The Year States Said Enough: Fourteen New Chatbot Safety Laws and the Fight for Kids Online
Fourteen states have enacted chatbot safety laws in 2026 alone, and Congress has finally moved a bipartisan youth-AI-safety package out of the House. The common thread: AI companions are no longer being treated as a novelty, but as a child-safety issue.
Two years ago, laws specifically regulating AI chatbots barely existed anywhere in the United States. In the first seven months of 2026 alone, fourteen states have passed them, eleven have already enacted comprehensive chatbot statutes, and the US House of Representatives has for the first time moved a bipartisan federal youth-AI-safety package out of committee and onto the floor. The pace and consistency of this legislative wave is not an accident — it follows a string of tragic, well-documented cases in which AI companion products were implicated in the self-harm or death of teenage users, and a growing body of research showing how deeply embedded chatbots have become in adolescent life.
How we got here
The scale of chatbot use among teenagers is a large part of what has driven lawmakers to act so quickly. Recent survey data found that roughly two-thirds of teenagers report using AI chatbots, with about a quarter using them daily — a level of engagement that has outpaced the safety infrastructure built around it. Multiple wrongful-death lawsuits, including cases involving Character.AI and Google, were quietly settled in early 2026 on behalf of families whose teenage children died by suicide after interactions with AI companion products. Advocacy groups working alongside state attorneys general have documented additional, less extreme but still troubling patterns: chatbots exposing minors to graphic sexual content, hate speech, and dangerous advice through open-ended roleplay features that were never designed with a teenage user in mind.
California moved first. Its Companion Chatbot Act, SB 243, was signed into law in the prior legislative session and took effect January 1, 2026, requiring chatbots to disclose their non-human nature, recognize signs of self-harm or suicidal ideation and route users to appropriate resources, and filter sexually explicit content for underage users. Governor Gavin Newsom, signing the bill, pointed to what he called truly horrific examples of young people harmed by unregulated technology as the reason the state could no longer stand by without imposing limits. A more sweeping alternative, AB 1064 — nicknamed the LEAD for Kids Act, which would have barred any AI companion from being offered to minors unless it was not foreseeably capable of causing harm — did not become law, with Newsom opting for California’s safeguard-based approach instead of an outright restriction.
Eleven states, one converging framework
What has happened since is less a single template being copied wholesale and more a set of states independently arriving at strikingly similar answers. As of June, eleven states — California, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island and Washington — have all passed chatbot laws regulating AI systems built to interact with consumers, with Hawaii’s own version awaiting the governor’s signature. Despite being drafted independently, the laws share a common architectural core: mandatory AI-identity disclosure, safety protocols for detecting expressions of suicidal ideation or self-harm, and specific protections for minor users.
New York’s law, S9051, developed in partnership with the state attorney general’s office and Common Sense Media, goes further than most in specifying prohibited design patterns rather than just outcomes. It bars chatbots from suggesting they are a real person or a genuine friend, from prioritizing user validation or engagement over safety, and from encouraging isolation or discouraging minors from seeking help from trusted adults. Common Sense Media’s chief executive has been blunt about the stakes, describing how quickly a chatbot marketed as a homework helper can turn into a simulated relationship or, in the worst cases, something resembling a companion in a mental-health crisis the product was never built to handle.
Idaho, Oregon and Washington took a narrower but still significant approach, specifically barring AI companion chatbots from claiming sentience or initiating sexually explicit conversations with users known to be minors — provisions aimed squarely at the roleplay and companion-app category rather than general-purpose assistants.
Nebraska’s Conversational Artificial Intelligence Safety Act, LB 525, and similar statutes elsewhere layer on parental-access tools, prohibitions on sexually explicit or emotionally manipulative content, and — notably — bans on gamifying user engagement, a direct response to concerns that some chatbot products have used the same behavioral-design techniques found in addictive mobile games and social media platforms.
