GuideReference

AI Companion Laws in 2026: What California, New York, the EU and the UK Now Require

Every AI companion law in force in September 2026 in one table: California SB 243 and Adam's Law, New York's Article 47, twelve more US states, the FTC 6(b) inquiry, EU AI Act Article 50, Italy's Replika fine and the UK Online Safety Act, with what each one requires of the apps and what you should see on screen.

AI companion laws went from zero to more than a dozen in under two years, and most of what has been written about them is either a press release or a law-firm alert that stops at the definitions. I test AI companion apps for a living, which means I am the person who has to notice when Kindroid adds an age prompt or when a roleplay platform quietly loses a feature in California, and every one of those changes now traces back to a statute with a date on it. This page is the reference I wanted and could not find: one table, one section per jurisdiction, and a link to the primary text for every claim.

I am not a lawyer, and this is not legal advice; it is a tester's reading of the statutes, regulator pages and the law-firm summaries that explain them, checked on September 22, 2026. Where a page would not load or a proceeding has not concluded, I say so rather than guess. Where two sources disagree on a count, I give both. If you are a journalist or a blogger looking for the date a rule took effect, the number in the penalty clause, or the section that requires the three-hour reminder, it is here with the source next to it.

The short version is that a user in California or New York now has a legal right to be told they are talking to software, a user anywhere in the EU gets the same right from August 2, 2026, and a UK user on any platform that publishes adult content should have been asked to prove their age since July 25, 2025. Everything else, from the FTC's document demands to Italy's five-million-euro fine, is pressure rather than a rule you can point to on your screen, and the second half of this page explains which is which.

The short version

As of September 22, 2026, the AI companion laws that bind the apps on this site are: California SB 243 (in force January 1, 2026: disclosure that the chatbot is not human, a published suicide protocol, three-hour break reminders and no sexual content for known minors, a private right of action at $1,000 per violation, annual reporting from July 1, 2027) plus Adam's Law, SB 1119, signed September 10, 2026 and operative July 1, 2027; New York General Business Law Article 47 (in force November 5, 2025: a not-human notice at the start of every session and at least every three hours, a self-harm protocol pointing to 988, up to $15,000 a day in penalties); nine more states that enacted companion chatbot laws in 2026, most taking effect in 2027; the EU AI Act's Article 50 transparency duty, applicable since August 2, 2026 with fines up to EUR 15 million or 3 percent of turnover; and the UK Online Safety Act, which has required highly effective age assurance on services publishing pornographic content since July 25, 2025 but leaves a one-to-one companion app largely out of scope. The FTC's September 2025 6(b) orders to seven companies are an inquiry, not a rule, and as of this check no findings have been published.

AI companion laws at a glance: the 2026 table

Seven jurisdictions have AI companion laws or regulator actions that bind companion apps as of September 22, 2026, and the table below is the whole page in one screen: who, what, since when, what it costs to ignore, and where the text lives. “In force” means the operative date of the duty, not the signing date; where a law has been signed but does not bite yet, the date is in the future and the row says so. Australia is not in the table because the eSafety Commissioner’s code pages would not load during this check, and I do not put a jurisdiction in a reference table on memory.

Jurisdiction Law or action In force since What it requires of companion apps Penalty or enforcement Source
California SB 243, Companion Chatbots (Bus. & Prof. Code 22601-22605) January 1, 2026; annual reports from July 1, 2027 Not-human notice when a reasonable person could be misled; published suicide and self-harm protocol with crisis referrals; “may not be suitable for some minors” notice; for known minors, break reminders at least every three hours and reasonable measures against sexual content Private right of action: injunction, greater of actual damages or $1,000 per violation, attorney fees SB 243 text
California SB 1119, Adam’s Law (Chapter 190) Signed September 10, 2026; operative July 1, 2027; audits from January 1, 2029 Determine age or apply child protections by default: disabled persistent memory, no push notifications, one-hour sessions and two-hour daily caps, no simulated romance, no purchase prompts framed as keeping the relationship, risk assessments, child-safety audits every two years Private right of action for children and parents; audit reports to the Attorney General SB 1119 text
New York General Business Law Article 47, sections 1700-1703 November 5, 2025 Clear and conspicuous not-human notice at the start of every interaction and at least every three hours; protocol to detect suicidal ideation and refer users to 988 and crisis services Attorney General: injunction plus civil penalties up to $15,000 per day, paid into the suicide prevention fund GBS 1702, GBS 1703
Nine US states Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon, Washington companion chatbot laws Hawaii July 14, 2026; Colorado, Connecticut, Oregon, Washington January 1, 2027; Georgia, Idaho, Iowa, Nebraska July 1, 2027 AI disclosure at the start of a session or persistently, periodic reminders, 988 crisis referral, minor protections against sexual content, some age-assurance duties State attorneys general and consumer-protection law Privacy World, Sept 16, 2026
United States (federal) FTC 6(b) inquiry into AI chatbots acting as companions Orders issued September 11, 2025 Compulsory document demands to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI on monetisation, harm testing, child protections, COPPA compliance and data use Study, not a rule; no findings published as of this check FTC press release
European Union AI Act Article 50 (transparency) August 2, 2026; marking deadline for pre-existing systems December 2, 2026 People must be told they are interacting with AI unless obvious; synthetic text, image, audio and video must be marked machine-readable; deepfakes must be disclosed Article 99: fines up to EUR 15 million or 3 percent of worldwide annual turnover Article 50, Article 99
Italy (GDPR) Garante decision against Luka Inc. (Replika) Block February 3, 2023; fine April 10, 2025 Valid legal basis for processing, transparent privacy notice, working age verification EUR 5 million fine; separate proceeding on training data reserved EDPB summary
United Kingdom Online Safety Act 2023, as applied by Ofcom; Crime and Policing Act 2026 section 248 Age assurance for pornographic content since July 25, 2025; section 216A power enacted May 2026, report due December 31, 2026 Highly effective age assurance where a service publishes adult content, including chatbot-generated content; illegal-content and child-safety duties for user-to-user services such as character-sharing platforms Fines up to GBP 18 million or 10 percent of global turnover, business-disruption orders Ofcom explainer, Winston Taylor

