Of all the AI topics that US state legislatures took up in 2026, none moved faster than AI companion chatbots — AI companions that talk like people and sustain a relationship across many interactions. As of July 1, 2026, states had enacted 109 AI laws, and among the subfields, companion chatbots were by far the most active area. Legislators introduced more than 100 bills on the topic and enacted 14 of them [source: Tech Policy Press, 2026]. That surge did not appear out of nowhere.
Which is exactly why now is the moment to look at it. What triggered it — a teenager's death and a wave of lawsuits — what these laws actually require, how "introduced" differs from "enacted," and where the safety demand of protecting minors collides with the rights demands of privacy and free speech: this article walks through that balance in order. To say it up front, there is no easy answer here. So rather than declaring one side right, it is more accurate to hold the competing values at the same eye level and look at them together.
A word first on how this article handles status, because in lawmaking the same subject can sit at several stages at once. A bill that has been introduced is a proposal. A bill voted out of committee has cleared one gate. A bill passed by both chambers still needs a signature. A signed law may not apply to anyone for months. And an allegation in a lawsuit is a claim a party has filed, not a fact a court has found. Everything below is labelled with the stage it has actually reached, and where sources disagree — they do, on at least two points here — the disagreement is shown rather than settled by picking the more convenient version.
Table of Contents
- Why now — companion chatbots at the front line of state AI lawmaking
- The tragedy that pushed the law — the Character.AI lawsuits
- What the laws require — California's SB 243 as the template
- 100+ bills, 14 laws — the spread and the gap
- Safety versus privacy and free speech
- The federal shadow — the GUARD Act and preemption pressure
- Conclusion — what to watch
Why now — companion chatbots at the front line of state AI lawmaking
Start with the scale. As of July 1, 2026, 29 states had enacted AI-related laws, totaling 109 measures [source: Tech Policy Press, 2026]. What is striking is where the weight fell within them. The same analysis judges that "AI companion chatbots were the most active area of state AI regulation in 2026," noting that related laws passed in states controlled by both Democrats and Republicans [source: Tech Policy Press, 2026]. In other words, this was a rare field that moved across party lines rather than serving one camp's agenda.
The 2026 numbers, in context
One hundred and nine laws in half a year sounds like an explosion, and in absolute terms it is. But the same count a year earlier was higher. As of July 1, 2025, states had enacted 121 AI laws, and 39 states had passed at least one, against 29 states at the same point in 2026 [source: Tech Policy Press, 2026]. Across all of 2025 the totals reached 159 AI laws and 37 data-center laws, while the first half of 2026 produced 109 AI laws and 28 data-center laws [source: Tech Policy Press, 2026]. Read together, the figures describe a field that is broad but no longer accelerating — fewer states writing AI law than a year before, at a comparable volume of output. What changed in 2026 was less the overall pace than where the effort concentrated, and it concentrated on chatbots built to behave like companions.
Where the laws came from — and where the parties split
These laws did not begin from a blank page. Most of them built on and expanded two laws enacted in California and New York in 2025 [source: Tech Policy Press, 2026]. In the details, though, a partisan split already shows. Positions diverge over age-verification and parental-oversight requirements, and Republican-backed bills tend to carry stronger age-verification and parental-oversight provisions [source: Tech Policy Press, 2026].
That split is worth stating precisely, because it is a tendency rather than a rule. The analysis does not say age verification is a Republican idea and disclosure a Democratic one. It says related laws passed in states controlled by both parties, and that Republican-backed bills tend to carry the stronger age-verification and parental-oversight requirements [source: Tech Policy Press, 2026]. The disagreement in 2026, in other words, was less about whether companion chatbots should be regulated than about which lever to pull — telling users what they are talking to, or checking who the user is before the conversation starts. That distinction matters later in this article, because the age-checking lever is the one that draws constitutional objections.
What is actually being regulated
The outline of what is being regulated is also narrowing. The Future of Privacy Forum, a privacy research institute, is tracking 98 chatbot-specific bills across 34 states plus three federal proposals, and it sorts this legislation into six categories: transparency, age verification and access controls, content safety, mental-health professional licensing, data protection, and liability and enforcement [source: Future of Privacy Forum, 2026]. It is worth being clear that the target here is not customer-service chatbots or workplace automation tools, but companion-type chatbots that "respond in a human-like way and sustain a relationship across multiple interactions."
