Skip to main content

The Chatbot Compliance Wave: California’s New Law Is Not the Only One to Watch

What You Need To Know

  • On September 10, 2026, California Gov. Gavin Newsom signed a follow-on child-safety package, including SB 1119 (Adam’s Law), that goes further than SB 243 (the companion chatbot law).
  • The new law requires covered chatbot operators to conduct a risk assessment before rolling out any feature aimed at, or reasonably likely to reach, minors (i.e., anyone under 18).
  • The companion chatbot law itself has now been in effect for nine months (signed October 13, 2025; effective January 1, 2026) and includes a private right of action. This means California residents, not just the attorney general, can sue chatbot operators directly.
  • At least 16 other states have enacted their own chatbot-specific laws to date, some of which also take a private-right-of-action approach.
  • Any company operating a chat, support, or companion interface reachable by residents (including minors under 18) of a state with an enacted chatbot law is most likely already within the scope of at least one enacted law today.

Current as of October 7, 2026 | This alert addresses fast-moving state legislation; some provisions summarized below are subject to further rulemaking or amendment.

Background on Companion Chatbot Law

The companion chatbot law, authored by Sen. Steve Padilla, was the first state law to pair AI chatbot safety and disclosure requirements with a private right of action and youth-specific protections. It took effect January 1, 2026, and requires covered operators to (1) clearly disclose that a user is talking to AI, not a human, whenever a reasonable person could otherwise be misled, particularly for “companion” chatbots designed to sustain ongoing, human-like relationships; (2) implement protocols to detect and respond to signs of self-harm or suicidal ideation, including referral to crisis resources; (3) apply additional safeguards for minors, including break reminders and restrictions on sexualized content; and (4) file annual reports to the Office of Suicide Prevention. Critically, the companion chatbot law created a private right of action, which has been the single biggest driver of exposure under the statute.

What Changed on September 10

On September 10, 2026, Newsom signed a follow-on package of child safety laws, including SB 1119 (aka Adam’s Law), that goes further than the companion chatbot law’s baseline disclosure-and-safeguards model. Covered operators must now conduct a risk assessment before rolling out any new chatbot feature aimed at, or reasonably likely to reach, minors, rather than addressing risk after a feature ships. Companies that violate Adam’s Law face penalties of up to $5,000 per affected child for each negligent violation, and up to $15,000 per affected child for each intentional violation. In addition, Adam’s Law creates a private right of action under which a prevailing plaintiff may recover actual damages, reasonable attorney’s fees and costs, injunctive or declaratory relief, and any other relief the court deems proper. Nine months after the companion chatbot law took effect, the trend line in Sacramento is toward more obligations, not fewer, and the state’s newest law shifts the compliance burden earlier in the product lifecycle, from disclosure at launch to risk assessment before launch.

SB 1119 does not change the definition of a companion chatbot. So, operators who previously determined that California’s companion chatbot law did not apply to them likely do not need to conduct the risk assessment. However, because the prior law includes many ambiguities about what is covered as a companion chatbot, any operator who previously determined it was not clear whether the law applied to them should consider revisiting that analysis in light of this development and heightened risk.

The State-by-State Ripple Effect

California is not alone. The following states have also enacted chatbot-specific laws, the majority of which will take effect after January 1, 2027, quickly fragmenting the compliance landscape and adding complexity for companies operating across states.

 

