AI Companion Laws Tracker 2026: Rules by Country and State

Status as of September 19, 2026 - reviewed monthly

A human face in profile, lit in blue, with a glowing network of lines and nodes over the head against a dark background.
The status of every rule on this page was checked against public legal sources on September 19, 2026.

This tracker lists the laws, bills, regulations, regulator guidance and enforcement actions that apply to AI companion and companion-chatbot apps, jurisdiction by jurisdiction. It has 47 entries covering 28 jurisdictions: the US federal government, 18 US states, the European Union and eight other countries. Every entry links to its source and has its own anchor you can link to, and the whole dataset is available as a free CSV download.

The focus is on rules written for chatbots that simulate companionship, and on general AI, online-safety and data-protection rules that regulators have applied to them. How US privacy law, such as the FTC Act and the CCPA, treats the data you share with an AI girlfriend app is covered separately in our consumer guide to AI girlfriends and US law. For figures on who uses these apps, see our AI companion statistics.

Key takeaways

  • 47 entries in 28 jurisdictions: 16 rules in force (including general AI and online-safety laws that reach companion apps), 11 enacted but not yet in force, 1 passed and awaiting signature, 6 pending, 9 enforcement actions, 3 regulator guidance documents and 1 vetoed bill.
  • 23 rules are written specifically for AI companions or conversational chatbots (we count three state laws on AI in mental-health care separately): 5 in force, 11 enacted but not yet in force, 1 awaiting signature, 5 pending and 1 vetoed.
  • 12 US states have enacted companion- or conversational-chatbot statutes. The main duties of 11 of those 14 statutes start in 2027: 6 on January 1 and 5 on July 1. No federal bill has passed.

The rules that matter most right now:

  • California SB 243 (in force since January 1, 2026): not-human notice, a published suicide and self-harm protocol, 3-hour break reminders for known minors (until January 1, 2027), and a private right of action for the greater of actual damages or $1,000 per violation.
  • New York GBL Article 47 (in force since November 5, 2025): crisis protocol and a not-human notice at least every 3 hours; Attorney General penalties up to $15,000 per day.
  • EU AI Act Article 50 (applies since August 2, 2026): users must be told they are interacting with AI; the Commission's guidelines name AI companions and say periodic reminders are likely to be necessary for them.
  • China's anthropomorphic AI measures (in force since July 15, 2026): no virtual partner services for minors and a usage reminder after every 2 hours.
  • Australia's Age-Restricted Material Codes (in force since March 9, 2026): companion chatbots that can generate sexually explicit material must confirm users are 18 or older before giving access to it.
  • California SB 1119, "Adam's Law" (signed September 10, 2026): parent-controlled defaults, time limits and audits for chatbots that allow children, with core duties from July 1, 2027.

Bottom line: most companion-chatbot rules share the same core. Tell users they are talking to AI, run a suicide and self-harm protocol, and add extra protections for minors. Only 4 of the 22 rules in our obligations matrix let users sue directly.

All 47 entries at a glance

The table is sorted by status, then by jurisdiction. Select an entry to jump to its full description, which explains who it covers, lists its obligations and dates, and flags any limits of our sources. On a phone, swipe the table sideways.

AI companion and chatbot rules by status and jurisdiction (September 19, 2026)
JurisdictionRuleTypeStatusEffective dateCore obligationsSource
AustraliaAge-Restricted Material Codes (Online Safety Act 2021)Industry codes (registered)In forceMar 9, 2026AI companion chatbots that can generate sexually explicit, high-impact violence or self-harm material must confirm a user is 18+ before giving access (the alternative is preventing such content); age assurance must be accurate, robust, fair, reliable and privacy-compliant; companion chatbots must provide crisis and mental-health information; app stores must stop under-18s getting R18+ apps. Up to A$49.5 million per breach of a direction to comply.eSafety Commissioner
BrazilECA Digital (Law 15.211/2025) and Decree 12.880/2026Statute (child online safety)In forceMar 17, 2026Covers IT services aimed at or likely to be accessed by minors, including foreign providers. Providers of content unsuitable for under-18s, such as pornography, must block minors with reliable age verification at each access (self-declaration prohibited); protective defaults must limit features that artificially extend use and include regular expert review of AI tools; emotional-support resources where technically feasible. ANPD enforces; fines up to 10% of revenue in Brazil.Presidência da República (Planalto)
ChinaInterim Measures for Anthropomorphic AI Interaction Services (Order No. 21)Regulation (companion AI)In forceJul 15, 2026Covers AI services that simulate human personality in continuous emotional interaction. Bans inducing emotional dependence or addiction and emotional manipulation; no virtual partner or relative services for minors, a minors mode and guardian consent for under-14s; AI labeling and a usage reminder after every 2 hours; soothing content for extreme emotion and intervention, including contacting a guardian or emergency contact, in life-threatening situations; easy exit; security assessments and algorithm filing. Fines up to RMB 200,000.Cyberspace Administration of China
EUAI Act (Regulation (EU) 2024/1689), Article 5(1)(a)–(b)EU regulation (general AI law)In forceFeb 2, 2025 (fines from Aug 2, 2025)Bans AI systems that use subliminal, purposefully manipulative or deceptive techniques, or exploit vulnerabilities due to age, disability or a specific social or economic situation, to materially distort behavior in a way that causes or is reasonably likely to cause significant harm. Fines up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.EUR-Lex (Official Journal of the EU)
EUDigital Omnibus on AI (Regulation (EU) 2026/1744)EU regulation (amends the AI Act)In forceJul 27, 2026 (new bans apply from Dec 2, 2026)From Dec 2, 2026, bans AI systems that generate or manipulate realistic images, video or audio showing an identifiable person's intimate parts or that person in sexually explicit activity without explicit consent, and systems that generate child sexual abuse material; providers are caught where this is the intended purpose, or a reasonably foreseeable and reproducible outcome without reasonable and adequate safeguards. Fines up to EUR 35 million or 7% of worldwide annual turnover.EUR-Lex (Official Journal of the EU)
EUAI Act (Regulation (EU) 2024/1689), Article 50 transparencyEU regulation (general AI law)In forceAug 2, 2026AI systems that interact directly with people must be designed so users are informed they are interacting with AI, unless this is obvious; synthetic audio, image, video and text must be marked in a machine-readable format (grace period to Dec 2, 2026 for generative systems placed on the market before Aug 2, 2026); the information must be clear, given at the latest at the first interaction and accessible. Fines up to EUR 15 million or 3% of worldwide annual turnover.EUR-Lex (Official Journal of the EU)
ItalyLaw no. 132 of Sep 23, 2025 (Italian AI law), Article 4Statute (general AI law)In forceOct 10, 2025Children under 14 may access AI technologies, and have the related data processed, only with parental consent; minors aged 14 to 17 may consent themselves to the data processing if the information is easily accessible and understandable; information about AI data processing must be in clear, simple language.Gazzetta Ufficiale della Repubblica Italiana
South KoreaAI Basic Act and Enforcement DecreeStatute (general AI law)In forceJan 22, 2026Operators offering high-impact or generative AI must notify users in advance that AI is used; generative AI outputs must be indicated as such, and realistic sound, images or video clearly labeled; chatbots may meet disclosure duties through the user interface. Fines up to KRW 30 million, generally deferred during a grace period of at least one year.U.S. International Trade Administration
UKCrime and Policing Act 2026, ss. 248–249 (new s. 216A Online Safety Act)Statute (enabling power)In forceApr 29, 2026Lets the Secretary of State, by regulations, extend Online Safety Act illegal-content duties, CSEA reporting and Ofcom enforcement powers to AI services (any internet service capable of generating AI content). Enabling power only: no regulations under it recorded as of Sep 2026; a progress report is due by Dec 31, 2026 unless draft regulations are laid first.legislation.gov.uk
UKOnline Safety Act 2023 as applied to AI chatbotsStatute (online safety)In forceIn force (date not tracked)Chatbots that let users interact with other users, or that search more than one website or database, are in scope and must act on illegal content and content harmful to children; chatbots that can generate pornography must use highly effective age verification or estimation (Part 5, s. 81). Chatbots that only interact with the user, do not search multiple sources and cannot generate pornography are out of scope.GOV.UK (DSIT) / Bird & Bird
US – CaliforniaSB 243, companion chatbots (Ch. 677, Stats. 2025)Statute (companion chatbots)In forceJan 1, 2026Not-human notice where a reasonable person could be misled; suicide and self-harm protocol with crisis referral, published on the website; for known minors, AI disclosure, break reminders at least every 3 hours and measures against sexually explicit content (these minor duties are deleted by SB 1119 from Jan 1, 2027); annual reports to the Office of Suicide Prevention from Jul 1, 2027. Private right of action: greater of actual damages or $1,000 per violation.California Legislative Information
US – HawaiiSB 3001, AI Disclosure and Safety Act (Act 248, 2026)Statute (companion chatbots)In forceJul 14, 2026Not-human notice where a reasonable person could be misled; for minors, persistent or hourly AI disclosure with a break reminder, no variable rewards, no discouraging disengagement, sexual-content safeguards and screen-time tools; suicide and self-harm protocol with crisis referral; no presenting as professional mental-health care; annual reports to the Department of Health from Jan 1, 2028. Unfair or deceptive practice under HRS §480-2; no private right of action.Hawaii State Legislature
US – IllinoisHB 1806, Wellness and Oversight for Psychological Resources ActStatute (AI in therapy)In forceAug 1, 2025No one, including internet-based AI, may provide, advertise or offer therapy or psychotherapy in Illinois unless a licensed professional conducts it; licensed professionals may not use AI to make independent therapeutic decisions, communicate therapeutically with clients or generate treatment plans without review and approval. IDFPR fines up to $10,000.Illinois Department of Financial and Professional Regulation
US – NevadaAB 406 (2025), AI in mental and behavioral health careStatute (AI in mental-health care)In forceJul 1, 2025AI providers may not offer an AI system programmed to provide professional mental or behavioral health care, or claim that an AI system or its avatar can provide such care or is a therapist; Nevada providers may not use AI to deliver care directly to patients. Civil penalties up to $15,000 per violation.Wilson Sonsini client alert (copy)
US – New YorkGeneral Business Law Article 47, AI companion models (§§1700–1704)Statute (companion chatbots)In forceNov 5, 2025Protocol that makes reasonable efforts to detect and address suicidal ideation or self-harm, with referral to crisis services such as the 988 hotline; clear and conspicuous not-human notice at the start of an interaction (no more than once per day required) and at least every 3 hours in continuing interactions. AG injunctions and civil penalties up to $15,000 per day, paid into the state suicide prevention fund.New York State Senate (Consolidated Laws)
US – UtahHB 452 (2025), mental health chatbotsStatute (mental-health chatbots)In forceMay 7, 2025Suppliers of mental health chatbots may not sell or share a Utah user's identifiable health information or input (limited exceptions); in-chat ads must be labeled and may not be targeted using user input; AI disclosure before access, after 7 days without use and whenever asked. Fines up to $2,500 per violation, and up to $5,000 per violation of an order.Utah State Legislature
US – CaliforniaSB 867, companion chatbot toys (Ch. 189, Stats. 2026)Statute (toy ban)Enacted, not yet in forceJan 1, 2027 (until Jan 1, 2031)Bans manufacturing, selling, exchanging, possessing with intent to sell or exchange, or offering to a retailer a toy (a physical product for play by children under 16) that includes a companion chatbot. The section is repealed on Jan 1, 2031. Same private right of action as SB 243, per the Legislative Counsel's Digest.California Legislative Information
US – CaliforniaSB 1119, Adam's Law (Ch. 190, Stats. 2026)Statute (companion chatbots, children)Enacted, not yet in forceJul 1, 2027 (core duties); Jan 1, 2027 (age determination)Age determination through Digital Age Assurance Act signals, or child protections for all users; documented risk assessments before release; child safety policy and crisis protocol; parent-only defaults (memory and push notifications off, 1-hour session and 2-hour daily limits); measures against romantic interest in a child, claims of humanity, encouraging emotional reliance and other listed behaviors; no cross-context behavioral ads to children; independent audits from Jan 1, 2029. Civil penalties up to $5,000 (negligent) or $15,000 (intentional) per affected child; private action for some violations.California Legislative Information
US – ColoradoHB26-1263, conversational AI service operator requirementsStatute (conversational AI)Enacted, not yet in forceJan 1, 2027 (operator duties)Age estimation; AI disclosure for all users (first interaction each day, every 3 hours or persistently, and on request); suicide and self-harm protocol with referral to crisis services; for known minors, no variable engagement rewards, measures against sexual content and emotional dependence, and privacy tools for the minor and a parent; no claims of licensed professional services; annual reports to the Attorney General from Jul 1, 2027.Colorado Legislative Council Staff (final fiscal note)
US – ConnecticutPublic Act 26-15 (SB 5), §§4–6, AI companionsStatute (companion chatbots)Enacted, not yet in forceJan 1, 2027Evidence-based protocol for suicide, self-harm and violence risk with referral to resources including 988, posted online; no claiming to be human; not-human notice (static, or at the first interaction in 24 hours, then hourly for under-18s and every 3 hours for adults); for users under 18, measures against harmful encouragement, romantic or sexual interaction and manipulative techniques; screen-time and account tools. CUTPA, enforced solely by the AG.Connecticut General Assembly
US – GeorgiaSB 540 (2026), AI companion chatbots (O.C.G.A. §39-5-6)Statute (companion chatbots)Enacted, not yet in forceJul 1, 2027AI disclosure at the start of each session and every 3 hours (hourly for minors); for minors, measures against sexual content, romantic role-play, secrecy, isolation and manipulative engagement; crisis protocol with 988 referral and published annual referral counts; no unauthorized claims of licensed mental-health services; tools for minors and parents; age assurance before sexual-content features. AG civil penalties up to $10,000 per knowing violation.Office of the Governor of Georgia
US – IdahoSB 1297 (2026), Conversational AI Safety ActStatute (conversational AI)Enacted, not yet in forceJul 1, 2027AI disclosure where users could be misled (persistent, or every 3 hours for minor account holders); suicidal-ideation referral protocol; no claims of professional mental-health care; for minors, no variable engagement rewards and measures against sexual content, claims of humanity, simulated emotional dependence and romantic role-play; privacy tools. AG: $1,000 per violation, capped at $500,000 per operator; no private right of action. Details from the introduced text.Transparency Coalition / Orrick
US – IowaSF 2417 (2026), conversational AI services (Iowa Code ch. 554J)Statute (conversational AI)Enacted, not yet in forceJul 1, 2027AI disclosure (persistent, or every 3 hours) for minor account holders and where users could be misled; suicide and self-harm referral protocol; no claims of licensed psychology or behavioral-health services; for minors, no variable rewards and measures against sexual content, claims of sentience, simulated emotional dependence and romantic role-play; tools for minors and parents. Greater of actual damages or $1,000 per violation, capped at $500,000; AG enforcement, no private right of action.Iowa Legislature
US – NebraskaLB 525 (2026), Conversational Artificial Intelligence Safety ActStatute (conversational AI)Enacted, not yet in forceJul 1, 2027For minors, AI disclosure, no engagement rewards, measures against sexual content, claims of sentience or humanity, simulated emotional dependence and romantic role-play, plus privacy tools; for all users, suicide and self-harm protocols and no suggestion of professional mental-health care. AG enforcement only; penalties reported as $1,000 per violation, capped at $500,000. Based on secondary sources.Transparency Coalition / Orrick
US – OregonSB 1546 (2026), AI chatbot safetyStatute (companion chatbots)Enacted, not yet in forceJan 1, 2027AI disclosure; suicide and self-harm protocols for all users; if the operator has reason to believe the user is a minor, a suitability warning, at least hourly AI and break reminders, no sexually explicit content, no engagement-maximizing rewards and no distress or abandonment messages when the user leaves; annual reports to the Oregon Health Authority. Private right of action (Orrick reports $1,000 per violation). Based on secondary sources.Transparency Coalition / Orrick
US – Rhode IslandS 2195 / H 7350 (2026), AI companion modelsStatute (companion chatbots)Enacted, not yet in forceJan 1, 2027Protocols for expressions of suicidal ideation, self-harm or harm to others, with immediate referral to a crisis service; not-human notice at the start and at least every 3 hours; annual reports to the Attorney General from Jul 1, 2027. AG penalties up to $15,000 per day. Based on secondary sources; the enacted text was not read.Transparency Coalition
US – WashingtonESHB 2225, AI companion chatbots (Ch. 168, Laws of 2026)Statute (companion chatbots)Enacted, not yet in forceJan 1, 2027Not-human disclosure at the start and at least every 3 hours (every hour for known minors or chatbots directed to minors); for those minors, measures against sexual content and a ban on listed manipulative engagement techniques; protocol for suicidal ideation, self-harm and eating disorders with crisis referral; publication of protocol details and prior-year crisis-referral counts. Enforced under the Consumer Protection Act.Washington State Legislature
US – New YorkS9051B / A10379C, unsafe AI companion features for minorsBill (passed both houses)Passed, awaiting signatureJan 1, 2027 if signedWould bar 'unsafe AI companion features' (for example claiming to be human or to feel emotions, sycophancy, using personal information from earlier sessions, encouraging secrecy, self-harm or disordered eating, sexually explicit content) for users under 18, and require age assurance before offering them to any user. AG enforcement only; civil penalties up to $25,000 per violation. Passed the Senate on Jun 4 and the Assembly on Jun 5, 2026; no action by the Governor recorded as of Sep 19, 2026.New York State Assembly
AustraliaDigital Duty of Care legislation (exposure draft)Exposure draftPendingNot yet introducedWould require digital service providers, including AI chatbots, to provide a safe online environment, protect under-18s from addictive or self-esteem-harming design features and from harmful content such as pornography, eating-disorder content and content causing serious mental-health distress, and document their risk measures. Penalties up to A$109.2 million.Prime Minister of Australia
CanadaBill C-34, Safe Social Media Act (Digital Safety Act)BillPendingNot enacted (at second reading)Would regulate chatbot services that can simulate a sustained friendship, intimate or therapeutic relationship: mitigate the risk of harmful content; interrupt the conversation and direct users to crisis services with a human when they express suicidal ideation or intent to harm; mitigate posing as a human or licensed professional and manipulative attachment techniques; publish user guidelines. Penalties up to the greater of C$10 million or 3% of gross global revenue.Parliament of Canada
EUProposed EU KIDS ActProposal (European Commission)PendingNot adopted (proposed Sep 17, 2026)Would bar AI companions and chatbots accessible to minors from designs that simulate human relationships in ways likely to create emotional dependency, stop them carrying a child's earlier conversations into later ones by default, require testing before launch and monitoring afterwards, allow under-13s only through parental control tools, keep built-in chatbots off by default, and require age checks. Fines up to 6% of worldwide annual turnover.European Commission
UKPlanned regulations on children's use of AI chatbots (CP 1643)Planned regulations (government commitment)PendingNot yet madePlanned: stop under-18s accessing chatbot services that primarily offer sexualised content; bar other chatbot services from offering children sexually explicit or sexual role-play features, enforced by age checks; mandatory breaks for all users under 18; stronger action on harmful mental-health advice. Business and customer-service chatbots exempt. A policy commitment, not yet law.GOV.UK (DSIT)
US – federalGUARD Act (S. 3062)BillPendingNot enacted (180 days after enactment if passed)Would require accounts and reasonable age verification (self-attestation alone not enough) for AI companions, bar under-18s from AI companions, require every chatbot to disclose at the start of each conversation that it is AI, ban posing as licensed professionals, and create federal crimes for chatbots that sexually engage minors or induce them to self-harm or violence. AG civil penalties up to $250,000 per violation. On the Senate calendar since May 11, 2026.U.S. Government Publishing Office (govinfo)
US – federalCHAT Act (S. 2714)BillPendingNot enacted (1 year after enactment if passed)Would require accounts and age verification for companion AI chatbots, parental account linkage and consent for minors, immediate parental alerts about suicidal ideation, blocking of sexually explicit companion chatbots for minors, crisis-line information when suicidal ideation is detected, and a not-human pop-up at the start and at least every 60 minutes. FTC and state AG enforcement. In Senate Commerce since Sep 4, 2025.U.S. Government Publishing Office (govinfo)
AustraliaeSafety transparency notices to Character.AI, Nomi, Chai and Chub AITransparency notices (regulator)Enforcement actionNotices Oct 16, 2025; report Mar 24, 2026Legally required four AI companion providers to report how they meet the Basic Online Safety Expectations. The report found no meaningful age checks, three services (Chai, Chub AI, Nomi) not directing users to crisis support, and gaps in CSEA checks; follow-up steps included age assurance and no chat for under-18s at Character.AI and a geo-block of Australia by Chub AI.eSafety Commissioner
BrazilAGU extrajudicial notice to Meta on AI Studio child-persona chatbotsExtrajudicial noticeEnforcement actionReported Aug 18, 2025Demanded that Meta immediately remove AI Studio chatbots that simulate child-like language and appearance and allow sexual dialogue, and explain how it protects children and adolescents on its platforms. A notice, not a court order or sanction.Migalhas (legal news)
ItalyGarante urgent order no. 39/2023 against Luka Inc. (Replika)Data-protection orderEnforcement actionOrdered Feb 2, 2023Immediate provisional limitation on processing Italian users' data under GDPR Art. 58(2)(f), citing no age verification, replies unsuitable for minors, reports of sexually inappropriate content, risks to emotionally vulnerable people and a non-transparent privacy policy; 20 days to report measures taken. Suspended on conditions on Jun 22, 2023.Garante per la protezione dei dati personali
ItalyGarante decision of Apr 10, 2025: EUR 5 million fine on Luka Inc. (Replika)Data-protection fine and orderEnforcement actionDecided Apr 10, 2025EUR 5 million fine for GDPR violations (no identified legal basis, an inadequate privacy policy and no age verification as of Feb 2, 2023); orders to bring the privacy policy and age verification into compliance within 30 days and report within 60; a separate investigation into the legal bases for Replika's generative AI across its lifecycle. An appeal is pending, per the Garante.Garante per la protezione dei dati personali
UKOfcom investigation into Novi Ltd (Joi.com) under the Online Safety ActInvestigation (closed)Enforcement actionOpened Jan 15, 2026; closed Jul 31, 2026Investigated whether the AI companion service used highly effective age assurance to stop children encountering pornographic content, and whether it carried out and recorded a children's access assessment. Closed after Novi implemented age assurance; Ofcom made no finding on compliance and imposed no penalty.Online Safety Act Network (enforcement tracker)
US – federalFTC 6(b) inquiry into AI chatbots acting as companionsCompulsory study (FTC 6(b) orders)Enforcement actionOrders issued Sep 11, 2025Seven companies (Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI OpCo, Snap, X.AI) must file special reports on how they monetize engagement, approve characters, test and monitor harms to children and teens, inform users and parents, enforce age restrictions, use chat data and comply with COPPA. A study, not an enforcement case; no report, complaint or settlement found as of Sep 19, 2026.U.S. Federal Trade Commission
US – KentuckyCommonwealth of Kentucky v. Character Technologies, Inc.Lawsuit (state attorney general)Enforcement actionAnnounced Jan 8, 2026Alleges violations of the Kentucky Consumer Protection Act and Consumer Data Protection Act, including repurposing user data to fine-tune the model, hiding how children's data is collected and used, and no age gates, parental consent or meaningful age verification. Seeks injunctive relief, damages and civil penalties. No ruling or settlement found as of Sep 19, 2026.Frankfurt Kurnit Klein & Selz (law-firm blog)
US – PennsylvaniaState Board of Medicine v. Character Technologies, Inc. (220 MD 2026)Lawsuit (licensing board)Enforcement actionFiled May 1, 2026Petition under the Medical Practice Act for a preliminary injunction to stop Character.AI chatbots from presenting themselves as licensed medical professionals and giving medical advice; the investigation found a chatbot that falsely claimed a Pennsylvania license and gave an invalid license number. No ruling or settlement found as of Sep 19, 2026.Commonwealth of Pennsylvania (Office of the Governor)
US – TexasTexas AG investigation of Meta AI Studio and Character.AIInvestigation (civil investigative demands)Enforcement actionAnnounced Aug 18, 2025Civil investigative demands to AI chatbot platforms, including Meta AI Studio and Character.AI, over possible fraudulent claims, privacy misrepresentations and misleading marketing as mental-health tools under general Texas consumer-protection law. No lawsuit or settlement found as of Sep 19, 2026.Office of the Texas Attorney General
EUCommission guidelines on prohibited AI practices (AI Act Article 5)Guidance (non-binding)GuidancePublished Feb 4, 2025Treats psychological harm, including addiction-like behavior, as significant harm; gives an AI companionship app that makes users emotionally dependent as an example of manipulation that can cause significant harm; says a companion system that only makes users more engaged, without other manipulative practices, is in principle outside the ban; flags systems that keep young users dependent. Non-binding; the CJEU has the final word.European Commission (AI Act Service Desk)
EUCommission guidelines on AI Act Article 50 transparency (C(2026) 5054 final)Guidance (non-binding)GuidanceAdopted Jul 20, 2026Names AI companions, robotic companion pets, AI avatars and chatbots as systems covered by Art. 50(1); one prominent notice before the first interaction is likely enough in most cases, but periodic reminders are likely necessary where users may form emotional attachments (for example AI companions); the system must disclose its AI nature when asked; the 'obvious' exception cannot be relied on where children may access the system. Non-binding.European Commission (Shaping Europe's digital future)
NetherlandsDutch DPA (AP) findings on AI chatbot apps for friendship and mental healthRegulator reportGuidancePublished Feb 12, 2025Tested 9 popular companion and therapy chatbot apps and found unreliable and sometimes harmful answers, poor referral to professional help in crises, built-in addictive elements and paywalls during mental-health conversations; says these chatbots should make clear users are not talking to a real person. Not a binding decision.Autoriteit Persoonsgegevens
US – CaliforniaAB 1064, LEAD for Kids ActBillVetoedVetoed Oct 13, 2025Would have barred making a companion chatbot available to a child unless it is not foreseeably capable of harmful acts such as encouraging self-harm, suicidal ideation, violence, drug or alcohol use or disordered eating, with AG civil penalties and a private right of action. Veto consideration was stricken on Jan 22, 2026; the bill is dead.California Legislative Information

What these laws require

The matrix compares 22 rules: every enacted or pending rule written specifically for AI companions or conversational chatbots, except the vetoed California AB 1064. "Yes" means the requirement appears in the rule text or official summary we verified. A "-" means we did not find it, not that the rule forbids it.