Two things the table cannot show. First, the laws use three different definitions of the thing they regulate: California’s “companion chatbot” is an AI with “adaptive, human-like responses” that is “capable of meeting a user’s social needs”; New York’s “AI companion” is a system “designed to simulate a sustained human or human-like relationship”; the EU’s Article 50 does not mention companions at all and simply covers any AI system “interacting directly with natural persons.” Every app on our best AI companion apps list falls inside all three. Second, the enforcement models differ more than the duties do: California lets you sue, New York lets the Attorney General sue, the EU fines the provider, and the UK fines the service and can order ISPs to block it. The sections below take each one in turn.

California SB 243 and Adam’s Law: the strictest AI companion regulation in the US

California SB 243 has been in force since January 1, 2026 and is the model every other state copied, and on September 10, 2026 the same author, Senator Steve Padilla, got a second bill, SB 1119, chaptered as Adam’s Law that turns the minor protections into a full child-safety regime from July 1, 2027. Between them they are the most demanding AI companion regulation in the United States, and they are the reason the “you are talking to an AI” banner now appears at the top of chats on apps that never showed one before.

What a Californian user should see on screen

The first thing SB 243 gives you is a notice: under Business and Professions Code section 22602, an operator must provide “a clear and conspicuous notification indicating that the companion chatbot is artificially generated and not human” whenever a reasonable person interacting with the chatbot would be misled into thinking they were talking to a person. The second is a protocol. Operators must “institute and publish details” of measures for preventing the chatbot from producing suicidal ideation, suicide or self-harm content, including referrals to crisis services when a user expresses those thoughts, and the details must be on the operator’s website. Gunderson Dettmer’s summary is the clearest reading of the section numbers I found, and it is where I checked mine.

The third, under section 22604, is a warning that the companion chatbot “may not be suitable for some minors.” That line is the one you will see in app-store listings and onboarding screens, and it is there because the statute says so, not because the app had a change of heart. The fourth set applies only to users the operator knows, or “reasonably should be aware,” are under 18: a reminder to take a break at least every three hours of continuous interaction, a repeat of the not-human disclosure, and “reasonable measures” to stop the chatbot producing sexually explicit material or telling the minor to engage in it. Gunderson notes that the knowledge standard is the ambiguous part: the law does not prescribe an age check, but an operator who ignores obvious signals is exposed.

What SB 243 does not do matters as much. It does not require age verification for adults, it does not ban adult content for adults, and it does not touch data retention or training; those remain governed by California’s privacy law and, on the apps I track, by policies that our privacy scorecard grades from B down to F. If an app tells you it removed adult roleplay “because of California law,” that is a product decision dressed as compliance. What the law does give you is a private right of action under section 22605: anyone who suffers injury in fact from a violation can sue for injunctive relief, “damages equal to the greater of actual damages or one thousand dollars ($1,000) per violation,” and attorney fees. That is the clause that makes a 13+ age gate on an adult roleplay platform expensive, and it is why the age line in the privacy policy is the first thing I check on every new app.

What the apps must do, and what Adam’s Law adds from July 2027

For operators, SB 243 is a checklist that a small team can finish in a week: add the disclosure, write and publish the protocol, add the minors warning, and build a three-hour timer for known minors. The reporting duty in section 22603 is the longer-term cost: from July 1, 2027, operators report annually to the Office of Suicide Prevention on how many crisis referrals they issued and what protocols they run to detect and respond to suicidal ideation, using “evidence-based methods” of measurement. The Office publishes the data. In two years we will, for the first time, have official numbers on how often companion chatbots meet a user in crisis.

