Article-by-article breakdown

California Chatbot Disclosure Requirements (SB 243)

California Senate Bill 243 - Companion Chatbot Disclosure Requirements

Article 1Scope and Definitions

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

This article defines the core terms that determine which AI systems and entities are subject to the regulation. A 'companion chatbot' is specifically an AI program designed to simulate human-like conversation and emotional interaction, aiming to create a social experience for users. This distinguishes it from simpler AI like customer service bots or limited-dialogue game characters, focusing on systems that foster ongoing emotional relationships.

An 'operator' is any entity that makes such a companion chatbot platform available to users in California. This broad definition ensures that both developers and providers are covered, regardless of where the AI was developed, as long as it's accessible within the state. The law also places special emphasis on 'minors,' defined as users known to be under 18, triggering heightened protective measures.

Key points

  • Defines 'companion chatbot' as AI simulating human-like emotional and social interaction.
  • Excludes basic AI like customer service bots or limited game characters.
  • Defines 'operator' as any entity making a companion chatbot available in California.
  • Highlights 'minors' (under 18) as a key protected group.

What you need to do

  1. 1.Assess if your AI system meets the 'companion chatbot' definition.
  2. 2.Determine if your entity qualifies as an 'operator' by making the service available in California.
  3. 3.Identify and implement mechanisms to distinguish between general users and minors for differentiated compliance.

Article 2General User Disclosure Requirements

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

This provision mandates transparency for all users interacting with companion chatbots. If there's a reasonable chance that a user could mistakenly believe they are communicating with a human, the operator must provide a clear and prominent notification. This notification must explicitly state that the interaction is with an artificially generated chatbot and not a human being.

The intent is to prevent deception and ensure users are fully aware of the nature of their interaction, especially given the human-like qualities companion chatbots are designed to emulate. The 'reasonable person' standard means operators must consider how an average user would perceive the interaction.

Key points

  • Mandatory disclosure if a user could reasonably mistake the chatbot for a human.
  • Disclosure must be clear, conspicuous, and state the AI nature.
  • Aims to prevent user deception regarding the interaction partner.

What you need to do

  1. 1.Implement prominent and persistent AI disclosure notices within your chatbot interface.
  2. 2.Review your chatbot's conversational style and UI/UX to ensure it doesn't mislead users.
  3. 3.Conduct user testing to confirm the clarity and conspicuousness of your disclosures.

Cross-jurisdiction equivalents

EUEU AI Act, Article 52The EU AI Act requires transparency for certain AI systems, such as those interacting with natural persons, to inform them that they are interacting with an AI system, unless obvious.

Article 3Minor-Specific Disclosure and Break Reminders

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

For users known to be minors, SB 243 imposes stricter disclosure requirements. Operators must explicitly inform minors that they are interacting with artificial intelligence. Beyond an initial disclosure, the law requires clear and conspicuous notifications to be provided at least every three hours during ongoing interactions, reminding minors to take a break and reiterating the chatbot's AI nature.

Additionally, all platforms must include a general suitability warning, advising that companion chatbots may not be appropriate for some minors. These measures are designed to protect minors from potential psychological harm, prevent excessive engagement, and ensure they maintain an awareness of the artificial nature of their companion.

Key points

  • Explicit AI disclosure required for users known to be minors.
  • Periodic reminders (at least every three hours) for minors to take a break and re-state AI nature.
  • Mandatory suitability warning on the platform that chatbots may not be appropriate for all minors.

What you need to do

  1. 1.Implement robust age verification or detection mechanisms for users.
  2. 2.Develop and integrate timed, recurring notifications for minors during interactions.
  3. 3.Add a clear and prominent suitability warning to your platform's onboarding or general information.

Cross-jurisdiction equivalents

UKAge Appropriate Design Code (Children's Code)The UK's Children's Code sets out 15 standards for online services likely to be accessed by children, including principles on transparency, detrimental use of data, and 'nudge' techniques, aiming to protect children's privacy and well-being.

Article 4Crisis Prevention Protocols and Referrals

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

This article mandates that operators establish and maintain a comprehensive protocol to prevent their companion chatbots from generating content that encourages or facilitates suicidal ideation, suicide, or self-harm. A critical component of this protocol is the requirement to provide notifications that refer at-risk users to crisis service providers, such as suicide hotlines or crisis text lines, whenever expressions of suicidal ideation or self-harm are detected.

Operators must also publish the details of this crisis prevention protocol on their website, ensuring transparency about their safety measures. The law emphasizes using evidence-based methods for measuring suicidal ideation, underscoring a commitment to effective and responsible harm prevention.

Key points

  • Operators must maintain a protocol to prevent suicidal ideation/self-harm content.
  • Protocol must include referrals to crisis service providers for at-risk users.
  • Details of the crisis prevention protocol must be published on the operator's website.
  • Requires use of evidence-based methods for detecting suicidal ideation.

What you need to do

  1. 1.Develop and implement a robust crisis detection and response system within your chatbot.
  2. 2.Integrate direct referral mechanisms to verified crisis hotlines and services.
  3. 3.Clearly document and publish your crisis prevention protocol on your company website.
  4. 4.Regularly review and update your protocol based on best practices and evidence-based research.

Cross-jurisdiction equivalents

EUEU AI Act, Article 9The EU AI Act requires high-risk AI systems to have a robust risk management system, which includes identifying and mitigating risks to health and safety, though not specifically focused on suicide prevention in chatbots.

