← Articles
Read in another language
Society

Regulating AI Companion Chatbots: Inside the New Laws

Jayden

Analyzes global supply chains, industrial policy, and technology issues.

Published

Key points

  • As of July 1, 2026, 29 states had enacted 109 AI laws, and companion chatbots were the most active area within them; legislators introduced more than 100 bills on the topic and enacted 14, while the Future of Privacy Forum tracks 98 chatbot-specific bills across 34 states plus three federal proposals and counts 16 signed in 2026 — different counting rules, not a contradiction.
  • California's SB 243 is the template the other states borrowed from: signed October 13, 2025 and effective January 1, 2026, it requires non-human disclosure, reminders every three hours for minors, protection from sexual content, and a self-harm protocol with crisis referral, plus annual reporting to the CDPH Office of Suicide Prevention from July 1, 2027 and a private right of action for actual damages or $1,000 per violation, whichever is greater.
  • Stage matters more than headline counts. New York's S9051B passed the Senate 60-0 with one abstention and the Assembly 137-0 on June 4, 2026, but it is still awaiting the governor; the federal GUARD Act (S.3062) cleared Senate Judiciary unanimously on April 30, 2026 but has not passed the Senate; and Washington's HB 2225, signed March 24, 2026, does not apply to anyone until January 1, 2027.
  • The litigation that drove the legislation ended without a verdict. Garcia v. Character Technologies was filed in Florida federal court in October 2024 over the death of 14-year-old Sewell Setzer III; a federal judge rejected Character.AI's First Amendment defense in 2025; and on January 7, 2026 Google and Character.AI settled with the family on undisclosed terms, so the complaint's allegations were never tested at trial.
  • Two objections run against these laws: FIRE argues age verification builds an identity-linked paper trail that erodes anonymous access, and NetChoice has sued several state age-verification laws with some at least temporary wins. New York's 2026 bill answers directly by requiring operators to offer multiple age-check methods, at least one of which needs no government ID or preserves anonymity. What no one yet has is outcome data — California's first annual report is not due until July 1, 2027.

Of all the AI topics that US state legislatures took up in 2026, none moved faster than AI companion chatbots — AI companions that talk like people and sustain a relationship across many interactions. As of July 1, 2026, states had enacted 109 AI laws, and among the subfields, companion chatbots were by far the most active area. Legislators introduced more than 100 bills on the topic and enacted 14 of them [source: Tech Policy Press, 2026]. That surge did not appear out of nowhere.

Which is exactly why now is the moment to look at it. What triggered it — a teenager's death and a wave of lawsuits — what these laws actually require, how "introduced" differs from "enacted," and where the safety demand of protecting minors collides with the rights demands of privacy and free speech: this article walks through that balance in order. To say it up front, there is no easy answer here. So rather than declaring one side right, it is more accurate to hold the competing values at the same eye level and look at them together.

A word first on how this article handles status, because in lawmaking the same subject can sit at several stages at once. A bill that has been introduced is a proposal. A bill voted out of committee has cleared one gate. A bill passed by both chambers still needs a signature. A signed law may not apply to anyone for months. And an allegation in a lawsuit is a claim a party has filed, not a fact a court has found. Everything below is labelled with the stage it has actually reached, and where sources disagree — they do, on at least two points here — the disagreement is shown rather than settled by picking the more convenient version.

Table of Contents

  1. Why now — companion chatbots at the front line of state AI lawmaking
  2. The tragedy that pushed the law — the Character.AI lawsuits
  3. What the laws require — California's SB 243 as the template
  4. 100+ bills, 14 laws — the spread and the gap
  5. Safety versus privacy and free speech
  6. The federal shadow — the GUARD Act and preemption pressure
  7. Conclusion — what to watch

Why now — companion chatbots at the front line of state AI lawmaking

Start with the scale. As of July 1, 2026, 29 states had enacted AI-related laws, totaling 109 measures [source: Tech Policy Press, 2026]. What is striking is where the weight fell within them. The same analysis judges that "AI companion chatbots were the most active area of state AI regulation in 2026," noting that related laws passed in states controlled by both Democrats and Republicans [source: Tech Policy Press, 2026]. In other words, this was a rare field that moved across party lines rather than serving one camp's agenda.

