Table of Contents
SB 1119 Companion Chatbot Rules: What Changed for Kids
California's SB 1119 companion chatbot law adds age checks, one-hour session caps, and audits. Here's what changed from SB 243 and when each rule starts.
The SB 1119 companion chatbot law is the first U.S. statute to tell an AI product how long a child may talk to it. One hour per session. Two hours a day. Memory off by default. No push notifications. Governor Newsom approved it on September 10, 2026, and the core obligations become operative July 1, 2027, which gives parents about nine months to understand what’s coming and companies about nine months to rebuild their products. Here’s what it actually requires, how it differs from the 2025 law it builds on, and what it will and won’t change in your house.
Key Takeaways
- SB 1119 (Padilla) was approved by the Governor and filed with the Secretary of State on September 10, 2026. It amends Business and Professions Code section 22602 and adds Chapter 11.6, sections 21810 through 21818.
- Core child protections are operative July 1, 2027. Independent child-safety audits begin January 1, 2029 (or at public launch, whichever is later) and repeat biennially. The Attorney General’s incident-reporting system is due January 1, 2028.
- Hard design requirements for child users: persistent conversational memory disabled by default, push notifications disabled, one-hour continuous session limit, two-hour daily cap.
- Operators must determine user age under the Digital Age Assurance Act, or rely on a system provider’s determination; if they can’t, they must apply all child protections to every user by default.
- Enforcement: civil penalties up to $5,000 per negligent violation and $15,000 per intentional violation per affected child, plus a private right of action for children or parents who suffer actual harm.
What the SB 1119 companion chatbot law requires, section by section
A companion chatbot, in California’s framing, is an AI system with a natural-language interface that gives adaptive, human-like responses and can meet a user’s social needs. SB 243, the 2025 law, defined it that way and SB 1119 builds on top.
The bill text sets out the following for child users.
Age determination (§21811). Operators must determine a user’s age using the Digital Age Assurance Act, or rely on an age determination from a system provider such as an operating system or app store. If they cannot do either, they must apply all child protections to all users by default. That last clause is the one with teeth: uncertainty defaults to protection rather than to the unrestricted product.
Disclosure, reinforced (§21812(d)(4)). Notice that the child is interacting with artificial intelligence must be given in age-appropriate language and “reinforced periodically during extended interactions.” SB 243 already required a reminder every three hours for known minors; SB 1119 generalizes the duty and ties the language to the child’s comprehension.
Default design limits (§21812(d)(3)). Persistent conversational memory disabled by default. Push notifications disabled. Continuous session use limited to one hour. Daily usage capped at two hours.
Content prohibitions (§21812(d)(5)). The bot must not engage in obscene matter or sexual abuse material with a child user, must not depict obscene content or a “sexual deepfake,” and must not express or simulate romantic interest in the child.
Crisis protocol (§21812(d)(1)). Documented crisis-response protocols with timely referrals to crisis services. On detecting a “credible and imminent threat,” the operator must notify parents or provide “streamlined access to connect directly with the 988 or equivalent crisis helpline.”
Public incident reporting (§21812(d)(7)). Operators must maintain a public mechanism so third parties can report child-safety risks.
Independent audits (§21814). Required by January 1, 2029, then every two years, with an auditor’s report signed under penalty of perjury certifying compliance.
Remedies (§21816). Prosecutors may seek up to $5,000 per negligent violation and $15,000 per intentional violation, per affected child. Children or parents may sue for actual harm to core protections, recovering actual damages, attorney fees, and injunctive relief.
SB 243 vs SB 1119: what actually changed
| Provision | SB 243 (chaptered Oct 13, 2025; effective Jan 1, 2026) | SB 1119 (approved Sept 10, 2026; core duties July 1, 2027) |
|---|---|---|
| Trigger for child protections | Operator knows the user is a minor | Operator must determine age via Digital Age Assurance Act or a system provider; if unable, protect everyone by default |
| AI disclosure | Clear and conspicuous notice when a reasonable person could be misled | Same, plus age-appropriate language reinforced periodically in extended interactions |
| Break reminders | At least every three hours for known minors | Periodic reinforcement plus hard session and daily caps |
| Session limits | None | One hour continuous; two hours per day for child users |
| Memory | Not addressed | Persistent conversational memory off by default |
| Push notifications | Not addressed | Disabled for child users |
| Romantic content | Reasonable measures against sexually explicit material | Explicit bar on expressing or simulating romantic interest in a child; bar on sexual deepfakes and CSAM |
| Crisis response | Protocol to prevent suicidal-ideation content; refer to crisis providers; annual report to Office of Suicide Prevention | Documented protocols; on credible and imminent threat, notify parents or give streamlined 988 access |
| Third-party reporting | Not addressed | Public incident reporting mechanism required |
| Audits | None | Independent child-safety audit by Jan 1, 2029, biennially thereafter, signed under penalty of perjury |
| Private right of action | Greater of actual damages or $1,000 per violation, plus fees | Actual damages, fees, injunctive relief for harm to core protections |
| Civil penalties | Private enforcement centered | Up to $5,000 negligent / $15,000 intentional per affected child |
The pattern: SB 243 was a disclosure-and-protocol law. SB 1119 is a product-design law. That’s the shift parents should notice, because design requirements change what the app does whether or not anyone reads a disclosure.
