
Companion Chatbots Get Their Own Laws: Privacy, Disclosure, and What California, Hawaii, and Pennsylvania Actually Regulate
The first generation of laws written specifically for companion chatbots is now on the books, and the gap between what they regulate and what the headlines say they regulate is wide enough to matter. If you build or operate a product that sustains an ongoing conversational relationship with users, your privacy obligations just changed in at least one jurisdiction, and the others are close behind. This piece walks through what California's SB 243 actually requires, where Hawaii's pending bills diverge, what Pennsylvania's SAFECHAT Act does (and does not) mandate, and what all of it means for product and legal teams shipping today.
Key Takeaways
- California's SB 243, effective January 1, 2026, is the first enacted law targeting companion chatbots specifically. It creates a private right of action with a $1,000-per-violation statutory minimum, plus attorney's fees.
- Nearly every enacted or pending bill centers on disclosure (telling users they are talking to AI) rather than data-minimization, retention limits, or encryption requirements for intimate conversational data. The harder architectural privacy problems remain largely unlegislated.
- Each state defines "companion chatbot" differently. Subtle product-architecture choices (whether your bot retains session history, whether it initiates unsolicited emotional messages) can move you in or out of scope across jurisdictions.
- Pennsylvania's SAFECHAT Act passed the state Senate nearly unanimously but does not explicitly require age verification, despite headlines suggesting otherwise. Governor Shapiro's separate budget proposal would go further.
- The FTC's September 2025 Section 6(b) inquiry into seven companion-chatbot companies is not a rule, but the specific categories it targets (monetization of conversations, data sharing, disclosures) preview what federal standards will likely demand.
What Does California's SB 243 Actually Require?
SB 243 imposes disclosure, safety-protocol, and annual-reporting requirements on operators of companion chatbots accessible to minors. Governor Newsom signed it on October 13, 2025, and it took effect January 1, 2026. It passed the state Senate 33-3 and the Assembly 59-1. This is not a contested, party-line bill. It is a near-unanimous mandate.
The law's definition of "companion chatbot" is notably broad. A system qualifies if it gives adaptive, human-like responses, can meet a user's social needs, displays anthropomorphic features, and can sustain a relationship across multiple interactions. Unlike New York's earlier chatbot law, SB 243 does not require the bot to retain conversation history or initiate unprompted messages. If your product feels like a companion to a user, it probably qualifies.
There are carve-outs. Skadden's analysis notes that tools used solely for customer service, business operations, video-game NPC interactions limited to in-game topics, and standalone consumer electronics that do not sustain ongoing relationships or provoke emotional responses are exempt. If you are building an NPC that only discusses quest objectives, you are probably fine. If that NPC remembers the player's emotional state across sessions and asks how they are feeling, you are probably not.
What Are the Penalties Under SB 243?
Real ones. Anyone injured by a violation can sue for actual damages or a statutory minimum of $1,000 per violation, plus attorney's fees. That per-violation structure matters. A product with a million minor users and a systemic disclosure failure is not facing a single fine. It is facing exposure that scales with the user base. For product teams, this means compliance is not a policy-review exercise you do once at launch. It is a runtime obligation.
What Did California Reject?
A companion bill that would have gone further was vetoed. That bill would have barred companion chatbots for children unless they were "not foreseeably capable of causing harm," a standard so broad that Newsom vetoed it over concerns it could unintentionally ban chatbot use by minors entirely. The contrast is instructive. California's enacted law regulates the wrapper around the experience (disclosures, safety protocols, reporting). The vetoed bill tried to regulate the experience itself. The legislature wanted both; the governor drew the line.
How Do Hawaii's Pending Bills Differ from California's Enacted Law?
Hawaii has not enacted a companion-chatbot-specific law comparable to SB 243. Its relevant bills are still moving through the legislature. But the specifics of those bills reveal a different regulatory philosophy.
HB 639 would require businesses to disclose when consumers are interacting with a chatbot that simulates human conversation using generative AI. This is a general chatbot-disclosure bill, not a companion-specific one. It covers customer-service bots, sales bots, and anything else that simulates human conversation.