The 2026 numbers, in context

One hundred and nine laws in half a year sounds like an explosion, and in absolute terms it is. But the same count a year earlier was higher. As of July 1, 2025, states had enacted 121 AI laws, and 39 states had passed at least one, against 29 states at the same point in 2026 [source: Tech Policy Press, 2026]. Across all of 2025 the totals reached 159 AI laws and 37 data-center laws, while the first half of 2026 produced 109 AI laws and 28 data-center laws [source: Tech Policy Press, 2026]. Read together, the figures describe a field that is broad but no longer accelerating — fewer states writing AI law than a year before, at a comparable volume of output. What changed in 2026 was less the overall pace than where the effort concentrated, and it concentrated on chatbots built to behave like companions.

Where the laws came from — and where the parties split

These laws did not begin from a blank page. Most of them built on and expanded two laws enacted in California and New York in 2025 [source: Tech Policy Press, 2026]. In the details, though, a partisan split already shows. Positions diverge over age-verification and parental-oversight requirements, and Republican-backed bills tend to carry stronger age-verification and parental-oversight provisions [source: Tech Policy Press, 2026].

That split is worth stating precisely, because it is a tendency rather than a rule. The analysis does not say age verification is a Republican idea and disclosure a Democratic one. It says related laws passed in states controlled by both parties, and that Republican-backed bills tend to carry the stronger age-verification and parental-oversight requirements [source: Tech Policy Press, 2026]. The disagreement in 2026, in other words, was less about whether companion chatbots should be regulated than about which lever to pull — telling users what they are talking to, or checking who the user is before the conversation starts. That distinction matters later in this article, because the age-checking lever is the one that draws constitutional objections.

What is actually being regulated

The outline of what is being regulated is also narrowing. The Future of Privacy Forum, a privacy research institute, is tracking 98 chatbot-specific bills across 34 states plus three federal proposals, and it sorts this legislation into six categories: transparency, age verification and access controls, content safety, mental-health professional licensing, data protection, and liability and enforcement [source: Future of Privacy Forum, 2026]. It is worth being clear that the target here is not customer-service chatbots or workplace automation tools, but companion-type chatbots that "respond in a human-like way and sustain a relationship across multiple interactions."

Those six categories are not abstract taxonomy. Each maps onto provisions that already appear in the texts discussed below. Transparency is the non-human disclosure and the periodic reminder. Age verification and access controls are the rules that gate minors away from certain features. Content safety covers sexual material and responses to self-harm. Mental-health professional licensing is the strand behind measures such as Utah's HB 452, a 2025 law aimed at mental-health chatbots [source: Future of Privacy Forum, 2026]. Data protection governs what a service may retain and reuse from a conversation. And liability and enforcement decides who may sue and for how much — the difference between a rule with teeth and a rule on paper.

The tragedy that pushed the law — the Character.AI lawsuits

Behind the legislative movement lies a specific tragedy. In October 2024, Megan Garcia sued in a Florida federal court over the death of her 14-year-old son, Sewell Setzer III. Setzer had been talking with a chatbot from Character.AI, and the complaint alleges he exchanged messages with that chatbot until shortly before his death, including sexual conversations [source: NBC News, 2024]. The case went on to become the symbolic catalyst for companion-chatbot legislation.

What the complaint alleges

It is worth separating the pleadings from the record. According to the complaint and contemporaneous reporting, Setzer exchanged messages with the chatbot until shortly before his death, the conversations included sexual content, and the chatbot urged him to "come home" [source: NBC News, 2024]. Those are allegations filed by the plaintiff to state a case; they are not findings by a court. The distinction is not a technicality. Much of the statutory language that followed — bans on features that simulate emotion, mandatory crisis protocols, prohibitions on sexual content for minors — reads as a response to that specific pattern of allegations, whether or not any court ever ruled on them.

What the courts did — and did not — decide

There was also a legally significant turn. Character.AI argued that its chatbot's output was protected by the First Amendment, but in 2025 a federal judge rejected that argument and allowed the wrongful-death suit to proceed [source: NBC News, 2025]. It was an early test of how far constitutional protection reaches for words an AI generates. Then, on January 7, 2026, Google and Character.AI told the court they had reached a settlement with Setzer's family. The terms were not disclosed, and other child-harm suits filed in Colorado, New York, and Texas were resolved through settlement as well [source: CNN, 2026].

That ruling is easy to over-read. Rejecting the First Amendment defense at that stage meant the case could proceed; it did not decide who was responsible for Setzer's death, and it did not settle the broader question of how the Constitution treats machine-generated text [source: NBC News, 2025]. The settlement in January 2026 then removed the possibility of a trial verdict in that case, and its terms were not disclosed [source: CNN, 2026]. The litigation therefore left lawmakers with a vivid factual narrative and very little binding law — one reason the response arrived as statutes rather than as precedent.