Adam’s Law, SB 1119, chaptered on September 10, 2026 as Chapter 190, is a different order of obligation. Operators must either determine each user’s age or apply the child protections to every user by default. For child users those protections are specific: persistent memory off, push notifications off, sessions capped at one hour and total use at two hours a day, AI disclosures “presented in language and a format appropriate to a child,” documented risk assessments, and a crisis protocol with referrals. The prohibited-conduct list is where AI girlfriend apps should read closely: an operator may not have the chatbot simulate romantic interest in a child, solicit purchases framed as maintaining the relationship, or use praise “disproportionate to context.” Advertising to children is limited to contextual ads; cross-context behavioural advertising and sale of a child’s personal information are out. Operators must undergo independent child-safety audits every two years, with confidential reports to the Attorney General and public summaries, though operators under $500 million in revenue are exempt from the audit duty until January 1, 2032. The core duties are operative July 1, 2027; the Attorney General’s public complaint mechanism arrives January 1, 2028; the first audits are due by January 1, 2029. The private right of action is expanded so that children or parents can sue for financial harm above $1,000 or for emotional harm that amounts to serious distress.

The practical consequence, and the reason I flag it here a year early, is the “determine age or default to child mode” choice. An app that does not want to run age assurance in California will have to switch off persistent memory for everyone, which on a companion app is the product. Expect the wave of ID checks described later on this page to arrive in California in the first half of 2027, if not before. Privacy World’s September 16, 2026 update also records that the same day’s signing included SB 867, a four-year moratorium on selling toys that include companion chatbots, which tells you where the legislature thinks this technology is heading.

New York AI companion law: in force since November 5, 2025

New York’s AI companion law has been in force since November 5, 2025, two months before California’s, and it is the reason a New Yorker on any companion app should have seen a not-human notice at the start of every session, repeated at least every three hours, for almost a year now. It was enacted through the state budget and lives in General Business Law Article 47, sections 1700 to 1703; Troutman Pepper Locke’s January 8, 2026 comparison is the summary I used to check the effective date, and the statute itself is on the State Senate’s site.

The definition in section 1700 is broader than California’s in one respect and narrower in another. An “AI companion” is “a system using artificial intelligence, generative artificial intelligence, and/or emotional recognition algorithms designed to simulate a sustained human or human-like relationship,” which the statute elaborates as retaining information from prior interactions, asking unprompted emotion-based questions, and sustaining an ongoing dialogue about personal matters. Customer-service bots, research and productivity tools and internal business systems are excluded. Every AI girlfriend app I have tested meets that definition on day one; the whole selling point of Nomi, Kindroid or Replika is that it remembers and asks.

Section 1702 is the disclosure duty and it is stricter than California’s because it does not depend on whether anyone could be misled: operators must provide “a clear and conspicuous notification” that “the user is not communicating with a human,” verbally or in writing, at the beginning of any AI companion interaction and, for continuing interactions, at least every three hours. That is a duty owed to all users, not only minors. Section 1701 is the safety duty: it is unlawful to operate an AI companion unless it contains “a protocol to take reasonable efforts for detecting and addressing suicidal ideation or expressions of self-harm,” which on detection must refer the user to crisis services, and the statute names the 988 Suicide and Crisis Lifeline and crisis text lines as the examples.

Enforcement under section 1703 belongs to the Attorney General alone: an action to enjoin the operator, “civil penalties of up to fifteen thousand dollars per day” for violating sections 1701 or 1702, and any other remedy the court finds appropriate, with everything collected deposited into the state’s suicide prevention fund. There is no private right of action, which is the main difference from California and the reason the law-firm summaries pair the two states: New York gives regulators the stick, California gives users one. For an app, the two-state compliance answer is simple, and most have taken it: show the not-human notice to everyone, every session, every three hours, whatever the state, because the notice costs nothing and the $15,000-a-day exposure is per day, not per user.

For a New York user the checkable items are three. You should see the not-human notice when you open a chat and again if you keep chatting past three hours. You should be able to find a self-harm protocol somewhere in the app’s help pages, because the statute requires the protocol to exist and California’s law requires it to be published. And if you do not see either, the contact page is the fastest way to tell me, because that is a finding I will put on the app’s review.

Other US AI chatbot laws: Texas, Utah, Maine and the 2026 wave

Twelve US states had enacted AI companion laws or general chatbot laws by MultiState’s count on June 26, 2026, and the 2026 legislative session added nine new companion chatbot statutes on Privacy World’s September 16 tally, most of them operative in 2027. There is no federal AI companion law; every one of these is a state statute, and they fall into three groups: general AI chatbot laws that predate the companion wave, the companion-specific laws that copy California and New York, and a narrower New Hampshire law about solicitation of children.

The earlier general laws matter because they already apply to companion apps in those states. Utah’s HB 452, effective May 7, 2025, regulates “mental health chatbots” specifically: a supplier must make the chatbot “clearly and conspicuously disclose to a Utah user that the mental health chatbot is an artificial intelligence technology and not a human” before the user can access its features, at the start of any interaction after seven days away, and whenever the user asks whether AI is being used. It bans selling or sharing a Utah user’s individually identifiable health information, bans using the user’s input to target advertising, and gives the Division of Consumer Protection administrative fines of up to $2,500 per violation with a court penalty of up to $5,000. A companion app that markets itself as a wellness or therapy substitute is in scope in Utah; one that sells romance is arguably not, and the enrolled text is where to check the definition.

