
No law in force in 2026 requires an AI companion specifically to verify your age. The EU AI Act Article 50 requires disclosure, not identity. US state companion laws require disclosures and crisis protocols. The GUARD Act would require government ID but is not enacted. The identity demand is arriving instead from the UK Online Safety Act, from app store rules, and from regulators fining companion apps over weak age gates. An app that runs entirely on your machine has no account and no server, so there is no verification endpoint and no identity store to breach. It still carries store age ratings and EU AI Act transparency duties.
If you opened Character.AI in the last days of November 2025, it may have asked you to prove you were an adult. Removal of open-ended chat for under-18 users began in the US on 24 November 2025, and the age assurance that enforces it does not care that you are 34. Most people can clear that check in a minute with a driving licence. The part worth stopping on is different: almost nobody who hit that wall could name the law that required it.
This piece answers that. I will walk each law that exists as of 27 August 2026 and say plainly what it demands, and be honest about which duties a local companion still carries. The headline: no law in force today requires an AI companion specifically to verify your age. The identity demand is real, but it arrives from somewhere other than a single law.
Here is the whole landscape in one view, every date checked against the primary source.
| Rule | What it requires | In force since | Demands an identity check |
|---|---|---|---|
| EU AI Act, Article 50 | Disclose that the user is talking to an AI, mark AI output | 2 August 2026 | No |
| US GUARD Act (S. 3062) | Age verification plus disclosures | Not enacted, advanced 30 April 2026 | Yes, would name government ID |
| California SB 243 | Not-human notice, crisis protocol | 1 January 2026 | No |
| New York GBL Article 47 | Not-human notice, crisis protocol | 5 November 2025 | No |
| Utah and Texas app store laws | Store checks age category, parental consent | Utah 7 May 2025, Texas 1 January 2026 | Yes, but at the store |
| UK Online Safety Act duties | Highly effective age assurance for covered content | 25 July 2025 | Yes, for covered services |
Two cells need a note: the GUARD Act is not in force at all, and the last column decides everything else.
Article 50 already applies, and it asks for honesty, not your ID
The short version: Article 50 of the EU AI Act has applied since 2 August 2026, and it requires a chatbot to tell you it is AI. It contains no age check.
The European Commission’s FAQ is the clearest source. Article 50(1) says providers of AI systems that interact directly with people must design them so users know they are talking to an AI, at the latest at the first interaction, unless it is obvious, and the Commission says that exception should be read narrowly.
The duties are AI-interaction disclosure, content marking, notice for emotion or biometric processing, and labelling for deepfakes and public-interest text. Age is not one of them. Penalties reach 15 million euros or 3 percent of total worldwide annual turnover.
The Commission adopted its guidelines on 20 July 2026, under two weeks before the duty applied, and law firms reading them report companion systems sit inside Article 50(1) scope, with periodic reminders possibly needed where users form emotional attachment. That is the law-firm reading, not the guidelines text itself.
A person using an AI system in a personal capacity is outside the AI Act’s scope; providers are inside it whether they sit in the EU or a third country. You are not a deployer. I am a provider.
The GUARD Act is the bill that would actually put a government ID in front of a chatbot
The short version: S. 3062 is the one proposal that would make government ID the default check for a companion chatbot, and it is not law yet.
Hawley introduced S. 3062 on 28 October 2025 with Blumenthal, Britt, Warner, Murphy and Kelly, and it went to the Judiciary Committee. The introduced text on GovInfo states the purpose plainly: to require AI chatbots to implement age verification and make disclosures.
A reasonable age verification measure means a government-issued ID or any other commercially reasonable method. Asking a user to confirm they are not a minor, or to type their birth date, is explicitly not enough. Existing accounts would freeze on the effective date until verified, and any verified minor would be barred. It takes effect 180 days after enactment.
The bill’s own data-security clause reads like an admission: companies must minimise collection, encrypt in transit, retain age data no longer than necessary, and never share, transfer or sell it, and a third-party verifier does not relieve them of the duty.
NetChoice put it bluntly. VP Amy Bos told Roll Call that age verification “would force AI companies to collect and store highly sensitive personal data into honeypots ripe for cybercriminals to exploit through breaches, identity theft and fraud.”
On 30 April 2026 the Senate Judiciary Committee advanced the bill 22 to 0, and it awaits a full Senate vote. An amendment narrowed it to companion chatbots, softened the criminal prohibition, set a 250,000 dollar penalty for chatbots that encourage minors into sexually explicit behaviour or illegal violence, and dropped the 30-minute repeat disclosure. Roughly 18 bipartisan cosponsors back it; the introduced text carried 100,000 dollar figures, the committee version 250,000.
