Table of Contents
States Companion Chatbot Laws: The 2026 Map for Parents
Twelve states companion chatbot laws are now on the books. Which state requires what, how reminder rules differ for minors, and what it means where you live.
The states companion chatbot laws now form a patchwork, and the differences are more interesting than the similarities. All twelve enacted laws require a chatbot to tell users it isn’t human and to have a protocol for users who express suicidal thoughts. After that they diverge: Washington and Connecticut want hourly reminders for minors while California and Oregon want them every three hours; some trigger protections only when an operator knows a user is a minor while others apply them universally to dodge the age-verification problem entirely. If you want to know what protects your kid, the answer depends on which state’s rulebook the company you use chose to follow.
Key Takeaways
- MultiState’s tracker counted twelve states with enacted companion chatbot laws as of June 26, 2026, including California, New York, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, Oregon, Rhode Island, and Washington.
- Every one of the twelve requires AI-disclosure reminders and a protocol for responding to expressions of suicidal ideation or self-harm, usually with referral to the 988 Suicide & Crisis Lifeline.
- Reminder frequency splits three ways: every three hours for all users (Colorado, Georgia, Iowa, New York, Rhode Island), every three hours for minors only (California, Idaho, Nebraska, Oregon), and hourly for minors with three-hourly for adults (Connecticut, Washington).
- California’s SB 1119, approved September 10, 2026, goes furthest: memory off by default, notifications off, one-hour session cap, two-hour daily cap for child users, operative July 1, 2027.
- Connecticut and Rhode Island extend crisis protocols to threats against others; Georgia and Washington include eating-disorder-related self-harm.
What a companion chatbot law actually regulates
A companion chatbot law governs AI systems that hold ongoing, human-like conversations capable of meeting a user’s social or emotional needs. That definition is doing a lot of work, and the states don’t agree on it.
Per the Future of Privacy Forum’s analysis of Oregon and Washington, published April 7, 2026, Oregon took a behavior-based approach requiring the system to exhibit relational behaviors like retaining user information across sessions. California and Washington used capability-based definitions, asking whether the system can generate human-like relational interaction. That distinction determines whether a general-purpose assistant is covered, which is the single biggest open question in this whole area.
The requirements themselves cluster into four buckets: disclosure that the user is talking to AI, break or disclosure reminders at some interval, content restrictions for minors, and crisis-response protocols.
The 2026 map of states companion chatbot laws: who requires what
| State | Reminder frequency | Minor protections | Notable extras |
|---|---|---|---|
| California | Every 3 hours for minors (SB 243); reinforced periodically plus hard caps under SB 1119 | Bar on sexually explicit content; SB 1119 adds bar on simulating romantic interest, memory off by default, notifications off, 1-hour session and 2-hour daily caps | SB 1119 approved Sept 10, 2026; core duties operative July 1, 2027; biennial independent audits from 2029 |
| New York | Every 3 hours for all users | Enacted Nov 5, 2025; AG enforcement | Civil penalties up to $15,000 per day per the AG’s authority |
| Washington | Hourly for minors, every 3 hours for adults (HB 2225) | Most expansive content rules: restricts suggestive dialogue, excessive praise, outputs mimicking emotional relationships | Effective Jan 1, 2027; violations folded into the Consumer Protection Act |
| Oregon | Every 3 hours, with break reminders (SB 1546) | Bars content suggesting self-harm and outputs simulating emotional dependence | Signed March 2026, effective Jan 1, 2027; $1,000 statutory damages per violation |
| Connecticut | Hourly for minors, every 3 hours for adults | Reasonable measures to prevent harms to minors | Crisis protocol extends to harm to others or imminent violence |
| Rhode Island | Every 3 hours for all users | Reasonable measures for minors | Crisis protocol extends to threats against others |
| Colorado | Every 3 hours for all users | Reasonable measures to prevent harms for minors | Part of a broader AI statutory framework |
| Georgia | Every 3 hours for all users | Reasonable measures for minors | Crisis protocol includes eating-disorder-related self-harm |
| Iowa | Every 3 hours for all users | Reasonable measures for minors | — |
| Idaho | Every 3 hours for minors | Reasonable measures for minors | — |
| Nebraska | Every 3 hours for minors | Reasonable measures for minors | — |
Sources for the table: MultiState’s June 26, 2026 tracker, FPF’s April 2026 analysis, Troutman’s January 2026 survey, and the California bill text. Where a state’s bill number or exact effective date wasn’t available in those sources, I’ve left the cell empty rather than guess.
The three real disagreements between states
Who has to be identified as a minor. California’s SB 243 triggered minor protections when an operator knew the user was underage. SB 1119 changed that to an affirmative duty to determine age, with a fallback of protecting everyone. Oregon uses a “knows or has reason to believe” standard, Washington covers systems “directed to children,” and some states apply restrictions universally specifically to avoid requiring age verification. This is the most consequential split, because it determines whether the law does anything for a kid who lied at signup.
How often to interrupt. The three-hour reminder in California’s SB 243 became the informal standard, then Washington and Connecticut decided minors need it hourly. Nobody has published evidence establishing the right interval, and the laws don’t cite one. The honest read is that three hours was a legislative compromise that then propagated.
