California's companion chatbot law has no small-dev exemption

Three states passed laws this year about AI that acts like it cares. If your product does that on purpose - not as a joke, as the actual feature - you're not adjacent to this. You're the definition.

I build an app that helps people process their emotions with an AI that remembers what they told it last time. When I went looking for whether that puts Murror inside any of the new AI-companion laws, the honest answer was: probably, and I wouldn't have guessed that a year ago.

Three states have live statutes now, not proposals. California's SB 243 was signed October 13, 2025, and its operator requirements - disclosure, safety protocols, the parts that bite - took effect January 1, 2026. New York's companion-AI law has been in effect since November 5, 2025. Tennessee's SB 1580 took effect July 1, 2026, ten weeks ago. None of these are "coming eventually." They're already running.

The part that surprised me is the definition, because I'd mentally filed "companion chatbot" under Replika-style romantic bots, and none of these statutes say that. California's text defines a companion chatbot as an AI system with a natural language interface that gives "adaptive, human-like responses to user inputs" and meets a user's social needs, "including by exhibiting anthropomorphic features and being able to sustain a relationship across multiple interactions." There's no romance requirement in there. There's no requirement that you call it a companion. Remembering someone and responding like you understand them is the whole test. The law does carve out customer-service bots, video game NPCs, and smart speakers by function - but a journaling app, a reflection app, an emotional-support app that talks back and remembers is not on that exclusion list. And there's no small-business exemption. The obligation attaches to whoever makes the platform available to a user, full stop.

If you're in scope, California asks for three concrete things, not a vague duty of care. Disclose that the user is talking to AI whenever a reasonable person could mistake it for a human, and for known minors, repeat that disclosure at least every three hours during a session. Maintain protocols for detecting suicidal ideation or self-harm content and referring users to crisis services, and publish those protocols where users can find them. Starting July 2027, report crisis-referral activity to the state's Office of Suicide Prevention, stripped of anything identifying. New York's version is narrower on substance but sharper on teeth: the same disclosure-plus-crisis-referral shape, enforced by the Attorney General for up to $15,000 per violation per day, funding a suicide-prevention fund. Tennessee's law is narrower still and worth reading precisely, because it's easy to over-read: it doesn't regulate companion behavior at all, it bans representing that your AI is or can act as a licensed mental health professional - psychiatrist, psychologist, therapist, social worker. If your marketing has ever used the word "therapy" loosely, that's the one to reread today, and it carries its own private right of action at $5,000 a violation under the state's consumer protection statute.

The gap that actually matters for a small team isn't any one requirement - disclosure banners and a self-harm keyword list are a weekend of work. It's that California and New York both hand enforcement to someone other than a regulator who has to prioritize. California's is a private right of action: any user who claims harm can sue for $1,000 minimum plus attorneys' fees, no state agency has to pick up the case first. That changes the risk math from "will the AG notice us" to "will one upset user's lawyer notice us," which is a much lower bar and the reason this is worth thirty minutes now instead of after the first letter arrives.

What I did this week, and what I'd do in any product where the AI is supposed to feel like it's listening: reread my own onboarding and marketing copy for anything that reads as a professional claim rather than a companion claim. Write down, in one place, what the product actually does when someone's input looks like a crisis - not what I assumed it does. Add the disclosure and the three-hour reminder even though Murror's users skew adult, because "a reasonable person could mistake it" is about the interaction, not the age gate. Publish the safety protocol somewhere a user can actually find it, not just in a privacy policy nobody opens.

None of this required a lawyer to identify. It required treating "companion chatbot" as a description of what the product does, not a genre it has to advertise itself as.

17 views

Add a comment

Replies

Be the first to comment