60 Bills in 60 Days: State AI Companion Proposals
60 Bills in 60 Days: State AI Companion Proposals Scott Babwah Brennen, Anna Vinals Musquera, and Afnan Abbassi. In 2025, two states, California and New York, enacted laws regulating companion chatbots. In the first two months of 2026, nearly 30 states have introduced almost 60 bills proposing to regulate companion chatbots. It is clear that regulating companion chatbots has quickly become one of the highest priorities for state lawmakers. But what exactly are they proposing? What trends are emerging across the dozens of introduced bills? In the table below, we map out some of the most important provisions across the dozens of introduced state bills this year. The table offers a snapshot of where things stand two months into the 2026 state sessions. At a high level, AI companion proposals include at least one of the following three provisions: Ban AI companions. While several bills would ban AI companions for all users, far more would prohibit minors from accessing companions. Set safeguards on the use of chatbots. Some safeguards apply to minors; others to everyone. Table 1 details many of these key provisions. Impose restrictions or requirements to protect consumer privacy. Defining Companions While each of the bills included in the table address companions, there is surprising variation in how legislators define the term. We observed four major categories of definitions. Importantly, these are not mutually exclusive, and elements of these four dimensions appear across definitions. Social needs: First, following California’s law enacted last year, at least 8 bills this year define companions as AI systems intended to “meet a user’s social needs” in particular by doing three things: Providing “Adaptive, human-like responses to user inputs” Exhibit anthropomorphic features. Sustaining a relationship across multiple interactions–that is having a memory. Social Relationships: Second, a handful of bills define companions as systems meant to simulate, build, or sustain social relationships. Some of these follow the definition used in New York’s law enacted in 2025, where a companion is “designed to simulate a sustained human or human-like relationship with a user” by: Remembering interactions/information across sessions Asking unprompted “emotion-based questions.” Sustain “ongoing dialogue” about “matters personal to the user” Other proposals, not based on New York’s law, define “social AI companion” as AI models “specifically designed, marketed, or optimized to form ongoing social or emotional bonds with users.” Social Conversation or interaction. Rather than focus on social needs or social relationships, a handful of bills define companions as models that facilitate or “simulate human conversation and interaction.” Here, the focus is less on sustaining relationships, and more on immediate emotionally resonant dialogue or communication. Social Mimicry. Finally, several bills include defining companions through their capacity to “mimic” humans. Some proposals include this directly in definitions of companions, such as an Oregon bill that defines companions as models that “mimic written or spoken natural language or social interaction that is adaptive, anthropomorphic and capable of meeting some users’ social needs.” Other bills prohibit features through which a companion mimics humans, either in appearance, voice, or mannerisms, personality, language, emotions or desires. Provisions The Table below maps out many of the central provisions across companion bills. But not all provisions are equal: several are likely to be far more consequential if implemented. Enforcement How proposed regulations are enforced has a massive impact both on compliance rates and compliance costs. Over the last several years, most state privacy, child online safety, and AI laws leave enforcement to the state Attorney General. Almost half of the companion bills in 2026 include a private right of action, permitting consumers to sue companies for violations. For example, last year’s California’s SB 243 creates a private right of action that allows injured individuals to seek damages of at least $1,000 along with injunctive relief and attorneys’ fees. PRAs compound the regulatory risk for AI companies: not only can they result in very high penalties, but can also require significant effort to respond to a large number of legal actions. Furthermore, several proposed bills establish criminal penalties for certain violations, for example, Tennessee’s SB 1493 would criminalize training AI companions that encourage suicide or form emotional bonds, and authorizes damages up to $150 000- something that we have not yet seen widely in state tech regulation. Age Verification Many of the proposals we analyzed establish requirements only for minors. But there are important differences when, or how laws require states to verify the ages of (all) users. About a quarter (26%) of laws explicitly state that companion deployers must verify the ages of all users. While the Supreme Court recently blessed age verification for adult content websites, they have also expressed skepticism over age verification for social media, following precedent that goes back more than 20 years. Other proposals establish a certain knowledge standard of when deployers have to enact safeguards for minors. Some use the “actual knowledge” standard that has been in place for COPPA compliance for decades, and that likely does not mean deployers have to proactively verify the ages of all users. Others use other knowledge standards, including “reasonable certainty” or “reason to believe” or “reasonably should have known.” At this point, it is unclear if these knowledge standards require proactive age verification. Audits and Reporting Many proposals would require deployers to audit their systems for risks before deployment, complete regular assessments after deployment, or report certain incidents to the government. Pre-deployment risk assessments – especially when combined with requirements to mitigate identified risks – have been at the center of debate in other areas of tech. Proponents suggest these measures are important to mitigating risks; opponents stress the high level of uncertainty and compliance burden to these audits. Data Privacy Finally, about a quarter of bills include data privacy protections. Most commonly, they include broad data minimization standards. These limit the ways that deployers can use the data they collect for other purposes. Data minimization has become a major focus in both consumer privacy and child online safety legislation more broadly. At the
