The fastest-growing category of AI legislation in 2026 was not about hiring, or frontier models. It was about chatbots that hold a conversation like a companion. California’s SB 243 — the first U.S. companion-chatbot law, in force since January 1, 2026 — set the template, and roughly a dozen other states followed with rules of their own.
This is a briefing where a word matters enormously, so let us define it before we alarm anyone.
What a “companion chatbot” actually is
SB 243 targets companion chatbots: AI systems designed to provide sustained, human-like, relational or social interaction — the “AI friend,” “AI partner,” and character-companion apps. It is not aimed at an ordinary customer-service FAQ bot or a task assistant. If your chatbot answers order-status questions, it is probably outside SB 243’s specific definition. Anyone telling a general business that SB 243 governs their support widget is overreaching.
That said, the duties the law imposes are a preview of where consumer conversational-AI regulation is heading generally — which is exactly why an ordinary business should read them.
The core duties
- Tell people it’s AI. If a reasonable person could be misled into thinking they are talking to a human, the operator must give a clear and conspicuous notice that the chatbot is AI.
- Handle crisis responsibly. Operators must maintain a protocol to keep the chatbot from producing suicidal-ideation, suicide, or self-harm content, and to refer at-risk users to crisis resources such as a suicide hotline or crisis text line.
- Protect minors. For users known to be minors: disclose that responses are AI-generated, remind them to take a break at least every three hours of continuous use, and take reasonable measures to prevent sexually explicit visual content.
- Report, annually. Beginning July 1, 2027, operators must report annually to California’s Office of Suicide Prevention on the protocols they use to detect and respond to suicidal ideation.
And it has teeth: SB 243 creates a private right of action. A person injured by a violation can sue for injunctive relief and damages — the greater of actual damages or $1,000 per violation — plus attorney’s fees.
Why an ordinary business should still care
Strip “companion” away and look at the underlying expectations: tell people they’re talking to a machine, handle a user in crisis like a responsible adult would, and take special care with minors. Those are not exotic. They are becoming the baseline expectation for any consumer-facing conversational AI, and they rhyme with Utah’s disclosure rule and with the chatbot provisions cropping up in other states. Regulators, plaintiffs’ attorneys, and your own customers are converging on the same three questions.
If your business — or a vendor acting under your brand — runs any customer-facing chatbot, answer them honestly:
- Does it clearly disclose that it is AI?
- What happens when a user says something that signals a crisis?
- Have you accounted for minors reaching it?
What to do now
1. Classify your bots. Which of your conversational AI systems are genuinely “companion” (relational/social) versus transactional? The former may be directly in scope in California; the latter should still meet the emerging baseline. 2. Turn on disclosure everywhere. A clear “you’re chatting with an AI assistant” is cheap, and it is the single most common duty across every chatbot law. 3. Write a crisis protocol. Decide, in advance, what your bot does when a user expresses self-harm — and route to real resources. 4. Inventory, as always. You cannot apply any of this to a bot you have not counted, including vendor bots behind your brand.
An honest limitation
We want to be scrupulous about scope, because scope is where this topic gets oversold. SB 243’s specific obligations attach to companion chatbots as the statute defines them, not to every business chatbot, and the “roughly a dozen states” figure reflects a fast-moving 2026 legislative wave whose individual laws vary in scope, definitions, and effective dates — verify the specific state and bill before acting. What is durable is the direction: disclosure, crisis-handling, and minor protection are becoming table stakes for consumer conversational AI, and the cheapest time to meet that bar is before a plaintiff or a regulator sets it for you.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 14, 2026.
See how a Gap Assessment maps your exposure →Running a customer-facing chatbot?
Let’s pressure-test it in 30 minutes.
The free AI Risk Exposure call maps your conversational AI to the disclosure, crisis, and minor-safety expectations now forming across the states.
Book the call →