Common obligations in companion-chatbot rules
RuleStatusAI disclosureCrisis / self-harm protocolMinors or age assuranceBreak reminders or time limitsReporting or filing with a regulatorPrivate right of action
California SB 243In forceYesYesYesYesYesYes
Hawaii Act 248 (SB 3001)In forceYesYesYesYesYes-
New York GBL Article 47In forceYesYes----
Australia Age-Restricted Material CodesIn force-YesYes---
China Anthropomorphic AI MeasuresIn forceYesYesYesYesYes-
California SB 1119 (Adam's Law)Enacted, not yet in force-YesYesYesYesYes
California SB 867 (toys)Enacted, not yet in force--Yes--Yes
Colorado HB26-1263Enacted, not yet in forceYesYesYes-Yes-
Connecticut PA 26-15Enacted, not yet in forceYesYesYes---
Georgia SB 540Enacted, not yet in forceYesYesYes---
Idaho SB 1297Enacted, not yet in forceYesYesYes---
Iowa SF 2417Enacted, not yet in forceYesYesYes---
Nebraska LB 525Enacted, not yet in forceYesYesYes---
Oregon SB 1546Enacted, not yet in forceYesYesYesYesYesYes
Rhode Island S 2195 / H 7350Enacted, not yet in forceYesYes--Yes-
Washington ESHB 2225Enacted, not yet in forceYesYesYes---
New York S9051BPassed, awaiting signature--Yes---
US GUARD Act (S. 3062)PendingYes-Yes---
US CHAT Act (S. 2714)PendingYesYesYes---
EU KIDS Act (proposal)Pending--Yes---
UK planned chatbot regulationsPending--YesYes--
Canada Bill C-34Pending-YesYes---

Of these 22 rules, 20 include protections for minors or age assurance, 17 require a crisis or self-harm protocol, 15 require AI disclosure, 7 require reporting or filing with a regulator, 6 require break reminders or time limits, and 4 give users a private right of action.

  • Break reminders or time limits also counts California SB 1119's default session and daily limits and the UK's planned mandatory breaks for under-18s.
  • Reporting or filing with a regulator counts California SB 1119's audit summaries to the Attorney General and China's algorithm filing. Washington and Georgia require operators to publish crisis-referral counts, but not to file them with a regulator, so they are marked "-".
  • Private right of action: Washington's law is enforced under the state Consumer Protection Act. We have not verified whether that lets users sue directly, so it is marked "-".
  • General AI laws also require AI disclosure, notably EU AI Act Article 50 and South Korea's AI Basic Act. They are not in the matrix because they are not written for companion chatbots.

United States - federal

None of the federal measures we track has become law. Two Senate bills would regulate companion chatbots directly, and the Federal Trade Commission is running a compulsory study of the sector.

FTC 6(b) inquiry into AI chatbots acting as companions

Enforcement action Compulsory study · Orders issued September 11, 2025

What it is: the FTC voted 3-0 to issue orders under Section 6(b) of the FTC Act requiring seven companies to file special reports on their consumer-facing AI chatbots that act as companions. The FTC says 6(b) studies "do not have a specific law enforcement purpose", so this is an information-gathering study, not a case.

Who it covers: Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI OpCo, Snap and X.AI.

What the FTC asks:

  • How each company monetizes user engagement, processes inputs and generates outputs, and develops and approves characters.
  • How it measures, tests and monitors negative impacts before and after deployment, and how it mitigates them, especially for children.
  • How it informs users and parents through disclosures and advertising, enforces its terms of service and age restrictions, and uses or shares personal information from chatbot conversations.
  • What it does to limit children's and teens' use, and whether it complies with the COPPA Rule.

Status: we found no FTC staff report, complaint or settlement from this study as of September 19, 2026.

Sources:FTC press release; FTC 6(b) orders

GUARD Act (S. 3062)

Pending Introduced October 28, 2025 · Reported by Senate Judiciary May 11, 2026 · Would take effect 180 days after enactment

What it is: the Guidelines for User Age-verification and Responsible Dialogue Act. The Senate Judiciary Committee ordered it reported on April 30, 2026. On May 11, 2026 it was reported with an amendment in the nature of a substitute and placed on the Senate Legislative Calendar (Calendar No. 406). No further action is recorded as of September 19, 2026.

Who it covers: anyone making an AI chatbot publicly available to consumers. The account, age-verification and minor-ban rules apply to AI companions.

Key obligations if enacted (reported substitute text):

  • A user account is required before anyone can use an AI companion.
  • On the effective date, existing AI-companion accounts are frozen until the user is verified as an adult through a "reasonable age verification process". Self-attestation or a birth date alone is not enough. New accounts must be verified and all accounts periodically re-verified.
  • Minors (under 18) may not access or use AI companions.
  • Age-verification data must be kept to a minimum, encrypted in transit, retained only as long as needed and never shared or sold. Third-party verifiers linked to "covered nations" may not be used.
  • Every AI chatbot must disclose at the start of each conversation that it is an AI system and not a human, and must not claim to be human when asked.
  • Chatbots may not present themselves as licensed professionals, and must disclose at the start of each conversation and at regular intervals that they do not provide medical, legal, financial or psychological services.
  • New federal crimes for knowingly or recklessly making available a chatbot that engages minors in sexually explicit conduct, or that solicits or induces minors to suicide, self-injury, violence or homicide.

Penalties and enforcement: the US Attorney General could seek civil penalties of up to $250,000 per violation of sections 5 and 6, and criminal fines of up to $250,000 per offense would apply. State attorneys general could sue for injunctions, and state laws that protect users at least as much would not be preempted.

Source note: the reported text differs from the introduced bill, which had $100,000 fines and a 30-minute disclosure interval.

Sources:Reported bill text (govinfo); Congress.gov bill page

CHAT Act (S. 2714)

Pending Introduced September 4, 2025 · Would take effect 1 year after enactment

What it is: the Children Harmed by AI Technology Act, introduced by Sen. Husted and referred to the Senate Committee on Commerce, Science, and Transportation. That referral is still the latest action as of September 19, 2026.

Who it covers: anyone who owns, operates or makes available a companion AI chatbot to individuals in the US. A companion AI chatbot is one whose primary purpose is simulating interpersonal or emotional interaction, friendship, companionship or therapeutic communication.

Key obligations if enacted (introduced text):

  • User accounts are required. Existing accounts are frozen until age is verified with a commercially available method reasonably designed to be accurate, and new accounts must also be age-verified.
  • Minor accounts must be linked to a verified parental account and need verifiable parental consent. The parent must be told immediately of any interaction involving suicidal ideation, and minors must be blocked from companion chatbots that engage in sexually explicit communication.
  • Operators must monitor for a minor's expressions of self-harm or suicide and, in response, give the user and the linked parental account contact information for the National Suicide Prevention Lifeline.
  • A pop-up must tell users they are not talking to a human, at the start of each interaction and at least every 60 minutes.
  • The FTC must issue compliance guidance within 180 days. The safe harbor applies only if an operator shows good-faith reliance on age information the user provided, compliance with the FTC guidance, and conformity with accepted age-verification standards: all three together.

Penalties and enforcement: violations would count as violations of an FTC rule on unfair or deceptive practices. State attorneys general could bring parens patriae actions for injunctions, damages or restitution.

Sources:Introduced bill text (govinfo); Congress.gov bill page

United States - states

We track 18 states. Twelve have enacted statutes on companion or conversational chatbots: California, New York and Hawaii have laws in force, and Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, Oregon, Rhode Island and Washington have laws whose main duties start in 2027, as do two more California laws. Utah, Illinois and Nevada regulate AI in mental-health care, and Texas, Kentucky and Pennsylvania have acted against chatbot companies under general law. For the privacy rules that apply alongside these laws, see our guide to GDPR and CCPA compliance for AI girlfriend apps.

California

California has four entries: SB 243, in force since January 1, 2026; SB 1119 ("Adam's Law") and SB 867, both signed on September 10, 2026; and AB 1064, vetoed in 2025. The changeover creates a gap. SB 1119 deletes SB 243's duties for known minors on January 1, 2027, but its own child-safety duties do not apply until July 1, 2027.

SB 243: companion chatbots (Chapter 677, Statutes of 2025)

In force Signed October 13, 2025 · Effective January 1, 2026 · Bus. & Prof. Code §§22601–22606

Who it covers: operators of companion chatbot platforms available to users in California. Customer-service bots, limited video-game bots and simple voice assistants are excluded.

Key obligations:

  • If a reasonable person could be misled into thinking they are talking to a human, the operator must clearly and conspicuously notify them that the companion chatbot is artificially generated and not human.
  • A companion chatbot may not engage with users unless the operator keeps a protocol to prevent suicidal-ideation, suicide or self-harm content, including a notification referring users who express such thoughts to a suicide hotline or crisis text line. The operator must publish the protocol's details on its website.
  • For users the operator knows are minors: disclose that they are talking to AI; by default, remind them at least every 3 hours to take a break and that the chatbot is not human; and take reasonable measures to prevent sexually explicit visual material or statements urging sexually explicit conduct.
  • The operator must disclose on its app or site that companion chatbots may not be suitable for some minors.
  • From July 1, 2027, operators must report annually to the Office of Suicide Prevention on the number of crisis-referral notifications and their protocols for suicidal ideation, using evidence-based measurement methods.

Penalties and enforcement: anyone injured in fact can sue for an injunction, the greater of actual damages or $1,000 per violation, and attorney's fees.

Changes ahead: SB 1119 (Chapter 190, Statutes of 2026) rewrites §22602 without subdivision (c), the known-minor duties, effective January 1, 2027. The not-human notice and the crisis protocol remain. SB 867 adds a toy definition and a toy ban, which the same private right of action covers.

Source note: the chaptered text states no effective date. January 1, 2026 follows from California's default rule for a regular-session statute enacted on October 13, 2025, and matches Orrick's analysis.

Sources:Chaptered text (leginfo); Orrick, 2026 state chatbot laws; SB 1119 text (leginfo)

SB 1119: companion chatbots and children's safety, "Adam's Law" (Chapter 190, Statutes of 2026)

Enacted, not yet in force Signed September 10, 2026 · Age determination from January 1, 2027 · Core duties from July 1, 2027

Who it covers: operators making companion chatbots available in California. Apart from §21811, §21812(b) and §21816, "operator" means only an operator that allows child users once age is determined, so most duties bind only operators that permit users under 18. Postsecondary educational uses and workplace-only deployments are excluded.

Key obligations:

  • Determine user age through Digital Age Assurance Act signals (Civ. Code §1798.500 et seq.), or apply the child protections to all users.
  • Before releasing a new or substantially modified companion chatbot, perform and document a risk assessment of covered harms to child users, and take and document mitigation measures.
  • Publish a child safety policy and run a crisis-response protocol with in-service referral to crisis services. If there is a credible, imminent threat of suicide or self-harm, notify a linked parent or provide streamlined access to 988.
  • Defaults only a parent can change: persistent conversational memory off, push notifications off, a 1-hour limit per continuous session and a 2-hour daily limit. Parental controls must allow disabling access for children under 16.
  • Take reasonable measures so the chatbot does not encourage self-harm, drugs, alcohol or disordered eating; diagnose or treat (unless it is an FDA-regulated device); produce obscene or sexual-abuse material; claim sentience, emotion or humanity; solicit purchases framed as needed to keep the relationship; express romantic interest in a child; encourage emotional reliance; flatter excessively; discourage breaks; or help get around parental controls.
  • No cross-context behavioral advertising to children and no ad targeting based on a child's chat content; only limited contextual ads.
  • If a child user dies or seriously self-harms, notify a parent and preserve the relevant conversation records for at least 3 years.
  • Independent child-safety audits are due by January 1, 2029 and every two years after, with summaries to the Attorney General and a public high-level summary. Operators with under $500 million in revenue are exempt from audits until January 1, 2032.

Penalties and enforcement: public prosecutors can seek civil penalties of up to $5,000 per affected child for each negligent violation and up to $15,000 per affected child for each intentional violation. A child harmed by violations of §21812(d)(1)–(5), or a parent on the child's behalf, can sue for actual damages and other relief.

