Legislation addressing the risks posed by "companion chatbots" has now been adopted in twelve states. Three jurisdictions—New York, California, and Hawaii—have already implemented their rules, while Colorado, Connecticut, Georgia, Iowa, Idaho, Nebraska, Oregon, Rhode Island, and Washington will enforce comparable laws beginning in 2027.
Despite variations in terminology and specific language, these statutes converge around shared regulatory priorities: requiring clear disclosure of AI interactions, establishing stronger safeguards when minors are involved, mandating crisis-response systems, and preventing false claims about professional qualifications. Yet the laws diverge meaningfully in their scope and the precise duties imposed on bot operators.
Scope of coverage
Each statute targets AI systems capable of sustained conversational engagement with users. Most restrict their reach to bots displaying human-like characteristics and maintaining relationships over time. Colorado, Connecticut, Idaho, Iowa, and Nebraska employ broader language capturing any bot that "simulates human conversation and interaction" via text, audio, or video. All jurisdictions except Hawaii carve out exceptions for business-oriented chatbots and narrow applications such as video game features.
Common principles and key differences
Analysis of the twelve statutes identifies four overarching regulatory principles that legislatures are effectively mandating for chatbot operators:
1. Transparency and disclosure requirements
All twelve laws obligate providers to inform users clearly and prominently that they are interacting with an AI system, not a human. The specifics differ across states: some demand disclosure at the start of conversation, others require ongoing or repeated notices during longer exchanges. Several impose stricter rules when the user is a minor. Washington's statute goes furthest by forbidding chatbots from claiming to be human to any user, whereas other states limit this prohibition to minor users only.
2. Heightened protections for minors
Except for New York and Rhode Island, the companion bot statutes establish stricter requirements when users are minors. Though details vary, these generally demand "reasonable measures" to address:
- Filtering sexually explicit material
- Blocking engagement-maximizing tactics like points or reward systems
- Preventing emotional manipulation and reliance on the bot rather than real-world support
- Offering parental tools to control privacy settings and usage limits
Most laws apply these safeguards when a provider knows or reasonably suspects a user is underage. Colorado and Georgia go further, requiring operators to employ "commercially reasonable" methods to determine user age—though Georgia narrows this obligation to situations where sexually explicit content risks are proportionate. Connecticut takes a distinct path, forbidding bot offerings to minors if it is "reasonably foreseeable" the bot "is capable of" specified harmful behaviors, a list broader than other state laws.
3. Crisis detection and mental health safeguards
All twelve statutes require operators to establish systems detecting expressions of suicidal thoughts or self-injury and directing users to crisis and mental health support. Some mandate publication of these protocols on company websites. Unlike other provisions, these protocols often function as a prerequisite for operating in the state. Several laws expand coverage to additional harms including severe emotional crises, violence toward others, and eating disorders.
Colorado, Georgia, and Oregon additionally require escalation procedures for users showing repeated or severe crisis signals. Oregon specifies that providers must apply "clinical best practices and expertise" to determine how the AI delivers "additional intervention" for users who continue expressing suicidal or self-harm thoughts after receiving crisis resources. Hawaii alone references "evidence-based methods" for measuring suicidal ideation.
4. Restrictions on mental health and professional representations
Multiple companion bot laws bar providers from enabling their systems to claim they are mental health professionals or capable of delivering professional mental or behavioral health services. Comparable restrictions appear in at least eight additional state statutes targeting bots specifically designed for or marketed as offering mental health support. Nevada, Utah, and Illinois enacted the first three such laws. Delaware, Maine, Tennessee, Rhode Island, and Vermont have since followed suit.
Connecticut includes a distinctive provision prohibiting bot offerings to minors if it is "reasonably foreseeable" the bot could "offer mental health services," subject to narrow exceptions. Colorado extends this concept by restricting claims about other licensed professions—healthcare providers, dietitians, lawyers—reflecting mounting concern that users may place excessive confidence in AI systems appearing to deliver expert guidance.
Colorado's proposed rules may shape enforcement
On August 11, Colorado's Attorney General unveiled proposed rules interpreting parts of the state's companion bot law, officially titled the Chatbot Safety Act. Though rulemaking is not mandated, the Attorney General stated that rules would clarify what compliance entails. The proposals notably address the statute's language requiring providers to adopt "technically feasible measures" and "reasonable measures" to block certain outputs directed at minors.
The law requires covered products to employ (a) "technically feasible measures" against specified explicit sexual content and (b) "reasonable measures" against "formulating, structuring, or optimizing a response that simulates emotional dependence or isolation from real-world supports." Sections 11.3 and 11.4 of the proposed rules outline factors the Attorney General would weigh in assessing compliance, including the availability and effectiveness of safeguards and the extent of the provider's testing, monitoring, remediation, and documentation efforts.
Many of these factors align with established corporate AI governance practices, encompassing testing, monitoring, and evaluation of AI products to confirm they function as designed and avoid causing harm. The rules underscore the importance of documenting such work and responding appropriately to adverse findings.
Because other companion bot states have not issued comparable guidance, Colorado's final rules could become a benchmark for regulators and courts interpreting similar language elsewhere. Public comment on the proposed rules—which also address the state's new law on automated decision-making systems—closes October 26.
Looking ahead
Companion bot regulation is moving swiftly. Beyond new legislation, state attorneys general and private litigants are bringing cases alleging chatbot use has led to self-harm, violence, and emotional reliance. Congress is weighing multiple AI and chatbot proposals, while industry bodies and nonprofits—including the Better Business Bureau, the Partnership on AI, and Common Sense Media—are drafting voluntary standards to work alongside legislative frameworks.
The landscape will continue to shift, with additional laws, litigation, and regulatory activity anticipated.
Source: Tech Policy Press



