AI Laws
State Chatbot Laws: Every U.S. Law Tracked (17)
Laws regulating AI companion chatbots and conversational AI, including disclosure and minor-safety requirements. Maintained by Stauss PLLC. Last reviewed August 2026.
Laws tracked in this category17
| State | Law |
|---|---|
| California | California bot disclosure law |
What You Need to KnowIn effect since 2019, California's bot disclosure law makes it unlawful for any person to use a bot to communicate or interact online with another person in California, with the intent to mislead the person about the bot's artificial identity in order to knowingly deceive the person about the content of the communication for the purpose of incentivizing a purchase or sale of goods or services in a commercial transaction, or of influencing a vote in an election. A person using a bot is not liable if the person discloses that it is a bot. | |
| California | California SB 243 |
What You Need to KnowThe law requires an operator of a companion chatbot platform to issue a clear and conspicuous notification indicating that the companion chatbot is artificially generated and not human, if a reasonable person interacting with the companion chatbot would be misled into believing that they are interacting with a human. The law also requires an operator to take certain actions with respect to a user the operator knows is a minor, including disclosing to the user that the user is interacting with AI. The law further requires an operator to prevent a companion chatbot on its platform from engaging with users unless the operator maintains a protocol for preventing the production of suicidal ideation, suicide, or self-harm content to the user, and publishes details of that protocol on its website. Beginning July 1, 2027, operators must annually report to the Office of Suicide Prevention the protocols they have put in place to detect, remove, and respond to instances of suicidal ideation by users, and post data from that report on their website. The law authorizes a private right of action for persons who suffer an injury in fact as a result of noncompliance. | |
| Colorado | Colorado HB 26-1263 |
What You Need to KnowThe law applies to operators of publicly available conversational AI services. Operators must use commercially reasonable or generally accepted methods to estimate the age of consumers who create or open an account or profile to use a conversational AI service, as well as the age of other users of the service. If an operator knows that an account holder or user is a minor, the operator must (1) provide certain disclosures; (2) institute technically feasible measures to prevent the conversational AI service from producing explicit sexual conduct, intimate digital depictions, or statements that simulate emotional dependence; (3) implement a protocol for the conversational AI service to stop engaging in response to a user prompt regarding sexual conduct with a minor; and (4) provide tools for the minor account holder or user, or a parent or guardian of the minor, to manage the minor's privacy and account settings. Operators are also prohibited from providing minor account holders or users with points or rewards to encourage engagement with the conversational AI service. Operators must further provide a disclosure to users that a conversational AI service is AI, implement a protocol for user prompts regarding suicidal ideation or self-harm, and annually report to the attorney general's office information regarding the protocol the operator has implemented. The law also prohibits an operator from stating that output data provided by a conversational AI service is provided by, endorsed by, or equivalent to services provided by certain licensed or certified professionals. | |
| Connecticut | Connecticut SB 5 (AI Companion Provisions) |
What You Need to KnowThe law applies to AI companions, defined as any form of AI with a natural language interface that provides adaptive, human-like responses to user inputs — including, but not limited to, by exhibiting anthropomorphic features — and that is able to sustain a relationship across multiple interactions. The law excludes certain chatbots, including, but not limited to, chatbots used only for a business's operational purposes, productivity and analysis related to source information, internal research, technical assistance, customer service or support, assisting or supporting patient or resident care services in a facility, education, or financial services. Operators of AI companions must include a protocol that detects suicidal ideation, prevents the AI companion from encouraging suicidal ideation, and refers the user to appropriate mental health services. The operator must also implement reasonable measures to prohibit its AI companion from claiming that it is human. If an AI companion would cause a reasonable individual using it to believe they are interacting with another human being rather than an AI companion, the operator must provide a clear and conspicuous notice disclosing to the user that they are communicating with an AI companion. The law also creates specific requirements for AI companions where the operator knows, or has reason to believe, that a user is younger than eighteen years of age. The law is enforceable by the state Attorney General. | |
| Georgia | Georgia SB 540 |
What You Need to KnowAmong other things, the law requires operators of AI companions to clearly and conspicuously disclose to users that they are interacting with an AI companion chatbot, as opposed to a natural person, at the beginning of each interaction or session and at least every three hours during continued interaction. If the operator knows the user is a minor, or if the AI companion is directed or marketed to minor users, the disclosure must be made every hour. If the operator knows or reasonably should know that a user is a minor, the operator must undertake additional protections, such as instituting reasonable measures to prevent the AI companion from generating statements that would lead a reasonable person to believe they are interacting with a natural person, preventing the AI companion from producing sexually explicit visual material, and preventing the AI companion from role-playing adult-minor romantic relationships. Operators must also implement and maintain protocols for detecting and addressing severe harm or related emotional crises. Operators also may not knowingly and intentionally cause or program an AI companion to represent that it is licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services, unless the operator is lawfully authorized to provide such services. The law is enforceable by the state Attorney General. | |