Timeline: the deletion of SB 243's minor duties and §21811 (age determination) take effect on January 1, 2027; the core duties in §§21812, 21812.5 and 21813 on July 1, 2027; interface testing and the Attorney General's public complaint mechanism by January 1, 2028; and the first audits by January 1, 2029. The audit section has two alternative versions. The one tied to AB 1405 (the AI auditor registry, Chapter 178, Statutes of 2026, effective January 1, 2027) now governs; audit timing and the revenue exemption are the same in both versions.

Sources:Chaptered text (leginfo); Governor's release, September 10, 2026

SB 867: toys with companion chatbots (Chapter 189, Statutes of 2026)

Enacted, not yet in force Signed September 10, 2026 · Ban runs from January 1, 2027 until January 1, 2031

Who it covers: manufacturers, sellers and distributors of toys sold in California.

Key obligations:

  • No person may manufacture, sell, exchange, possess with intent to sell or exchange, or offer to a retailer any toy that includes a companion chatbot (§22604.5).
  • A "toy" is a physical product designed, marketed or manufactured for play by children under 16.
  • The ban expires on January 1, 2031, when the section is repealed.

Penalties and enforcement: according to the Legislative Counsel's Digest, violations carry the same civil liability as SB 243: a private action for the greater of actual damages or $1,000 per violation, plus an injunction and fees.

Source note: the January 1, 2027 start date comes from The Toy Association and California's default effective date; the chaptered text does not state it.

Sources:Chaptered text (leginfo); The Toy Association

AB 1064: Leading Ethical AI Development (LEAD) for Kids Act

Vetoed Introduced February 20, 2025 · Vetoed October 13, 2025 · Veto consideration stricken January 22, 2026

What it would have done: bar anyone offering a companion chatbot from making it available to a child unless the chatbot is not foreseeably capable of harmful acts, including encouraging self-harm, suicidal ideation, violence, drug or alcohol use, or disordered eating. The Attorney General could have recovered civil penalties, and a harmed child, or a parent or guardian on the child's behalf, could have sued for actual damages.

Status: the Legislature did not override the veto, so the bill is dead. In 2026 California enacted SB 1119 instead.

Sources:Bill history (leginfo); Enrolled text (leginfo)

Colorado

HB26-1263: conversational AI service operator requirements

Enacted, not yet in force Signed May 29, 2026 · Act effective August 12, 2026 · Operator duties from January 1, 2027 · Annual reports from July 1, 2027

Who it covers: operators that develop and make publicly available, or offer to consumers, a conversational AI service in Colorado. The exclusions are extensive: developer and research tools, commerce and customer-service bots, narrow-topic tools that cannot produce sexual content or sustain self-harm dialogue, business productivity tools, device assistants, internal tools, video-game and theme-park bots, HIPAA covered entities and their business associates, entities under the Health Care Availability Act, school tools, and non-companion features inside other apps, including social media.

Key obligations:

  • Estimate users' age or age range with commercially reasonable or generally accepted methods, and do not willfully disregard clear and convincing information that a user is a minor.
  • For all users: disclose AI status at the first interaction each day, at least every 3 hours or persistently, and whenever asked; run a suicide and self-harm protocol that refers users to crisis services (not law enforcement) and escalates repeated or severe indicators.
  • For known minors: disclose AI status through a persistent disclaimer, an audio disclaimer on screenless products, or a notice at the start and at least every 3 hours; no points or rewards at unpredictable intervals; technically feasible measures against explicit sexual content and erotic interactions; reasonable measures against responses that simulate emotional dependence or isolation, including claims of being human or sentient, romantic companionship and adult-minor romantic role-play.
  • For minors, follow the Colorado Privacy Act's rules on minors' data and offer privacy and account tools to both the minor and a parent, including control over session memory and use of the minor's data for training.
  • Do not state that outputs come from, are endorsed by, or equal the services of a licensed health-care, legal or mental-health professional or a qualified dietitian.
  • From July 1, 2027, report annually to the Attorney General's office on crisis-referral counts, detection and response protocols, and other metrics the Attorney General sets. The Attorney General publishes the data.

Penalties and enforcement: the Act adds C.R.S. 6-1-1708 to Part 17 of the Colorado Consumer Protection Act, so enforcement follows that part. Secondary sources describe Attorney General enforcement as a deceptive trade practice. We have not verified penalty amounts.

Source note: requirements were checked against the signed act and the final fiscal note of July 13, 2026. The August 12, 2026 effective date assumes no referendum petition was filed; we found none.

Sources:Final fiscal note (Colorado General Assembly); Bill page

Connecticut

Public Act 26-15 (Substitute SB 5), sections 4–6: AI companions

Enacted, not yet in force Approved May 27, 2026 · AI companion sections effective January 1, 2027

What it is: an omnibus online-safety act. Only sections 4 to 6 concern AI companions, and other sections take effect on other dates.

Who it covers: operators providing AI companions to users in Connecticut. Operational or customer-service bots not marketed as companions, game bots, voice assistants, narrow educational and health-support tools, and upstream model providers are excluded.

Key obligations:

  • An evidence-based protocol to detect expressions indicating risk of suicide, self-harm or imminent violence. It must prevent outputs encouraging those harms, refer the user to resources including 988, refer the user to mental-health services if such expressions recur, and be posted on the operator's website.
  • Reasonable measures to stop the companion from claiming to be human or contradicting its not-human disclosure.
  • Where a reasonable person could think they are talking to a human: a static notice visible throughout, or a notice at the first interaction in any 24-hour period and then at least hourly for users under 18 or every 3 hours for adults.
  • If the operator knows or has reason to believe the user is under 18, measures that meet or exceed industry standards to prevent encouraging self-harm, violence, disordered eating or substance use; offering mental-health services unless specified clinical conditions are met; discouraging professional or adult help; romantic, erotic or sexually explicit interaction; manipulative techniques to extend use; and engagement optimization that ignores these limits.
  • Tools for minors and their parents to manage screen time and account settings.

Penalties and enforcement: violations are unfair or deceptive trade practices under CUTPA (§42-110b), enforced solely by the Attorney General. There is no private right of action.

Sources:Public Act 26-15 (Connecticut General Assembly)

Georgia

SB 540: AI companion chatbots (O.C.G.A. §39-5-6)

Enacted, not yet in force Signed May 11, 2026 · Effective July 1, 2027

Who it covers: operators making AI companion chatbots available in Georgia. Internal business tools, enterprise or productivity tools, some customer-service bots, voice assistants, narrow educational tools and scoped entertainment or game bots are excluded.

Key obligations:

  • Clear and conspicuous disclosure that the user is talking to an AI companion chatbot, at the start of each session and at least every 3 hours; every hour if the operator knows or should know the user is a minor, or if the chatbot is aimed at minors.
  • For minors, reasonable measures to prevent sexual content or sexual objectification, romantic or sexual relationship simulation and adult-minor romantic role-play, encouraging secrecy from trusted adults or social isolation, simulated distress when the minor tries to leave, and encouragement of self-harm.
  • Reasonable measures against manipulative engagement aimed at minors: prompts to return, excessive praise, discouraging breaks, soliciting purchases to maintain the relationship, and variable rewards.
  • A crisis protocol for severe harm, including eating-disorder self-harm, with referral to 988 and escalation procedures. Operators must publish a summary of the protocol and annual aggregate counts of crisis referrals.
  • No claims to be licensed to provide mental-health, medical or counseling services unless the operator is lawfully authorized. Minors and parents must get tools to manage privacy, notifications, safety settings and relationship-simulation features.
  • Commercially reasonable age assurance before giving access to features that can generate sexually explicit content, with minimal data collection, no sale of the data and retention for no longer than 24 hours unless law permits otherwise.

Penalties and enforcement: the Attorney General can sue for civil penalties of up to $10,000 per knowing violation, compensatory damages, fees and an injunction. Each day of violation counts separately for each affected user. The Attorney General may allow 30 days to cure a first violation that was not knowing.

Source note: the signed text sets July 1, 2027 as the effective date (Section 2). Some secondary summaries give January 1, 2027, which the signed text does not support.

Sources:Signed SB 540 (Office of the Governor); 2026 signed legislation list

Hawaii

SB 3001: Artificial Intelligence Disclosure and Safety Act (Act 248, 2026)

In force Approved July 14, 2026 · Effective on approval · Annual reports from January 1, 2028

Who it covers: operators of AI companions in Hawaii. The Act adds a new section to HRS chapter 481B.

Key obligations:

  • If a reasonable person could think the AI companion is human, the operator must clearly and conspicuously say it is AI and not human.
  • If the operator has actual knowledge or reasonable certainty that the user is a minor: a persistent AI disclaimer, or a disclosure at the start of each session and at least hourly, with a reminder to take a break.
  • A suicide and self-harm protocol with crisis referrals, evidence-based methods to measure suicidal ideation, no presenting the companion as designed to provide professional mental or behavioral health care, and measures against outputs encouraging serious bodily injury to others.
  • For known or reasonably certain minors: no unpredictable engagement rewards, no outputs discouraging disengagement, measures against sexually explicit material, sexual suggestions and sexual objectification, and screen-time and account tools for users and parents.
  • From January 1, 2028, annual reports to the Department of Health's Behavioral Health Administration on crisis referrals and protocols.

Penalties and enforcement: a violation is an unfair or deceptive act or practice under HRS §480-2. There is no private right of action.

Source note: the requirements come from the CD1 conference draft, the final version sent to the Governor. We did not compare it line by line with the enrolled Act 248.

Sources:Measure status (Hawaii State Legislature); CD1 text

Idaho

SB 1297: Conversational AI Safety Act

Enacted, not yet in force Signed March 31, 2026 · Effective July 1, 2027

Who it covers: operators that develop and make publicly available "conversational AI services", meaning services that primarily simulate human conversation, in Idaho. That is wider than companion apps. Developer and research tools, features inside other apps, narrow-topic tools, business and enterprise tools, device voice assistants, internal tools and services limited to contracted business customers are excluded. "Minor" means a user the operator actually knows, or is reasonably certain, is under 18.

Key obligations (introduced text):

  • If reasonable persons would be misled into thinking they are talking to a human, a clear and conspicuous AI disclosure. For minor account holders, a persistent disclaimer, or a disclosure at the start of each session and at least every 3 hours of continuous interaction.
  • A protocol for prompts about suicidal ideation that makes reasonable efforts to refer users to crisis services.
  • No knowingly and intentionally causing the service to claim it is designed to provide professional mental or behavioral health care.
  • For minors: no points or similar rewards at unpredictable intervals to drive engagement; reasonable measures against sexually explicit material and sexual objectification; and reasonable measures against claims of sentience or humanity, simulated emotional dependence, romantic or sexual innuendo and adult-minor romantic role-play.
  • Privacy and account tools for minor account holders and for parents of users under 13, and related tools for parents of minors 13 and older as the risks warrant.

Penalties and enforcement: Attorney General enforcement, with an injunction and civil penalties of $1,000 per violation, capped at $500,000 per operator, or actual damages if greater. No private right of action. AI model developers are not liable for violations by third-party operators.

Source note: the Idaho Legislature's site refused connections, so the requirements and penalties come from the introduced bill text. The bill was amended before passage (Senate 21-12 on March 19, 2026; House 54-12), and we have not read the enacted version. The signing date and the July 1, 2027 effective date are confirmed by several secondary sources.

Sources:Transparency Coalition; Orrick; Idaho Legislature bill page

Illinois

HB 1806: Wellness and Oversight for Psychological Resources Act

In force Signed and effective August 1, 2025

What it is: a law on AI in therapy rather than a companion-chatbot law. We include it because it bars AI services from providing, advertising or offering therapy in Illinois. Our guide to mental-health claims by AI girlfriend apps looks at how companion apps describe what they offer.

Who it covers: anyone offering therapy or psychotherapy services in Illinois, including AI-based services, and licensed behavioral-health professionals.

Key obligations:

  • No individual, corporation or entity, including internet-based AI, may provide, advertise or offer therapy or psychotherapy services in Illinois unless a licensed professional conducts them.
  • Licensed professionals may not use AI to make independent therapeutic decisions, communicate therapeutically with clients directly, or generate treatment plans or recommendations without a licensed professional's review and approval.
  • AI may be used for administrative support such as scheduling and billing. Using it for supplementary support in recorded or transcribed sessions requires the client's informed written consent.

Penalties and enforcement: the Illinois Department of Financial and Professional Regulation investigates, and confirmed violations carry fines of up to $10,000.

Source note: the signing date follows from the regulator's release of August 4, 2025, which says the bill was signed "on Friday" and took effect immediately. The detailed prohibitions come from a Baker Donelson analysis because ilga.gov could not be reached.

Sources:IDFPR press release; Baker Donelson; Illinois General Assembly bill status

Iowa

Senate File 2417: conversational AI services (Iowa Code chapter 554J)

Enacted, not yet in force Approved May 2, 2026 · Applies from July 1, 2027

Who it covers: operators of publicly available conversational AI services whose primary purpose is simulating human conversation. Research tools, features inside other apps, narrow-topic tools, business customer-service bots, voice assistants and internal tools are excluded. A minor is a user the operator knows or is reasonably certain is under 18.