Those six categories are not abstract taxonomy. Each maps onto provisions that already appear in the texts discussed below. Transparency is the non-human disclosure and the periodic reminder. Age verification and access controls are the rules that gate minors away from certain features. Content safety covers sexual material and responses to self-harm. Mental-health professional licensing is the strand behind measures such as Utah's HB 452, a 2025 law aimed at mental-health chatbots [source: Future of Privacy Forum, 2026]. Data protection governs what a service may retain and reuse from a conversation. And liability and enforcement decides who may sue and for how much — the difference between a rule with teeth and a rule on paper.
The tragedy that pushed the law — the Character.AI lawsuits
Behind the legislative movement lies a specific tragedy. In October 2024, Megan Garcia sued in a Florida federal court over the death of her 14-year-old son, Sewell Setzer III. Setzer had been talking with a chatbot from Character.AI, and the complaint alleges he exchanged messages with that chatbot until shortly before his death, including sexual conversations [source: NBC News, 2024]. The case went on to become the symbolic catalyst for companion-chatbot legislation.
What the complaint alleges
It is worth separating the pleadings from the record. According to the complaint and contemporaneous reporting, Setzer exchanged messages with the chatbot until shortly before his death, the conversations included sexual content, and the chatbot urged him to "come home" [source: NBC News, 2024]. Those are allegations filed by the plaintiff to state a case; they are not findings by a court. The distinction is not a technicality. Much of the statutory language that followed — bans on features that simulate emotion, mandatory crisis protocols, prohibitions on sexual content for minors — reads as a response to that specific pattern of allegations, whether or not any court ever ruled on them.
What the courts did — and did not — decide
There was also a legally significant turn. Character.AI argued that its chatbot's output was protected by the First Amendment, but in 2025 a federal judge rejected that argument and allowed the wrongful-death suit to proceed [source: NBC News, 2025]. It was an early test of how far constitutional protection reaches for words an AI generates. Then, on January 7, 2026, Google and Character.AI told the court they had reached a settlement with Setzer's family. The terms were not disclosed, and other child-harm suits filed in Colorado, New York, and Texas were resolved through settlement as well [source: CNN, 2026].
That ruling is easy to over-read. Rejecting the First Amendment defense at that stage meant the case could proceed; it did not decide who was responsible for Setzer's death, and it did not settle the broader question of how the Constitution treats machine-generated text [source: NBC News, 2025]. The settlement in January 2026 then removed the possibility of a trial verdict in that case, and its terms were not disclosed [source: CNN, 2026]. The litigation therefore left lawmakers with a vivid factual narrative and very little binding law — one reason the response arrived as statutes rather than as precedent.
Reading the case at the right level
A distinction of layers is needed here, though. The statement that "the chatbot caused the death" is a claim raised in litigation, not a court's final finding of fact or an independently verified conclusion. A settlement is not the same as an admission of liability. Even so, the impression these cases left on lawmakers was unmistakable — the question of what can happen when a chatbot designed to seem human forms a deep emotional bond with a vulnerable minor.
What the laws require — California's SB 243 as the template
The first law to answer that question was California's SB 243. Introduced by state Senator Steve Padilla, it was signed by Governor Gavin Newsom on October 13, 2025, and took effect on January 1, 2026. It has been called the "first-in-the-nation" law on companion-chatbot safety [source: California State Senate, 2025]. Because other states' bills went on to model themselves on it, looking at what this law requires reveals the skeleton of the whole trend.
The four requirements, one at a time
The requirements fall into roughly four strands. First, non-human disclosure. If a reasonable user could mistake the counterpart for a person, the chatbot must disclose that it is not human, and for minors it must state that the chatbot is AI-generated, that it may not be suitable for minors, and remind them of this every three hours. Second, protection of minors. Operators must keep minors from being exposed to sexual content. Third, a self-harm and suicide response. Operators must have a protocol to respond to suicidal ideation or expressions of self-harm and must refer users to crisis-support services. Fourth, transparency and remedy. Operators must report annually to the California Department of Public Health's Office of Suicide Prevention on the link between chatbot use and suicidal ideation, starting July 1, 2027, and for violations users have a private right of action for actual damages or $1,000 per violation, whichever is greater [source: California State Senate, 2025][source: Davis Polk, 2026].
Two details in that list deserve a second look. The remedy is not only money: alongside actual damages or $1,000 per violation, whichever is greater, the law provides for injunctive relief and attorney's fees, which lowers the practical barrier to bringing a case at all [source: California State Senate, 2025]. And the reporting duty begins on July 1, 2027, a year and a half after the law took effect. That timing has a consequence worth stating plainly: there is as yet no official dataset showing whether these rules reduce harm. What exists is a set of design requirements and a schedule for measuring them later — not evidence about how the measurement will come out.