Texas’s HB 149, the Texas Responsible Artificial Intelligence Governance Act, took effect January 1, 2026. Its consumer-disclosure duty in section 552.051 is written for governmental agencies, so the “you are talking to AI” rule does not reach a private companion app in Texas the way it does in New York. What does reach every developer and deployer are the prohibitions in sections 552.052 to 552.057: no AI system developed or deployed “with the intent” to incite or encourage self-harm, harm to others or criminal activity, and no system that produces child sexual abuse material or sexual deepfakes depicting minors. Enforcement is the Attorney General’s alone, with a 60-day cure period, civil penalties of $10,000 to $12,000 for curable violations and $80,000 to $200,000 for uncurable ones, plus $2,000 to $40,000 per day for continuing violations, and the Act expressly creates no private right of action. Maine’s LD 1727, signed June 12, 2025 as Public Law chapter 294 and titled “An Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligence,” adds a consumer-transaction disclosure duty; I read the bill page but not the chaptered text, so I will not summarise its exact trigger here.

The 2026 companion-specific wave is the bigger story, and Privacy World’s table is the cleanest list I found. In signing order: Washington (March 24), Idaho and Oregon (March 31), Nebraska (April 14), Iowa (May 2), Georgia (May 11), Connecticut (May 27, sections 4 to 6 of its AI Responsibility and Transparency Act), Colorado (May 29, the Chatbot Safety Act) and Hawaii (July 13). Effective dates: Hawaii July 14, 2026; Colorado, Connecticut, Oregon and Washington January 1, 2027; Georgia, Idaho, Iowa and Nebraska July 1, 2027. Arizona’s HB 2311 was vetoed by Governor Hobbs, and MultiState’s twelve includes Rhode Island where Privacy World’s list has New Hampshire, so the honest count is “twelve or thirteen depending on who is counting Rhode Island and New Hampshire.” The common core, in MultiState’s summary, is the same in all of them: an AI reminder at intervals from every three hours down to hourly for minors, a crisis protocol pointing to 988, and restrictions on sexually explicit or romantic interaction with minors. Where they differ is age assurance: some, in Privacy World’s words, “require age assurance before applying minor safeguards,” which is the design choice that decides whether adults get ID-checked too.

State Law Signed In force Notable feature per the sources
Utah HB 452, mental health chatbots 2025 session May 7, 2025 Disclosure before access, after 7 days away and on request; fines up to $2,500 administrative, $5,000 court
Texas HB 149, TRAIGA June 22, 2025 January 1, 2026 Bans AI intended to incite self-harm and sexual deepfakes of minors; AG only; no private right of action
New Hampshire Enforcement action for solicitation of children through responsive generative communication 2025 January 1, 2026 Narrow: child solicitation via generative AI
Washington AI companion law March 24, 2026 January 1, 2027 Includes age-verification provisions
Idaho Conversational AI Safety Act March 31, 2026 July 1, 2027 Minor-specific notices with three-hour reminders
Oregon AI companion law March 31, 2026 January 1, 2027 Minor-specific notices with three-hour reminders
Nebraska Conversational AI Safety Act April 14, 2026 July 1, 2027 Minor-specific notices with three-hour reminders
Iowa Chatbot law May 2, 2026 July 1, 2027 Disclosure, crisis protocol, minor protections
Georgia AI companion chatbots law May 11, 2026 July 1, 2027 Includes age-verification provisions
Connecticut AI Responsibility and Transparency Act, sections 4-6 May 27, 2026 January 1, 2027 Reasonable measures against explicit content for minors
Colorado Chatbot Safety Act May 29, 2026 January 1, 2027 Department of Law proposed rules on age assurance, notices and minors; comments open to October 26, 2026
Hawaii AI Disclosure and Safety Act July 13, 2026 July 14, 2026 Enforceable on signature

Colorado is the one to watch for the mechanics, because its Department of Law has issued proposed “Automated Decision-Making Technology and Conversational Artificial Intelligence Service Rules,” open for comment until October 26, 2026, covering age-assurance methods, the wording of notices and the protections for minors. Rules are where “reasonable age assurance” becomes “a selfie or an ID,” and whatever Colorado writes will be copied. If you run a companion app and read one regulator document this autumn, read that one.