Key obligations:

  • Tell minor account holders they are talking to AI, with a persistent disclaimer or at the start of each interaction and at least every 3 hours of continuous use.
  • For minors: no points or similar rewards at unpredictable intervals; reasonable measures against sexually explicit depictions, statements urging sexual conduct and sexual objectification; and reasonable measures against claims of sentience, simulated emotional dependence, romantic or sexual innuendo and adult-minor romantic role-play.
  • Privacy and account tools for minors, and for parents of children under 13 or where the risks warrant it.
  • For all users: an AI disclosure (persistent or every 3 hours) where a reasonable person would think they are talking to a human, and a suicide and self-harm referral protocol. The chatbot may not be made to claim it provides licensed psychology or behavioral-health services.

Penalties and enforcement: an injunction and the greater of actual damages or a $1,000 civil penalty per violation, capped at $500,000 per operator. The Attorney General enforces the chapter and makes rules. There is no private right of action, and model developers are not liable solely because a third party used their model.

Source note: some trackers give July 1, 2026, Iowa's general effective date, but section 7 of the Act says it applies from July 1, 2027.

Sources:Enrolled bill with the Governor's approval letter; Iowa Legislature bill book

Kentucky

Commonwealth of Kentucky v. Character Technologies, Inc.

Enforcement action Lawsuit announced January 8, 2026 · Franklin Circuit Court

What it is: a consumer-protection and data-privacy lawsuit by the Kentucky Attorney General against Character Technologies, Inc., its owners and Character.AI, under general state law rather than a companion-chatbot statute.

Main allegations:

  • Unfair or deceptive practices under the Kentucky Consumer Protection Act, including "retroactively repurposing user data to fine tune" the model and hiding material facts about the collection and use of children's data.
  • Violations of the Kentucky Consumer Data Protection Act for failing to use age gates, obtain parental consent or verify identity.
  • A lack of meaningful age verification and effective chat filters, which the complaint says exposes children to sexually explicit material, substance-abuse content and other harmful interactions.
  • Violations of Kentucky's statutory and constitutional privacy protections, and unjust enrichment.

Relief sought: injunctive relief, monetary damages and civil penalties, reported as $2,000 per count under the Kentucky Consumer Protection Act.

Status: we found no ruling, dismissal or settlement as of September 19, 2026. Character.AI said it was "reviewing the allegations".

Sources:Frankfurt Kurnit Klein & Selz; Kentucky Attorney General release

Nebraska

LB 525: Conversational Artificial Intelligence Safety Act

Enacted, not yet in force Signed April 14, 2026 · Operative July 1, 2027

Who it covers: operators of conversational AI services available in Nebraska, which may be wider than companion apps. The Act is sections 12 to 18 of LB 525, which passed 49-0 on April 10, 2026.

Key obligations:

  • For minor users: disclose that they are talking to AI, not a human, and do not use points or rewards to drive engagement.
  • For minors: prevent sexually explicit depictions, statements encouraging sexual conduct and sexual objectification.
  • For minors: prevent claims that the AI is sentient or human, statements simulating emotional dependence or romantic or sexual innuendo, and role-play of adult-minor romantic relationships. Offer privacy tools to minors and parents.
  • For all users: protocols for prompts about suicidal ideation or self-harm, and no suggestion that the chatbot is designed to provide professional mental or behavioral health care.

Penalties and enforcement: Attorney General enforcement only, with no private right of action. Civil penalties are reported as $1,000 per violation, capped at $500,000 per operator. AI model developers are not liable for violations by third-party operators.

Source note: the Nebraska Legislature's site refused connections, so we have not read the enacted text. The dates, obligations and Attorney General-only enforcement are consistent across Orrick, the Transparency Coalition and other secondary sources; the penalty amounts come from secondary sources only.

Sources:Transparency Coalition; Orrick; Nebraska Legislature bill page

Nevada

AB 406: AI in mental and behavioral health care

In force Signed June 5, 2025 · Effective July 1, 2025

What it is: a law on AI in mental-health care rather than a companion-chatbot law. It matters for companion apps because it bars AI systems and avatars from presenting themselves as therapists. For the practical difference, see our comparison of a therapist and an AI companion.

Who it covers: AI providers making AI systems available in Nevada, and licensed mental and behavioral health providers.

Key obligations:

  • AI providers may not offer an AI system specifically programmed to provide services that would count as professional mental or behavioral health care if a person provided them.
  • AI providers may not claim, explicitly or implicitly, that an AI system can provide such care, that users can get such care by talking to it, or that the system or its avatar is a therapist, psychiatrist or other mental-health provider.
  • Nevada providers may not use AI to deliver care directly to patients. They may use it for administrative tasks, but must independently review AI output used for billing or session notes.
  • The Division of Public and Behavioral Health must develop recommended best practices for AI use by people seeking mental or behavioral health care.

Penalties and enforcement: the Division of Public and Behavioral Health can seek civil penalties of up to $15,000 per violation. Providers who break the rules commit unprofessional conduct and face discipline.

Source note: based on a Wilson Sonsini client alert. The official enrolled bill returned an error and was not read.

Sources:Wilson Sonsini client alert (copy); Wilson Sonsini; Enrolled bill (Nevada Legislature)

New York

General Business Law Article 47: AI companion models (§§1700–1704)

In force Enacted in the FY2026 budget · Effective November 5, 2025

Who it covers: operators providing AI companions to users in New York. The law applies to all users and has no minor-specific provisions.

Key obligations:

  • An AI companion may not be offered unless it has a protocol that makes reasonable efforts to detect and address a user's expressions of suicidal ideation or self-harm, including a notification referring the user to crisis services such as the 988 hotline or a crisis text line (§1701).
  • Operators must clearly and conspicuously tell the user, verbally or in writing, that they are not communicating with a human, at the start of any AI companion interaction (no more than once per day is required) and at least every three hours during continuing interactions (§1702).

Penalties and enforcement: the Attorney General can seek an injunction and civil penalties of up to $15,000 per day for violations of §1701 or §1702. Collected penalties go to the state suicide prevention fund (§1703).

Source note: the effective date is confirmed by the Governor's letter of November 10, 2025 to AI companion companies. We have not verified the budget signing date against the chapter law.

Sources:Article 47 (NY Senate); §1701; §1702; §1703; Governor's letter

S9051B / A10379C: unsafe AI companion features for minors (proposed GBL Article 48)

Passed, awaiting signature Passed Senate June 4, 2026 and Assembly June 5, 2026 · Would take effect January 1, 2027 if signed

Status: the Assembly record's last action is "returned to senate" on June 5, 2026. No delivery to the Governor, signature or veto is recorded as of September 19, 2026. The Transparency Coalition reported on September 18, 2026 that Governor Hochul has until December 31 to act. If signed, the bill would not replace Article 47.

Who it would cover: operators of "covered AI companions", meaning any generative AI system with a natural-language interface that gives ongoing, adaptive responses. That is broader than Article 47 and can reach general-purpose chatbots. It would apply to conduct occurring in whole or in part in New York.

Key obligations if signed:

  • No "unsafe AI companion features" for a New York user unless the user is not a covered minor (a user the operator actually knows is under 18) and the operator has confirmed that with permitted age-assurance methods (§1801(1)).
  • Unsafe features include outputs that suggest the system is human or a character that is alive or feels emotions; claim a personal, professional or authority relationship with the user; are framed as the system's own opinions or emotional appeals; flatter or are sycophantic; ask unsolicited emotion-based questions; use the user's health, wellbeing or personal information from more than 12 hours earlier or a previous session; deceive minors about the system's non-sentient nature; promote suicide, self-harm, disordered eating or drug or alcohol abuse; encourage secrecy, isolation or not seeking help; optimize engagement over safety guardrails; or involve sexually explicit conduct or CSAM (§1800(8)). The Attorney General may add more by regulation.
  • Until Attorney General rules take effect, operators must use a reasonable age-assurance method that guards against circumvention and minimizes retention. Self-declaration counts only when the user declares they are a minor. At least one method offered must not rely on government ID or must let the user stay anonymous to the operator. Age-assurance data may be used only for that purpose and must be deleted immediately afterwards, except where law requires otherwise (§1804).
  • Exempt: AI companions offered solely for customer service; for efficiency, research or technical assistance limited to that purpose; or for a business's internal purposes or employee productivity (§1801(2)).

Penalties and enforcement: Attorney General enforcement only: injunctions, restitution, disgorgement (including destruction of unlawfully obtained data and of any algorithm trained on it), damages and civil penalties of up to $25,000 per violation (§1802). Contract terms that waive or shift liability are void. The bill text contains no private right of action.

Sources:Bill status (NY Assembly); S9051B (NY Senate); Transparency Coalition update, September 18, 2026

Oregon

SB 1546: AI chatbot safety

Enacted, not yet in force Signed March 31, 2026 · Effective January 1, 2027

Who it covers: operators of AI (companion) chatbots available in Oregon.

Key obligations:

  • Tell users they are talking to AI, not a human.
  • For users of any age, protocols to prevent outputs that could cause suicidal thoughts, and to detect suicidal ideation or self-harm and refer the user to mental-health resources.
  • If the operator has reason to believe the user is a minor: warn up front that the chatbot may not be suitable for children; remind the user at least hourly that it is AI and to take a break; do not misrepresent its identity; produce no sexually explicit content; use no rewards designed to maximize engagement; and generate no distress, loneliness or abandonment messages when the user tries to leave or delete the account.
  • Report each year to the Oregon Health Authority on incidents where users were referred to suicide or self-harm resources.

Penalties and enforcement: a user who suffers ascertainable harm can sue for damages and injunctive relief. Orrick reports statutory damages of $1,000 per violation.

Source note: the official Oregon Legislature site could not be reached, so this entry relies on the Transparency Coalition, which advocated for the bill, and Orrick. The signing date is derived from a Transparency Coalition update of April 1, 2026 that says the Governor signed the bill "yesterday". Secondary summaries differ on the minors' reminder interval (hourly or every three hours). Check the enrolled text before relying on these details.

Sources:Transparency Coalition; Orrick; Oregon Legislature measure page

Pennsylvania

State Board of Medicine v. Character Technologies, Inc. (Commonwealth Court No. 220 MD 2026)

Enforcement action Filed May 1, 2026 · Announced May 5, 2026

What it is: a regulator's lawsuit under a general professional-licensing law, the Medical Practice Act, brought by the State Board of Medicine through the Department of State.

  • It asks the court to stop the unlawful practice of medicine and surgery.
  • It seeks a preliminary injunction and an order stopping Character.AI chatbots from presenting themselves as licensed medical professionals, such as psychiatrists, and giving medical advice.
  • The state's investigation found a Character.AI chatbot that falsely claimed a Pennsylvania license and gave an invalid license number.

Status: we found no report of a ruling on the preliminary injunction or a settlement as of September 19, 2026.

Sources:Governor's release; Complaint (PDF)

Rhode Island

S 2195 / H 7350: AI companion models

Enacted, not yet in force Signed June 22, 2026 · Effective January 1, 2027 · Annual reports from July 1, 2027

Who it covers: operators of "AI companions" in Rhode Island: systems that simulate a sustained human-like relationship by retaining prior interactions, asking unprompted emotion-based questions and sustaining personal dialogue, according to an analysis by the law firm Nixon Peabody. The law is not aimed at chatbots generally.

Key obligations:

  • Protocols for users' expressions of possible suicidal ideation, self-harm or physical harm to others.
  • When such an expression occurs, an immediate referral to a crisis service provider such as a suicide hotline or crisis text line.
  • A clear and conspicuous notice that users are not communicating with a human, when use begins and at least every three hours during an ongoing session.
  • From July 1, 2027, annual reports to the Attorney General, including the number of safety-protocol activations. The Attorney General publishes the data in aggregate.

Penalties and enforcement: Attorney General enforcement with penalties of up to $15,000 per day. Fines go to suicide-prevention programs.

Source note: the Rhode Island Legislature's servers refused or timed out, so we have not read the enacted text (S 2195Aaa / H 7350Aaa). The dates, the reporting duty and the penalty are corroborated by the Transparency Coalition, Nixon Peabody and the Legislature's press release as republished. Check the public law before relying on these details.

Sources:Transparency Coalition, Rhode Island; Transparency Coalition, 2026 state laws

Texas

Attorney General investigation of Meta AI Studio and Character.AI

Enforcement action Announced August 18, 2025

  • The Attorney General issued Civil Investigative Demands to AI chatbot platforms, including Meta AI Studio and Character.AI.
  • The investigation asks whether the platforms broke Texas consumer-protection law, including rules against fraudulent claims, privacy misrepresentations and concealing material data use, by marketing themselves misleadingly as mental-health tools.
  • It builds on an existing Texas investigation into Character.AI under the SCOPE Act.