Article 5Content Guardrails for Minors

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

To protect minors, this provision requires operators to implement reasonable measures to prevent their companion chatbots from generating or promoting sexually explicit content. Specifically, chatbots must not produce visual material depicting sexually explicit conduct, nor should they directly encourage minors to engage in such conduct.

This aims to create a safe online environment for younger users, shielding them from inappropriate material and harmful influences that could arise from interactions with AI systems designed to be emotionally engaging.

Key points

  • Prohibits chatbots from generating visual material of sexually explicit conduct.
  • Prohibits chatbots from directly encouraging minors to engage in sexually explicit conduct.
  • Focuses on protecting minors from inappropriate content.

What you need to do

  1. 1.Implement robust content moderation filters and safety mechanisms for chatbot outputs.
  2. 2.Train AI models to recognize and avoid generating sexually explicit content or prompts.
  3. 3.Regularly audit chatbot interactions and outputs to ensure compliance with these guardrails.

Cross-jurisdiction equivalents

UKOnline Safety Act 2023The UK's Online Safety Act imposes duties on online service providers to protect children from illegal and harmful content, including sexually explicit material, aligning with the goal of safeguarding minors online.

Article 6Preventing Harmful Engagement Patterns

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

This article addresses the potential for companion chatbots to foster unhealthy engagement patterns, particularly among minors. Operators are required to take reasonable steps to prevent their chatbots from providing 'unpredictable rewards' or otherwise encouraging increased engagement, usage, or response rates, especially when interacting with minors.

This provision aims to mitigate the risk of addiction or excessive reliance on companion chatbots, recognizing the psychological impact that emotionally engaging AI can have. It encourages the design of systems that promote healthy, balanced interaction rather than maximizing user time on the platform through manipulative techniques.

Key points

  • Prohibits chatbots from providing unpredictable rewards.
  • Requires measures to prevent encouragement of increased engagement or usage rates.
  • Specific focus on protecting minors from potentially addictive design elements.

What you need to do

  1. 1.Review your chatbot's design and interaction mechanics to identify and remove 'unpredictable reward' systems.
  2. 2.Avoid gamification or other features that might encourage excessive use, particularly for minors.
  3. 3.Design your chatbot interactions to promote healthy, balanced engagement rather than maximizing screen time.

Cross-jurisdiction equivalents

UKAge Appropriate Design Code (Principle 12)The UK's Children's Code includes a principle against using 'nudge techniques' to lead children to make poor privacy decisions or engage in excessive use, aligning with the goal of preventing harmful engagement patterns.

Article 7Annual Reporting to Office of Suicide Prevention

Applies from: 2027-07-01

Applies to

  • Operators of companion chatbot platforms

Plain English

Beginning July 1, 2027, operators of companion chatbot platforms are mandated to submit annual reports to the California Office of Suicide Prevention. These reports are a crucial mechanism for monitoring the effectiveness of safety protocols and the overall impact of companion chatbots on user mental health.

The reports must detail the number of times crisis service provider referral notifications were issued in the preceding calendar year. Operators must also outline the specific protocols they have established to detect, remove, and respond to instances of suicidal ideation by users, as well as describe protocols implemented to prohibit chatbot responses that encourage or facilitate suicidal ideation or actions. Importantly, these reports must not include any personal identifiers to protect user privacy. The Office of Suicide Prevention will then publish aggregated data from these reports.

Key points

  • Mandatory annual reporting to the California Office of Suicide Prevention.
  • Reports must include the number of crisis service referrals issued.
  • Details of protocols for detecting, responding to, and preventing suicidal ideation content.
  • Reports must be anonymized, containing no personal identifiers.

What you need to do

  1. 1.Establish robust data collection systems to track crisis service referrals accurately.
  2. 2.Document your crisis prevention and response protocols comprehensively.
  3. 3.Develop a process for generating and submitting anonymized annual reports by July 1, 2027.
  4. 4.Ensure strict adherence to privacy principles by removing all personal identifiers from reported data.

Article 8Private Right of Action and Penalties

Applies from: 2026-01-01

Applies to

  • Operators of companion chatbot platforms

Plain English

This article establishes a significant enforcement mechanism by granting individuals a private right of action. Any person who suffers an 'injury in fact' directly caused by an operator's failure to comply with SB 243's requirements can bring a civil action against that operator. This empowers users to seek legal recourse for harms sustained due to non-compliance.

Injured individuals may seek various forms of relief, including damages of at least $1,000 per violation, injunctive relief to stop further non-compliant behavior, and the recovery of attorney's fees. The inclusion of a minimum damage amount and the ability to recover legal costs is intended to make it more feasible for individuals to pursue claims, thereby placing a substantial burden of accountability on operators and encouraging proactive compliance.

Key points

  • Individuals have a private right of action for 'injury in fact' due to non-compliance.
  • Allows for civil actions against non-compliant operators.
  • Potential remedies include damages (minimum $1,000 per violation), injunctive relief, and attorney's fees.
  • Empowers users and increases operator accountability.

What you need to do

  1. 1.Prioritize comprehensive compliance to mitigate significant legal and financial risks.
  2. 2.Ensure all compliance measures are well-documented and auditable.
  3. 3.Be prepared for potential litigation from individuals claiming harm due to non-compliance.
  4. 4.Understand that the minimum damage amount can lead to substantial penalties for multiple violations.

Cross-jurisdiction equivalents

EUGDPR, Article 82The GDPR grants individuals the right to compensation for material or non-material damage suffered as a result of an infringement of the regulation, similar to a private right of action.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →