AI Companion Chatbot Laws: What Changed and What's Next

AI Companion Chatbot Laws: What Changed and What's Next

Companion chatbots went from unregulated to specifically regulated in about a year. New York and California both passed laws aimed at them, the Federal Trade Commission opened an inquiry into the major providers, and the EU’s transparency rules for AI systems that talk to people began applying in August 2026.

The common thread across all of it is narrow: tell users they’re talking to a machine, have a plan for users who express suicidal thoughts, and treat minors differently. None of it regulates what a companion can say to a consenting adult. This is a summary of public sources rather than legal advice.

California SB 243 #

Signed on October 13, 2025, California’s companion chatbot law applies to operators of chatbots designed to sustain ongoing personal relationships. Its main requirements:

  • Disclosure. If a reasonable person might believe they’re talking to a human, the operator must give a clear and conspicuous notification that the chatbot is artificially generated and not human.
  • A warning about suitability. Platforms must disclose that companion chatbots may not be suitable for some minors.
  • Break reminders for minors. By default, minors must get a clear notification at least every three hours reminding them to take a break and that the chatbot isn’t a person.
  • Protection against sexual content involving minors. Operators must take reasonable measures to prevent the chatbot producing it.
  • Crisis protocols. Operators must maintain a protocol for preventing the production of content about suicide, self-harm or suicidal ideation, including referring users who express such thoughts to crisis services. The protocol has to be published on the operator’s website.
  • Reporting. Annual reporting to the state’s Office of Suicide Prevention begins July 1, 2027.

You can read the bill text on the California Legislature’s site.

New York’s AI companion law #

New York added Article 47 to its General Business Law, covering AI companion models. Two requirements stand out.

Crisis detection and referral. Under GBL § 1701, operators must have a protocol making reasonable efforts to detect and address suicidal ideation or expressions of self-harm, and to notify users who express them, referring them to crisis services such as the 988 Suicide and Crisis Lifeline or a crisis text line.

Recurring AI disclosure. Under GBL § 1702, operators must tell users clearly and conspicuously, verbally or in writing, that they aren’t communicating with a human. The notice is required at the start of an interaction and at least every three hours during a continuing one, with the initial notification not required more than once a day.

Notably, New York’s disclosure rule applies to all users, not just minors.

The FTC inquiry #

On September 11, 2025, the Federal Trade Commission issued 6(b) orders to seven companies: Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI, Snap and X.AI.

A 6(b) study is an information-gathering exercise, not an enforcement action, and it doesn’t allege anyone broke the law. It’s asking how these firms test companion chatbots for safety, what they do to limit access by children and teens, how they monitor for harms, how they handle data from conversations, and how they comply with the Children’s Online Privacy Protection Act. Studies like this often precede rulemaking or enforcement, so it’s a reasonable indicator of where federal attention is heading.

The EU: Article 50 of the AI Act #

The EU AI Act takes a broader approach: rather than regulating companions specifically, Article 50 requires that AI systems intended to interact directly with people inform those people that they’re interacting with an AI, unless it would be obvious to a reasonably well-informed person. The disclosure has to be made clearly, at the latest at the first interaction, and must meet accessibility requirements. These transparency obligations began to apply on August 2, 2026.

For a companion app the practical effect is modest, since an app whose premise is a fictional character is expected to say so somewhere visible.

What the laws have in common #

RequirementCalifornia SB 243New York GBL Art. 47EU AI Act Art. 50
Say it’s an AIYesYes, repeated every 3 hoursYes, at first interaction
Repeated remindersMinors, every 3 hoursAll users, every 3 hoursNot specified
Crisis protocolRequired and publishedRequired, with 988 referralNot covered
Rules specific to minorsYesNot the focusNot covered
Regulates adult content between adultsNoNoNo

What none of these laws do #

Worth being clear, because coverage of this area tends to blur it:

  • They don’t ban companion apps or set an age limit for adults.
  • They don’t require age verification with documents. Age gates in these apps remain self-declared, which is why device-level parental controls are still the more reliable tool for families.
  • They don’t create a privacy standard for chat content. That’s handled by general privacy law, and it’s why checking an app’s own practices still matters. See what data AI chat apps collect.
  • They don’t make anything therapeutic. A required crisis referral is a signpost, not care, as covered in can an AI companion replace therapy.

What this means if you use these apps #

Expect to see more in-app notices telling you the character isn’t real, including periodically during long sessions, and expect crisis resources to appear if you type something that trips a detector. Both are required behavior in some states rather than a judgment about you.

Beyond that, the rules address disclosure and crisis handling, and leave privacy largely to you. An app’s architecture still decides whether your conversations exist on a server at all. Xin runs its model on the phone with no account, so chats and memories stay in a local database on the device, and it’s 18+ with an age confirmation at setup and an adults-only cast. That design answers the privacy question, not the legal-compliance one, and any app’s obligations under these laws are a matter for its operator.

Our broader checklist for picking one is in are AI companion apps safe.

Frequently asked questions #

Yes, for adults, in the US and EU. The recent laws regulate how they must behave, particularly around disclosure, minors and crisis situations, rather than prohibiting them. Rules differ by country, and some jurisdictions have taken action against specific apps over data protection.

Do AI companion apps have to tell you they’re not human? #

In New York, yes, at the start of an interaction and at least every three hours during a continuing one. California requires the disclosure where a reasonable person might be misled. The EU AI Act requires it at first interaction unless it would be obvious from context.

What are the rules for minors using AI companion chatbots? #

California requires platforms to disclose that companion chatbots may not be suitable for some minors, to remind minor users at least every three hours that they’re talking to an AI and should take a break, and to take reasonable measures against producing sexual content involving minors. The FTC is separately examining how these companies restrict access by children and teens. Most companion apps are rated for adults and aren’t intended for anyone under 18.

Do these laws apply to apps based outside the state? #

Generally they apply based on where the user is rather than where the company is, which is the usual pattern for state consumer-protection law. A small developer anywhere can fall under them by having users in California or New York. Operators should get their own legal advice; this article is a summary of public sources.

Is this area still changing? #

Yes. Several more states have introduced similar bills, the FTC study is ongoing, and enforcement under the existing laws is just beginning. Check the current text of any law before relying on it, since the details above reflect the position as of September 2026.