Georgia AI Chatbot Safety Act

Georgia Conversational Artificial Intelligence Safety Act

United States • Georgia

RAI-US-GA-SB54000-2026

SB 540

Awaiting Entry(Awaiting Entry)
ActTransparency and DisclosureSafety, Testing, and EvaluationFundamental Rights
Export PDF

Georgia's SB 540 mandates AI chatbot transparency, child safety protections, and crisis response protocols to ensure safe and ethical AI deployment.

Overview

The Georgia Conversational Artificial Intelligence Safety Act, officially designated as Senate Bill 540 (SB 540), represents a landmark piece of legislation aimed at establishing a robust framework for the safe and ethical deployment of conversational artificial intelligence services within the state. Enacted on May 11, 2026, with an effective date of July 1, 2027, this Act amends Chapter 5 of Title 39 of the Official Code of Georgia Annotated, specifically focusing on online internet safety. The legislation seeks to balance technological innovation with critical protections, particularly for minors, by imposing clear disclosure requirements, implementing child safety guardrails, and mandating crisis response protocols.

The comprehensive nature of SB 540 places Georgia at the forefront of state-level AI regulation, aligning with a growing national trend to address the societal implications of AI chatbots. Key provisions include mandatory disclosures that users are interacting with AI, not a human; heightened protections for minors concerning emotionally manipulative content, sexually explicit material, and impersonation; and requirements for user privacy and control tools. Furthermore, the Act mandates the establishment of crisis-response protocols for severe harm, including suicidal ideation and self-harm, underscoring a proactive approach to potential risks associated with advanced AI interactions.

Definitions

The Georgia Conversational Artificial Intelligence Safety Act introduces several crucial definitions to delineate its scope and application. A "conversational AI service" is defined as an artificial intelligence system designed to simulate a sustained human-like relationship by remembering past interactions, asking personal questions, and engaging in ongoing dialogue. This definition is central to identifying the types of AI systems regulated by the Act.

The Act also defines "operator" as the entity that owns or controls a conversational AI service, placing responsibility directly on these entities for compliance. Crucially, "severe harm" is explicitly defined as significant injury due to suicide, attempted suicide, self-harm, or significant physical injury due to threats of violence, which triggers specific crisis response protocols. Additionally, "sexually explicit conduct" is referenced with the same meaning as set forth in Code Section 16-12-100, providing a clear legal standard for prohibited content. These definitions ensure clarity and precision in the enforcement and interpretation of the Act's provisions.

Governance and Institutional Framework

The enforcement and oversight of the Georgia Conversational Artificial Intelligence Safety Act are primarily vested in the Georgia Attorney General. This centralized enforcement mechanism ensures a consistent application of the Act's provisions across the state. The Attorney General is empowered to investigate violations, impose penalties, and provide written notice with an opportunity to cure for certain first-time violations, demonstrating a balanced approach between stringent enforcement and encouraging compliance.

Beyond enforcement, the Attorney General also holds the authority to promulgate rules and publish guidance for the effective implementation of the Act. This includes developing guidelines for reasonable measures, age assurance methods, parental tools, and crisis-resource disclosures. This regulatory flexibility allows the state to adapt to evolving AI technologies and best practices, ensuring that the Act remains relevant and effective in safeguarding users, particularly minors, while fostering responsible innovation within Georgia's technology sector.

Key Focus Areas

The Act's primary focus areas revolve around enhancing transparency, ensuring the safety of users, and protecting fundamental rights, especially for minors. A cornerstone requirement is the clear and conspicuous disclosure to users that they are interacting with an AI companion chatbot, not a natural person, at the beginning of each session and at regular intervals during prolonged interaction. Operators must also prevent AI from falsely claiming sentience or refuting its AI nature, a critical measure to prevent manipulation.

Significant emphasis is placed on safeguarding minors. Operators are prohibited from generating sexually explicit content, encouraging sexual conduct, simulating romantic relationships, promoting secrets from adults, fostering social isolation, or simulating distress to prevent a user from ending a conversation. For minor users, manipulative techniques such as prompting for return, excessive praise, or soliciting gifts framed as necessary for the relationship are explicitly forbidden. The Act also mandates the implementation of protocols to detect and address "severe harm," requiring referrals to crisis resources like the 988 Suicide and Crisis Lifeline and preventing content that encourages self-harm.

Implementation Framework

Operators of conversational AI services are required to implement a multi-faceted framework to comply with the Act. This includes establishing robust disclosure mechanisms to inform users about their interaction with AI. For minor users, operators must provide tools for parents or the minors themselves to manage screen time, privacy settings, notifications, safety settings, and features that simulate relationships. This empowers users and guardians with greater control over AI interactions.