What counts as harmful. Washington restricts “suggestive dialogue” and “excessive praise” and outputs that mimic emotional relationships. That’s substantially broader than California’s original focus on explicit content, and it reaches into ordinary conversational warmth. Whether that’s protective or overbroad is a genuine policy disagreement, not a settled question.
Why this matters even if your state isn’t listed
Companies rarely maintain twelve product variants. When California requires memory off by default for child users, the cheapest compliant path is usually to change the default everywhere and let parents opt in. That’s how California’s auto emissions rules worked for decades, and it’s the dynamic to expect here.
There’s a countervailing force: Congress has repeatedly considered preempting state AI laws, most recently as part of the 2026 National Defense Authorization Act, according to U.S. PIRG Education Fund. Rory Erlich of U.S. PIRG, quoted in that release: “From Texas to California, states are leading the way when it comes to protecting kids from harmful chatbot companions. But more regulation is needed. While Congress should also act, we know it moves slowly, so states must continue to address these threats.” If federal preemption passes, the patchwork collapses, and what replaces it is unknown.
What to do at home, regardless of your state
Identify which apps are actually companions
The laws target products with a persistent persona, memory, and notifications that pull a user back. A homework assistant may not be covered at all. Make the list, mark which ones are companion-style, and focus your attention there. Our overview of AI companion apps and kids covers the distinction.
Set the protections yourself instead of waiting
Every protection these laws mandate has a settings equivalent you can turn on now: memory off, notifications off, no romantic content. In ChatGPT specifically, the parental controls give you memory and notification switches today without waiting for July 2027.
Watch for the reminder, and ask what your kid does with it
Once the three-hour or hourly reminders appear, ask your kid what they do when one shows up. The honest answer is usually “tap it away,” which tells you something real about how much protection an interstitial actually provides.
What not to do
Don’t assume a law in your state means the app is compliant. Effective dates run into 2027, enforcement lags further, and California’s audit requirement doesn’t start until 2029. Laws set floors on a delay; settings work today.
What to Watch For Over the Next 3 Months
- Week 4: Find out whether any state law covers you, and check whether the apps your kid uses show AI-disclosure reminders. Their presence or absence tells you which rulebook the company chose.
- Month 2 red flags: A companion app with no disclosure reminder at all; notifications that resume conversations, which several states now prohibit for minors; any bot that claims to be human when asked directly.
- Month 3 self-check: Watch the federal preemption question. If Congress preempts state AI laws, the twelve-state patchwork and everything in the table above becomes moot, and the replacement framework is what will matter.
Frequently Asked Questions
How many states have companion chatbot laws?
Twelve had enacted laws as of MultiState’s June 26, 2026 tracker, including California, New York, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, Oregon, Rhode Island, and Washington. More bills are pending, and the count has risen steadily through 2026.
Which state has the strictest rules?
It depends what you’re measuring. California’s SB 1119 has the most aggressive design requirements (memory off, session and daily caps, independent audits). Washington has the broadest content restrictions for minors, including suggestive dialogue and excessive praise, plus hourly reminders.
Does any of this apply if I live in a state without a law?
Not legally, but often practically. Companies tend to ship one product configuration rather than twelve, so the strictest state’s requirements often become the default everywhere. That’s a tendency, not a guarantee.
What does every one of these laws require?
Two things: disclosure reminders that the user is interacting with AI rather than a human, and a protocol for responding to expressions of suicidal ideation or self-harm, typically with referral to crisis resources like the 988 Suicide & Crisis Lifeline.
Could Congress wipe these out?
It’s been proposed. Per U.S. PIRG, Congress has considered banning states from passing their own AI laws multiple times, including as part of the 2026 National Defense Authorization Act. Nothing has passed as of this writing, but it’s the single biggest variable in this area.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- MultiState. (2026). “State AI Companion Chatbot Laws: 12 States Enact Regulations.” June 26, 2026. https://www.multistate.ai/updates/vol-105-state-ai-companion-chatbot-laws
- Future of Privacy Forum. (2026). “The Rest of the West: Oregon and Washington Build on California Chatbot Law.” April 7, 2026. https://fpf.org/blog/the-rest-of-the-west-oregon-and-washington-build-on-california-chatbot-law/
- California Legislature. (2026). “SB 1119: Companion chatbots: children’s safety.” Approved September 10, 2026. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB1119
- Future of Privacy Forum. (2025). “Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond.” November 4, 2025. https://fpf.org/blog/understanding-the-new-wave-of-chatbot-legislation-california-sb-243-and-beyond/
- Troutman Pepper Locke. (2026). “Analyzing the New AI Companion Chatbot Laws.” January 8, 2026. https://www.troutmanprivacy.com/2026/01/analyzing-the-new-ai-companion-chatbot-laws/
- U.S. PIRG Education Fund. (2025). “Report update: AI chatbot toys come with new risks.” https://pirg.org/edfund/media-center/report-update-ai-chatbot-toys-come-with-new-risks/