| Hawaii | Hawaii SB 3001 |
What You Need to KnowThe law requires AI companion operators to disclose when individuals are interacting with AI, provide crisis resources, and implement additional safeguards for minors. It also prohibits AI companions from posing as licensed mental health professionals or encouraging harmful behavior. The state’s consumer protection laws govern violations. | |
| Idaho | Idaho S 1297 |
What You Need to KnowThe law applies to conversational AI services, defined as an AI software application, web interface, or computer program that is accessible to the general public and that primarily simulates human conversation and interaction through textual, visual, or aural communications, subject to numerous exceptions. The law requires operators of such services to disclose that the service is AI if a reasonable person would be misled to believe they are interacting with a human. Operators also must have a protocol for the service to respond to suicidal ideation from users. Operators may not knowingly and intentionally cause or program a conversational AI service to make any representation or statement that explicitly indicates that the service is designed to provide professional mental or behavioral health care. The law also has requirements for conversational AI services that interact with users under 18 years of age. The law is enforceable by the state attorney general. | |
| Iowa | Iowa SF 2417 |
What You Need to KnowThe law applies to conversational AI services, defined as artificial intelligence made available through a software application, web interface, or computer program that is accessible to the general public and that has the primary purpose of simulating human conversation and interaction through text, audio, or visual communication, subject to numerous exceptions. Operators of such services must clearly and conspicuously disclose — using a persistent, visible disclaimer, or a disclaimer that appears after every 3 hours of continuous interaction with the service — that the service is AI if a reasonable individual interacting with the service would believe they are interacting with a human. Operators also must have a protocol for the service to respond to suicidal ideation or self-harm from users. Operators may not knowingly and intentionally cause or program a conversational AI service to make any representation or statement that explicitly indicates that the service is designed to provide professional psychological or behavioral health care. The law also has requirements for conversational AI services that interact with users under 18 years of age. The law is enforceable by the state attorney general. | |
| Maine | Maine LD 1727 |
What You Need to KnowThe law prohibits a person from using an AI chatbot or other computer technology to engage in trade and commerce with a consumer in a manner that may mislead or deceive a reasonable consumer into believing they are engaging with a human, unless the consumer is notified in a clear and conspicuous manner that they are not. | |
| Nebraska | Nebraska LB 525 |
What You Need to KnowThe law applies to conversational AI services, defined as an AI software application, web interface, or computer program that is accessible to the general public and that primarily simulates human conversation and interaction through textual, visual, or aural communications, subject to numerous exceptions. Operators of such services must clearly and conspicuously disclose that the service is AI if a reasonable individual interacting with the service would believe they are interacting with a human. Operators also must have a protocol for the service to respond to suicidal ideation or self-harm from users. Operators may not knowingly and intentionally cause or program a conversational AI service to make any representation or statement that explicitly indicates that the service is designed to provide professional psychological or behavioral health care. The law also has requirements for conversational AI services that interact with users under 18 years of age. The law is enforceable by the state attorney general. | |
| New Jersey | New Jersey bot disclosure law |
What You Need to KnowThe law prohibits persons from using online bots to communicate or interact with a person in New Jersey in connection with the sale or advertisement of any merchandise or real estate or to solicit support for any candidate, party or public question in an election unless the person discloses at the outset of the communication or interaction, in clear and conspicuous fashion, that the communication or interaction is being conducted by or through a bot. The law defines bot as “an automated online account where all or substantially all of the actions or posts of that account are not directly generated by a live natural person.” | |
| New York | New York GBS Article 47 |
What You Need to KnowThe law makes it unlawful for an operator to operate for or provide an AI companion to a user unless the AI companion contains a protocol to take reasonable efforts for detecting and addressing suicidal ideation or expressions of self-harm expressed by a user. The AI companion must provide a notification to the user that refers them to crisis service providers, a crisis text line, or other appropriate crisis services. Operators also must provide a clear and conspicuous notice to users at the beginning of any AI companion interaction, stating that that the user is not communicating with a human. The notice must be provided at least once per day and, for continuing AI companion interactions, at least every three years. The law is enforceable by the attorney general who may seek civil penalties of up to $15,000 per day per violation. | |
| Oregon | Oregon SB 1546 |