Congress finally moves — sort of
Washington has historically lagged behind the states on this issue, but that changed on June 29, when the House passed H.R. 7757 under a suspension of the rules, by a lopsided 267–117 vote. The bill is not a single, purpose-built chatbot law; it is a consolidation of several previously separate proposals — pieces of the Kids Online Safety Act, COPPA 2.0, the Safe Messaging for Kids Act, the SPY Kids Act, the Safer GAMING Act, and, most relevant here, the SAFE Bots Act — bundled into one youth-safety package alongside data-broker disclosure rules and online-safety research funding.
The SAFE Bots Act provisions apply to any chatbot provider serving users the provider knows, or reasonably should have known, are minors — a “should have known” standard that is likely to draw significant industry pushback given how difficult reliable age verification remains in practice. Among its more specific requirements: a chatbot cannot claim to be a licensed professional — a therapist, for instance — unless that claim happens to be true. The bill now moves to the Senate, where existing proposals on youth privacy, platform design and AI safety will need to be reconciled with the House text before anything can reach the President’s desk.
A separate, narrower federal proposal, Senator Ed Markey’s Youth AI Privacy Act, introduced in March, focuses specifically on the data practices behind chatbot personalization rather than content safety. It would restrict chatbots to using only recently collected data when personalizing responses to a minor, ban advertising to minors entirely, prohibit training models on minors’ personal data, and bar behavioral profiling of young users. Markey has argued that AI chatbots pose serious new risks to children’s privacy and safety, and that the industry has consistently prioritized engagement-driven design over those risks.
What “safety” actually requires in practice
For companies building or deploying conversational AI, the practical upshot of this legislative wave is that “chatbot safety” has stopped being a vague aspiration and started being a specific, checkable list of engineering and policy requirements: clear, repeated, and difficult-to-miss disclosure that the user is talking to software rather than a person; reliable detection of self-harm and suicidal-ideation signals, paired with a defined escalation path to real human resources; content filtering tuned specifically for users who may be minors, not just general-audience filtering; a ban on manipulative engagement mechanics — push notifications, streaks, gamified rewards — when the audience includes children; and, increasingly, restrictions on how much personal data collected from a young user can be used to shape future responses.
What makes 2026’s wave different from earlier waves of state tech regulation is the near-total absence of industry-versus-state conflict that characterized, say, early social media privacy laws. Chatbot providers, facing settled wrongful-death litigation and a documented pattern of harm, have largely not fought these bills in the way earlier privacy statutes were fought. The open questions now are less about whether AI companies should be required to protect young users, and more about whether fifty-plus overlapping state definitions of “minor protection,” combined with a still-unresolved federal package sitting in the Senate, can converge into something companies can actually implement consistently — rather than a compliance patchwork nearly as fragmented as the harms it was written to prevent.
The age-verification problem nobody has solved
Underneath nearly every one of these new statutes sits a technical problem that legislation alone cannot fix: reliably knowing that a given user is a minor in the first place. Most of the laws passed so far, including the federal SAFE Bots Act provisions moving through Congress, rely on a “knew or should have known” standard rather than mandating hard age verification at the point of signup — largely because privacy advocates have raised serious concerns about the data-collection and identity-document requirements that robust age verification would itself introduce. That leaves platforms in an uncomfortable middle ground: legally obligated to protect users they can identify as minors, but not legally required, and in many cases not incentivized, to build the verification infrastructure that would let them reliably identify those users in the first place.
Some companies have responded by building behavioral inference systems that attempt to estimate a user’s likely age bracket from writing patterns, activity timing and other signals, applying protective defaults automatically when the signals suggest a younger user, without requiring an uploaded ID. Whether regulators eventually treat that kind of inferential approach as sufficient compliance, or push toward harder verification requirements the way several states have already done for adult content platforms, is likely to be one of the more consequential open questions in this space over the next legislative cycle.
What responsible deployment looks like right now
For companies that want to get ahead of this rather than simply react to the next state law, the emerging consensus among child-safety advocates, state attorneys general and now federal lawmakers points toward a consistent baseline: default to the most protective setting when a user’s age is uncertain rather than the least protective one, build crisis-detection and human escalation paths before they are legally mandated rather than after, and treat engagement-maximizing design patterns — the same techniques that drew scrutiny for social media — as a liability rather than a growth strategy when the audience includes anyone under eighteen.