State AI Chatbot Laws
State / Law Effective Date Core Requirement Private Right of Action
Utah - AI Applications Relating to Mental Health (HB 452) May 7, 2025 Covers mental health chatbots only. Bars sale/sharing of health data and user input; restricts targeted/undisclosed advertising; requires AI disclosure; voluntary clinical-safety policy filing grants affirmative defense. No
Maine - An Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligence (LD 1727) September 24, 2025 AI disclosure when reasonable consumer could be misled into thinking they are talking to a human in trade/commerce contexts. Yes (under Maine Unfair Trade Practices Act)
New York - AI Companion Models Law (S 3008C) November 5, 2025 Universal AI disclosure, mandatory suicide/self-harm detection, and crisis referral protocol. No
California - Companion Chatbot Law (SB 243) January 1, 2026 Non-human disclosure, minor safeguards, mandatory suicide/self-harm crisis protocols (public and reported), annual reporting from July 1, 2027. Yes
California - Adam’s Law (SB 1119) January 1, 2027 Mandatory age assurance and pre-launch child safety risk assessment; crisis protocol; default safety settings; extensive behavioral prohibitions; ad/data restrictions; biennial independent child safety audits (reported to AG); three-year conversation preservation after serious self-harm. Yes
New Hampshire - Endangering Welfare of Child; Responsive Generative Communication (HB 143) January 1, 2026 Subject to certain exemptions, criminalizes and creates civil liability for AI chatbot operators who knowingly/intentionally direct communications encouraging a child toward sexual conduct, drug/alcohol use, self-harm/suicide, or violence. Yes
Tennessee - SB 1580 July 1, 2026 Bars AI systems from being advertised/represented as qualified mental-health professional. Yes (through Tennessee Consumer Protection Act of 1977)
Hawaii - Artificial Intelligence Disclosure and Safety Act (SB 3001) July 14, 2026 AI disclosure; crisis-response protocol; no false mental-health-provider claims; no posing as human during crisis intervention; minor protections; annual DOH reporting from January 1, 2028. No
Colorado - Conversational Artificial Intelligence Service Operator Requirements (HB26-1263) August 12, 2026; most operator obligations begin January 1, 2027 Age estimation duty; minor safeguards; general AI disclosure and suicide/self-harm referral protocol; bar on false professional endorsement claims; annual AG reporting from July 1, 2027. No
Connecticut - SB 5 January 1, 2027 Crisis detection/referral protocol; no claiming to be human; AI disclosure; minor protections. No
New York - Safe by Design Act (S 9008C) January 1, 2027 Broader minor safety/age assurance law; for AI companions specifically: age assurance required before granting access, disabled by default for minors, parent-override only; plus platform-wide defaults restricting adult-minor contact, parental visibility/consent/spending controls. No
Oregon - SB 1546 January 1, 2027 AI disclosure; suicide/self-harm protocol; minor protections; annual public reporting. Yes
Rhode Island - AI Companion Models (SB 2195) January 1, 2027 Mandatory suicide/self-harm and physical-harm-to-others detection protocol with crisis referral; universal AI disclosure (all users); annual AG reporting from July 1, 2027. No
Washington - AI Companion Chatbots (HB 2225) January 1, 2027 Mandatory universal AI disclosure; minor protections; suicide/self-harm/eating disorder detection and referral protocols. Yes (under Washington’s existing Consumer Protection Act, chapter 19.86 RCW)
Georgia - SB 540 July 1, 2027 AI disclosure; minor protections; crisis detection/referral protocol; no false professional licensure claims; parental controls; age assurance for explicit content with data-minimization. No
Idaho - Conversational AI Safety Act (SB 1297) July 1, 2027 AI disclosure; crisis referral protocol for suicidal ideation; no false mental-health-licensure claims; minor protections; parental controls (mandatory under 13). No
Iowa - SF 2417 July 1, 2027 AI disclosure (minors and general consumers); minor protections; parental controls (mandatory under 13); suicide/self-harm referral protocol; no false mental-health-licensure claims. No
Nebraska - Conversational AI Safety Act (LB 525) July 1, 2027 AI disclosure; minor protections; parental controls (mandatory under 13); suicide/self-harm referral protocol; no false mental-health-licensure claims. No

Source: Future of Privacy Forum 2026 Chatbot Legislation Tracker

The Parallel Track: Wiretapping Theories

Separately from the disclosure obligations under these chatbot laws, plaintiffs’ firms are using decades-old wiretapping and eavesdropping laws to challenge chatbots that record conversations or route them to third-party AI vendors without consent. This theory has grown from roughly two federal cases in 2021 to more than 58 active matters in early 2026, including recent suits alleging that “incognito” chat modes did not actually stop data from reaching third-party partners. This risk exists independent of the companion chatbot law or any state-specific chatbot law, and it is not resolved by compliance with any of the laws summarized above.