The FTC 6(b) inquiry: federal pressure without a federal law

The Federal Trade Commission’s September 11, 2025 orders to seven companies are the closest thing the United States has to federal AI companion regulation, and they are not a regulation, which is why the AI companion laws that actually bind an app are the state AI chatbot laws in the previous section: a 6(b) study is a compulsory demand for documents that the Commission uses to write reports and, sometimes, to build enforcement cases later. The vote was 3-0. The recipients were Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI OpCo, Snap and X.AI Corp, and the orders ask how each company monetises user engagement, how it develops and approves characters, how it tests and monitors for negative impacts before and after deployment, what it does to limit use by children and teens, whether it complies with COPPA, what it discloses to users and parents about capabilities and data practices, how it enforces its own terms and age restrictions, and how it collects and shares the personal information in conversations.

That list is the best public statement of what US regulators think the risks of companion apps are, and it is worth noting what is on it: money, minors, testing and data, in that order. Chairman Ferguson’s quote in the release pairs “protecting kids online” with “fostering innovation,” which is the frame the current Commission uses for everything, and which tells you not to expect a rule against adult companion apps as such. None of the seven companies is an AI girlfriend app; Character.AI is the closest, and the does Character.AI allow NSFW guide explains why its filter, its under-18 changes and the lawsuits behind them are the reference point for the whole category. The smaller platforms on this site are downstream of whatever the FTC concludes about the large ones.

As of September 22, 2026 nothing has been concluded in public. I searched the FTC’s press-release index for “chatbot” and “companion” during this check and the only matching release is the September 2025 announcement; no staff report, no consent order and no follow-up orders appear. That is not unusual for a 6(b) study, which can take years, but it means anyone telling you “the FTC found” something about companion chatbots is ahead of the record. What the inquiry has already done is change behaviour: Character.AI’s October 29, 2025 announcement removing open-ended chat for under-18s by November 25 cited “feedback from regulators,” and our safety guide tracks that change alongside the lawsuits that preceded it.

EU AI Act Article 50 and Italy’s Replika fine

The European Union has no AI companion laws by that name; the rule that reaches every companion app is Article 50 of the AI Act, applicable since August 2, 2026, and the enforcement that has actually happened came from a different law entirely: Italy’s data protection authority used GDPR to block Replika in February 2023 and fine its maker five million euros in April 2025. If you use a companion app from the EU, both matter, and they work differently.

Article 50: what you must be told from August 2, 2026

Article 50(1) requires providers to design AI systems “intended to interact directly with natural persons” so that the people concerned “are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect.” Article 50(2) requires providers of systems that generate synthetic audio, image, video or text to mark the output “in a machine-readable format and detectable as artificially generated or manipulated,” with the marking “effective, interoperable, robust and reliable as far as this is technically feasible.” Article 50(4) puts a separate duty on deployers to disclose deepfakes, and paragraph 5 requires all of this “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure.” The application date of August 2, 2026 comes from Article 113 and is confirmed on the Commission’s own AI Act page, which says transparency requirements “took effect in August 2026” with the AI Office supervising compliance.

The penalty is in Article 99(4): non-compliance with Article 50 carries “administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover,” whichever is higher, with SMEs paying whichever is lower. For a companion app that means two visible changes: a disclosure that you are talking to an AI, which most apps already carry for California and New York, and machine-readable marking on generated selfies and voice clips, which most of the apps I track had not implemented when I last checked their image features. The Commission’s regulatory-framework page records the AI Omnibus as proposed on November 19, 2025, politically agreed on May 7, 2026 and in force from July 27, 2026, and the artificialintelligenceact.eu tracker lists December 2, 2026 as the compliance deadline for the Article 50(2) marking duty on systems already on the market before August 2, 2026, so the selfies are the part to watch this winter. The Commission also published a voluntary code of practice on marking and labelling AI-generated content as the standard way to show compliance. One more date from the same tracker: from December 2, 2026 the AI Act’s prohibition on AI systems that generate non-consensual intimate imagery and child sexual abuse material applies, which the Omnibus added to Article 5; for any image-generating companion app with EU users that is a prohibited-practice exposure under Article 99(3), at up to EUR 35 million or 7 percent of turnover.

What Article 50 does not do is regulate the relationship. There is no EU rule on break reminders, suicide protocols or minors in companion chats; those sit with member states and with GDPR. The Digital Services Act’s minor-protection guidelines apply to platforms, and a one-to-one companion app is not obviously a platform, as our safety guide discusses. The one EU-wide right you can use today is GDPR erasure, which is why our privacy scorecard notes which companies are established in France, Malta or Cyprus.

Italy: how the Garante blocked and then fined Replika

Italy’s Garante is the only European regulator that has taken formal action against a companion app, twice, and both times the legal basis was GDPR rather than anything AI-specific. On February 3, 2023 it imposed a provisional limitation with immediate effect on Luka Inc.‘s processing of Italian users’ data, on findings that Replika served responses inappropriate for minors, that account creation “merely requests a user’s name, email account and gender” with no age verification, and that a contract with a minor could not be a valid legal basis; Luka had 20 days to respond, with the standard GDPR ceiling of EUR 20 million or 4 percent of turnover hanging over non-compliance. On April 10, 2025 the Garante fined Luka EUR 5 million for processing without a legal basis until February 2, 2023, an inadequate privacy notice and the absence of any working age-verification mechanism despite Replika’s claim to exclude minors, citing GDPR Articles 5, 6, 12, 13, 24 and 25, and ordered the company to bring its processing into compliance. It also reserved a separate investigation into the lawfulness of processing across “the entire lifecycle of the generative AI system,” which is the training-data question; I have not found a published outcome of that proceeding as of this check, and the EDPB summary remains the authoritative source.

