From One State Law to Thirteen in Under a Year
Regulatory waves in tech policy often take years to spread from a single pioneering state to a critical mass of others. Chatbot safety legislation didn’t. The Transparency Coalition’s 2026 mid-year legislative report documents that 14 chatbot safety measures have passed or been enacted across 13 states as of the report’s publication — Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island, South Carolina, Washington, and Wyoming — in the roughly ten months since California’s SB 243 became the first law of its kind, signed in September 2025.
The political spread is what makes this wave distinct from most tech regulation fights. Chatbot safety measures have passed in Republican-controlled legislatures like Georgia and Idaho and in Democratic strongholds like Washington and New York within the same legislative cycle — a bipartisan pattern rare enough in AI policy generally that it signals the underlying concern (protecting minors from AI companion products) has crossed the usual left-right divide that stalls most technology regulation.
What the Laws Actually Require
Despite the geographic and political spread, the substance of these 14 laws clusters around a consistent set of requirements. Disclosure sits at the center: chatbot operators must clearly notify users they are interacting with AI rather than a human. Minor-specific protections form a second cluster — restrictions on sexually explicit content generated for or accessible to minors, prohibitions on manipulative engagement tactics, and mandates for parental control tools. A third recurring requirement addresses crisis response directly: chatbot platforms must implement protocols to detect and respond to expressions of suicidal ideation or self-harm, typically by routing users to crisis resources rather than continuing the conversation unaddressed. A fourth theme targets product design itself — several laws specifically ban gamification features and reward systems built to maximize engagement when the user is a minor.
Two state laws illustrate how specific this legislation has become. Georgia’s SB 540 requires chatbot safety disclosure and child-protection measures, taking effect January 1, 2027. Washington’s HB 2225 goes further on a specific mechanic: it prohibits “manipulative engagement techniques,” explicitly naming simulated emotional support or romantic bonding directed at minor users, also effective January 1, 2027. Idaho’s SB 1297 takes the broadest approach among the group, addressing both AI misrepresentation generally and minor-specific safeguards, with a longer runway to July 1, 2027 compliance.
The Future of Privacy Forum’s analysis of the broader trend situates these state laws as extensions of California SB 243’s original template — the first law to specifically target AI companion chatbots as a distinct regulatory category separate from general AI or data-privacy rules, rather than folding chatbot-specific harms into broader technology legislation. That categorization choice by California, since replicated across 13 additional states, effectively created a new legislative subcategory that didn’t exist in state tech policy before September 2025: AI companion and chatbot safety as its own regulated product class, distinct from social media, data privacy, or general AI governance frameworks.
Why the Effective Dates Cluster Around Early 2027
The pattern of effective dates matters as much as the requirements themselves. With Georgia’s and Washington’s laws both landing on January 1, 2027 and Idaho’s following six months later, AI companion and chatbot product teams face a compressed compliance window rather than a staggered one — multiple state requirements activating within the same several-month period rather than spreading gradually across years. That clustering effectively forces a single national compliance sprint for any company operating chatbot products across state lines, since building state-specific product variants for 13 different jurisdictions is rarely commercially viable; most companies will build to the most restrictive common denominator across the laws and apply it nationally rather than maintain a patchwork of state-specific product behavior.
The bipartisan breadth combined with the compressed 2027 compliance timeline suggests this wave isn’t a temporary legislative moment that will fade — it’s establishing what’s likely to become the practical national baseline for AI companion and chatbot products, regardless of whether federal legislation ever catches up to codify a single standard. Companies waiting for federal clarity before building compliance infrastructure are, in practice, already behind: the state-level requirements are enforceable law with real effective dates, independent of anything Congress does or doesn’t pass. Legal analysis from Orrick tracking the 2026 wave confirms that state chatbot regulation has shifted from broad AI-governance frameworks toward targeted rules addressing specific use cases like child safety and professional services — a narrower, more surgical legislative approach than the sweeping AI acts several states attempted in earlier legislative sessions, and one that appears to be moving through statehouses considerably faster as a result.
Advertisement
What This Means for AI Product Teams Building Chatbots
1. Build disclosure and minor-protection features to the strictest state standard now, not per-state later
Given that at least 13 states already require AI disclosure and minor-specific safeguards with January-July 2027 effective dates, product teams should treat Washington’s explicit ban on simulated emotional/romantic bonding with minors and Georgia’s disclosure mandate as the practical design floor for any chatbot or AI companion product with any US user base, rather than building minimum-viable compliance state by state.
2. Implement crisis-response protocols before a law forces the issue, not after
Since multiple states now mandate self-harm and suicidal-ideation detection with crisis-resource referral, any consumer-facing conversational AI product should treat this as a near-term product requirement even in states without an enacted law yet — the direction of travel across 13 states in under a year makes it a near-certainty more states follow, and building the capability proactively avoids a rushed, high-stakes implementation under legal deadline pressure.
3. Audit engagement-maximizing design features against the emerging anti-gamification standard
With several of the 14 laws specifically targeting reward systems and gamification features aimed at minors, product and growth teams should audit existing engagement mechanics — streaks, variable reward notifications, relationship-building progression systems — against this standard now, since retrofitting a product’s core engagement loop under a compliance deadline is materially harder than designing it compliant from the outset.
The National Standard Nobody Voted On Nationally
What’s unfolding across these 13 states is a case study in how state-level legislation can functionally set national policy without a single federal law ever passing. No US Congress vote created this chatbot safety baseline — a rolling wave of state legislatures, spanning the full political spectrum, did it independently and arrived at strikingly similar requirements: disclosure, minor protections, crisis referral, anti-gamification. For AI companies building conversational products, the practical reality is that federal inaction doesn’t mean regulatory absence — it means the regulatory floor is being set state by state, and companies that wait for Washington DC to clarify the rules risk discovering that 13 state capitals already did the job for them, with enforcement dates arriving in early 2027 regardless of what Congress decides to do in the meantime.
Frequently Asked Questions
How many US states have passed chatbot safety laws in 2026?
According to the Transparency Coalition’s mid-year 2026 legislative report, 13 states — Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island, South Carolina, Washington, and Wyoming — enacted 14 separate chatbot safety measures, building on California’s SB 243, the first such law, signed in September 2025.
What do the new chatbot safety laws typically require?
Common requirements include mandatory AI-use disclosure, restrictions on sexually explicit content involving minors, bans on manipulative engagement tactics, parental control tools, crisis-response protocols for self-harm or suicidal ideation, and restrictions on gamification and reward systems that target minor users.
When do these chatbot safety laws take effect?
Effective dates cluster around early 2027: Georgia’s SB 540 and Washington’s HB 2225 both take effect January 1, 2027, while Idaho’s SB 1297 takes effect July 1, 2027. The clustering creates a compressed compliance window for AI companies operating across multiple states.
Sources & Further Reading
- Watershed Year for Chatbot Safety: 14 New State Laws Passed So Far in 2026 — Transparency Coalition
- State AI Chatbot Regulation: 2026 Laws & Trends — MultiState AI
- Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond — Future of Privacy Forum
- 2026 State Chatbot Laws: Key Provisions and Regulatory Trends — Orrick