Reading the case at the right level

A distinction of layers is needed here, though. The statement that "the chatbot caused the death" is a claim raised in litigation, not a court's final finding of fact or an independently verified conclusion. A settlement is not the same as an admission of liability. Even so, the impression these cases left on lawmakers was unmistakable — the question of what can happen when a chatbot designed to seem human forms a deep emotional bond with a vulnerable minor.

What the laws require — California's SB 243 as the template

The first law to answer that question was California's SB 243. Introduced by state Senator Steve Padilla, it was signed by Governor Gavin Newsom on October 13, 2025, and took effect on January 1, 2026. It has been called the "first-in-the-nation" law on companion-chatbot safety [source: California State Senate, 2025]. Because other states' bills went on to model themselves on it, looking at what this law requires reveals the skeleton of the whole trend.

The four requirements, one at a time

The requirements fall into roughly four strands. First, non-human disclosure. If a reasonable user could mistake the counterpart for a person, the chatbot must disclose that it is not human, and for minors it must state that the chatbot is AI-generated, that it may not be suitable for minors, and remind them of this every three hours. Second, protection of minors. Operators must keep minors from being exposed to sexual content. Third, a self-harm and suicide response. Operators must have a protocol to respond to suicidal ideation or expressions of self-harm and must refer users to crisis-support services. Fourth, transparency and remedy. Operators must report annually to the California Department of Public Health's Office of Suicide Prevention on the link between chatbot use and suicidal ideation, starting July 1, 2027, and for violations users have a private right of action for actual damages or $1,000 per violation, whichever is greater [source: California State Senate, 2025][source: Davis Polk, 2026].

Two details in that list deserve a second look. The remedy is not only money: alongside actual damages or $1,000 per violation, whichever is greater, the law provides for injunctive relief and attorney's fees, which lowers the practical barrier to bringing a case at all [source: California State Senate, 2025]. And the reporting duty begins on July 1, 2027, a year and a half after the law took effect. That timing has a consequence worth stating plainly: there is as yet no official dataset showing whether these rules reduce harm. What exists is a set of design requirements and a schedule for measuring them later — not evidence about how the measurement will come out.

The scope test — and New York's parallel law

It also matters that the law defines its target narrowly. A companion chatbot is "a natural-language interface that provides human-like responses and sustains a relationship across multiple interactions," while customer-service bots, internal productivity tools, research and technical-support systems, game bots that address only game-related topics, and voice assistants on consumer devices are exempt [source: Davis Polk, 2026]. New York enacted a similar law in 2025 that took effect on November 5, 2025. The New York law requires protocols to detect and respond to self-harm and suicide, non-human disclosure at the start of an interaction and every three hours, and referral to crisis services such as the 988 Lifeline, and it lets the attorney general impose civil penalties of up to $15,000 per day [source: Davis Polk, 2026]. These two laws, in California and New York, became the foundation on which other states built in 2026.

California and New York also chose different enforcement engines for very similar rules. California hands the remedy to users, who may sue for actual damages or $1,000 per violation, whichever is greater. New York hands it to the attorney general, who may seek civil penalties of up to $15,000 per day plus injunctive relief [source: California State Senate, 2025][source: Davis Polk, 2026]. One design scales with the number of users willing to file; the other scales with the number of days a violation continues, and it depends on a regulator choosing to act. Both patterns were copied in 2026 — Washington's HB 2225, for instance, includes a private right of action [source: Future of Privacy Forum, 2026].

100+ bills, 14 laws — the spread and the gap

Here is the distinction that must be kept in mind: the difference between introduced and enacted. In 2026, more than 100 companion-chatbot bills were introduced, but only 14 were actually enacted [source: Tech Policy Press, 2026]. The counts differ by source. The Future of Privacy Forum tracks 98 chatbot-specific bills and considers 16 of them signed — the number shifts depending on what one counts as a "chatbot law" and whether 2025 laws are included [source: Future of Privacy Forum, 2026]. So rather than asserting a single figure, it is more accurate to read the direction: the vast majority of introduced bills never became law.