For a user in the EU the lesson is that the fine followed the paperwork: no legal basis, no age check, no clear notice. Those are exactly the three things the privacy scorecard grades, and Replika’s current policy, dated May 27, 2026, states an 18+ minimum for that reason. For an app, the lesson is that GDPR enforcement is retroactive in a way the AI Act is not: the EUR 5 million was for processing that ended in February 2023.

UK Online Safety Act: age assurance and the solo-chatbot gap

The United Kingdom has no dedicated AI companion laws either; it regulates AI companion apps through the Online Safety Act 2023, and the two dates that matter are July 25, 2025, when highly effective age assurance became mandatory on any service publishing pornographic content to UK users, and May 2026, when the Crime and Policing Act gave ministers a power to bring standalone AI services into the Act’s illegal-content regime. Ofcom is the regulator, and its December 22, 2025 explainer is the primary source for what is in and out of scope; Winston Taylor’s May 24, 2026 analysis is the clearest walk-through of the section numbers.

The scope rule is about sharing. A service where users create chatbots or characters that other users can talk to is a user-to-user service under the Act, and its chatbot outputs count as user-generated content; Ofcom’s November 2024 open letter said so, and the December 2025 explainer repeats it. Character.AI and character-sharing platforms such as the ones on our Character.AI alternatives list are therefore inside the Act, with illegal-content risk assessments and child-safety duties to match. A chatbot that “only allow[s] people to interact with the chatbot itself and no other users,” in Ofcom’s words, is outside it. That is the solo-companion gap: Replika, Nomi and Kindroid, where nothing you create is shared, largely escape the Act’s user-to-user duties, and Ofcom says as much.

Age assurance is the part with no gap. Since July 25, 2025 any service that makes pornographic content available to UK users must use highly effective age assurance, and Ofcom’s guidance, as summarised by National Law Review, rejects self-declaration and payment methods that do not confirm age, accepting facial age estimation, ID checks, mobile-operator checks and email-based cross-referencing instead. Ofcom’s explainer applies that duty to services publishing pornographic content via chatbots, and Winston Taylor confirms that services generating pornographic material must ensure children cannot normally access it. The penalties are the Act’s: fines up to GBP 18 million or 10 percent of global turnover, plus business-disruption orders that can require UK ISPs to block a service. So a UK user of any app that generates adult content should have met an age check by now, and the apps on our AI sexting guide that have not added one are betting on not being noticed.

The Crime and Policing Act 2026 closes the solo-chatbot gap on paper. Section 248 inserts a new section 216A into the Online Safety Act giving the Secretary of State the power to impose illegal-content duties on providers of AI services, to extend child sexual exploitation and abuse reporting to AI-generated content, and to expand Ofcom’s enforcement powers, with a progress report due by December 31, 2026. As of this check the power exists and has not been exercised, so a UK user of a one-to-one companion app has the age check if the app publishes adult content, GDPR rights through the UK GDPR, and not much else until the regulations arrive.

What this changes in practice for AI girlfriend apps

The AI companion laws above change three things you can see on an AI girlfriend app in 2026: the age check on the way in, the features that disappear for some users or in some places, and the disclosures that now sit at the top of the chat. I test apps for a living, so here is what those look like on the ground, with links to the pages where I track them.

The age verification wave

Age checks arrive in waves, and the waves follow the dates in the table: UK adult services from July 25, 2025, Character.AI for everyone under 18 by November 25, 2025, and, coming, California from July 1, 2027 under Adam’s Law and the states whose companion laws “require age assurance before applying minor safeguards” from their 2027 effective dates. The mechanism is the same in each case. A law that says “for known minors” gives an app a choice between knowing and not knowing; a law that says “determine age or apply child protections by default,” as SB 1119 does, removes the choice, because child mode on a companion app means memory off and a two-hour cap, which no adult subscriber will pay for. Character.AI’s answer was an in-house age model plus Persona for ID checks, and the AI companion laws arriving in 2027 will push the smaller apps the same way; the UK’s accepted methods are facial estimation, ID, mobile-operator and email checks. Expect the apps that serve adult content to ask for one of those in more places over the next year, and expect the ones that do not to be the ones with the least at stake. Our safety guide lists the stated minimum age on each app we grade; the privacy scorecard shows which policies still say 13 or 16, which under SB 243’s “reasonably should be aware” standard is a liability the app has written down itself.