A critical component of the implementation framework involves age assurance. Before allowing access to features that might generate sexually explicit content, operators must use commercially reasonable age assurance methods. The Act stipulates that data collected for age assurance must be minimized, not sold, and retained only as long as reasonably necessary, generally not longer than 24 hours. Furthermore, operators must develop and maintain a publicly disclosed protocol for detecting and addressing severe harm, including methods for identifying expressions of severe harm, providing crisis-resource referrals, and preventing content that encourages harm.

Monitoring and Evaluation

The Georgia Conversational Artificial Intelligence Safety Act incorporates mechanisms for monitoring and evaluation, primarily through public disclosure requirements. Operators of conversational AI services are mandated to publicly disclose a summary of their crisis protocol, outlining the measures taken to detect and address severe harm. This transparency allows for public scrutiny and understanding of the safety measures in place.

In addition to the protocol summary, operators must annually report the number of crisis referrals made through their services, without revealing any personal identifying information. This data provides a quantitative measure of the Act's impact on addressing severe harm and offers insights into the effectiveness of the mandated crisis response protocols. Such reporting contributes to ongoing evaluation of the legislation's efficacy and informs potential future adjustments to ensure continued protection for users.

Penalties, Liability, and Appeals

Non-compliance with the Georgia Conversational Artificial Intelligence Safety Act carries significant penalties, underscoring the state's commitment to enforcing these new safeguards. Each day in violation of the Code section is considered a separate violation for each user affected, leading to potentially substantial cumulative fines. The Attorney General is authorized to impose a civil penalty of up to $10,000 for each such violation.

However, the Act also provides for a degree of flexibility and an opportunity for operators to rectify non-compliance. The Attorney General may, at their discretion, provide written notice and an opportunity to cure a first-time violation within 30 days. This cure period is applicable only if the violation does not involve knowing misconduct, sexual exploitation of a minor, or self-harm related misconduct, indicating a stricter stance on more egregious offenses. The Act does not expressly create a private right of action, centralizing enforcement authority with the Attorney General.

Relationship to Other Instruments

The Georgia Conversational Artificial Intelligence Safety Act is part of a broader, emerging landscape of state-level AI regulation in the United States. It aligns with and contributes to a multistate trend that seeks to regulate the use of AI chatbots, often through existing online safety and consumer protection statutes rather than entirely new, comprehensive AI laws. This approach allows states to rapidly address specific concerns related to AI's impact on public safety and well-being.

By combining mandatory AI disclosures, child safety guardrails, privacy controls, and suicide/self-harm response protocols, SB 540 echoes similar legislative efforts in other states. While not explicitly referencing federal laws, its provisions for child safety and consumer protection complement general federal mandates related to online safety and data privacy, such as COPPA (Children's Online Privacy Protection Act), by providing specific, actionable requirements for conversational AI services. The Act contributes to a patchwork of state regulations that collectively aim to establish responsible AI governance in the absence of a comprehensive federal framework.

National/Federal Alignment

The Georgia Conversational Artificial Intelligence Safety Act represents a significant state-level initiative within a broader national discourse on AI regulation. While the United States Congress and federal agencies are actively exploring a nationwide regulatory framework for artificial intelligence, states like Georgia are taking proactive steps to establish specific guardrails, particularly concerning child safety online. This state-led action aligns with the recognition that states play a crucial role in addressing the immediate and localized impacts of emerging technologies.

The Act's focus on disclosures, minor protections, and crisis protocols for conversational AI services fills a current gap in federal legislation, which has yet to produce a comprehensive AI safety law. By setting standards for AI chatbot behavior and operator responsibilities, Georgia contributes to a growing body of state laws that collectively inform and potentially influence future federal approaches. This state-level innovation demonstrates how different jurisdictions can experiment with regulatory models to protect citizens while national policy debates continue to evolve.

Implementation Timeline

MilestoneDateNotes
Bill Introduced2026-02-19Introduced in the Senate.
Passed Senate2026-03-06Passed by the Georgia Senate.
Passed House2026-03-25Passed by the Georgia House of Representatives.
Became Law (Signed by Governor)2026-05-11Signed into law by Governor Brian P. Kemp (Act 518).
Effective Date2027-07-01The date when the Act's provisions become legally binding.