HB 1782 is more targeted. It would require disclosure that a minor is talking to AI, not a human, at the start of every session and every three hours thereafter. That three-hour interval is a concrete design requirement. If your product has sessions that run longer than three hours (and companion chatbots often do, especially with younger users who leave them open in the background), you need an interstitial reminder mechanism.
The Hawaii bills are lighter on enforcement specifics than SB 243. They do not create a private right of action with statutory minimums. But they extend the disclosure concept beyond companion chatbots to generative-AI chatbots generally. If you operate any customer-facing chatbot in Hawaii, not just a companion product, HB 639 would put you in scope.
What Does Pennsylvania's SAFECHAT Act Actually Regulate?
The SAFECHAT Act (SB 1090) passed the Pennsylvania state Senate nearly unanimously in March 2026. It defines chatbot operators as those deploying generative AI algorithms that simulate human relationships with the user. Like California, it focuses on disclosure and periodic reminders. Like Hawaii's HB 1782, it requires reminder notices at least every three hours that the AI companion is artificially generated and not human.
The enforcement mechanism is different. The Pennsylvania Attorney General's office would enforce the law, with civil penalties up to $10,000 per violation. There is no private right of action. This shifts the enforcement dynamic: individual users cannot sue, but a single AG investigation could aggregate violations at scale.
Does Pennsylvania's Bill Require Age Verification?
No. This is one of the most common misreadings in coverage of the SAFECHAT Act. The bill as passed by the Senate does not explicitly require age verification. It applies to interactions with known minors, but it does not mandate a particular mechanism for determining who is a minor. Headlines that describe it as an "age-verification mandate" are conflating the bill with Governor Shapiro's separate budget-linked AI proposal, which would require age verification and parental consent to use AI companion bots. The executive branch wants more than the legislature has passed. If you are a legal team tracking this, the distinction matters for your compliance roadmap.
Why Do the Definitions Matter So Much?
Because each state defines "companion chatbot" differently, and small product-architecture decisions can change your regulatory exposure across jurisdictions. SB 243 hinges on adaptive responses, anthropomorphic features, and the ability to sustain a relationship across multiple interactions. It does not require memory or unsolicited outreach. Pennsylvania's SAFECHAT Act keys on "simulating human relationships." Hawaii's HB 1782 focuses on minors specifically.
Consider a concrete example. Suppose your product maintains no persistent memory between sessions. Under California's SB 243, you are likely still in scope if the product displays anthropomorphic features and gives adaptive, human-like responses. Under a definition that requires sustained relationship continuity (as some earlier bills proposed), you might argue you are out of scope. Whether your bot retains session history, whether it asks unsolicited emotional questions, whether it uses a human name and avatar: these are all architecture and design choices that move you across definitional boundaries.
This is not just a legal risk. It is a product-design risk. If you build to the narrowest definition, you may find yourself in scope anyway when the next state's bill uses a broader one. If you build to the broadest definition, you are imposing compliance overhead on product categories that some jurisdictions explicitly exempt. There is no single safe default.
What Do All These Laws Leave Out?
Almost everything related to what happens to the data after it is collected. This is the most striking gap across all three states' approaches. California, Hawaii, and Pennsylvania all focus heavily on disclosure: telling users they are talking to AI, reminding them periodically, reporting on safety protocols. None of them impose data-minimization requirements specific to companion chatbot conversations. None mandate retention limits on intimate conversational data. None require encryption standards for the deeply personal content users share with these products.
Think about what a companion chatbot collects over months or years of use. A July 2025 Common Sense Media report found that 72% of teens have used AI companion chatbots at least once, over half use them multiple times a month, and one in three use them for social or romantic interaction. One in three teens reported feeling uncomfortable with something the chatbot said or did. These are therapy-grade disclosures flowing into systems with no statutory obligation to minimize, expire, or encrypt them.
The laws regulate the "human interface" problem: making sure users know they are talking to software. They leave the harder architectural problem, what happens to years of therapy-like disclosures, almost entirely untouched. If you are a product team that takes privacy seriously, the current wave of legislation is the floor, not the ceiling.
How Does the FTC's 6(b) Inquiry Change the Picture?
The FTC's inquiry signals that federal data-handling standards for companion chatbots are coming, even if they arrive as enforcement actions rather than formal rules. On September 11, 2025, the FTC voted 3-0 to issue orders under Section 6(b) to seven companies operating consumer-facing AI companion chatbots. The orders seek data on how companies monetize conversations, what disclosures they make, how conversational data is used or shared, and what monitoring they perform.