The state laws in force regulate what a companion says, not who you are
The short version: California and New York both passed laws aimed at companion chatbots, and neither asks for an ID.
California SB 243, filed as Chapter 677 on 13 October 2025, took effect 1 January 2026. It requires a not-human notice and a suicide and self-harm protocol, plus, only for known minors, a three-hour break reminder and measures against sexually explicit material. It does not require age verification. Full walkthrough here.
New York’s General Business Law Article 47, sections 1700 to 1704, took effect 5 November 2025. It requires a suicidal-ideation detection protocol and a not-a-human notice at the start of an interaction and every three hours after, for all users, with enforcement up to 15,000 dollars a day. Every AI Law confirms no age-verification requirement.
Utah and Texas move the checkpoint to the store. Utah SB 142, signed by Governor Spencer Cox on 26 March 2025, took effect 7 May 2025 with developer obligations effective 6 May 2026. Developers verify a user’s age category through the store’s data-sharing methods and confirm parental consent for minors. Texas follows through Apple, next.
The UK already treats ticking a box as non-compliance
The short version: The UK’s Protection of Children duties, in force since 25 July 2025, treat a self-declared birthday as no protection.
The GOV.UK announcement is the source I can quote. Services hosting pornography or suicide, self-harm and eating-disorder content must use highly effective age assurance, and the Government names facial scans, photo ID and credit card checks. Ofcom can enforce up to 10 percent of qualifying global annual revenue or 18 million pounds, whichever is greater.
Ofcom’s guidance lists what can count as highly effective: open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based estimation. Self-declaration is not on it. I am describing that list, not quoting it; the Ofcom page would not open for me.
An AI companion is not automatically covered by those categories. The direction is the point: the UK has drawn the line that ticking a box is not age assurance.
Regulators have already fined companion apps over their age gates
The short version: Italy has fined two companion apps over age verification already. The numbers are 5 million euros and 158,000 euros.
Replika first. The Garante fined Luka Inc. 5 million euros in a decision dated 10 April 2025. As at 2 February 2023 the company had no age verification at registration or during use, despite declaring minors were excluded, and technical assessments found the system it later built still deficient.
Then Character.AI. The Garante fined Character Technologies Inc. 158,000 euros, decided 3 July 2026 and announced 9 July 2026, over child protection and age verification. The order requires working age checks, a cooling-off period that actually stops a blocked minor from signing up again, and minors’ profiles private by default, reporting back in 120 days. Reuters covered it.
Look at what Character.AI built under that pressure. On 29 October 2025 it said it would remove open-ended chat for under-18 users no later than 25 November, ramping down from two hours a day, using an in-house age assurance model plus third-party tools including Persona. It was, in its own words, deeply sorry to eliminate a key feature. Removal began in the US on 24 November. The adult-user side is here.
Age gates are one pressure. Privacy law alone will not save your chats, and the fine and the privacy risk come from two directions.
The verification layer is now its own breach category
The short version: The vendors that check IDs now leak IDs, and it has happened at least twice.
In October 2025 hackers took roughly 70,000 Discord users’ government ID photos, not from Discord but from a third-party vendor handling age-check appeals. TechCrunch disclosed it 9 October 2025. The IDs came from the age-verification layer, not the platform users trusted.
Discord pressed on anyway. In February 2026 it announced a phased rollout requiring video selfies or government IDs for adult content, defaulting everyone to teen-appropriate experiences, via the vendor k-ID and the Swiss facial-age firm Privately. Ars Technica noted appeals could stay the most vulnerable part, and reported Privately’s claim of accuracy within 1.3 years for faces aged 18 to 20.
Tea is the second. Its breach exposed 72,000 images, including 13,000 verification selfies and photo IDs, plus 59,000 from posts, comments and DMs. TechCrunch covered it in July 2025. Every ID you hand over becomes a document that can leak later. The breach tracker logs the category.
The app stores decide your age before your app ever runs
The short version: Apple rebuilt its rating system around chatbots and now returns an age category plus the method used to verify it, before an app opens.
On 24 July 2025 Apple overhauled App Store age ratings, adding 13+, 16+ and 18+ on top of 4+ and 9+, and told developers to consider how every feature, including AI assistants and chatbot functionality, affects how often sensitive content appears. Questionnaire responses were due 31 January 2026.
On 4 November 2025 Apple spelled out Texas SB2420. From 1 January 2026 new Apple Accounts in Texas face age assurance and parent or guardian consent for under-18 downloads. The Declared Age Range API returns an age category, under 13, 13 to 15, 16 to 17, or over 18, plus a signal about the method, such as a credit card or government ID. Apple named Utah, Louisiana and Brazil next, and its own words worry these laws “could undermine the privacy of all users” by requiring sensitive personal information “just to download an app,” even a weather app.