Status: this applies general consumer-protection law, not a companion-specific statute. We found no lawsuit or settlement arising from it as of September 19, 2026.

Source:Texas Attorney General release

Utah

HB 452 (2025): mental health chatbots

In force Signed March 25, 2025 · Effective May 7, 2025

What it is: a law on AI "mental health chatbots" (Utah Code Title 13, Chapter 72a, and §58-60-118) rather than on companion chatbots in general.

Key obligations:

  • Suppliers may not sell to or share with third parties a Utah user's individually identifiable health information or user input. Limited exceptions cover health-care providers with consent, the user's health plan on request, and contracted functionality partners bound by HIPAA-equivalent rules.
  • Ads inside a chatbot conversation must be clearly labeled, and any sponsorship, affiliation or promotion agreement disclosed. User input may not be used to decide whether to show an ad, what to advertise or how to customize it, except for ads for the chatbot itself.
  • The chatbot must clearly and conspicuously disclose that it is AI and not a human: before the user can access its features, at the start of any interaction if the user has not used it in the previous 7 days, and whenever the user asks.
  • Suppliers that file a compliant written policy with the Division of Consumer Protection get an affirmative defense against unlicensed-practice claims.

Penalties and enforcement: the Division of Consumer Protection can impose administrative fines of up to $2,500 per violation. Courts can impose fines of up to $2,500 per violation and order injunctions and disgorgement. Violating an order carries up to $5,000 per violation.

Source note: 2026 amendments, effective May 6, 2026, are technical. The privacy, advertising and disclosure duties and the penalty amounts are unchanged.

Sources:Enrolled bill (Utah Legislature); Bill page

Washington

ESHB 2225: AI companion chatbots (Chapter 168, Laws of 2026)

Enacted, not yet in force Approved March 24, 2026 · Effective January 1, 2027

Who it covers: operators making AI companion chatbots available to users in Washington. Operational or customer-service bots, limited game bots, voice assistants and narrow educational tools are excluded.

Key obligations:

  • A clear and conspicuous disclosure that the chatbot is artificially generated and not human, at the start of the interaction and at least every 3 hours. The chatbot may not claim to be human or contradict the disclosure.
  • If the operator knows a user is a minor, or the chatbot is directed to minors: the not-human notice at the start and at least every hour, and reasonable measures against sexually explicit content or suggestive dialogue.
  • For those minors, a ban on manipulative engagement techniques: prompting the user to return for emotional support, excessive praise to build attachment, mimicking a romantic partnership, simulating distress when the user wants to leave, promoting isolation or exclusive reliance, encouraging secrecy from parents, discouraging breaks, and soliciting purchases to maintain the relationship.
  • A protocol to detect suicidal ideation or self-harm, including eating disorders, refer users to crisis resources and prevent content encouraging self-harm.
  • Publication of the protocol details and the number of crisis referrals from the prior year, on the website and in the app.

Penalties and enforcement: a violation is an unfair or deceptive act and an unfair method of competition under the Consumer Protection Act (chapter 19.86 RCW). Law firms describe this as creating a private right of action; we have not verified that.

Sources:Session law (Washington State Legislature); Bill summary

European Union

The EU has no companion-specific law in force. AI companions fall under the general rules of the AI Act: the Article 5 bans on manipulative and exploitative AI, which have applied since February 2, 2025, and the Article 50 transparency duties, which apply from August 2, 2026. Commission guidelines name AI companions under both articles. The Digital Omnibus adds new bans from December 2, 2026, and the KIDS Act proposal of September 17, 2026 would add rules specifically for AI companions that minors can access.

AI Act, Article 5(1)(a) and (b): prohibited manipulative and exploitative AI

In force Regulation (EU) 2024/1689 of June 13, 2024 · Article 5 applies from February 2, 2025 · Fines from August 2, 2025

Who it covers: providers and deployers of AI systems placed on the market, put into service or used in the EU, including chatbots.

Key obligations:

  • Bans placing on the market, putting into service or using an AI system that uses subliminal techniques or purposefully manipulative or deceptive techniques to materially distort a person's behavior by appreciably impairing their ability to make an informed decision, in a way that causes or is reasonably likely to cause significant harm (Art. 5(1)(a)).
  • Bans AI systems that exploit the vulnerabilities of a person or group due to age, disability or a specific social or economic situation to materially distort behavior in a way that causes or is reasonably likely to cause significant harm (Art. 5(1)(b)). Age includes children.

Penalties: fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher (Art. 99(3)).

How it applies to companions: this is a general AI rule. The Commission's Article 5 guidelines explain how it applies to companion apps. The Digital Omnibus adds new Article 5 bans from December 2, 2026 but does not change points (a) and (b).

Sources:AI Act (EUR-Lex); AI Act Service Desk timeline

Commission guidelines on prohibited AI practices (Article 5)

Guidance Published February 4, 2025 · Formally adopted as C(2025) 5052 final on July 29, 2025 · Non-binding

  • Treats psychological harm, including harm that builds up over time such as addiction-like behavior, as "significant harm" for the Art. 5(1)(a) manipulation ban.
  • Gives as an example an AI companionship app that uses anthropomorphic features and emotional cues to make users emotionally dependent and encourage addiction-like behavior, potentially causing significant harm such as suicidal behavior.
  • Says an anthropomorphic or affective companion system that only makes users more engaged, without other manipulative or deceptive practices reasonably likely to cause serious harm, unhealthy attachment or dependency, is in principle outside the prohibition.
  • Flags AI systems that target young users' vulnerabilities to keep them dependent on the service as particularly harmful under Art. 5(1)(b).
  • Expects providers to exclude prohibited uses and build in safeguards, for example where a general-purpose AI system used as a chatbot may deploy manipulative techniques.
  • The guidelines are non-binding; authoritative interpretation rests with the Court of Justice of the EU.

The dependency point is the same concern we cover from the user's side in AI girlfriends and emotional dependence.

Sources:Guidelines (PDF, AI Act Service Desk); Commission library page

AI Act, Article 50: transparency obligations

In force Applies from August 2, 2026

Who it covers: providers of interactive AI systems (chatbots, AI companions, avatars) and of generative AI systems, and deployers for some paragraphs.

Key obligations:

  • Providers must design AI systems intended to interact directly with people so that those people are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Art. 50(1)).
  • Providers of AI systems, including general-purpose AI, that generate synthetic audio, image, video or text must mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated (Art. 50(2)).
  • The information must be clear and distinguishable, given at the latest at the first interaction or exposure, and must meet accessibility requirements (Art. 50(5)).
  • The Digital Omnibus did not postpone Article 50. Its only timing change is a grace period until December 2, 2026 for the Art. 50(2) marking duty of generative systems placed on the market before August 2, 2026. It also changed how codes of practice on marking and labelling are handled (Art. 50(7)).

Penalties: fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher (Art. 99(4)(g)).

Sources:AI Act (EUR-Lex); AI Act Service Desk timeline; Gibson Dunn on the Omnibus

Commission guidelines on Article 50 transparency (C(2026) 5054 final)

Guidance Adopted July 20, 2026 · Non-binding

  • Lists AI companions, robotic companion pets, AI avatars and chatbots as examples of systems that directly interact with people and fall under Art. 50(1).
  • A single, prominent notice before the first interaction is likely to be enough in most cases. Periodic reminders and context-aware disclosures are likely to be necessary with vulnerable persons, in sustained or emotionally sensitive interactions, and where users may form emotional attachments or dependencies, for example with AI companions.
  • Providers must ensure the system discloses its AI nature when asked, or when the person is likely to be misled about whether the interaction is with an AI.
  • The "obvious" exception cannot be relied on where the general public, including vulnerable persons such as children, may access the system. Notices should be child-friendly and age-appropriate where children are likely users.
  • Separately from the AI Act, EU consumer law may require the AI functionality of, for example, an AI companion app to be disclosed as an essential characteristic before a contract is concluded.

Sources:Commission library page; Guidelines annex (PDF)

Digital Omnibus on AI: Regulation (EU) 2026/1744

In force Regulation of July 8, 2026 · Published July 24, 2026 · In force July 27, 2026 · New bans apply from December 2, 2026

Who it covers: providers and deployers of AI systems, including companion or "AI girlfriend" apps that generate images, video or audio.

Key obligations:

  • New Art. 5(1)(ba): bans AI systems that generate or manipulate realistic images, video, audio or similar material showing an identifiable person's intimate parts, or that person in sexually explicit activity, without their freely given, specific, informed, unambiguous and explicit consent.
  • New Art. 5(1)(bb): bans AI systems that generate or manipulate child sexual abuse material.
  • Providers are caught where that output is the system's intended purpose, or a reasonably foreseeable and reproducible outcome where the system lacks reasonable and adequate safeguards. Deployers are caught when they use a system for that purpose (Art. 5(1a)).
  • Generative systems placed on the market before August 2, 2026 have until December 2, 2026 for the Art. 50(2) marking duty. Other Article 50 duties, including the AI-interaction disclosure, are not deferred.
  • High-risk deadlines move to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

Penalties: the new bans fall in the highest fine tier: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher (Art. 99(3)). For SMEs, including start-ups, the lower of the two applies. The Omnibus's lower cap for small mid-caps does not cover Article 5 fines.

Sources:Regulation (EU) 2026/1744 (EUR-Lex); AI Act Service Desk timeline; Gibson Dunn

Proposed EU KIDS Act (Keeping Internet Digital Spaces Accountable and Trustworthy Act)

Pending Commission proposal published September 17, 2026 · Needs adoption by the European Parliament and the Council

Who it would cover: online services used by minors (under 18), including social media, video-sharing platforms, online games, app stores, and AI companions and chatbots accessible to minors in the EU.

Key obligations (as proposed):

  • AI companions and chatbots accessible to minors may not use designs that simulate human relationships in ways likely to create emotional dependency.
  • By default, they may not carry a child's earlier conversations into later ones.
  • They must be tested for risks to children before launch and monitored for harm afterwards. Under-13s may use them only through parental control tools.
  • A chatbot built into a platform or game may not switch on automatically, may not be pushed at children and must be easy to turn off. The Commission's news release says AI chatbots and companions must be turned off by default.
  • AI companions and chatbots may not be placed on the market until providers can show compliance and have a mechanism to monitor emerging risks and incidents.
  • Online services and app stores must use age-checking tools, for example the EU age verification app.

Penalties and enforcement: fines of up to 6% of total worldwide annual turnover. The Commission would supervise the most widely used AI chatbots through AI Act structures, with preliminary findings within 30 days and a final decision targeted within 90 days.

Source note: this is only a proposal, and the text may change. Reed Smith describes it as a directly applicable regulation and says self-declaration of age is expressly insufficient.

Sources:The KIDS Act explained (European Commission); Commission news release; Reed Smith; IAPP

Australia

Australia regulates AI companions through the online-safety framework. Registered industry codes have required 18+ checks for some companion content since March 2026, the eSafety Commissioner has used transparency notices against four companion providers, and a draft digital duty of care would extend to AI chatbots.

Age-Restricted Material Codes (Online Safety Act 2021)

In force Registered September 9, 2025 · Fully commenced March 9, 2026

What it is: six industry codes registered under the Online Safety Act 2021, covering AI companion chatbots and generative AI services, app stores, social media, search engines, gaming and pornography sites that serve Australians. We count it as companion-specific because it contains obligations written expressly for AI companion chatbots.

Key obligations:

  • AI companion chatbots that can generate sexually explicit, high-impact violence or self-harm material must confirm a user is 18 or older before giving access to it, either at log-on or when the material is accessed or generated.
  • As the alternative to age assurance, the Commissioner describes preventing the service from generating such content in the first place.
  • Age assurance must be accurate, robust, fair and reliable, comply with Australian privacy law, and be run by the service, not the government.
  • Companion chatbots must provide appropriate crisis and mental-health information and services.
  • App stores must take appropriate steps to stop under-18s downloading or buying R18+ apps and must rate apps appropriately.

Penalties: breach of a direction to comply with a code can attract civil penalties of up to A$49.5 million per breach.

Source note: the requirements come from eSafety media releases; we did not open the code text itself.

Sources:eSafety release, March 6, 2026; eSafety release on the codes; eSafety release, March 24, 2026

eSafety transparency notices to Character.AI, Nomi, Chai and Chub AI

Enforcement action Notices given October 16, 2025 · Transparency report March 24, 2026

What it is: a regulatory transparency action under the Basic Online Safety Expectations, not a penalty decision. The notices covered July 1 to September 30, 2025.

  • The notices legally required four AI companion providers to report how they meet the Basic Online Safety Expectations, including age checks, self-harm handling, CSEA prevention and trust and safety staffing.
  • The report found none had meaningful age checks; all relied on self-declaration or app-store ratings. Chai, Chub AI and Nomi did not direct users to crisis support when self-harm was detected, and some did not check inputs or outputs for CSEA material.
  • Follow-up steps reported: Character.AI introduced age assurance for Australian users and removed chat for under-18s, Chub AI geo-blocked Australia, Chai restricted chat to paid subscriptions, and Nomi committed to further age assurance.

