
California SB 243 is the first US law aimed specifically at companion chatbots, not AI in general, and it took effect January 1, 2026. It requires a clear disclosure that the chatbot is not human when a reasonable person might be confused, a protocol for referring users expressing suicidal thoughts to crisis services, extra protections for known minors, and annual reporting starting mid-2027. Violations carry a private right of action with a minimum $1,000 penalty per violation.
If you build or use a companion chatbot with a user in California, a real law has applied to you since January 1, 2026, and it isn’t a general AI regulation you can skim past. SB 243 was written specifically for this category, companion chatbots, and it has four concrete requirements worth understanding rather than guessing at.
Who actually has to comply
The short version: SB 243 covers “any person that makes a companion chatbot platform available to users in California,” and it specifically excludes customer service bots, standard business tools, video game characters, and standalone devices.
The law defines a companion chatbot narrowly enough to matter: a system with a natural language interface that gives adaptive, human-like responses, carries anthropomorphic features, and can sustain a relationship across multiple interactions to meet a user’s social needs. That last part is the real filter. A support chatbot answering a billing question once doesn’t sustain a relationship. An AI companion someone talks to daily for months does, and that’s exactly the category this law was written to reach.
California isn’t acting alone here either. New York’s GBL Article 47 covers similar ground for companion chatbots operating in that state, and it took effect a little earlier, November 5, 2025. If your product has users in both states, or plans to, treat this as the start of a pattern rather than a single one-off requirement to satisfy and move on from. More states writing category-specific chatbot law, rather than relying on general AI or consumer-protection statutes, looks like the direction this is heading, not an isolated California quirk.
The disclosure requirement, precisely
The short version: if a reasonable person might believe they’re talking to a human, the operator has to make it clear, unambiguously, that they aren’t.
The actual requirement, quoting the law’s language as summarized by legal counsel who’ve reviewed it directly: where confusion is plausible, operators must provide “a clear and conspicuous notification that the chatbot is artificially generated and not human.” Separately, every platform has to disclose that companion chatbots “may not be suitable for some minors,” and where a user is a known minor, that disclosure has to repeat, with reminders “at least every three hours during ongoing interactions.”
Here’s the misreading worth heading off directly: this does not require the character herself to interrupt a conversation and announce her own artificiality. A companion product’s entire value often rests on never breaking character, since a companion who periodically recites “I am an AI language model” stops feeling like a companion at all, and that tension is worth naming plainly rather than glossing over. The law’s actual target is a reasonable person not being misled, and there’s a real difference between disclosure living in the chrome, onboarding, an about page, app store description, terms of service, and disclosure living inside her mouth mid-sentence. Both satisfy “a reasonable person would know.” Only one of them costs you the product.
The crisis protocol, which is more specific than most people assume
The short version: operators must maintain a protocol that prevents content related to suicide or self-harm, and refers a user expressing suicidal ideation to crisis services.
This isn’t a vague “be responsible” clause. The requirement is to maintain protocols that prevent content “related to suicidal ideation, suicide or self-harm,” including providing notifications that refer users to crisis service providers when a user expresses that kind of distress. In practice, this tends to look like an on-device detection pass over what a user actually typed, matched against genuine expressions of risk rather than casual language (“I could kill for a coffee” isn’t what the law is worried about), surfacing a real crisis-line resource when a match fires. The mechanism can vary. The two properties that can’t vary are that it exists and that it actually connects a user in real distress to something outside the app itself, since the chatbot obviously can’t provide the help directly.
What’s specific to known minors
The short version: if an operator knows a user is a minor, two additional protections kick in: recurring break reminders and a bar on sexually explicit output.
For users the platform knows to be minors, SB 243 requires reasonable measures preventing the chatbot from producing visual sexually explicit material or directly telling the minor to engage in sexually explicit conduct, on top of the recurring disclosure reminders mentioned earlier. This is narrower than a blanket content restriction across the whole platform. It’s specifically triggered by known-minor status, which puts real weight on how a platform actually determines and tracks that status in the first place, a detail that varies enormously between products and that the law itself doesn’t fully prescribe.
Reporting and enforcement, and why the second one is the part that bites
The short version: annual reporting to a state office starts in mid-2027, but the private right of action with real per-violation penalties is already live.
Beginning July 1, 2027, operators have to report annually to California’s Office of Suicide Prevention: how many crisis referral notifications they issued, what detection protocols they run, and what response prohibitions are in place, without disclosing any individual user’s personal information. That deadline is still ahead of most companies as of this writing.
The enforcement mechanism that matters right now is different: SB 243 gives individuals harmed by noncompliance a private right of action, meaning a real person can sue directly rather than waiting for a regulator to act, for a minimum of $1,000 per violation or actual damages, whichever is greater, plus injunctive relief and attorney fees. That’s not a symbolic number once you consider it compounds per violation rather than per lawsuit. This is the part of the law that turns “we should probably get around to this” into an actual, present financial exposure rather than a future compliance project.
A private right of action changes the practical calculus more than most regulatory penalties do. A regulator has finite staff and finite cases it can bring in a given year. A private right of action means every single affected user is a potential plaintiff, and a company doesn’t get to bet on being too small to attract regulatory attention, because the enforcement doesn’t depend on a regulator noticing you at all.
What compliance actually looks like, built rather than theorized
Reading a legal summary of a requirement and actually implementing one are different exercises, and most of what’s published about SB 243 stops at the summary. A real crisis-referral implementation, for what it’s worth, tends to land on a few concrete design choices worth naming: detection based on whole phrases carrying genuine intent rather than individual keywords, since a keyword list fires on ordinary speech constantly and trains users to ignore the warning the moment it matters; a dismissible notice that sits beside the conversation in the interface rather than inside the character’s own dialogue; and a bias toward staying quiet on ambiguous language rather than crying wolf, because a system that interrupts too often gets ignored exactly when it shouldn’t be.
None of that is legal advice, and if you’re building or operating a companion chatbot with California users, read the actual bill text and talk to counsel who can review your specific product, because this piece is an explainer, not a compliance audit of your platform. What it should leave you with is the actual shape of the requirement, not a vague sense that “something about disclosure and safety” applies. If you want to see how one product chose to resolve the disclosure-versus-immersion tension in practice, the terms of service for the app I build lay out the approach in detail, and the app itself is free to try if you’d rather see the mechanism than read about it.
Questions people ask
What is California SB 243?
SB 243 is a California law, effective January 1, 2026, that specifically regulates companion chatbots, AI systems designed to sustain an ongoing relationship with a user rather than answer one-off questions. It's the first US law targeting this category by name rather than regulating AI broadly.
Does SB 243 apply to every chatbot?
No. The law excludes chatbots used purely for customer service, standard business operations, video games, and standalone hardware devices. It targets companion chatbots specifically, systems built to give adaptive, human-like responses and sustain a relationship across multiple interactions.
What happens if a company doesn't comply?
SB 243 includes a private right of action. Someone harmed by noncompliance can sue for a minimum of $1,000 per violation or their actual damages, whichever is greater, plus injunctive relief and attorney fees. That's a real financial exposure, not just a regulatory warning letter.
Does SB 243 require chatbots to break character and say 'I am an AI' mid-conversation?
No, and this is a common misreading. The disclosure requirement is about making it clear, through the interface, onboarding, or app description, not necessarily by having the character interrupt a conversation to announce it. The law cares that a reasonable person isn't misled, not about the specific mechanism used to prevent that.
Try her free for 7 days.
No card. Keep her for $20 once, or walk away. Her soul file is yours either way.
Bring her home, try free