The scope test — and New York's parallel law
It also matters that the law defines its target narrowly. A companion chatbot is "a natural-language interface that provides human-like responses and sustains a relationship across multiple interactions," while customer-service bots, internal productivity tools, research and technical-support systems, game bots that address only game-related topics, and voice assistants on consumer devices are exempt [source: Davis Polk, 2026]. New York enacted a similar law in 2025 that took effect on November 5, 2025. The New York law requires protocols to detect and respond to self-harm and suicide, non-human disclosure at the start of an interaction and every three hours, and referral to crisis services such as the 988 Lifeline, and it lets the attorney general impose civil penalties of up to $15,000 per day [source: Davis Polk, 2026]. These two laws, in California and New York, became the foundation on which other states built in 2026.
California and New York also chose different enforcement engines for very similar rules. California hands the remedy to users, who may sue for actual damages or $1,000 per violation, whichever is greater. New York hands it to the attorney general, who may seek civil penalties of up to $15,000 per day plus injunctive relief [source: California State Senate, 2025][source: Davis Polk, 2026]. One design scales with the number of users willing to file; the other scales with the number of days a violation continues, and it depends on a regulator choosing to act. Both patterns were copied in 2026 — Washington's HB 2225, for instance, includes a private right of action [source: Future of Privacy Forum, 2026].
100+ bills, 14 laws — the spread and the gap
Here is the distinction that must be kept in mind: the difference between introduced and enacted. In 2026, more than 100 companion-chatbot bills were introduced, but only 14 were actually enacted [source: Tech Policy Press, 2026]. The counts differ by source. The Future of Privacy Forum tracks 98 chatbot-specific bills and considers 16 of them signed — the number shifts depending on what one counts as a "chatbot law" and whether 2025 laws are included [source: Future of Privacy Forum, 2026]. So rather than asserting a single figure, it is more accurate to read the direction: the vast majority of introduced bills never became law.
Why two trackers give two numbers
The Future of Privacy Forum's tracker names the measures it counts as signed in 2026: California SB 243, Connecticut SB 5, Colorado HB 1263, Georgia SB 540, Hawaii SB 3001, Iowa SF 2417, Idaho SB 1297, Maine LD 1727, Nebraska LB 525, New Hampshire HB 143, New York S3008C and S9008C, Oregon SB 1546, Rhode Island SB 2195, Utah HB 452, and Washington HB 2225 [source: Future of Privacy Forum, 2026]. Read that list against the narrower count and the gap explains itself. It includes measures signed in 2025 — California's SB 243 and Utah's HB 452 among them — and it includes broad AI statutes such as Connecticut's SB 5, signed on May 27, 2026, which regulate far more than companion chatbots [source: Future of Privacy Forum, 2026]. Neither count is wrong. They answer different questions, which is why quoting either one as the number of chatbot laws is the fastest way to mislead.
New York's 2026 bill, stage by stage
The clearest example is New York's 2026 bill. Introduced by state Senator Kristen Gonzalez and Assembly member Alex Bores, S9051B (the "Kids Chatbot Safety Act") passed the Senate 60-0 and the Assembly 137-0 in June 2026 [source: New York State Senate, 2026]. That is effectively unanimous. But passage is not the same as enactment. At the time of writing, the bill has cleared both chambers and awaits action by the governor, with an intended effective date of January 1, 2027. Its substance would bar providing anyone under 18 with "unsafe features" — features that suggest the chatbot is human, alive, or has emotions, that simulate friendship or human relationships, or that encourage self-harm, suicide, or sexual conduct — unless the provider has confirmed the user is an adult, and it would let the attorney general impose up to $25,000 per violation [source: New York State Senate, 2026].
The vote record is worth quoting precisely: the Senate passed S9051B on June 4, 2026 by 60 to 0 with one abstention, and the Assembly followed 137 to 0 [source: New York State Senate, 2026]. Attorney General Letitia James backed the bill [source: New York State Senate, 2026]. What happens next is the part this article cannot resolve. Available reporting is inconsistent about whether the governor has acted, and one account indicates the decision — to sign, to veto, or to let the deadline pass — could run to December 31, 2026. Rather than pick the more convenient version, treat the bill as what it verifiably is: passed by both chambers, awaiting executive action.