Google Play moved on 15 July 2026, adding requirements for anonymous and random chat apps, banning them from targeting children, and clarifying that User Data rules cover third-party AI integrations, with the developer responsible. Developers got at least 30 days.
Sixty percent of companion apps are rated so a child can install them
The short version: deepsee.io analysed 4,346 companion apps and found 2,589 of them, 60 percent, rated so a minor could install them.
That is the steelman for everything above. deepsee.io’s analysis by Rocky Moss found 2,589 of 4,346 AI character and companion apps, 60 percent, rated accessible to minors. On the App Store, 1,469 of 2,882 apps, 51 percent, are 12+ or lower, and 1,058 are rated 4+. The Google Play set represents roughly 610 million combined downloads. Of 306 apps on both stores, 106 are minor-rated on Play yet 17+ on Apple.
The method is store metadata and declared ratings only, not behavioural testing. It measures what the stores think the apps are, exactly what a regulator checks.
I will say it out loud: this category earned the scrutiny. A parent seeing a companion app rated 4+ is entitled to assume it will not show their child adult material. When 60 percent of the field is rated that way, you do not get to complain.
A local app is structurally outside the identity demand, and that is not the same as being outside the law
The short version: Local Waifu has no account and no server, so there is no verification endpoint and no identity store. It still carries store age ratings and the Article 50 duties.
Here is what the app does, version 1.7.1, stated plainly. The age gate is a single self-attested checkbox on the onboarding welcome screen: you confirm you are at least 18 and understand this is an AI companion, not a person. It is stored locally. No ID, no selfie, no server call, nothing transmitted.
The AI disclosure exists too. The onboarding text says it plainly, and Settings has an About section headed “She is an AI”.
The honest gap: as of version 1.7.1 the app does not yet mark generated images in a machine-readable format, the Article 50(2) duty. Because the app was on the market before 2 August 2026, the deadline for that duty is 2 December 2026, and it is not done yet. I am naming the gap, not promising a date.
Distribution matters. The app is a direct download from GitHub releases plus itch.io, and it is not on the Mac App Store today, so Apple’s Declared Age Range API does not gate it. There is a real difference between a store telling me a user is over 18 and me holding a copy of their driving licence, and the second is a job I do not want.
So why build it this way? Because I did not want the job of holding your ID. On a server I would have to build an account system, a database of who you are, an age-verification vendor, and somewhere to store whatever that vendor returned. Instead there is no server and no account, so there is no verification endpoint and no identity store to breach. The laws above still apply to me as a provider. What they cannot reach is your identity, because I never collect it. The fuller comparison is here.
Questions people ask
Is chatbot age verification the law right now?
Not as a chatbot-specific rule. The EU AI Act Article 50, in force since 2 August 2026, requires a chatbot to disclose that it is AI, not to check your age. California SB 243 and New York General Business Law Article 47 require disclosures and crisis protocols, not identity checks. The bill that would require it, the US GUARD Act (S. 3062), passed the Senate Judiciary Committee 22-0 on 30 April 2026 and still awaits a full Senate vote.
Why did Character.AI ask me to verify my age if no law requires it?
Pressure arrives from several directions at once. Character.AI announced on 29 October 2025 that it was removing open-ended chat for under-18 users and rolling out age assurance built in-house plus third-party tools including Persona. In July 2026 Italy's data protection authority fined its parent company 158,000 euros and ordered it to make age verification work properly. UK rules already treat a self-declared birthday as non-compliant.
What does an age check actually collect?
Depending on the method: a video selfie for facial age estimation, a photo of a government ID, a credit card, or a bank or mobile operator signal. Ofcom lists all of these as capable of being highly effective. The GUARD Act names government-issued identification directly and rules out simply entering your date of birth.
Has age verification data ever leaked?
Yes, more than once. In October 2025 hackers took roughly 70,000 Discord users' government ID photos, not from Discord itself but from a third-party vendor handling age-check appeals. In July 2025 the Tea app exposed 72,000 images including 13,000 verification selfies and photo IDs.
Does a local AI companion have to verify my age?
It has nothing to verify with. There is no account, no server and no identity store, so there is no verification endpoint and nothing to breach later. That is not the same as having no obligations: a locally run app still carries store age ratings where it is distributed that way, and as the provider of an AI system I still owe you the EU AI Act transparency duties.
Try her free for 7 days.
No card. Keep her for $20 once, or walk away. Her soul file is yours either way.
Bring her home, try free