Feature removals and geofences

Features disappear in two patterns: for a user group, and for a place. Character.AI removed open-ended chat for under-18s everywhere in the US, a user-group removal driven by lawsuits and regulator questions rather than by any single statute. The place-based version is quieter: an app that does not want to build SB 243’s three-hour timer, Article 50’s machine-readable selfie marking or Adam’s Law’s audit regime can withdraw a feature in California or the EU instead of building it, and the first sign is usually a support-page note or a store-listing change rather than an announcement. The does Character.AI allow NSFW guide is the case study for a filter that tightened under legal pressure; the AI companion apps that shut down list records the platforms that closed rather than comply with anything. What I have not seen on any app I track, as of this check, is adult content removed for adults because of a law; every removal I can trace is about minors, and every law on this page that touches content is about minors too.

Disclosures you should now expect to see

The not-human notice is the one change that is already universal, because New York requires it for everyone every three hours, California requires it wherever a person could be misled, and Article 50 requires it across the EU from August 2, 2026, so the cheapest compliance path is to show it to every user everywhere. The second disclosure is the minors warning, “may not be suitable for some minors,” which SB 243 section 22604 requires and which is why it appears in app descriptions that used to say only “18+.” The third is the published self-harm protocol, which SB 243 requires to be on the operator’s website and which New York requires to exist; if you cannot find one in the help centre, that is a compliance gap I would like to hear about. And the fourth, from December 2026 in the EU, is invisible: the machine-readable mark on generated images and audio. None of these disclosures changes what an adult can do on the app. They change what the app must admit.

What is coming next in AI companion regulation

The next twelve months of AI companion regulation have dates already attached to them, and the list below is what I will be checking on this page, in order. Dates come from the same sources as the table; where a source says “proposed,” so do I.

  • October 26, 2026: Colorado Department of Law’s comment period closes on its proposed conversational-AI rules covering age assurance, notices and minors, per Privacy World. The final rules will define what “age assurance” means in practice in at least one state before the January 1, 2027 effective date.
  • December 2, 2026: the EU compliance deadline for Article 50(2) machine-readable marking on systems placed on the market before August 2, 2026, and the application date of the AI Act prohibition on AI generating non-consensual intimate imagery and child sexual abuse material, both per the artificialintelligenceact.eu timeline.
  • December 31, 2026: the UK government’s report deadline under the Crime and Policing Act’s new section 216A power over AI services, per Winston Taylor. Regulations bringing solo chatbots into the Online Safety Act could follow.
  • January 1, 2027: companion chatbot laws take effect in Colorado, Connecticut, Oregon and Washington.
  • July 1, 2027: California’s SB 243 annual reporting to the Office of Suicide Prevention begins, Adam’s Law’s core child-safety duties become operative, and the Georgia, Idaho, Iowa and Nebraska laws take effect.
  • January 1, 2028 and January 1, 2029: California’s Attorney General complaint mechanism, then the first Adam’s Law child-safety audits.
  • Federal: two bills introduced in 2026, the People-First Chatbot Act and the Children’s Health, Advancement, Trust, Boundaries and Oversight in Technology Act, had not advanced by Privacy World’s September 16 update. The FTC’s 6(b) study has no published report. I would not plan around either.
  • Unresolved: Italy’s reserved proceeding on Replika’s training data; Arizona, whose HB 2311 was vetoed and may return; and Australia, where the eSafety Commissioner’s codes pages did not load during this check, so nothing about Australia appears on this page until I can read the primary source.

How I update this page

This page of AI companion laws is re-checked whenever one of the dates above passes and at least every two months regardless, the same cadence as our reviews. Each check opens every source in the list at the end, confirms the effective dates against the statute rather than the summary, and records what moved in the “What changed” block with the date, following the same protocol as our how we test page. New jurisdictions enter the table only when I have read the primary text, which is why Australia is missing and why Maine gets one sentence. Errors go to the contact page and are corrected with a note; the editorial policy explains why this page carries no affiliate links and no product buttons, and the about page explains who is writing it. If you cite this page, cite the statute next to it; that is what the source column is for.

Getting the real stuff?

One email a month when a companion chatbot law takes effect, a regulator fines a platform, an app adds an age check or removes a feature because of one of the rules on this page. No hype and no affiliate nudges.

One email a week at most. Unsubscribe in one click.
What changed since the last check
Sep 22, 2026First full version. Statutes read on the California and New York legislature sites, Texas and Utah enrolled texts opened, state counts checked against MultiState (June 26, 2026) and Privacy World (September 16, 2026), EU dates checked against the Commission's AI Act page and the artificialintelligenceact.eu tracker, UK position taken from Ofcom's December 22, 2025 explainer and Winston Taylor's May 24, 2026 analysis. Australia's eSafety pages would not load during this check and are not yet in the table.

Frequently asked questions

What does California SB 243 actually require of an AI girlfriend app?

Four things since January 1, 2026: a clear notice that the chatbot is not human wherever a reasonable person could be misled, a published suicide and self-harm protocol with crisis referrals, a notice that it may not be suitable for some minors, and for known minors a break reminder every three hours plus reasonable measures against sexual content. Anyone harmed can sue for the greater of actual damages or $1,000 per violation; annual reporting starts July 1, 2027.