This is an information-gathering action, not a rule. But the specific categories the FTC is targeting are worth reading as a preview of what federal standards will eventually require. If you cannot answer the questions the FTC is asking these seven companies, your compliance posture has a gap. The categories are concrete enough to function as an audit checklist:
- How do you monetize conversational data?
- What disclosures do you make to users about data use?
- How is personal information shared with companions used, stored, or shared with third parties?
- What monitoring do you perform for harmful outputs?
The inquiry specifically targets risks to children, but the data-handling questions apply to any user base. If you are building a companion product for adults only, the FTC's framing still previews the kind of scrutiny you should expect.
How Big Is the Market These Laws Target?
Big enough that legislatures noticed. AI companion apps had been downloaded over 220 million times globally as of July 2025, with the companionship-app market projected to generate more than $120 million in revenue by end of 2025. These are not niche products. The usage data, combined with the Common Sense Media findings on teen engagement, created the political conditions for legislation. Bipartisan 33-3 votes do not happen in a vacuum.
Is This a Multi-State Pattern or a One-Off?
It is a pattern, and it is accelerating. Beyond California, Hawaii, and Pennsylvania, Oregon (SB 1546) and Washington (HB 2225) moved on companion chatbot minor-safety bills in March 2026. Virginia's HB 635, covering safety, disclosure, and data-privacy rules for companion chatbots, was carried over to the 2027 session. This is now at least six states with active legislative efforts, and the pattern shows no sign of slowing.
There is also a federal preemption question hanging over all of this. Pennsylvania lawmakers have been contending with a Trump executive order aimed at blocking state AI regulations. Whether that executive order has the legal force to preempt state companion-chatbot laws is an open question, but it creates uncertainty for any legal team trying to build a single compliance framework across jurisdictions.
What Should Product and Legal Teams Do Now?
Start with the definitions. Map your product's features against the definitional criteria in each jurisdiction where you have users. Does your product retain conversation history across sessions? Does it display anthropomorphic features? Does it initiate unsolicited emotional messages? Each answer changes your scope exposure.
Then look at the disclosure requirements. California requires disclosure and safety protocols. Pennsylvania and Hawaii's pending bills require periodic reminders (every three hours in both cases). Build the interstitial infrastructure now, because these intervals are likely to become a de facto standard as more states legislate.
Then look at what the laws do not require, and decide whether you want to be ahead of or behind the next wave. None of these laws mandate data-minimization for companion conversations. None impose retention limits. None require encryption of conversational content. If your product collects intimate disclosures from users (and companion chatbots by definition do), the question is whether you wait for the next legislative cycle to impose those requirements or build the architecture now.
We build Selina with the assumption that the next wave is coming. Memory is encrypted at rest, though we are honest about the limit: memory is NOT end-to-end encrypted, because a slice of each request reaches a frontier provider at inference. Files and transfers via SelinaSEND are end-to-end encrypted. Non-content operational metadata is kept for a short retention window. The account is protected; content is encrypted. We think the distinction between what is encrypted and what is protected matters, and we state it plainly rather than hiding it behind marketing language. When a user deletes their data, it is gone. Actually gone.
The current crop of companion-chatbot laws regulates the label on the bottle. The contents of the bottle, the years of intimate conversational data flowing through these systems, remain largely unregulated. If you are building in this space, the laws on the books today are worth complying with carefully. But the real compliance challenge is the one the legislatures have not written yet.
If you want to see how we handle this in practice: start a free 7-day trial, no card required.
Frequently Asked Questions
What does California's SB 243 actually require?
SB 243 imposes disclosure, safety-protocol, and annual-reporting requirements on operators of companion chatbots accessible to minors, and it took effect January 1, 2026. It defines companion chatbots broadly based on adaptive responses, anthropomorphic features, and the ability to sustain a relationship, without requiring memory retention or unsolicited outreach.
What penalties can operators face under SB 243?
SB 243 creates a private right of action allowing anyone injured by a violation to sue for actual damages or a statutory minimum of $1,000 per violation, plus attorney's fees. Because penalties are per-violation, exposure scales with the size of a product's user base.