Why the one-hour cap is the most interesting provision
Session and daily caps are unusual in U.S. tech regulation, and they’re worth thinking about carefully rather than cheering or dismissing.
The case for: the harm pattern that prompted these laws is not a single bad message, it’s accumulation. Common Sense Media’s July 2025 report on AI companions found 72% of teens had used one, over half used them at least a few times a month, and about a third had taken a serious conversation to an AI instead of a person. A cap targets the dose.
The honest caveat: I’m not aware of published evidence establishing that one hour is the right number, and the bill doesn’t cite a study for it. The American Psychological Association’s June 2025 health advisory calls for development-appropriate safeguards and AI literacy rather than specific time thresholds. So this is a legislature drawing a line in a place where the evidence base is thin. That may still be the right call: waiting for perfect data on a product that ships weekly is its own decision.
There’s also the practical question of who the cap binds. It applies to companion chatbots as defined, which is not the same as every AI assistant. A general-purpose product used for homework isn’t obviously a companion chatbot, and part of what the next two years will settle is where that boundary sits.
What this means for your family, honestly
If you’re in California, expect the app to change in mid-2027
The obligations that will be visible to your kid are the caps, the memory default, and the missing push notifications. If your teen currently uses a companion app with a persistent “relationship,” that persistence is what the memory default targets.
If you’re not in California, expect it anyway
Companies rarely build two products. A dozen states have now enacted companion-chatbot laws, tracked by MultiState as of June 26, 2026, with Oregon’s SB 1546 and Washington’s HB 2225 both effective January 1, 2027, and Washington requiring hourly rather than three-hourly reminders for minors. The map is in the states now regulating companion chatbots.
Age assurance is the quiet consequence
To apply child protections, an operator must know who is a child. The law’s fallback (protect everyone) is generous, but the commercial incentive points toward age checks. Expect more age verification, which means more data collection, which is its own trade-off. Our piece on how AI age verification actually works covers the mechanics.
What not to do
Don’t treat July 1, 2027 as the date your kid becomes safe. Compliance dates are floors, enforcement takes years, and the audit requirement doesn’t bite until 2029. Everything in the law is a backstop to the thing that actually works now: knowing which apps your kid uses and talking about them.
What to Watch For Over the Next 3 Months
- Week 4: Make a list of every chatbot on your kid’s devices, and note which ones are companion-style (persistent persona, memory, notifications that pull them back). Those are the apps this law is about.
- Month 2 red flags: Apps that send push notifications designed to resume a conversation; a bot that remembers and references your kid’s personal life across sessions; any app that responds to “are you real?” with anything other than a clear no.
- Month 3 self-check: Watch for company announcements about age assurance and session limits. Early compliance moves in late 2026 and early 2027 will tell you which products intend to comply and which are hoping the definition doesn’t cover them.
Frequently Asked Questions
When does SB 1119 actually take effect?
The Governor approved it September 10, 2026, but the core child protections in sections 21812 and 21813 are operative July 1, 2027. The Attorney General’s incident reporting system is due January 1, 2028, and independent audits start January 1, 2029 or at public launch, whichever is later.
Does it apply to ChatGPT or Gemini?
It applies to “companion chatbots” as defined: natural-language AI giving adaptive, human-like responses capable of meeting social needs. Whether a general-purpose assistant falls inside that definition is exactly the contested question, and companies will litigate or comply differently. Several have already adopted overlapping policies voluntarily.
What happens if a company ignores it?
Prosecutors can seek up to $5,000 per negligent violation and $15,000 per intentional violation, per affected child. Separately, a child or parent who suffers actual harm can sue for damages, attorney fees, and an injunction.
Does the two-hour daily cap apply to my kid using AI for homework?
Only if the product is a companion chatbot under the statute. A homework tool isn’t automatically covered. This is one of the real ambiguities in the law as written, and it will get clarified by enforcement and guidance rather than by the text.
Is there evidence that one hour is the right limit?
Not that I can point to. The bill doesn’t cite a study for the specific number, and the APA’s 2025 advisory recommends development-appropriate safeguards without naming thresholds. The caps are a policy judgment made ahead of the evidence, which is worth knowing when you decide how much weight to give them.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- California Legislature. (2026). “SB 1119: Companion chatbots: children’s safety.” Approved by Governor and filed with Secretary of State September 10, 2026. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB1119
- California Legislature. (2025). “SB 243: Companion chatbots.” Chaptered October 13, 2025; effective January 1, 2026. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
- Future of Privacy Forum. (2025). “Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond.” November 4, 2025. https://fpf.org/blog/understanding-the-new-wave-of-chatbot-legislation-california-sb-243-and-beyond/
- MultiState. (2026). “State AI Companion Chatbot Laws: 12 States Enact Regulations.” June 26, 2026. https://www.multistate.ai/updates/vol-105-state-ai-companion-chatbot-laws
- Common Sense Media. (2025). “Talk, Trust, and Trade-Offs: How and Why Teens Use AI Companions.” July 16, 2025. https://www.commonsensemedia.org/research/talk-trust-and-trade-offs-how-and-why-teens-use-ai-companions
- American Psychological Association. (2025). “Health advisory: Artificial intelligence and adolescent well-being.” June 2025. https://www.apa.org/topics/artificial-intelligence-machine-learning/health-advisory-ai-adolescent-well-being