What 12 State ‘Companion Bot’ Laws Demand of AI Providers
Danny Tobey, Ashley Carr, Michael Atleson / Sep 1, 2026
The Colorado State Capitol is framed by buildings along Sherman Street Friday, June 27, 2025, in Denver. (AP Photo/David Zalubowski)
Twelve states now have passed laws aimed at reducing potential risks associated with “companion chatbots,” particularly for minors. Although the terminology for these products varies, these “companion bot laws” are already in effect in New York, California, and Hawaii, while similar laws in Colorado, Connecticut, Georgia, Iowa, Idaho, Nebraska, Oregon, Rhode Island, and Washington will take effect in 2027.
The 12 companion bot laws share several common regulatory themes across jurisdictions. Lawmakers have focused on disclosures regarding AI interactions, safeguards for minor users, crisis-intervention protocols, and prohibiting misrepresentations relating to licensed professional services. The laws are not substantively identical, however, with significant differences in both product coverage and the specific obligations or prohibitions applicable to bot providers in a given state.
Scope of coverage
All of the companion bot laws regulate AI systems that engage users through ongoing conversational interactions. Most of them restrict coverage to bots that exhibit anthropomorphic features and sustain relationships across multiple interactions. The laws in Colorado, Connecticut, Idaho, Iowa, and Nebraska have broader language that cover any bot that “simulates human conversation and interaction” through text, audio or video. With the exception of Hawaii, the laws all provide exceptions for chatbots used for business purposes or for other, narrow functions, such as a limited video game feature.
Common principles and key differences
An analysis of the substantive provisions of the 12 state companion bot laws reveals four overarching principles that state legislatures are effectively requiring chatbot providers to adopt:
1. Transparency and disclosure requirements
All 12 laws require providers to clearly and conspicuously disclose to users that they are communicating with an AI system rather than a human being.
The scope of this requirement varies. Some states require disclosure at the outset of an interaction, while others require repeated or persistent notices during extended conversations. Several statutes impose stricter disclosure requirements when users are minors. Washington’s law goes furthest by requiring providers to prevent chatbots from expressly representing themselves as human to any user, whereas this requirement exists in several other states only for minor users.
2. Heightened protections for minors
With the exception of New York and Rhode Island, the companion bot laws impose heightened compliance obligations when the user is a minor. While the specifics vary, these obligations generally include “reasonable measures” for
- Blocking sexually explicit content
- Preventing manipulative or maximizing engagement (e.g., offering points or rewards)
- Preventing emotional manipulation and dependency (e.g., discouraging users from seeking help from adults)
- Parental controls (i.e., requirements providers give parents or guardians tools to manage privacy settings and screen time)
Most companion bot laws apply these requirements when a provider knows, or has reason to know, that a user is a minor. Colorado and Georgia go further by imposing an affirmative duty to use "commercially reasonable” methods to estimate user age. However, the Georgia law limits this duty to when it is proportionate to the risk of access to features that may generate sexually explicit content.
As we described in a prior client alert, Connecticut adopts a notably different approach. Rather than focusing primarily on reasonable measures to prevent certain outputs, it forbids offering a companion bot to minors if “reasonably foreseeable” that the bot “is capable of” specified harmful interactions. The list of such interactions is broader than the other state laws.
3. Crisis detection and mental health safeguards
All 12 laws require operators to implement protocols that detect user expressions of suicidal ideation or self-harm and refer them to appropriate crisis or mental health resources. Some of the laws require posting of these protocols on the operator’s website. Unlike the other substantive provisions of these laws, these protocols are usually framed as being required for providers as a precondition for offering chatbots in the state. Several of the laws expand the scope of the required protocols to include additional harms such severe emotional crises, violence to others, and eating disorders.
The Colorado, Georgia, and Oregon laws also require the protocols to include escalation procedures for users with repeated or severe crisis indicators. Oregon’s law specifies that providers must use "clinical best practices and expertise" to establish how the AI provides "additional intervention" for a user who continues to express suicidal or self-harm ideation even after being given crisis resources. The only other law with even an indirect reference to clinical practices is Hawaii’s, which requires "evidence-based methods" for measuring suicidal ideation.
4. Restrictions on mental health and professional representations
Several of the companion bot laws prohibit providers from programming or permitting their AI products to represent that they are mental health professionals or can provide professional or licensed mental or behavioral health care. Such restrictions are also found in at least 8 other state laws that focus solely on bots designed for, or representing themselves as capable of providing, mental health. The first three of these laws—in Nevada, Utah, and Illinois—were discussed in a prior DLA Piper client alert. Other states following suit are Delaware, Maine, Tennessee, Rhode Island, and Vermont.
Our earlier client alert on the Connecticut AI law also describes a unique provision that prohibits offering a companion bot to a minor if reasonably foreseeable that the bot is capable of “offering mental health services,” outside tightly defined exceptions.
Colorado’s law extends the concept further by restricting representations related to additional licensed professions, including health care providers, dietitians, and attorneys. These provisions reflect growing concern that users may place undue trust in AI systems that appear to provide professional advice.
Colorado’s proposed rules may shape enforcement
On August 11, the Colorado Attorney General released proposed rules relating in part to its companion bot law, now called the Chatbot Safety Act. The law does not mandate rulemaking, but the Attorney General indicated that rules would help to clarify compliance obligations. Of particular note, the proposed rules address the statute’s standards requiring providers to adopt “technically feasible measures” and "reasonable measures" to prevent certain categories of outputs to minor users.
For covered products, the law requires providers to institute (a) “technically feasible measures” to prevent specified types of explicit sexual content and (b) “reasonable measures” to prevent “formulating, structuring, or optimizing a response that simulates emotional dependence or isolation from real-world supports.” Sections 11.3 and 11.4 of the proposed rules detail several factors that the Attorney General would consider in determining whether providers had complied with those requirements, including the availability and effectiveness of safeguards and the extent to which the provider engaged in effective testing, monitoring, remediation, and related documentation.
Many of these factors mirror crucial aspects of recommended corporate AI governance programs, including testing, monitoring, and assessing AI products and tools to ensure that they are working as intended and not causing harm. The provisions also indicate the importance of documenting those efforts and responding appropriately to any problematic results.
Given the absence of comparable interpretive guidance in the other states with companion bot laws, Colorado's final rules could become an influential reference point for regulators and courts analyzing similar statutory language. Public comments on the proposed rules—which also cover the recently enacted state law on automated decision-making technology—are due by October 26.
Looking ahead
Companion bot regulation is evolving rapidly. In addition to new legislation, state attorneys general and private plaintiffs continue to file cases in which chatbot usage has allegedly caused self-harm, violence, and emotional dependency. Congress is considering multiple AI and chatbot-related proposals, while industry organizations and nonprofits—such as the Better Business Bureau, the Partnership on AI, and Common Sense Media—are developing voluntary standards intended to complement legislative efforts.
The only thing certain in this area is change, with more laws, cases, and other activity on the horizon.
Authors