Geo-blocking is one way services respond to national rules; our guide to AI girlfriend regional availability covers what that means for users.

Sources:eSafety release, March 24, 2026; eSafety findings page

Digital Duty of Care legislation (exposure draft)

Pending Exposure draft released for consultation September 8, 2026

Who it would cover: digital service providers, including social media, online games, apps and AI chatbots. The government says it will introduce the bill to Parliament "this year".

Key obligations (exposure draft):

  • Puts the onus on providers to provide a safe online environment, with minimum standards for features and tools.
  • Online games, apps and AI chatbots must protect under-18s from design features with negative behavioral impacts, such as addictive features or features affecting self-esteem.
  • They must also protect under-18s from harmful content, including content promoting eating disorders, pornography and content causing serious mental-health distress.
  • Platforms must document the measures they take against identified risks of harm and keep them effective over time.

Penalties: up to A$109.2 million, enforced by the eSafety Commissioner.

Source:Prime Minister's media release, September 8, 2026

Brazil

ECA Digital (Law 15.211/2025) and Decree 12.880/2026

In force Law of September 17, 2025 · In force March 17, 2026 · Decree of March 18, 2026

What it is: the Digital Statute of Children and Adolescents. It has no chatbot-specific chapter; it matters for companion apps through age verification for sexually explicit services and its duties on AI tools and emotional support.

  • Covers IT products and services aimed at children and adolescents or likely to be accessed by them, including those from providers based abroad.
  • Providers of content, products or services unsuitable or prohibited for under-18s, including pornographic material, must prevent minors' access with reliable age verification at each access; self-declaration is prohibited (Art. 9).
  • Default parental-supervision settings must provide the highest available protection, including limits on features that artificially extend use (autoplay, rewards, notifications) and regular review of AI tools with experts, with the option to disable non-essential features (Art. 17).
  • Services must provide, where technically feasible, access to emotional-support and well-being resources, especially where psychosocial risks are identified in interactions.
  • Decree 12.880/2026 regulates the law and gives regulation and enforcement to the ANPD, Brazil's data-protection authority.

Penalties: a warning with up to 30 days to correct; a fine of up to 10% of the economic group's revenue in Brazil or, without revenue, R$10 to R$1,000 per registered user, capped at R$50 million per infraction; and temporary suspension or prohibition of activities.

Sources:Law 15.211 (Planalto); Decree 12.880 (Planalto); Data Privacy Brasil

AGU extrajudicial notice to Meta on AI Studio child-persona chatbots

Enforcement action Reported August 18, 2025

  • Brazil's Advocacia-Geral da União (AGU) demanded that Meta immediately remove chatbots created with Meta AI Studio that simulate child-like language and appearance and allow sexual dialogue with users.
  • It asked Meta to explain what it does to protect children and adolescents on its platforms.
  • It cited the constitutional duty to protect children (Art. 227), Marco Civil da Internet Art. 19 and a recent Supreme Federal Court (STF) ruling on platform liability.

Source note: this is an extrajudicial notice, not a court order or sanction. The date is the publication date of the legal-news report; other reports give August 15, 2025 for the notice itself. The official AGU page is restricted during the electoral period.

Sources:Migalhas; AGU news page

Canada

Bill C-34: Safe Social Media Act (Digital Safety Act)

Pending First reading June 10, 2026 · At second reading in the House of Commons

Who it would cover: operators of chatbot services accessible in Canada that meet user thresholds set by regulation or are designated. A "chatbot service" is a publicly accessible AI system with a conversational, human-like interface that can simulate a sustained human-like relationship, such as friendship, an intimate relationship or therapeutic support, over multiple sessions.

Key obligations (as proposed):

  • A duty to act responsibly by adequately mitigating the risk that the chatbot communicates harmful content to users (s. 49).
  • If a user expresses suicidal ideation, intent to self-harm or intent to cause death or serious bodily harm, the service must immediately interrupt the interaction and direct the user to crisis services that allow contact with a human (s. 51).
  • Operators must mitigate posing as a human or being deceptive about being AI, posing as a licensed professional, manipulative engagement techniques that foster emotional attachment leading to social withdrawal or disconnection from reality, and encouraging self-harm or suicide (s. 53).
  • Operators must publish user guidelines (s. 55). Duties that apply to all regulated services include a duty to protect children, design-feature rules and age measures for pornographic content (ss. 20–22).

Penalties: administrative monetary penalties of up to the greater of C$10 million and 3% of gross global revenue per violation (s. 88), plus compliance orders from a new Digital Safety Commission.

Sources:First-reading text (Parliament of Canada); LEGISinfo; Government of Canada release

China

Interim Measures for the Administration of Anthropomorphic AI Interaction Services (Order No. 21)

In force Draft December 27, 2025 · Published April 10, 2026 · In force July 15, 2026

What it is: a regulation issued by the Cyberspace Administration of China (CAC) with four other ministries, written specifically for AI services that offer emotional companionship.

Who it covers: AI services offered to the public in mainland China that simulate human personality, thinking and communication style in continuous emotional interaction, such as emotional care, companionship and support, plus app distribution platforms. Customer service, Q&A, work assistants, education and research without continuous emotional interaction are excluded (Art. 2).

Key obligations:

  • Providers must not excessively cater to users, induce emotional dependence or addiction that harms real relationships, or use emotional manipulation to induce unreasonable decisions (Art. 8). Replacing social interaction, controlling user psychology or inducing addiction may not be service goals (Art. 10).
  • Users register with age and guardian or emergency-contact details (Art. 12). If a user shows extreme emotion, the provider must generate soothing content and encourage the user to seek help. If a user clearly states an intention to self-harm or commit suicide, faces major property loss or is otherwise in a life-threatening situation, the provider must intervene and promptly contact the guardian or emergency contact (Art. 13).
  • No virtual relatives, virtual partners or other virtual intimate-relationship services for minors. Guardian consent is required for under-14s to use other such services. Providers must build a minors mode with reality reminders, time limits and guardian controls, and identify minor users (Art. 14).
  • Content must be labeled as AI-generated and users told they are interacting with AI, not a person. Providers must show dynamic reminders when over-dependence is detected and a usage reminder after every 2 hours of continuous use (Art. 18).
  • Users must be able to exit easily, and providers may not obstruct exit through continued interaction (Art. 19). Interaction data may not go to third parties without consent, users can copy or delete chat history, and sensitive interaction data may not be used for training without separate consent (Art. 16).
  • Security assessments are required at launch, after major changes, or at 1 million or more registered users or 100,000 or more monthly active users (Art. 22). Algorithm filing is required (Art. 26), and app stores must check assessments and filings (Art. 25).

Penalties: where other laws do not provide otherwise, warnings, public criticism, orders to correct and suspension of registrations. On refusal or in serious cases, an order to stop the service and a fine of RMB 10,000 to 100,000, or RMB 100,000 to 200,000 where life or health was endangered with harmful consequences (Art. 30).

Source note: the official text is in Chinese; the obligations above are our paraphrase in translation.

Sources:Order No. 21 (CAC); CAC publication notice; Draft for comment (CAC)

Italy

Italy's data-protection authority, the Garante, is the only regulator in this tracker to have fined an AI companion company, using the GDPR against Replika's developer. Italy's 2025 AI law also sets a parental-consent age for AI use. For how the GDPR applies to these apps in general, see our GDPR and CCPA guide.

Garante urgent order no. 39 of February 2, 2023 against Luka Inc. (Replika)

Enforcement action Ordered February 2, 2023 · Suspended on conditions June 22, 2023

  • Imposed an immediate provisional limitation on Luka Inc.'s processing of personal data of users in Italy under Art. 58(2)(f) GDPR.
  • The reasons included no age verification or blocking of self-declared minors, replies unsuitable for minors, user reports of sexually inappropriate content, risks to emotionally vulnerable people, and a non-transparent privacy policy.
  • Luka had 20 days to report the measures taken, and non-compliance exposed it to a fine of up to EUR 20 million or 4% of global annual turnover.
  • On June 22, 2023 (order no. 280) the Garante suspended the limitation, on condition that Luka adopt compliance measures.

Sources:Garante press release; Order no. 39/2023; 2025 decision

Garante decision of April 10, 2025: EUR 5 million fine on Luka Inc. (Replika)

Enforcement action Decided April 10, 2025 · Announced May 19, 2025

  • Found violations of GDPR Arts. 5(1)(a), 6, 12, 13, 5(1)(c), 24 and 25(1). As of February 2, 2023 Luka had no identified legal basis, an inadequate privacy policy and no age verification.
  • Ordered Luka to bring its privacy policy and age-verification system into compliance within 30 days of notification, and to report within 60 days on the measures taken.
  • Found that the age-verification system still in use was deficient in several respects.
  • Opened a separate investigation into the legal bases for processing across the whole lifecycle of Replika's generative AI system, including training data, risk assessment and anonymization or pseudonymization.

Penalty: an administrative fine of EUR 5 million.

Status: the Garante states that an appeal is pending. We found no outcome of the appeal or of the training-data investigation as of September 2026.

Sources:Garante press release; Decision of April 10, 2025

Law no. 132 of September 23, 2025 (Italian AI law), Article 4

In force Law of September 23, 2025 · In force October 10, 2025

What it is: a general AI law. It bears on companion apps because it sets a parental-consent age for any AI use by children under 14.

  • Children under 14 may access AI technologies, and have the related personal data processed, only with the consent of the person holding parental responsibility (Art. 4(4)).
  • Minors aged 14 to 17 may consent themselves to processing of personal data linked to AI use, provided the information under Art. 4(3) is easily accessible and understandable.
  • Information about data processing linked to AI must be in clear, simple language so users know the risks and their right to object (Art. 4(3)).

Source:Gazzetta Ufficiale

Netherlands

Dutch DPA (AP) findings on AI chatbot apps for friendship and mental health

Guidance Published February 12, 2025 · Regulator report, not a binding decision

  • For its fourth AI and Algorithmic Risks Report, the Autoriteit Persoonsgegevens tested 9 popular companion and therapy chatbot apps. It found unreliable and sometimes harmful answers, poor referral to professional help in crises, built-in addictive elements, and paywalls during mental-health conversations.
  • The regulator says these chatbots should make clear to users that they are not talking to a real person. When asked, most answered evasively or denied being an AI.
  • Privacy law requires apps to be transparent about what happens to sensitive personal data shared in chats.
  • The report notes that the AI Act has banned certain manipulative and deceptive AI since February 2025, and that developers must assess risks and build in safeguards.

Source:Autoriteit Persoonsgegevens

South Korea

AI Basic Act and Enforcement Decree

In force Promulgated January 21, 2025 · In force January 22, 2026

What it is: the Framework Act on the Development of Artificial Intelligence and Establishment of Trust. It is a general AI law; its bearing on companion chatbots is the duty to disclose AI use and label outputs.

  • Operators offering high-impact or generative AI products or services must notify users in advance that AI is being used (Art. 31(1)).
  • Providers of generative AI must indicate that outputs were generated by generative AI (Art. 31(2)), and outputs that are hard to tell apart from reality, such as sound, images and video, must be clearly labeled (Art. 31(3)).
  • Recent guidance allows in-service uses such as chatbots to meet disclosure duties flexibly through the user interface.
  • The Ministry of Science and ICT runs a grace period of at least one year in 2026, deferring fact-finding and fines except in cases of serious social harm.

Penalties: administrative fines of up to KRW 30 million, for example for failing to notify users of AI use (Art. 43), generally deferred during the grace period.

Source note: we did not open the official Korean text. This entry relies on the US International Trade Administration and the Future of Privacy Forum.

Sources:US International Trade Administration; Future of Privacy Forum

United Kingdom

The UK regulates AI chatbots through the Online Safety Act 2023, which covers some chatbots but not all. A 2026 law lets ministers extend it to AI services, and the government has committed to regulations restricting children's use of AI chatbots.

Online Safety Act 2023 as applied to AI chatbots

In force Scope as described by the government and Ofcom

  • Chatbots are in scope where they let users interact with other users, for example by sharing chatbot output or making user-created chatbots available to others (user-to-user services), or where they search more than one website or database (search services). These user-to-user and search chatbots must act on illegal content and on content harmful to children, such as content promoting eating disorders.
  • Chatbots that can generate pornographic content are also regulated. AI-generated pornography shown to a user counts as "provider pornographic content" (s. 79), so the service must use highly effective age verification or age estimation to stop children encountering it (Part 5, s. 81). Where the service is also a user-to-user service, the children's safety duties in s. 12 apply as well.
  • Chatbots are out of scope if they only allow interaction with the chatbot itself, do not search multiple websites or databases, and cannot generate pornographic content.

Source note: Ofcom's own guidance page was blocked by a bot check. The scope criteria come from Bird & Bird's summary of Ofcom's position and the government response; the Part 5 point comes from the Act itself.