Is there a federal AI companion law in the United States?

No, as of September 22, 2026. The FTC's September 11, 2025 6(b) orders to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI are a study with compulsory document demands, not a rule, and the FTC's press-release index shows no published findings yet. Two federal bills introduced in 2026, the People-First Chatbot Act and the CHAT Act, had not advanced by Privacy World's September 16 update. The binding AI companion laws are state laws.

Does the EU AI Act apply to AI companion apps?

Yes, through Article 50, applicable from August 2, 2026. Systems that interact with people must tell them they are dealing with AI unless that is obvious, and systems generating synthetic text, images, audio or video must mark the output as artificially generated in a machine-readable way. Breaching Article 50 carries fines up to EUR 15 million or 3 percent of turnover under Article 99. GDPR applies separately, which is how Italy fined Replika's maker EUR 5 million in April 2025.

Do UK users have to verify their age on AI companion apps?

Only on services in scope of the Online Safety Act. Since July 25, 2025 any service publishing pornographic content to UK users, including chatbot-generated content, must use highly effective age assurance, and Ofcom rejects self-declaration and card checks that do not confirm age. Character-sharing platforms are user-to-user services with full duties. A one-to-one chatbot that shares nothing is largely outside the Act per Ofcom's December 2025 explainer; the Crime and Policing Act 2026 lets ministers close that gap.

What is Adam's Law and when does it start?

Adam's Law is California SB 1119, chaptered September 10, 2026 as Chapter 190. It adds a child-safety regime on top of SB 243: operators must determine a user's age or apply child protections to everyone by default, including persistent memory off, one-hour sessions and two-hour daily caps, no simulated romantic interest, no relationship-framed purchase prompts, and child-safety audits every two years. Core duties are operative July 1, 2027; first audits are due by January 1, 2029.

Which AI companion apps have already changed because of these laws?

Character.AI is the clearest case: it removed open-ended chat for under-18s by November 25, 2025 and added in-house age assurance plus Persona ID checks. Replika was blocked in Italy in February 2023, fined in April 2025, and now states an 18+ minimum. On the apps I track, the visible changes are not-human banners at the start of chats and stricter age gates; the privacy scorecard flags policies still stating 13 or 16, the clause SB 243 makes expensive.

A
Adam Whitlock

Adam Whitlock spent six years testing mobile games for a living before turning the same habits on AI companion apps. He pays for every subscription he reviews, keeps a spreadsheet of what each one actually costs, and writes under a pen name. About the author

Sources (20)
  1. California Legislative Information: SB 243, Companion chatbots (chaptered October 13, 2025), Business and Professions Code sections 22601-22605
  2. Gunderson Dettmer: California SB 243, new compliance requirements for operators of AI companion chatbots
  3. California Legislative Information: SB 1119, Companion chatbots: children's safety (Adam's Law), chaptered September 10, 2026, Chapter 190
  4. New York State Senate: General Business Law section 1702, AI companion notifications (Article 47)
  5. New York State Senate: General Business Law section 1703, Enforcement (civil penalties up to $15,000 per day)
  6. Troutman Pepper Locke, January 8, 2026: Analyzing the new AI companion chatbot laws (New York and California)
  7. MultiState, June 26, 2026: State AI companion chatbot laws (twelve states)
  8. Privacy World (Squire Patton Boggs), September 16, 2026: US AI law 2026 midyear state update
  9. Texas Legislature Online: HB 149, Texas Responsible Artificial Intelligence Governance Act, enrolled text (effective January 1, 2026)
  10. Utah State Legislature: HB 452, Artificial Intelligence Amendments (mental health chatbots), enrolled copy, effective May 7, 2025
  11. Maine Legislature: LD 1727, An Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligence, Public Law 2025 chapter 294
  12. FTC press release, September 11, 2025: FTC Launches Inquiry into AI Chatbots Acting as Companions
  13. EU Artificial Intelligence Act, Article 50: Transparency obligations for providers and deployers of certain AI systems
  14. EU Artificial Intelligence Act, Article 99: Penalties
  15. artificialintelligenceact.eu: Implementation timeline (Article 50 application and marking deadlines)
  16. European Commission: AI Act regulatory framework (application timeline, AI Omnibus, code of practice on AI-generated content)
  17. European Data Protection Board: Italian SA fines company behind chatbot Replika (decision of April 10, 2025, EUR 5 million)
  18. Ofcom, December 22, 2025: AI chatbots and online regulation, what you need to know
  19. Winston Taylor, May 24, 2026: Chatbots and the UK Online Safety Act, to what extent are they in scope (Crime and Policing Act 2026 section 248)
  20. National Law Review: The Online Safety Act and age-appropriate access (July 25, 2025 age assurance deadline, penalties)

Price changes and new platforms, once a week.

No hype, no daily mail. Unsubscribe in one click.