California SB 243 Explained: What the New AI Companion Chatbot Law Requires
The first US law written specifically for AI companion chatbots took effect in January 2026. Its private right of action changes who can enforce it — and how often.
What SB 243 is
California Senate Bill 243 is the first law in the United States specifically targeting AI companion chatbots — products designed to simulate a sustained, personal relationship with a user, as distinct from general-purpose AI assistants. It took effect on January 1, 2026, and applies to companies operating companion chatbot products with users in California, regardless of where the company is headquartered.
The bill was introduced against the backdrop of the litigation and public scrutiny covered in our Character.AI postmortem — lawsuits alleging companion AI products caused serious harm to minors, and broader concern that sustained emotional engagement with an AI system carries risks existing consumer-protection law didn't clearly address.
Core requirements
- AI-identity disclosure. Users must be clearly told they are interacting with an AI system, not a human, at the start of an interaction and periodically thereafter in extended sessions.
- Break reminders for minors. Platforms must show a break reminder to known or suspected minor users roughly every three hours of continuous use.
- Content restrictions for minors. Sexual content and other age-inappropriate content must be blocked when the user is identified or reasonably believed to be underage.
- Suicide and self-harm risk protocols. Platforms must implement a defined response protocol when a user's messages indicate risk, including surfacing crisis resources.
These are narrower and more specific than general platform-safety guidance. They're written as concrete, auditable product behaviors rather than broad principles — which is part of why compliance has been treated as a near-term engineering task rather than a policy statement.
The private right of action
The enforcement mechanism is what makes SB 243 unusually consequential. The law includes a private right of action: individual users, not just the California Attorney General, can sue a noncompliant platform directly. Statutory damages start at a minimum of $1,000 per violation, plus attorney's fees for a prevailing plaintiff.
This matters structurally. It removes the enforcement bottleneck that limits many consumer-protection statutes — where practical enforcement depends on a state regulator's limited resources and priorities — and instead makes every user a potential enforcer. For a platform with a large user base, even a modest per-user violation rate translates into meaningful exposure.
The federal angle
SB 243 is a state law, but it arrived alongside growing federal attention to the same category. In September 2025, the FTC opened a formal Section 6(b) inquiry into seven companies — Alphabet, Character Technologies, Meta, OpenAI, Snap, Instagram, and xAI — seeking data on their AI chatbots' safety practices, monetization approach, and impact on minors. That inquiry followed weeks of reporting on Meta's own internal chatbot policies specifically — see our breakdown of the Meta case for what that reporting found and how it escalated into a Senate investigation, and our case studies on Snap's My AI lawsuits, the OpenAI wrongful-death suit, and Google's Gemini lawsuit and child-safety fight for how three of the other named companies are facing similar scrutiny. The following month, a group of U.S. senators including Alex Padilla and Adam Schiff separately sent a letter to the FTC requesting further investigation and clearer federal disclosure requirements.
No federal companion-chatbot statute has passed as of this writing. But the direction of travel — state law first, then a formal federal regulatory inquiry, then continued legislative pressure — mirrors what happened in data privacy, and operators should treat SB 243 as a leading indicator rather than an isolated state requirement.
The cross-state trend
California was first, not alone. New York's AI Companion Models Law (N.Y. Gen. Bus. Law § 1700 et seq.) took effect November 5, 2025, requiring AI-identity disclosure and self-harm detection protocols similar to SB 243's. New York went further in June 2026, passing a second law (S 9051) that outright prohibits offering companion chatbots to minors under 18, backed by state attorney general fines of up to $25,000 per violation — a materially stricter approach than SB 243's disclosure-and-safeguards model. Multiple other states have introduced comparable bills — see our state-by-state regulation tracker for the full current picture. For any company with a national user base, this creates a practical reality: designing to the strictest currently-enacted standard is usually cheaper than maintaining state-by-state variants — the same pattern the industry settled into after CCPA and GDPR, and the gap between California's and New York's approaches suggests that strictest standard is still rising.
Compliance checklist for operators
- Implement AI-identity disclosure at session start and at recurring intervals in long sessions.
- Build age detection and a break-reminder system for minor or suspected-minor accounts, triggering around the three-hour mark.
- Implement content filtering keyed to age status, blocking sexual and otherwise age-inappropriate content for minors.
- Define and test a self-harm risk-response protocol — what the system says, what resources it surfaces, how escalation works.
- Document your compliance measures. Given the private right of action, an auditable record of what safeguards exist and when they shipped is meaningful risk reduction on its own.
- Monitor New York and other state legislation before assuming a single national configuration is sufficient.
Why this matters beyond California
Character.AI's own safety-driven product changes — age verification, content limits, usage caps — preceded SB 243's effective date but anticipated exactly this kind of requirement. Its experience shows both sides of the trade-off: compliance is achievable, but it carries a real cost in user retention and, ultimately, valuation. Meeting SB 243's requirements is now a baseline cost of operating in this category, not an optional risk-management choice.
Open the switching cost calculator
Legislation and enforcement in this area are moving quickly (last re-checked August 2026). Verify current statutory language before relying on this summary. This article is analysis, not legal advice.