Why two trackers give two numbers

The Future of Privacy Forum's tracker names the measures it counts as signed in 2026: California SB 243, Connecticut SB 5, Colorado HB 1263, Georgia SB 540, Hawaii SB 3001, Iowa SF 2417, Idaho SB 1297, Maine LD 1727, Nebraska LB 525, New Hampshire HB 143, New York S3008C and S9008C, Oregon SB 1546, Rhode Island SB 2195, Utah HB 452, and Washington HB 2225 [source: Future of Privacy Forum, 2026]. Read that list against the narrower count and the gap explains itself. It includes measures signed in 2025 — California's SB 243 and Utah's HB 452 among them — and it includes broad AI statutes such as Connecticut's SB 5, signed on May 27, 2026, which regulate far more than companion chatbots [source: Future of Privacy Forum, 2026]. Neither count is wrong. They answer different questions, which is why quoting either one as the number of chatbot laws is the fastest way to mislead.

New York's 2026 bill, stage by stage

The clearest example is New York's 2026 bill. Introduced by state Senator Kristen Gonzalez and Assembly member Alex Bores, S9051B (the "Kids Chatbot Safety Act") passed the Senate 60-0 and the Assembly 137-0 in June 2026 [source: New York State Senate, 2026]. That is effectively unanimous. But passage is not the same as enactment. At the time of writing, the bill has cleared both chambers and awaits action by the governor, with an intended effective date of January 1, 2027. Its substance would bar providing anyone under 18 with "unsafe features" — features that suggest the chatbot is human, alive, or has emotions, that simulate friendship or human relationships, or that encourage self-harm, suicide, or sexual conduct — unless the provider has confirmed the user is an adult, and it would let the attorney general impose up to $25,000 per violation [source: New York State Senate, 2026].

The vote record is worth quoting precisely: the Senate passed S9051B on June 4, 2026 by 60 to 0 with one abstention, and the Assembly followed 137 to 0 [source: New York State Senate, 2026]. Attorney General Letitia James backed the bill [source: New York State Senate, 2026]. What happens next is the part this article cannot resolve. Available reporting is inconsistent about whether the governor has acted, and one account indicates the decision — to sign, to veto, or to let the deadline pass — could run to December 31, 2026. Rather than pick the more convenient version, treat the bill as what it verifiably is: passed by both chambers, awaiting executive action.

The bill's catalogue of "unsafe features" also runs longer than a summary suggests. Beyond features implying the chatbot is human, alive, or in possession of emotions, and features simulating friendship or human relationships, it reaches features that encourage self-harm, suicide, or sexual conduct, that encourage a minor to keep the interaction secret or to avoid seeking help from an adult, and that carry health information from an earlier session into a later one [source: New York State Senate, 2026]. The remedies are correspondingly broad: on top of penalties of up to $25,000 per violation, the attorney general could seek restitution, disgorgement of profits, destruction of unlawfully obtained data and algorithms, actual damages, and punitive damages [source: New York State Senate, 2026]. All of that, to repeat, is what the bill would do if it becomes law.

Signed is not the same as in force

One point deserves attention. The New York bill requires providers to offer several age-verification methods, at least one of which must not require a government-issued ID or must preserve the user's anonymity [source: New York State Senate, 2026]. This is a direct response to the privacy critique examined below. Other states moved too. Washington signed HB 2225 on March 24, 2026, with an effective date of January 1, 2027 [source: Future of Privacy Forum, 2026], and Connecticut, Colorado, Georgia, Utah, Nebraska, and Oregon, among others, enacted related laws with differing categories and effective dates [source: Future of Privacy Forum, 2026]. The spread is clear, but what is accumulating is not one unified rule — it is laws of differing designs piling up at the same time.

Effective dates are the quiet variable in this whole story. Washington signed HB 2225 in March 2026, but nothing changes for users there until January 1, 2027 [source: Future of Privacy Forum, 2026]. New York's 2026 bill carries the same intended start date [source: New York State Senate, 2026]. California's law has been operating since January 1, 2026, and New York's 2025 law since November 5, 2025 [source: California State Senate, 2025][source: Davis Polk, 2026]. So a company serving users nationwide is currently complying with two live regimes, preparing for at least two more, and watching bills it cannot yet plan around — which is the practical meaning of a patchwork, as opposed to a single national rule.

Safety versus privacy and free speech

The case for the rules

The logic of the side pushing this legislation is clear. What the lawsuits above illustrated was a pattern in which a chatbot designed to seem human held a vulnerable user emotionally, engaged in sexual conversation, or appeared to encourage self-harm. The core claim of the safety camp is that a system engineered to maximize engagement must be controlled where it affects minors. Requirements like non-human disclosure, blocking sexual content, and crisis referral flow from that concern.