Why It Matters

  • Laws’ scope may be broader than expected. Companies with a chat, support, or companion interface reachable by a resident of the above listed states are likely already in scope of at least one enacted law.
  • Disclosure alone may not be enough. Several of the newest laws call for repeated or context-specific disclosure, rather than a one-time banner at sign-up, requiring product and engineering changes.
  • Vendor and backend conduct is an independent risk not covered by compliance with chatbot laws. Plaintiffs’ firms are separately pursuing wiretapping and eavesdropping claims against any chatbot operators whose conversations are recorded or routed to third-party AI vendors without adequate consent, including claims that “private” or “incognito” modes did not match backend behavior.
  • The compliance timeline has moved earlier. California’s newest law requires a pre-launch risk assessment for features reaching minors. Companies built around a launch-then-fix compliance model may need to move that review earlier in the product cycle.

Next Steps

Companies with a chat, support, or companion product may want to consider the following:

  • Exposure and scope mapping. Identify every AI chat, support, or companion feature that could reach a resident (including a minor) of a state with an enacted chatbot law. Because several states’ definitions turn on specific design features (memory/personalization, unprompted emotional questions, sustained relationship-building) rather than the word “chatbot” itself, a feature-by-feature review may be necessary to determine what is in scope.
  • Disclosure design, not just disclosure language. A one-time banner will not satisfy most of the newer laws. Disclosure cadence varies by state and by user age, commonly a persistent visible disclaimer or a disclosure at the start of each session plus a recurring reminder every one to three hours, with several states requiring the shorter (hourly) interval specifically for minors. Companies operating across multiple states may want a single disclosure design built to the strictest applicable cadence, rather than maintaining state-specific logic.
  • Crisis and self-harm response protocols. Nearly every law enacted requires a documented protocol for detecting expressions of suicidal ideation or self-harm and referring the user to crisis resources (the 988 lifeline is the common reference point). Several states also require that protocol to be published publicly and, in some cases, that referral counts be reported annually. Companies may want to confirm they have (a) an actual detection mechanism, not just a static disclaimer, (b) a real crisis-service referral flow, and (c) a retained, auditable record of when the protocol triggered, since several statutes require reporting aggregate activation counts and a defensible record is the only way to produce that data credibly if challenged.
  • Litigation exposure triage. As described in the table above, exposure differs meaningfully by state. Some laws (California, Oregon) allow individuals to sue directly for statutory or actual damages, while others (New York, Colorado, Nebraska, Idaho, Hawaii, and Iowa) expressly limit enforcement to the state’s attorney general. Companies may want to treat these two categories differently in their risk assessment, prioritizing remediation in private-right-of-action states where a single user complaint may become a claim without regulator involvement.
  • Reporting and recordkeeping calendar. Several states (California, Colorado, Georgia, Hawaii, Oregon, Rhode Island, and Washington) impose annual public reporting obligations with staggered effective dates (some beginning July 2027, others January 2028). Companies may want to build a reporting calendar now, since the underlying data (crisis referral counts, protocol details) needs to be captured prospectively; it generally cannot be reconstructed retroactively if the operator did not log it at the time.
  • Vendor and data-flow diligence. Beyond the chatbot-specific laws, plaintiffs’ firms are separately pursuing wiretapping and eavesdropping theories against operators whose chat data is recorded or routed to third-party AI vendors without adequate consent, including claims specifically targeting “private” or “incognito” modes that don’t match their backend behavior. This exposure is independent of compliance with any state’s chatbot laws, so vendor contracts and data-flow diagrams should be reviewed for any feature marketed as private or incognito.
  • Launch process timing. Adam’s Law requires a risk assessment before any new or updated chatbot feature reaches minors, shifting compliance review from a launch-day checklist item to a design-and-spec-stage gate. Companies may want to build this assessment into their existing product review process now, rather than relying on launch-readiness or legal sign-off to catch it after the feature is built. Retrofitting compliance post-launch may be harder and, under Adam’s Law’s framing, potentially noncompliant on its own terms.
  • Ongoing monitoring. With additional bills pending and several enacted laws still subject to attorney general rulemaking (e.g., Colorado) a one-time compliance review unlikely suffices. Companies may want to establish a recurring (e.g., quarterly) legislative and rulemaking review rather than treating this as a one-time project.