Policymakers’ Guide to Developing Age Assurance Legislation
Policymakers’ Guide to Developing Age Assurance Legislation. By: Scott Babwah Brennen, Lama Mohammed, and Afnan Abbassi After years of debating if and how we should verify the ages of users to restrict minors from accessing harmful digital content, it is happening in the U.S. In the last several years, dozens of U.S. states have enacted laws requiring adult content websites, social media platforms, and app stores to verify users’ age. And while we should continue to interrogate the value of requiring age assurance, it is essential that we now also consider how to enact these policies in ways that best protect user privacy, security, and speech rights. There is no perfect way to implement age assurance; each approach will involve significant trade-offs. For example, while requiring users to submit government IDs may make systems more accurate, doing so raises the risk of both privacy violations and unjust exclusion. It is essential that lawmakers understand the trade-offs of each option to balance the choices they must make when drafting age assurance legislation. Below, we offer a guide for state lawmakers considering new age assurance requirements. We map out six key decision points that lawmakers will confront in crafting age assurance legislation, elucidating both the set of choices and the trade-offs inherent in each. We draw heavily on what states have already done, or at least considered, to map out real options for state lawmakers. Decision Point 1: What is age assurance meant to accomplish? Lawmakers establish age assurance requirements to protect minors. There are several distinct ways lawmakers generally pursue this. Restricting minors’ access to harmful content or features. Trade-offs There is broad public support for limiting minors’ access to harmful or inappropriate content or features. However, the courts have long held that minors do have limited First Amendment rights. In that there is no single understanding of what constitutes “harmful” or “inappropriate,” overly broad definitions may restrict important or beneficial content. Information about sexual health, LGBTQ+ content, or sexually explicit art or literature could be limited by overbroad efforts to limit “inappropriate” sexual content. Similarly, efforts to protect children from “harmful” social media features or platforms likely limit their ability to express themselves. Once they turn 18, minors will gain full access to all legal content. Restrictions on access to social media or AI platforms may leave minors unprepared to use them safely and responsibly. Simultaneously, it is impossible to restrict minors’ access to content without also imposing some burden on adults. Until Paxton v. FSC, the courts had determined that online age verification imposes a significant and unconstitutional burden on adults’ access to legal content. Finally, broad restrictions on minors’ access to content restrict parents’ control over what their children access online. Rather than leaving the decision to parents or guardians about what content is appropriate for their children, these approaches relocate that decision making authority to the government. Example: Wyoming HB 43 Requiring parental consent for minors to access apps or content. Once determined that an account belongs to a minor, some laws require that the account be associated with a parent or guardian. Trade-offs This approach grants parents control over what content their children access. Yet, requiring parental consent poses significant functional challenges. Consent requirements may fail if parents are not actively involved in their children’s lives. The burden of repeated consent requirements, such as approving account creations or certain followers, may prove untenable for parents who choose to bypass the system. Example: Nebraska LB 383 Restricting access to certain features or setting defaults. Rather than limit access to entire platforms, some lawmakers are considering laws that would require platforms to restrict only certain content or features for minors, or to set default settings for minors. Trade-offs This approach preserves minors’ access to apps while reducing access to the most concerning content or features. It permits apps to target controls to different age groups and has a higher chance of surviving First Amendment scrutiny as narrowly tailored. However, implementing this poses significant technical challenges. Smaller companies may struggle to accurately age-gate specific features or content. It also poses significant privacy risks. Apps must maintain age data or regularly reassess user ages. This may mean holding on to sensitive data, rerunning age assurance multiple times. Example: Nebraska LB 504 Decision Point 2: Who will assess ages? Whatever the reason for age assurance, legislators must verify which party should be responsible for verifying a user’s age; these include: The user Over the past several decades, self-declaration, in which the user attests that they are over (or under) an age cut-off, has been the most common method of age assurance. Trade-offs Self-declaration protects user privacy by preventing apps from collecting sensitive or personal data. In contrast to other approaches, it is both easy to implement and presents little friction for users, most of whom have experience with these systems. Example: California AB 1043 First-party service (which grants access) Trade-offs Targeted applicability. Only apps that pose specific risks to children are required to implement age assurance measures, thereby limiting restrictions on access to legal adult speech. Rather than granting a single company (such as an app store) the ability to control access to thousands of apps, requiring each app that gives access to content to implement age assurance, decentralizes decision making across the entire ecosystem. On the other hand, every app that conducts its own age assurance creates significant friction for users. User experience suffers when users must repeatedly undergo age assurance processes. This also likely imposes non-trivial compliance costs—especially for start-ups or smaller companies, which may give larger, more established companies a competitive advantage. Similarly, first-party assurance poses significant privacy risks, as every covered app must collect users’ personal data, or hire a commercial firm to do so. This vastly increases the number of companies that must collect, store, and process personal data. Finally, distributing compliance across the entire ecosystem may lead to reduced oversight and lower compliance rates. Few state Attorney General offices will have sufficient resources to