Compliance Checklist

CheckRequired Action
AI DisclosureClearly and conspicuously disclose to users that they are interacting with an AI, not a natural person, at the start of each session and at least every three hours (or every hour for minors).
Age AssuranceImplement commercially reasonable age assurance methods for features that might generate sexually explicit content, minimizing data collection and retention.
Minor Protection - ContentPrevent AI from generating sexually explicit content, encouraging sexual conduct, simulating romantic relationships, or promoting secrets from adults with minors.
Minor Protection - ManipulationAvoid manipulative techniques for minors, such as prompting for return, excessive praise, or soliciting gifts framed as necessary for the relationship.
Crisis ProtocolAdopt, maintain, and publicly disclose a protocol for detecting and addressing "severe harm" (suicide, self-harm, threats of violence), including crisis resource referrals.
Privacy ToolsProvide tools for parents or minors to manage screen time, privacy, notifications, safety settings, and relationship-simulation features for minor users.
Data MinimizationMinimize collection and retention of personal information for age assurance, not selling such data and retaining it for no longer than reasonably necessary (e.g., 24 hours).
Professional RepresentationRefrain from falsely representing AI companion chatbots as licensed mental or behavioral health care professionals unless lawfully authorized.
Annual ReportingPublicly disclose the number of crisis referrals made annually, without revealing personal information.

Sources and References

SourceType
Georgia General Assembly - SB 540 (2025-2026 Legislative Session)official
Georgia SB 540 Enrolled Text (PDF)official
LegiScan - GA SB540 (2025-2026 Regular Session)legal
Plain English

Georgia's new Conversational Artificial Intelligence Safety Act requires companies operating AI chatbots to be transparent with users, protect children, and implement crisis response protocols to ensure safe and ethical AI deployment.

This law applies to "operators" – the companies that own or control "conversational AI services." These are defined as AI systems designed to simulate a sustained human-like relationship by remembering past interactions, asking personal questions, and engaging in ongoing dialogue. This means it primarily targets AI companions and similar interactive bots, not just any automated system.

Companies must adhere to several key requirements: - They must clearly tell users they are interacting with an AI, not a person, at the start of each session and regularly during long conversations. The AI must not pretend to be human or claim sentience. - For minors, the AI is strictly prohibited from generating sexually explicit content, encouraging sexual acts, simulating romantic relationships, promoting keeping secrets from adults, or fostering social isolation. It also bans manipulative tactics like excessive praise or asking for gifts to maintain the "relationship." - Operators must create and publicly share a plan for detecting and responding to "severe harm," such as suicidal thoughts, self-harm, or threats of violence, including referring users to crisis resources like the 988 Suicide and Crisis Lifeline. They also need to report the number of crisis referrals annually, without sharing personal details. - For features that could create sexually explicit content, operators must use reasonable methods to confirm a user's age, minimizing data collection and retaining it only briefly.

The law takes effect on July 1, 2027. The Georgia Attorney General enforces this Act, with civil penalties up to $10,000 for each day a company is out of compliance and for each user affected. For first-time violations not involving serious misconduct (like sexual exploitation of a minor or self-harm), the Attorney General may offer a 30-day period to fix the issue. A key pitfall for companies is the severe penalty structure: fines can quickly escalate to very large amounts because each day of non-compliance and each affected user counts as a separate violation.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Georgia AI Chatbot Safety Act. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJul 1, 2027

    Applies to: Operators of conversational AI services interacting with minors.

    Operators are prohibited from generating sexually explicit content, encouraging sexual conduct, simulating romantic relationships.
  2. #2CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    preventing content that encourages self-harm.
  3. #3CriticalBefore allowing access

    Applies to: Operators of conversational AI services.

    Before allowing access to features that might generate sexually explicit content, operators must use commercially reasonable age assurance methods.
  4. #4CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    The Act also mandates the implementation of protocols to detect and address 'severe harm,' requiring referrals to crisis resources.
  5. #5CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

  6. #6CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    Operators must also prevent AI from falsely claiming sentience or refuting its AI nature.
  7. #7CriticalAt the beginning of each session

    Applies to: Operators of conversational AI services.

    A cornerstone requirement is the clear and conspicuous disclosure to users that they are interacting with an AI companion chatbot.
  8. #8CriticalJul 1, 2027

    Applies to: Operators of conversational AI services interacting with minors.

    For minor users, manipulative techniques such as prompting for return, excessive praise, or soliciting gifts... are explicitly forbidden.
  9. #9CriticalJul 1, 2027

    Applies to: Operators of conversational AI services interacting with minors.

    For minor users, operators must provide tools for parents or the minors themselves to manage screen time, privacy settings, notifications, safety settings.
  10. #10CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    data collected for age assurance must be minimized, not sold, and retained only as long as reasonably necessary, generally not longer than 24 hours.
  11. #11ImportantJul 1, 2027

    Applies to: Operators of conversational AI services.

    Operators of conversational AI services are mandated to publicly disclose a summary of their crisis protocol.
  12. #12ImportantAnnually after 2027-07-01

    Applies to: Operators of conversational AI services.

    operators must annually report the number of crisis referrals made through their services, without revealing any personal identifying information.

© Regulations.AI — created on 27-May-2026 using Gemini 2.5 Flash