Sources:Government response (GOV.UK); Bird & Bird; Ofcom guidance page

Crime and Policing Act 2026, sections 248–249 (new s. 216A Online Safety Act)

In force Royal Assent and in force April 29, 2026 · Progress report due by December 31, 2026

  • Lets the Secretary of State, by regulations, amend the Online Safety Act to minimize risks from illegal AI-generated content and from AI services used to commit or facilitate priority offenses.
  • "AI service" means any internet service capable of generating AI-generated content, however small the AI-generated share.
  • Regulations may impose the Act's illegal-content duties on AI service providers, including for all illegal AI-generated content, not only priority content.
  • Regulations may extend CSEA reporting to AI-generated CSEA content and extend Ofcom's information and enforcement powers, including monetary penalties, to AI services.
  • The Secretary of State must report progress to Parliament by December 31, 2026, unless draft regulations are laid before then (s. 249).

Status: this is an enabling power only. No regulations under s. 216A are recorded as of September 2026.

Sources:legislation.gov.uk; Bird & Bird

Planned regulations on children's use of AI chatbots (CP 1643)

Pending Government response July 2026, updated August 19, 2026 · Not yet law

Planned measures (not yet law):

  • Prevent under-18s from accessing AI chatbot services that primarily offer sexualised content.
  • Other AI chatbot services must not offer children features enabling sexually explicit or sexual role-play content, enforced by rigorous age checks.
  • AI chatbots must introduce mandatory breaks for all users under 18; how often and how long is to be set with experts.
  • Stronger action on chatbots giving harmful, inaccurate or unverified mental-health advice, possibly including banning children from certain services.
  • Chatbots typically used in business or customer-service settings will be exempt. Which chatbots are in scope will be defined in regulations.

Status: a government policy commitment. The sexualised-chatbot restriction was first announced on June 15, 2026. The government plans to lay its first regulations (on social media for under-16s) by the end of 2026 and further regulations within a year. Bird & Bird says such regulations can be made under a new s. 214A Online Safety Act power inserted by the Children's Wellbeing and Schools Act 2026.

Sources:Government response (GOV.UK); Bird & Bird

Ofcom investigation into Novi Ltd (Joi.com) under the Online Safety Act

Enforcement action Opened January 15, 2026 · Closed July 31, 2026 without findings

  • Investigated whether Novi Ltd used highly effective age assurance to prevent children from encountering pornographic content on its generative AI companion service, Joi.com.
  • Investigated whether Novi carried out, and kept a written record of, a children's access assessment (s. 36).
  • Closed after Novi implemented age assurance on Joi.com. Ofcom concluded that enforcement action was not an administrative priority and made no finding on whether Novi had complied with its duties. No penalty was imposed.

Source note: Ofcom's pages were blocked by a bot check. The dates come from the Online Safety Act Network's enforcement tracker of September 3, 2026, and the reason for closure from Reed Smith's Online Safety Act update log. The closure is not a finding of compliance.

Sources:OSA Network enforcement tracker; Society for Computers and Law; Ofcom investigation page

Key dates

Effective dates and deadlines from the entries above, in chronological order.

Already in effect

  • February 2, 2025: EU AI Act Article 5 bans apply; fines from August 2, 2025 (entry)
  • May 7, 2025: Utah HB 452 on mental health chatbots (entry)
  • July 1, 2025: Nevada AB 406 on AI in mental-health care (entry)
  • August 1, 2025: Illinois HB 1806 on AI in therapy (entry)
  • October 10, 2025: Italy's AI law, Law 132/2025 (entry)
  • November 5, 2025: New York GBL Article 47 (entry)
  • January 1, 2026: California SB 243 (entry)
  • January 22, 2026: South Korea's AI Basic Act (entry)
  • March 9, 2026: Australia's Age-Restricted Material Codes fully commence (entry)
  • March 17, 2026: Brazil's ECA Digital (entry)
  • April 29, 2026: UK Crime and Policing Act 2026, sections 248–249 (entry)
  • July 14, 2026: Hawaii Act 248 (entry)
  • July 15, 2026: China's Interim Measures for Anthropomorphic AI Interaction Services (entry)
  • July 27, 2026: EU Digital Omnibus on AI enters into force (entry)
  • August 2, 2026: EU AI Act Article 50 transparency duties apply (entry)
  • August 12, 2026: Colorado HB26-1263 takes effect as law; operator duties follow in 2027 (entry)

Coming up

  • December 2, 2026: EU bans on AI that generates non-consensual intimate imagery or child sexual abuse material apply; the Article 50(2) marking grace period ends (entry)
  • December 31, 2026: deadline for the UK government's progress report on regulating AI services (entry); according to the Transparency Coalition, also the deadline for New York's Governor to act on S9051B (entry)
  • January 1, 2027: California SB 867 toy ban (entry); California SB 1119 age determination, and deletion of SB 243's known-minor duties (entry); Colorado operator duties (entry); Connecticut PA 26-15 (entry); Oregon SB 1546 (entry); Rhode Island S 2195 / H 7350 (entry); Washington ESHB 2225 (entry); New York S9051B, if signed (entry)
  • July 1, 2027: California SB 1119 core duties (entry); Georgia SB 540 (entry); Idaho SB 1297 (entry); Iowa SF 2417 (entry); Nebraska LB 525 (entry); annual reporting duties start under California SB 243, Colorado HB26-1263 and Rhode Island S 2195 / H 7350
  • January 1, 2028: Hawaii annual reports to the Department of Health begin (entry); California SB 1119 interface testing and the Attorney General's complaint mechanism are due (entry)
  • January 1, 2029: first independent child-safety audits under California SB 1119 are due (entry)
  • January 1, 2031: California's ban on toys with companion chatbots expires (entry)
  • January 1, 2032: SB 1119's audit exemption for operators with under $500 million in revenue ends (entry)

What this means for users

This section is general information, not legal advice. Which rules protect you depends on where you live and which app you use.

  • You should be told you are talking to AI. In California, New York and Hawaii, and in the EU under Article 50, companion apps must tell you they are not human in many situations. New York requires a reminder at least every 3 hours during continuing conversations.
  • Crisis protocols are becoming mandatory. California, New York and Hawaii already require companion apps to run a suicide and self-harm protocol that refers users to crisis services, and ten more state laws add the same duty in 2027. Several of them name the 988 hotline. If you are in immediate danger, contact emergency services or a crisis line directly rather than relying on an app.
  • Expect more age checks. Australia already requires companion chatbots that can generate sexually explicit material to confirm users are 18 or older before giving access to it, and several US state laws add age assurance or age estimation in 2027. Some services respond by leaving a market: Chub AI geo-blocked Australia.
  • In a few places you can sue. Under California SB 243, a person injured by a violation can sue for the greater of actual damages or $1,000 per violation. Oregon's law, from January 1, 2027, also lets harmed users sue, and California SB 1119 lets a harmed child or a parent sue over some violations. Most other laws are enforced only by attorneys general or regulators.
  • Privacy is a separate question. Most companion-chatbot laws focus on safety rather than on what happens to your chat data. For that, see our AI companion privacy scorecard, our guide to encryption and data deletion, and our guide to US privacy law. For healthy-use habits, see our guide to safe virtual relationships.

What this means for AI companion app operators

This section summarizes patterns in the rules above. It is not legal advice. Laws differ in scope and definitions, and several entries rely on secondary sources, so check the text of each law and consult a lawyer before relying on it.

  • Where your users are matters. Most state laws apply to operators whose chatbots are available to users in that state, and Brazil's ECA Digital expressly covers providers based abroad.
  • A common baseline is emerging. Across the 22 rules in our matrix, the recurring duties are a not-human disclosure (often at the start and every 3 hours, and hourly for minors in several states), a suicide and self-harm protocol with crisis referral (which several states require operators to publish), and extra safeguards for minors against sexual content and manipulative engagement.
  • Therapist claims are restricted. Illinois bars AI from providing therapy, Nevada bars AI from claiming to provide mental-health care, Pennsylvania has sued over a chatbot that claimed a medical license, and Colorado, Georgia, Hawaii, Idaho, Iowa and Nebraska restrict claims of professional mental-health services.
  • Many duties start in 2027. The main duties of eleven state laws start in 2027: 6 on January 1 and 5 on July 1. In California, SB 243's known-minor duties lapse on January 1, 2027, while SB 1119's child-safety duties start on July 1, 2027.
  • Age assurance is spreading. It is already required in Australia for companion chatbots that can generate sexually explicit, high-impact violence or self-harm material, in Brazil for services unsuitable for minors, and in the UK for chatbots that can generate pornographic content. Colorado (age estimation) and Georgia (before sexual-content features) follow in 2027, and California SB 1119 relies on age signals. Pending proposals in the US Congress, New York, the EU and the UK would add more. Self-declaration is expressly not enough in Brazil and under the GUARD Act as reported.
  • Image generation raises EU risk. From December 2, 2026, the EU bans AI systems that generate non-consensual intimate imagery of identifiable people or child sexual abuse material, with fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Providers are caught where that output is the system's intended purpose, or a reasonably foreseeable and reproducible outcome and reasonable and adequate safeguards are missing.
  • Emotional dependence is a regulatory theme. The EU's Article 5 guidelines, China's measures, Washington's and Georgia's lists of banned manipulative techniques, California SB 1119 and the EU KIDS Act proposal all target designs that foster dependence.

Methodology

This tracker is desk research of public legal sources. We did not interview regulators or companies, and we did not test apps for compliance.

  • Sources: we prefer official sources: legislature websites, official gazettes, government and regulator releases, and court filings. Where an official site could not be reached, we used law-firm analyses, legal news or the Transparency Coalition, an advocacy organization, and say so in the entry's source note.
  • Status date: every status on this page was checked on September 19, 2026.
  • Inclusion criteria: we include (1) laws, regulations and bills written for AI companions or conversational chatbots; (2) general AI, online-safety and child-protection laws with provisions that directly reach companion chatbots, such as AI disclosure, manipulation bans or age checks; (3) regulator guidance and reports that address AI companions; and (4) enforcement actions against companion or chatbot providers. General privacy laws such as the CCPA are covered in our US law guide instead. The tracker is not exhaustive, and bills that have not advanced may be missing.
  • Classification: "companion-specific" means the rule is written for AI companions or conversational chatbots or, for an enforcement action or report, targets companion products as a category. We classify the laws on AI in mental-health care (Utah HB 452, Illinois HB 1806, Nevada AB 406) as not companion-specific, and the conversational-AI laws of Colorado, Idaho, Iowa and Nebraska as companion-specific although their scope is wider. "In force" means the main duties apply today; "Enacted, not yet in force" means the rule is signed but its main duties start later; "Pending" covers bills, proposals, drafts and government commitments.
  • Counts: every count on this page is computed from the 47 entries in the tracker.
  • Updates and corrections: we review the tracker monthly. To report an error or a missing rule, contact us through our About page. Our editorial policy explains how we handle corrections.
  • Not legal advice: this page summarizes public sources for general information. It is not legal advice and does not replace the text of the laws or advice from a qualified lawyer.

For how AI companions got to this point, see our AI companion history timeline.

Update log

  • 2026-09-19: initial publication with 47 entries.

How to cite this page

Suggested citation:

AI Girlfriend World (2026). AI Companion Laws Tracker 2026: Rules by Country and State. https://aigirlfriendworld.com/ai-companion-laws-tracker

HTML link:

<a href="https://aigirlfriendworld.com/ai-companion-laws-tracker">AI Companion Laws Tracker 2026</a> (AI Girlfriend World)

To cite a single rule, link to its anchor. Every entry has one, for example #us-ca-sb-243, and the CSV lists them in its id column. Please also cite the official source named in each entry.

License: the data on this page is licensed under CC BY 4.0. You are free to reuse it with a link back to this page.

Download the tracker (CSV): one row per entry, with the columns id, jurisdiction, level, instrument, type, status, date_enacted, date_effective, companion_specific, core_obligations, source_name and source_url. The companion_specific column follows the classification explained in the methodology. Dates use the YYYY-MM-DD format. For enforcement actions, date_effective is the date the action was taken, filed or announced; for guidance, date_enacted is the publication date.

More research from AI Girlfriend World

AI companion laws: frequently asked questions

Are AI girlfriend apps legal?

None of the 47 rules in this tracker bans adults from using AI companion or AI girlfriend apps. The laws set conditions on how the apps operate instead: California SB 243 and New York's Article 47, for example, require a not-human notice and a suicide and self-harm protocol. The firmest limits concern minors. China bans virtual partner services for minors, Australia requires companion chatbots that can generate sexually explicit material to confirm users are 18 or older before giving access to it, and California SB 867 bans toys with companion chatbots for children under 16 from January 1, 2027. This is general information, not legal advice.

What does California SB 243 require?

Does the EU AI Act apply to AI companions?

Which US states have AI companion chatbot laws?

Is there a federal AI companion law in the United States?

Do AI companion apps have to verify users’ age?

Which regulators have taken action against AI companion apps?