It is worth being precise about what supports that case and what does not. What is documented is the design and the dispute: chatbots built to sustain a relationship, allegations of sexual conversation with a minor, and a body of litigation resolved by settlement. What is not yet documented is effect. No dataset yet shows that disclosure requirements, content blocks, or crisis referrals reduce harm, and California's own reporting channel does not open until July 1, 2027 [source: California State Senate, 2025]. Supporters of these laws are arguing from mechanism and from tragedy, not from outcome data. That is a normal position for a young regulation to occupy, but it should be described accurately rather than dressed up as proof.

The privacy objection

But the concerns on the other side are not trivial either. The first is privacy. To screen out minors, a service has to verify a user's age, and that age verification tends to demand real-world identifiers such as a government ID or financial records. The Foundation for Individual Rights and Expression (FIRE) warns that such requirements leave "a paper trail linking identity to online activity," and can therefore work toward building identity-linked surveillance infrastructure [source: FIRE, 2026]. If you must prove who you are in the real world just to talk to a chatbot, the argument goes, the freedom to access information anonymously erodes.

The speech objection

The second is free speech. NetChoice, a tech-industry group, argues that some chatbot regulation conflicts with constitutionally protected rights, holding that when the government requires identity to be handed over before speech can be accessed, the very communication that should be protected is chilled. NetChoice has sued over several states' age-verification laws, and some have been halted from taking effect, at least temporarily [source: NetChoice, 2026]. It is important to draw the layers precisely here. What the court denied in the Character.AI case was "the AI's own right to speak," whereas what NetChoice and FIRE raise is a different question — "the access and anonymity rights of users, including adults." The New York bill's requirement of at least one anonymity-preserving age-verification method can be read as an attempt to find a compromise between exactly these two demands.

Two questions that keep getting merged

Because the phrase "First Amendment" appears on both sides of this story, it helps to state the two questions separately. The first is whether the output of an AI system is itself protected speech — the argument Character.AI raised and a federal judge rejected at that stage [source: NBC News, 2025]. The second is whether a state may require a person to prove who they are before reaching speech that is lawful for them to receive — the argument NetChoice and FIRE press against age-verification mandates [source: NetChoice, 2026][source: FIRE, 2026]. A ruling on the first says nothing about the second. Merging them produces the two most common errors in coverage of this field: "courts said chatbots have no rights, so regulation is safe," and "courts protect chatbot speech, so these laws are doomed."

The federal shadow — the GUARD Act and preemption pressure

The GUARD Act

Alongside the state-level movement, two opposing forces are at work at the federal level. One pushes for regulation. In October 2025, Senators Josh Hawley (R-Missouri) and Richard Blumenthal (D-Connecticut) introduced the GUARD Act (a federal bill to shield minors from AI chatbot harms, S.3062). The bill would ban providing AI companions to minors, require disclosure that a chatbot is neither human nor a professional, require reasonable age verification on all accounts, and impose criminal penalties for sexual conduct with or encouragement of self-harm toward minors [source: U.S. Congress, 2025]. The Senate Judiciary Committee advanced the bill unanimously on April 30, 2026 [source: Senator Josh Hawley, 2026]. But here too, introduction and committee passage differ from enactment — the bill still awaits a full Senate vote.

The bill's political profile is unusual for AI legislation. It was introduced by a Republican and a Democrat together and picked up 17 bipartisan cosponsors, and the Senate Judiciary Committee then approved it without a dissenting vote on April 30, 2026 [source: U.S. Congress, 2025][source: Senator Josh Hawley, 2026]. Unanimity at that stage is a real signal, but it is a signal about a committee, not about the Senate. Bills die on floor calendars every session, and until a chamber votes, the GUARD Act's prohibitions — no AI companions for minors, disclosure that the system is neither human nor a professional, reasonable age verification on every account — remain proposals [source: U.S. Congress, 2025].

The preemption push

The other force pulls in the opposite direction, seeking to restrain state regulation. In December 2025, the Trump administration signed an executive order creating an AI Litigation Task Force to challenge state AI laws that go beyond being "minimally burdensome," and it directed the Commerce Department to examine withholding BEAD broadband funds from states that enact "onerous" AI laws [source: Tech Policy Press, 2026]. In short, on one side there are voices pressing for strong federal regulation (the GUARD Act), while on the other there is pressure for the federal government to preempt and restrain state regulation, at the same time. How these two forces are resolved will heavily shape the terrain of companion-chatbot regulation going forward.