How do Hawaii's pending bills differ from California's law?
Hawaii has not enacted a companion-chatbot law like SB 243; HB 639 is a general chatbot-disclosure bill covering any business chatbot, while HB 1782 specifically requires disclosing to minors that they're talking to AI at session start and every three hours after. Unlike SB 243, neither Hawaii bill creates a private right of action with statutory minimums.
Does Pennsylvania's SAFECHAT Act require age verification?
No, the SAFECHAT Act as passed by the Senate does not explicitly require age verification, though it applies to interactions with known minors. That confusion stems from conflating it with Governor Shapiro's separate budget proposal, which would require age verification and parental consent.
What do these companion chatbot laws generally fail to address?
Nearly all the enacted or pending bills focus on disclosure, telling users they're talking to AI, rather than on data-minimization, retention limits, or encryption for intimate conversational data. The harder architectural privacy problems around what happens to collected data remain largely unlegislated.
Sources & References
- AI Regulatory Update: California's SB 243 Mandates Companion AI Safety and Accountability | Jones Walker LLP
- Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond - Future of Privacy Forum
- New California ‘Companion Chatbot’ Law Imposes Disclosure, Safety Protocol and Annual Reporting Requirements | Insights | Skadden, Arps, Slate, Meagher & Flom LLP
- SB 243 - California Legislative Information - CA.gov
- California SB243 | 2025-2026 | Regular Session
- Senate Bill (SB) 243 - California Legislative Information - CA.gov
- California SB 243: Setting New Standards for Regulating and Ensuring Integrity of AI Companion Chatbots
- First-in-the-Nation AI Chatbot Safeguards Signed into Law | California State Senator Steve Padilla
- Analyzing the New AI Companion Chatbot Laws | Privacy + Cyber + AI
- AI Chatbot Legislation Across the States | Stateside Associates
- SB640 | Hawaii 2026 | Artificial Intelligence; Chatbots; Unfair or Deceptive Practices; Penalties - Legislative Tracking | PolicyEngage
- Bill Text: HI HB639 | 2026 | Regular Session | Introduced | LegiScan
- HB639: Relating To Artificial Intelligence. | Hawaii AI Law
- HI HB1782 | BillTrack50
- sjud.senate.ca.gov
- California Passes the World’s First AI Companion Law — And Why It Matters
- Senate Co-Sponsorship Memo 47475 Information; 2025-2026 Regular Session - PA State Senate
- PA lawmakers advance SAFECHAT Act to protect children from AI chatbot interactions - City & State Pennsylvania
- Pennycuick, Miller Measure to Protect Children from Harmful AI Chat Interactions Approved by Senate Committee - Pennsylvania Senate Republicans
- Pa. Senate passes bill regulating AI chatbots used by children and teens | News From The States
- Governor Shapiro Takes Action to Protect Pennsylvanians Using AI | Commonwealth of Pennsylvania
- PA HB2100 | BillTrack50
- House Co-Sponsorship Memo 47517 Information; 2025-2026 Regular Session - PA House of Representatives
- Pa. Senate passes bill regulating AI chatbots used by children and teens • Pennsylvania Capital-Star
- PA Senate Passes SAFECHAT AI Chatbot Bill
- Pennsylvania Senate passes AI chatbot safety bill | Pennsylvania | thecentersquare.com
- Nelson Mullins - FTC Announces Children’s Privacy Enforcements and Launches AI Chatbot Inquiry
- AI Companions and Child Safety: What the FTC’s 2025 Action Means - Blog - MEF
- FTC Orders Inquiry Into Effects of AI-Powered Chatbots on Children - Lewis Brisbois Bisgaard & Smith LLP
- FTC Probes AI Companion Chatbots for Risks to Minors - Davis+Gilbert LLP
- FTC Launches Inquiry into AI Chatbots Acting as Companions | Federal Trade Commission
- FTC launches inquiry into AI 'companion' chatbots ...
- FTC Launches Inquiry Into AI Chatbots Acting as Companions: What It Means for Advertisers and Platforms, Holly Melton
- FTC Launches Inquiry into AI Chatbots Acting as Companions — The AI Forum
- Chairman Guthrie and Ranking Member Pallone Applaud FTC Decision to Investigate Safety of AI Chatbots