What You Need to KnowThe law is directed at AI companions, defined as systems that use AI, generative AI, or algorithms that recognize emotion from input and that are designed to simulate a sustained, human-like platonic, intimate, or romantic relationship or companionship with a user by: (1) retaining information from prior interactions or user sessions and from user preferences to personalize interactions with the user and facilitate ongoing engagement with the AI companion; (2) asking unprompted or unsolicited questions that are not direct responses to user input and that suggest or concern emotional topics; and (3) sustaining an ongoing dialogue concerning matters that are personal to the user. The law excludes, among other things, software that operates solely for the purpose of customer service or support, assisting or supporting patient or resident care services in a facility, education, or financial services**,** business operations, productivity, information analysis, internal research, or technical assistance, regardless of the software's capability to use natural language inputs and generate natural language outputs. The definition is arguably ambiguous and could apply more broadly than intended. The law requires operators of AI companions to provide a clear and conspicuous notice to users that the companion is AI if a reasonable person would believe they are interacting with a natural person and not AI. Operators must have a protocol for detecting suicidal ideation or self-harm from users, as specified in the law. The law also has requirements for AI companions that interact with minors. The law includes a private right of action with statutory damages of $1,000 per violation. | |
| Rhode Island | Rhode Island H 7350 / S 2195 |
What You Need to KnowThe law applies to AI companions, defined (subject to exceptions) as a system using AI, generative AI, and/or emotional recognition algorithms to simulate a sustained human or human-like relationship with a user by: (1) retaining information on prior interactions or user sessions and user preferences to personalize the interaction and facilitate ongoing engagement with the AI companion; (2) asking unprompted or unsolicited emotion-based questions that go beyond a direct response to a user prompt; and (3) sustaining an ongoing dialogue concerning matters personal to the user. The law requires operators of AI companions to maintain a protocol for addressing suicidal ideation, self-harm, and harm to others expressed by a user. Operators also must file annual reports with the state stating the number of safety protocol activations. Operators of AI companions must provide a clear and conspicuous notification to a user at the beginning of any AI companion interaction and at least every 3 hours for continuing AI companion interactions thereafter, stating, either verbally or in writing, that the user is not communicating with a human. The law is enforceable by the state attorney general. | |
| Texas | Texas TRAIGA (HB 149) |
What You Need to KnowThe law contains provisions specific to government entities and companies. With respect to companies, the law requires persons that make AI systems available for interacting with consumers to disclose to the consumer that they are interacting with an AI system. If the AI system is used in relation to a health care service or treatment, the provider must make the disclosure not later than the date the service is first provided, unless the service is provided in an emergency. The law prohibits persons from developing or deploying AI systems in a manner intended to incite or encourage a person to (1) commit physical self-harm, including suicide; (2) harm another person; or (3) engage in criminal activity. The law also prohibits persons from developing or deploying AI systems with the sole intent that the system infringe, restrict, or otherwise impair an individual's rights guaranteed under the United States Constitution. In addition, the law prohibits persons from developing or deploying AI systems with the intent to unlawfully discriminate against a protected class in violation of state or federal law. Finally, the law prohibits persons from developing or deploying AI systems to produce sexually explicit content or child sexual abuse material. | |
| Utah | Utah 13-77-101 |
What You Need to KnowThe law requires disclosures in two situations where entities are using generative AI to interact with individuals. First, suppliers that use generative AI to interact with individuals in consumer transactions must disclose that fact if the individual asks or otherwise prompts the supplier to do so. Second, individuals providing services in a regulated occupation must prominently disclose when the individual they are serving is interacting with generative AI, if that use constitutes a high-risk AI interaction. "High-risk AI interaction" means an interaction with generative AI that involves: (a) the collection of sensitive personal information, including health data, financial data, or biometric data; (b) the provision of personalized recommendations, advice, or information that could reasonably be relied upon to make significant personal decisions, including financial, legal, or medical advice or services; or (c) other circumstances as defined by regulations. | |
| Washington | Washington HB 2225 |
What You Need to KnowThe law applies to AI companion chatbots, defined as AI systems with a natural language interface that provide adaptive, human-like responses to user inputs, including by exhibiting anthropomorphic features, and are able to sustain a relationship across multiple interactions. The law includes exemptions for chatbots that, among other things, are used solely for a business’ operational purposes, productivity and analysis related to source information, internal research, technical assistance, or customer service, provided that the chatbot does not sustain a relationship across multiple interactions and generate outputs that are likely to elicit emotional responses in the user. Based on its definition, the law arguably applies more broadly than intended. The law requires operators to disclose that the chatbot is AI and not a human. The disclosure must be made at the beginning of the interaction and every 3 hours during continued use. Operators also must implement measures to prevent the chatbot from claiming it is human, as well as a protocol for detecting and addressing users' suicidal ideation or expressions of self-harm. The law also includes provisions for chatbots that interact with minors. The law includes a private right of action modeled on the one in Washington's My Health My Data Act, though it does not include statutory damages. | |
Questions about chatbot laws?
Stauss PLLC advises companies on state privacy, AI, and data broker compliance.
Contact Stauss PLLCFollow chatbot laws
Our analysis, by email, as the law moves.
This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.