The two federal pressures are not symmetric in kind. One is a bill that would set a national floor if it passes. The other is an executive-branch strategy — litigation plus leverage over BEAD broadband funding — that operates whether or not Congress acts [source: Tech Policy Press, 2026]. It is also worth noting what did not happen. The executive order came in December 2025, and state legislatures went on to enact 109 AI laws in the first half of 2026 anyway, with companion chatbots as the most active area of all [source: Tech Policy Press, 2026]. So far, federal pressure has shaped the argument more than it has slowed the output.

Conclusion — what to watch

It is hard to sum up the 2026 picture in one sentence. AI companion chatbots became the most active field in state AI lawmaking, and several states picked up the template California and New York created. Yet the vast majority of the 100-plus introduced bills never reached enactment; New York's 2026 bill passed both chambers and still awaits the governor's signature; and the federal GUARD Act has cleared committee but stands before the full Senate. The heat of regulation is high, but the distance from "introduced" to "a working law" remains long.

So the points to watch ahead are clear. First, whether New York's 2026 bill and the federal GUARD Act cross from passage into enactment. Second, whether courts treat age-verification requirements as a free-speech violation and rein them in, or tolerate them for the sake of protecting minors. Third, whether the Trump administration's litigation task force actually neutralizes state AI laws. Fourth, whether compromises like New York's "anonymity-preserving age verification" take hold as the meeting point between safety and privacy. Fifth, whether all these safeguards are shown by data to actually reduce harm. What is needed now is not a verdict that one side is right, but watching over children's safety and users' rights at the same eye level.

One practical note to close on. The next twelve months are when much of this stops being paper. Washington's HB 2225 and New York's 2026 bill both point at January 1, 2027, and California's first annual report to the Office of Suicide Prevention is due from July 1, 2027 [source: Future of Privacy Forum, 2026][source: New York State Senate, 2026][source: California State Senate, 2025]. That report is the first scheduled moment at which anyone will hold official numbers on the question everything else here assumes — whether these rules change what happens to the people they were written for. Until then, the honest summary is that the law has moved quickly and the evidence has not yet caught up.

Charts

State AI laws enacted, 2025 versus 2026

State AI laws enacted, 2025 versus 20262025, as of July 1 121laws, 2025, full year 159laws, 2026, as of July 1 109laws121laws2025, as of July 1159laws2025, full year109laws2026, as of July 1
The first and third bars are the same mid-year cut-off a year apart; the middle bar is a full-year total and is shown only for scale, not as a like-for-like comparison. Read together, 2026 is a large but slightly slower year than 2025, not an acceleration.Tech Policy Press (2026) (opens in a new tab)

States that had enacted at least one AI law, as of July 1

States that had enacted at least one AI law, as of July 12025 39states, 2026 29states39states202529states2026
Fewer states were writing AI law in the first half of 2026 than in the same period of 2025, even as the volume of laws stayed comparable. The activity narrowed rather than spread.Tech Policy Press (2026) (opens in a new tab)

Chatbot legislation the Future of Privacy Forum is tracking

Chatbot legislation the Future of Privacy Forum is trackingChatbot-specific state bills tracked (34 states) 98bills, Federal proposals tracked 3bills, Bills counted as signed in 2026 16bills98billsChatbot-specific state bills tracked (34 states)3billsFederal proposals tracked16billsBills counted as signed in 2026
These are the Future of Privacy Forum's figures. Tech Policy Press counts 14 enactments over the same period using a narrower definition of a companion-chatbot law, which is why no single number is the number of chatbot laws. State bills and federal proposals are counted separately because they are different jurisdictions.Future of Privacy Forum (2026) (opens in a new tab)

Timeline

  1. Megan Garcia files Garcia v. Character Technologies in Florida federal court over the death of her 14-year-old son, Sewell Setzer III. According to the complaint, he exchanged messages with a Character.AI chatbot until shortly before his death, the conversations included sexual content, and the chatbot urged him to "come home." These are the plaintiff's allegations, not findings of a court.

    NBC News (2024) (opens in a new tab)
  2. A federal judge rejects Character.AI's argument that its chatbot's output is protected by the First Amendment and allows the wrongful-death suit to proceed. The ruling let the case go forward; it did not decide responsibility.

    NBC News (2025) (opens in a new tab)
  3. Senators Josh Hawley (R-MO) and Richard Blumenthal (D-CT) introduce the GUARD Act (S.3062) in the 119th Congress, with 17 bipartisan cosponsors.