The bill's catalogue of "unsafe features" also runs longer than a summary suggests. Beyond features implying the chatbot is human, alive, or in possession of emotions, and features simulating friendship or human relationships, it reaches features that encourage self-harm, suicide, or sexual conduct, that encourage a minor to keep the interaction secret or to avoid seeking help from an adult, and that carry health information from an earlier session into a later one [source: New York State Senate, 2026]. The remedies are correspondingly broad: on top of penalties of up to $25,000 per violation, the attorney general could seek restitution, disgorgement of profits, destruction of unlawfully obtained data and algorithms, actual damages, and punitive damages [source: New York State Senate, 2026]. All of that, to repeat, is what the bill would do if it becomes law.
Signed is not the same as in force
One point deserves attention. The New York bill requires providers to offer several age-verification methods, at least one of which must not require a government-issued ID or must preserve the user's anonymity [source: New York State Senate, 2026]. This is a direct response to the privacy critique examined below. Other states moved too. Washington signed HB 2225 on March 24, 2026, with an effective date of January 1, 2027 [source: Future of Privacy Forum, 2026], and Connecticut, Colorado, Georgia, Utah, Nebraska, and Oregon, among others, enacted related laws with differing categories and effective dates [source: Future of Privacy Forum, 2026]. The spread is clear, but what is accumulating is not one unified rule — it is laws of differing designs piling up at the same time.
Effective dates are the quiet variable in this whole story. Washington signed HB 2225 in March 2026, but nothing changes for users there until January 1, 2027 [source: Future of Privacy Forum, 2026]. New York's 2026 bill carries the same intended start date [source: New York State Senate, 2026]. California's law has been operating since January 1, 2026, and New York's 2025 law since November 5, 2025 [source: California State Senate, 2025][source: Davis Polk, 2026]. So a company serving users nationwide is currently complying with two live regimes, preparing for at least two more, and watching bills it cannot yet plan around — which is the practical meaning of a patchwork, as opposed to a single national rule.
Safety versus privacy and free speech
The case for the rules
The logic of the side pushing this legislation is clear. What the lawsuits above illustrated was a pattern in which a chatbot designed to seem human held a vulnerable user emotionally, engaged in sexual conversation, or appeared to encourage self-harm. The core claim of the safety camp is that a system engineered to maximize engagement must be controlled where it affects minors. Requirements like non-human disclosure, blocking sexual content, and crisis referral flow from that concern.
It is worth being precise about what supports that case and what does not. What is documented is the design and the dispute: chatbots built to sustain a relationship, allegations of sexual conversation with a minor, and a body of litigation resolved by settlement. What is not yet documented is effect. No dataset yet shows that disclosure requirements, content blocks, or crisis referrals reduce harm, and California's own reporting channel does not open until July 1, 2027 [source: California State Senate, 2025]. Supporters of these laws are arguing from mechanism and from tragedy, not from outcome data. That is a normal position for a young regulation to occupy, but it should be described accurately rather than dressed up as proof.
The privacy objection
But the concerns on the other side are not trivial either. The first is privacy. To screen out minors, a service has to verify a user's age, and that age verification tends to demand real-world identifiers such as a government ID or financial records. The Foundation for Individual Rights and Expression (FIRE) warns that such requirements leave "a paper trail linking identity to online activity," and can therefore work toward building identity-linked surveillance infrastructure [source: FIRE, 2026]. If you must prove who you are in the real world just to talk to a chatbot, the argument goes, the freedom to access information anonymously erodes.
The speech objection
The second is free speech. NetChoice, a tech-industry group, argues that some chatbot regulation conflicts with constitutionally protected rights, holding that when the government requires identity to be handed over before speech can be accessed, the very communication that should be protected is chilled. NetChoice has sued over several states' age-verification laws, and some have been halted from taking effect, at least temporarily [source: NetChoice, 2026]. It is important to draw the layers precisely here. What the court denied in the Character.AI case was "the AI's own right to speak," whereas what NetChoice and FIRE raise is a different question — "the access and anonymity rights of users, including adults." The New York bill's requirement of at least one anonymity-preserving age-verification method can be read as an attempt to find a compromise between exactly these two demands.
Two questions that keep getting merged
Because the phrase "First Amendment" appears on both sides of this story, it helps to state the two questions separately. The first is whether the output of an AI system is itself protected speech — the argument Character.AI raised and a federal judge rejected at that stage [source: NBC News, 2025]. The second is whether a state may require a person to prove who they are before reaching speech that is lawful for them to receive — the argument NetChoice and FIRE press against age-verification mandates [source: NetChoice, 2026][source: FIRE, 2026]. A ruling on the first says nothing about the second. Merging them produces the two most common errors in coverage of this field: "courts said chatbots have no rights, so regulation is safe," and "courts protect chatbot speech, so these laws are doomed."
