You might already be a "companion chatbot" under the law — and not know it
California's SB 243 took effect this year. The definition is broader than the word "companion" sounds, and most of what it asks for is stuff a decent builder would want to ship anyway.
If you're building anything where a person talks to your AI about their life — a journaling tool, a coaching app, a "supportive" assistant, a character — there's a law worth reading this month, and it's probably not the one you think. Not the EU AI Act. A California statute called SB 243. It took effect January 1st, and I'd bet most makers in this space haven't checked whether they're inside its fence. The reason to care isn't that the penalty is scary (though it's real). It's that the law quietly wrote down a definition of "companion chatbot," and the definition is broad enough that a lot of products land inside it by accident.
Here's the definition, roughly: an AI that gives adaptive, human-like responses, is capable of meeting a user's social needs, has some anthropomorphic feel to it, and can sustain a relationship across multiple sessions. Read that again as a builder, not a lawyer. "Human-like responses" is every LLM. "Sustains a relationship across sessions" is any product with memory. "Meets social needs" is the part people wave away — "we're a productivity tool, not a companion" — but if your users keep coming back to talk and feel a little better after, the label on your landing page won't be what decides it. There are carveouts (pure customer-service bots, game NPCs that can't discuss mental health, plain voice assistants), but the middle is fuzzy on purpose, and fuzzy-on-purpose is exactly where indie products live.
If you're in scope, here's what SB 243 actually requires, and I want to make the case that none of it is unreasonable. One: disclose that it's AI when a reasonable person might think they're talking to a human — clear and conspicuous, not buried in a terms-of-service page. Two: have a real protocol for self-harm and suicidal ideation — don't generate that content, route people to a crisis line, publish how you handle it, and file an annual number with California's Office of Suicide Prevention. Three: if you know a user is a minor, tell them it's AI, nudge them to take a break every three hours, and keep it away from sexual content. And backing all of it, a private right of action — a harmed user can sue for at least $1,000 per violation plus attorney's fees. That last part is why this isn't theater. You don't need a regulator to notice you; a plaintiff will do.
I build Murror, which is squarely a companion-adjacent product — an AI for understanding your own emotions — so I'm not writing this from the cheap seats. Here's the opinion I'll defend: treat this as a design spec, not a compliance tax. Almost every requirement is something you'd want to do anyway if you actually cared about the person on the other end. The "you're talking to a machine" disclosure isn't a disclaimer, it's honesty, and honesty is the whole product in this category. The break reminder for a minor isn't friction the law imposed on you; it's the same anti-over-engagement instinct I've written about here before — the fact that your most engaged user and your healthiest user are often not the same person. And the crisis protocol is the one thing you cannot afford to improvise at 2am when it's real.
Two places I'd be careful. First, the self-harm detection requirement quietly pushes you toward reading and retaining sensitive messages, which can collide head-on with the privacy promise that made people trust you in the first place. You have to design that tension deliberately, not stumble into logging everything "for safety." Second, don't file this under "California problem." New York already has its own version, Utah and Maine passed chatbot laws, there's a federal bill (the GUARD Act) that would go further for minors, and the FTC opened an inquiry into companion chatbots last fall. Analysts are calling 2026 "the year of the chatbots" for a reason. If your product talks to people about their inner lives, the rules are coming to you; the only choice is whether they find you already doing the decent version or scrambling to bolt it on.
The uncomfortable-in-a-good-way truth is that a lot of what earns trust and a lot of what the law now requires are the same list. That's rare in regulation. I'd take the gift.


Replies