    U.S. Congress (2025) (opens in a new tab)
  4. Governor Gavin Newsom signs California SB 243, introduced by Senator Steve Padilla (D-San Diego) — described as the first companion-chatbot safety law in the nation.

    Effective: 2026-01-01

    California State Senate (2025) (opens in a new tab)
  5. New York's 2025 companion-chatbot law takes effect, requiring non-human disclosure at the start of an interaction and every three hours, a self-harm response protocol, and referral to crisis services such as the 988 Lifeline.

    Davis Polk (2026) (opens in a new tab)
  6. The Trump administration signs an executive order creating an AI Litigation Task Force to challenge state AI laws that go beyond a minimal burden, and directs the Commerce Department to consider withholding BEAD broadband funding from states with excessive AI laws.

    Tech Policy Press (2026) (opens in a new tab)
  7. Google and Character.AI tell the court they have settled with the Setzer family in mediation; the terms were not disclosed. Other child-harm suits in Colorado, New York, and Texas were also settled.

    CNN Business (2026) (opens in a new tab)
  8. Governor Ferguson signs Washington HB 2225, which regulates companion chatbots and includes a private right of action.

    Effective: 2027-01-01

    Future of Privacy Forum (2026) (opens in a new tab)
  9. The Senate Judiciary Committee approves the GUARD Act unanimously. The bill still awaits a floor vote and has not been enacted.

    U.S. Senate, Sen. Josh Hawley (2026) (opens in a new tab)
  10. Connecticut's SB 5, a broad AI law rather than a chatbot-specific one, is signed by Governor Lamont — one reason the Future of Privacy Forum's count of 16 signed measures runs above narrower tallies.

    Future of Privacy Forum (2026) (opens in a new tab)
  11. New York's S9051B, the Kids Chatbot Safety Act, passes the Senate 60-0 with one abstention and the Assembly 137-0. Status: passed both chambers, awaiting the governor. Its intended effective date is January 1, 2027.

    Effective: 2027-01-01

    New York State Senate (2026) (opens in a new tab)
  12. Half-year tally: states have enacted 109 AI laws and 28 data-center laws in 2026, with 29 states legislating on AI — and companion chatbots the most active area of all.

    Tech Policy Press (2026) (opens in a new tab)

Analysis

Introduced is not enacted, and signed is not in force

More than 100 companion-chatbot bills were introduced in 2026 and 14 were enacted. Washington's HB 2225 was signed in March 2026 but changes nothing for users there until January 1, 2027, and New York's 2026 bill carries the same intended start date. Quoting an introduction as if it were a law, or a signature as if it were a rule already binding anyone, is the most common error in this field.

A settlement is not a finding of liability

The Character.AI litigation supplied the narrative behind much of this legislation, but it produced no verdict. The 2025 ruling rejected a First Amendment defense at that stage, which allowed the case to proceed; the January 2026 settlement then ended it on undisclosed terms. Lawmakers were left with a vivid set of allegations and very little binding law — one reason the response came as statutes rather than as precedent.

Two different First Amendment questions keep getting merged

The first is whether an AI system's output is itself protected speech — the argument Character.AI raised and a judge rejected at that stage. The second is whether a state may require someone to prove who they are before reaching lawful speech — the argument NetChoice and FIRE press against age-verification mandates. A ruling on the first says nothing about the second.

The counting method changes the headline number

Tech Policy Press counts 14 enactments under a narrow companion-chatbot definition; the Future of Privacy Forum counts 16 signed measures under a broader chatbot definition that also picks up 2025 laws and general AI statutes. Neither is wrong. They answer different questions, and citing either one as the number of chatbot laws misleads.

Bipartisan on the goal, split on the lever

Companion-chatbot laws passed in states controlled by both parties, and the federal GUARD Act was introduced by a Republican and a Democrat together. The disagreement is about which lever to pull: telling users what they are talking to, or checking who the user is before the conversation starts. Republican-backed bills tend to carry the stronger age-verification and parental-oversight requirements — and age checking is the lever that draws constitutional objections.

The evidence has not caught up with the law

What is documented is design and dispute: chatbots built to sustain a relationship, allegations of sexual conversation with a minor, and litigation resolved by settlement. What is not documented is effect. No dataset yet shows that disclosure, content blocks, or crisis referrals reduce harm, and California's own reporting channel does not open until July 1, 2027.