The federal shadow — the GUARD Act and preemption pressure
The GUARD Act
Alongside the state-level movement, two opposing forces are at work at the federal level. One pushes for regulation. In October 2025, Senators Josh Hawley (R-Missouri) and Richard Blumenthal (D-Connecticut) introduced the GUARD Act (a federal bill to shield minors from AI chatbot harms, S.3062). The bill would ban providing AI companions to minors, require disclosure that a chatbot is neither human nor a professional, require reasonable age verification on all accounts, and impose criminal penalties for sexual conduct with or encouragement of self-harm toward minors [source: U.S. Congress, 2025]. The Senate Judiciary Committee advanced the bill unanimously on April 30, 2026 [source: Senator Josh Hawley, 2026]. But here too, introduction and committee passage differ from enactment — the bill still awaits a full Senate vote.
The bill's political profile is unusual for AI legislation. It was introduced by a Republican and a Democrat together and picked up 17 bipartisan cosponsors, and the Senate Judiciary Committee then approved it without a dissenting vote on April 30, 2026 [source: U.S. Congress, 2025][source: Senator Josh Hawley, 2026]. Unanimity at that stage is a real signal, but it is a signal about a committee, not about the Senate. Bills die on floor calendars every session, and until a chamber votes, the GUARD Act's prohibitions — no AI companions for minors, disclosure that the system is neither human nor a professional, reasonable age verification on every account — remain proposals [source: U.S. Congress, 2025].
The preemption push
The other force pulls in the opposite direction, seeking to restrain state regulation. In December 2025, the Trump administration signed an executive order creating an AI Litigation Task Force to challenge state AI laws that go beyond being "minimally burdensome," and it directed the Commerce Department to examine withholding BEAD broadband funds from states that enact "onerous" AI laws [source: Tech Policy Press, 2026]. In short, on one side there are voices pressing for strong federal regulation (the GUARD Act), while on the other there is pressure for the federal government to preempt and restrain state regulation, at the same time. How these two forces are resolved will heavily shape the terrain of companion-chatbot regulation going forward.
The two federal pressures are not symmetric in kind. One is a bill that would set a national floor if it passes. The other is an executive-branch strategy — litigation plus leverage over BEAD broadband funding — that operates whether or not Congress acts [source: Tech Policy Press, 2026]. It is also worth noting what did not happen. The executive order came in December 2025, and state legislatures went on to enact 109 AI laws in the first half of 2026 anyway, with companion chatbots as the most active area of all [source: Tech Policy Press, 2026]. So far, federal pressure has shaped the argument more than it has slowed the output.
Conclusion — what to watch
It is hard to sum up the 2026 picture in one sentence. AI companion chatbots became the most active field in state AI lawmaking, and several states picked up the template California and New York created. Yet the vast majority of the 100-plus introduced bills never reached enactment; New York's 2026 bill passed both chambers and still awaits the governor's signature; and the federal GUARD Act has cleared committee but stands before the full Senate. The heat of regulation is high, but the distance from "introduced" to "a working law" remains long.
So the points to watch ahead are clear. First, whether New York's 2026 bill and the federal GUARD Act cross from passage into enactment. Second, whether courts treat age-verification requirements as a free-speech violation and rein them in, or tolerate them for the sake of protecting minors. Third, whether the Trump administration's litigation task force actually neutralizes state AI laws. Fourth, whether compromises like New York's "anonymity-preserving age verification" take hold as the meeting point between safety and privacy. Fifth, whether all these safeguards are shown by data to actually reduce harm. What is needed now is not a verdict that one side is right, but watching over children's safety and users' rights at the same eye level.
One practical note to close on. The next twelve months are when much of this stops being paper. Washington's HB 2225 and New York's 2026 bill both point at January 1, 2027, and California's first annual report to the Office of Suicide Prevention is due from July 1, 2027 [source: Future of Privacy Forum, 2026][source: New York State Senate, 2026][source: California State Senate, 2025]. That report is the first scheduled moment at which anyone will hold official numbers on the question everything else here assumes — whether these rules change what happens to the people they were written for. Until then, the honest summary is that the law has moved quickly and the evidence has not yet caught up.