California SB 243 Explained: What the New AI Companion Chatbot Law Requires
The first US law written specifically for AI companion chatbots took effect in January 2026. Its private right of action changes who can enforce it — and how often.
What SB 243 is
California Senate Bill 243 is the first law in the United States specifically targeting AI companion chatbots — products designed to simulate a sustained, personal relationship with a user, as distinct from general-purpose AI assistants. It took effect on January 1, 2026, and applies to companies operating companion chatbot products with users in California, regardless of where the company is headquartered.
The bill was introduced against the backdrop of the litigation and public scrutiny covered in our Character.AI postmortem — lawsuits alleging companion AI products caused serious harm to minors, and broader concern that sustained emotional engagement with an AI system carries risks existing consumer-protection law didn't clearly address.
Core requirements
- AI-identity disclosure. Users must be clearly told they are interacting with an AI system, not a human, at the start of an interaction and periodically thereafter in extended sessions.
- Break reminders for minors. Platforms must show a break reminder to known or suspected minor users roughly every three hours of continuous use.
- Content restrictions for minors. Sexual content and other age-inappropriate content must be blocked when the user is identified or reasonably believed to be underage.
- Suicide and self-harm risk protocols. Platforms must implement a defined response protocol when a user's messages indicate risk, including surfacing crisis resources.
These are narrower and more specific than general platform-safety guidance. They're written as concrete, auditable product behaviors rather than broad principles — which is part of why compliance has been treated as a near-term engineering task rather than a policy statement.
The private right of action
The enforcement mechanism is what makes SB 243 unusually consequential. The law includes a private right of action: individual users, not just the California Attorney General, can sue a noncompliant platform directly. Statutory damages start at a minimum of $1,000 per violation, plus attorney's fees for a prevailing plaintiff.
This matters structurally. It removes the enforcement bottleneck that limits many consumer-protection statutes — where practical enforcement depends on a state regulator's limited resources and priorities — and instead makes every user a potential enforcer. For a platform with a large user base, even a modest per-user violation rate translates into meaningful exposure.
The federal angle
SB 243 is a state law, but it arrived alongside growing federal attention to the same category. In October 2025, a group of U.S. senators including Alex Padilla and Adam Schiff sent a letter to the Federal Trade Commission requesting an investigation into AI companion chatbot companies over child-safety practices, and calling for clearer disclosure requirements at the federal level. The FTC has separately signaled interest in consumer education resources related to AI chatbot risks.
No federal companion-chatbot statute has passed as of this writing. But the direction of travel — state law first, federal regulatory and legislative attention following — mirrors what happened in data privacy, and operators should treat SB 243 as a leading indicator rather than an isolated state requirement.
The cross-state trend
California was first, not alone. New York has passed comparable legislation addressing AI companion chatbot safety obligations, and multiple other states have introduced similar bills. For any company with a national user base, this creates a practical reality: designing to the strictest currently-enacted standard is usually cheaper than maintaining state-by-state variants — the same pattern the industry settled into after CCPA and GDPR.
Compliance checklist for operators
- Implement AI-identity disclosure at session start and at recurring intervals in long sessions.
- Build age detection and a break-reminder system for minor or suspected-minor accounts, triggering around the three-hour mark.
- Implement content filtering keyed to age status, blocking sexual and otherwise age-inappropriate content for minors.
- Define and test a self-harm risk-response protocol — what the system says, what resources it surfaces, how escalation works.
- Document your compliance measures. Given the private right of action, an auditable record of what safeguards exist and when they shipped is meaningful risk reduction on its own.
- Monitor New York and other state legislation before assuming a single national configuration is sufficient.
Why this matters beyond California
Character.AI's own safety-driven product changes — age verification, content limits, usage caps — preceded SB 243's effective date but anticipated exactly this kind of requirement. Its experience shows both sides of the trade-off: compliance is achievable, but it carries a real cost in user retention and, ultimately, valuation. Meeting SB 243's requirements is now a baseline cost of operating in this category, not an optional risk-management choice.
Open the switching cost calculator
Legislation and enforcement in this area are moving quickly. Verify current statutory language before relying on this summary. This article is analysis, not legal advice.