemption push rather than swept in with it.

What is a 'virtual companion' under China's regulatory definition?

Under China's Interim Measures for the Administration of Anthropomorphic AI Interaction Services, a virtual companion sits within the broader category of anthropomorphic AI interaction services — systems designed to present humanlike personality, memory, and responsiveness in ongoing interaction with a user. The measure's most specific prohibition targets "virtual intimate relationship services" for minors within that broader category, distinguishing romantic or intimate-relationship-simulating products from other anthropomorphic AI uses like educational tutoring companions, per Rimon Law's July 2026 analysis. The precise regulatory boundaries of the broader "anthropomorphic AI interaction service" category are still being clarified in practice as Chinese regulators apply the framework, but the minor-specific intimate-relationship prohibition is its most concrete, unambiguous provision.

What penalties can Ofcom impose on an AI companion chatbot service under the Online Safety Act?

Ofcom's enforcement powers under the Online Safety Act 2023 generally include the ability to require companies to take specific remedial actions, impose substantial fines calculated as a percentage of global revenue for serious violations, and in the most severe cases pursue measures that can restrict a service's ability to operate in the UK, though the specific penalties applied to any individual AI companion chatbot investigation depend on the facts of that case. What is established, per Scaffold Digital's 2026 UK AI regulation guide, is that Ofcom has already opened investigations and issued enforcement actions against AI character-companion services under this existing authority, meaning UK regulatory risk for this category of product is live and being actively exercised, not merely a theoretical future possibility.

How does the EU AI Act's Article 50 disclosure requirement apply to companion chatbots operating in Europe?

The EU AI Act's Article 50 requires that users be informed they are interacting with an AI system, unless that fact is already obvious from the surrounding context, and it applies across the EU regardless of a specific member state having its own chatbot-specific child-safety statute. For companion chatbots operating in Europe, this means the baseline disclosure obligation discussed throughout this piece — telling users clearly they are talking to an AI, not a human — is not optional or state-by-state the way it can feel in the fragmented US legislative landscape; it is a bloc-wide legal requirement. It does not, on its own, impose the more specific crisis-protocol or minor-protection duties found in laws like California's SB 243, which is part of why Germany's and France's more chatbot-specific legal activity in 2026 concentrated on copyright rather than companion-AI child safety.

Is there a federal chatbot safety law in the US as of August 2026, or only state laws?

As of ITIF's August 2026 analysis, there is no enacted federal chatbot-safety law in the United States — only state laws. Six federal bills were pending at that point: the KIDS Act, GUARD Act, CHAT Act, CHATBOT Act, KOSA, and SAFE BOTS Act, and of those, only the KIDS Act had cleared even a single chamber of Congress, passing the House in June 2026 but not the Senate. That means the entire operative legal framework governing companion and conversational AI child safety in the US currently runs through state legislatures — California's SB 243, Oregon's SB 1546, Nebraska's Conversational AI Safety Act, and roughly 97 other bills in various stages — rather than through any single national standard, which is exactly the fragmented compliance landscape discussed earlier in this piece.

Should AI companion apps be required to give crisis-referral prompts for suicidal ideation?

The direction of the 2026 policy consensus, reflected in California's SB 243 and echoed in several other state proposals, is yes — that companion AI products should be required to detect signals of suicidal ideation or self-harm and route users toward real crisis resources rather than continuing an ordinary conversational flow. ITIF's August 2026 analysis treats this as one of the more defensible, targeted interventions available to policymakers, precisely because it addresses the specific harm exposed by the Character.AI litigation directly, rather than relying on a blunter tool like a blanket usage ban. The harder open question is not whether crisis-referral prompts should exist, but how reliably a given system can actually detect the relevant signals in open-ended conversation, which remains a genuine technical challenge regardless of the legal requirement.

What does an 'opt-in child flag' mean as a proposed alternative to mandatory age verification?

An opt-in child flag is a proposed mechanism where a parent or guardian actively designates an account as belonging to a minor, triggering additional protections for that account, rather than requiring every user on a platform to undergo age-verification checks to determine who is and isn't a minor. ITIF's August 2026 analysis discusses this as a less privacy-invasive alternative to mandatory age verification, since it avoids collecting identity-verification data from the entire adult user base just to identify the minority of users who are minors. The tradeoff is coverage: an opt-in system only protects minors whose parents actively engage with it, whereas a mandatory verification system, despite its privacy costs, would in theory catch minors regardless of parental involvement — which is exactly the kind of tradeoff regulators are still actively weighing across the nearly 100 state bills currently in motion.

Want results like this?

Keep reading