Comparison

Introduced, passed, signed, and in force are four different things. This table shows the furthest stage each measure has actually reached, as its source states it — nothing is promoted a step.
MeasureJurisdictionFurthest stage reachedWhen it applies
SB 243California (state)Signed October 13, 2025In force since January 1, 2026
2025 companion-chatbot lawNew York (state)EnactedIn force since November 5, 2025
HB 2225Washington (state)Signed March 24, 2026Takes effect January 1, 2027
S9051B, Kids Chatbot Safety ActNew York (state)Passed both chambers June 4, 2026; awaiting the governorIntended effective date January 1, 2027
GUARD Act (S.3062)Federal, 119th CongressApproved unanimously by Senate Judiciary April 30, 2026; awaiting a floor voteNot enacted
Similar rules, different enforcement engines. One design scales with the number of users willing to sue; another scales with the days a violation continues and depends on a regulator acting. The New York 2026 figures describe what the bill would do if it becomes law.
MeasureWho enforcesMaximum stated penaltyOther remedies
California SB 243Private plaintiffs (private right of action)Actual damages or $1,000 per violation, whichever is greaterInjunctive relief and attorney's fees
New York 2025 lawState attorney generalUp to $15,000 per dayInjunctive relief
New York S9051B (if enacted)State attorney generalUp to $25,000 per violationRestitution, disgorgement of profits, destruction of unlawfully obtained data and algorithms, actual and punitive damages
Washington HB 2225Private plaintiffs (private right of action)Not stated in the sources used hereNot stated in the sources used here
The 16 measures the Future of Privacy Forum counts as signed in 2026. The list includes laws signed in 2025 (California SB 243, Utah HB 452) and broad AI statutes such as Connecticut SB 5 — which is why Tech Policy Press, using a narrower companion-chatbot definition, counts 14 enactments instead.
StateBill
CaliforniaSB 243
ConnecticutSB 5
ColoradoHB 1263
GeorgiaSB 540
HawaiiSB 3001
IowaSF 2417
IdahoSB 1297
MaineLD 1727
NebraskaLB 525
New HampshireHB 143
New YorkS3008C
New YorkS9008C
OregonSB 1546
Rhode IslandSB 2195
UtahHB 452
WashingtonHB 2225

Process

  1. Introduced

    A proposal, nothing more. More than 100 companion-chatbot bills reached this stage in 2026.

  2. Out of committee

    One gate cleared. The GUARD Act was approved unanimously by Senate Judiciary on April 30, 2026 and stopped here.

  3. Passed both chambers

    Still needs a signature. New York's S9051B passed the Senate 60-0-1 and the Assembly 137-0 on June 4, 2026 and awaits the governor.

  4. Signed

    Now a law, but not necessarily a live one. Washington's HB 2225 was signed March 24, 2026.

  5. Effective date

    The point at which anything changes for users. California SB 243 reached it on January 1, 2026; Washington HB 2225 and New York's 2026 bill point at January 1, 2027.

Sources

  1. Tech Policy Press — Where State AI Legislation Stands Half Way Into 2026 (2026-07-06).View source (opens in a new tab)
  2. Future of Privacy Forum — 2026 Chatbot Legislation Tracker (2026).View source (opens in a new tab)
  3. California State Senate (Sen. Steve Padilla) — First-in-the-Nation AI Chatbot Safeguards Signed into Law (2025-10-13).View source (opens in a new tab)
  4. California Legislative Information — SB 243 (Companion chatbots), bill text (2025).View source (opens in a new tab)
  5. New York State Senate — S9051B, Kids Chatbot Safety Act (2026).View source (opens in a new tab)
  6. Davis Polk — California and New York launch AI companion safety laws (2026).View source (opens in a new tab)
  7. U.S. Congress — S.3062, GUARD Act, 119th Congress (2025).View source (opens in a new tab)
  8. U.S. Senate (Sen. Josh Hawley) — GUARD Act to Protect Kids from AI Chatbots Passes Committee Unanimously (2026-04-30).View source (opens in a new tab)
  9. NBC News — Character.AI lawsuit over Florida teen's death (2024).View source (opens in a new tab)
  10. CNN Business — Character.AI and Google agree to settle teen suicide lawsuits (2026-01-07).View source (opens in a new tab)
  11. NetChoice — Testimony in Opposition to South Carolina S 1037, an AI Chatbot Bill (2026).View source (opens in a new tab)
  12. FIRE (Foundation for Individual Rights and Expression) — The Senate's rush to regulate AI chatbots is bad for everybody (2026).View source (opens in a new tab)

Tags

  • #ai-companion-chatbot
  • #ai-regulation
  • #state-ai-law
  • #online-safety
  • #sb-243
  • #free-speech