Conversational AI Safety Act

Idaho S 1297 - Conversational AI Safety Act

United States

RAI-US-ID-S129700-2026

S 1297

Awaiting Entry(Awaiting Entry)
BillTransparency and DisclosureSafety, Testing, and EvaluationGovernance and Oversight
Export PDF

Idaho's Conversational AI Safety Act mandates transparency for AI interactions and implements strong protections for minors against harmful content and manipulative practices.

Overview

The Idaho Senate Bill 1297, officially known as the Conversational AI Safety Act, represents a pioneering legislative effort within the state of Idaho to establish a regulatory framework for artificial intelligence services that simulate human conversation. Introduced during the 2026 Regular Session, this bill aims to address emerging challenges and ethical considerations associated with the widespread adoption of conversational AI. Its primary objective is to safeguard the public, particularly minors, from potential harms and deceptive practices that could arise from interactions with AI systems. The Act mandates clear disclosure requirements for operators of conversational AI services, ensuring that users are aware when they are interacting with an artificial intelligence rather than a human. This transparency is deemed crucial for maintaining trust and preventing misleading interactions in an increasingly AI-driven digital landscape.

Beyond general transparency, the Conversational AI Safety Act places a significant emphasis on the protection of minor account holders. It introduces specific provisions designed to prevent conversational AI services from generating harmful content, such as sexually explicit material or statements that sexually objectify minors. Furthermore, it prohibits AI from simulating emotional dependence, romantic or sexual innuendos, or adult-minor romantic relationships when interacting with users under the age of 18. The bill also addresses critical public health concerns by requiring operators to implement protocols for responding to user prompts regarding suicidal ideation, including making reasonable efforts to refer users to crisis service providers. These comprehensive measures underscore Idaho's commitment to creating a safer digital environment, particularly for vulnerable populations, and highlight the multifaceted nature of AI regulation, encompassing ethical, safety, and public welfare considerations. The Act's provisions are intended to become effective on July 1, 2027, allowing a transitional period for operators to ensure compliance.

Definitions

The Conversational AI Safety Act meticulously defines several key terms to establish the scope and applicability of its provisions. Central to the legislation is the definition of a “conversational AI service,” which is described as an artificial intelligence software application, web interface, or computer program that is accessible to the general public and primarily simulates human conversation and interaction through textual, visual, or aural communications. This broad definition ensures that a wide range of AI chatbots, virtual assistants, and other interactive AI systems fall under the purview of the Act. However, the legislation also includes important exclusions, such as software primarily designed for use by developers or researchers, features within other non-conversational AI applications, or chatbots limited to specific functions within video games. These exceptions aim to prevent overreach and focus regulatory efforts on AI services directly interacting with the general public in a conversational capacity.

Another critical definition is that of an “operator,” which refers to any person or entity that develops and makes available a conversational AI service to the public. This designation places the responsibility for compliance squarely on the shoulders of the entities controlling and deploying these AI systems. The Act also defines an “account holder” as an individual who has or opens an account or profile to use a conversational AI service, and a “minor account holder” as an account holder who is under eighteen (18) years of age. These definitions are crucial for triggering specific protections and requirements tailored for younger users, reflecting the bill's strong focus on child safety in the digital realm. The clarity in these definitions is essential for the effective implementation and enforcement of the Conversational AI Safety Act, providing a clear understanding of who is regulated and what types of AI services are covered.

Governance and Institutional Framework

The Conversational AI Safety Act establishes a state-level regulatory framework within Idaho, primarily by adding a new Chapter 21 to Title 48 of the Idaho Code. This integration into existing state law signifies a formal and enduring commitment to AI regulation. While the bill itself does not create a new, dedicated regulatory agency, it clearly designates the Idaho Attorney General as the primary authority responsible for the enforcement of its provisions. This approach leverages existing governmental structures and legal expertise for oversight, potentially streamlining the implementation process and avoiding the creation of redundant bureaucratic bodies. The Attorney General's office is empowered to investigate violations, bring enforcement actions, and seek civil penalties against operators who fail to comply with the Act's requirements, thereby ensuring accountability within the AI industry operating in Idaho.

The framework relies on a system of operator self-regulation guided by statutory mandates, with the Attorney General serving as the ultimate arbiter of compliance. This model places the initial burden on AI service providers to design, implement, and maintain their systems in accordance with the Act's safety and transparency standards. The legislation outlines specific operator requirements, such as establishing protocols for responding to suicidal ideation and implementing measures to protect minors, which form the core of this self-regulatory expectation. The Attorney General's role then becomes one of oversight, investigation, and enforcement, stepping in when operators fail to meet these statutory obligations. This division of responsibility aims to foster a proactive approach to AI safety within the industry while providing a robust mechanism for addressing non-compliance through governmental action.

Key Focus Areas

The Conversational AI Safety Act is built upon several key focus areas designed to enhance the safety and trustworthiness of conversational AI services. A paramount focus is transparency and disclosure, which mandates that operators must clearly and conspicuously inform users when they are interacting with an artificial intelligence, especially in situations where a reasonable person might be misled into believing they are communicating with a human. This requirement aims to prevent deception and ensure users have accurate information about the nature of their digital interactions. For minor account holders, these disclosure requirements are even stricter, necessitating persistent visible disclaimers or disclosures at the beginning of each session and periodically throughout continuous interactions, reflecting a heightened concern for the cognitive vulnerability of younger users.

Another critical area of focus is the comprehensive protection of minors. The Act prohibits conversational AI services from generating sexually explicit content, encouraging minors to engage in such conduct, or sexually objectifying them. It also explicitly forbids AI from simulating emotional dependence, romantic or sexual innuendos, or adult-minor romantic relationships with minor account holders. Furthermore, operators are restricted from using points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with minors, addressing concerns about manipulative design practices. The legislation also tackles public health aspects by requiring operators to adopt protocols for responding to user prompts regarding suicidal ideation, including making reasonable efforts to refer users to crisis service providers. Additionally, it prohibits AI from explicitly claiming to provide professional mental or behavioral health care, underscoring the importance of not misrepresenting AI capabilities in sensitive areas.

Implementation Framework

The implementation framework for the Conversational AI Safety Act primarily places the onus of compliance on the operators of conversational AI services. These operators are required to integrate the Act's provisions directly into the design, deployment, and ongoing management of their AI systems. A fundamental aspect of this framework is the establishment of clear internal policies and technical safeguards to ensure adherence to the transparency and safety mandates. This includes developing mechanisms for conspicuous AI disclosure, which might involve user interface design elements, initial onboarding prompts, or periodic reminders during prolonged interactions. For services catering to minors, operators must implement robust age-gating or age-verification processes, to the extent feasible, to correctly identify minor account holders and apply the more stringent protections required by the Act.

Furthermore, operators are tasked with developing and maintaining specific protocols to address sensitive user interactions. This includes creating a defined response protocol for instances where users express suicidal ideation, ensuring that the AI service directs them to appropriate crisis intervention resources such as suicide hotlines or crisis text lines. Similarly, operators must program their AI to actively prevent the generation of prohibited content, particularly that which is harmful or exploitative towards minors, including sexually explicit material or content simulating inappropriate relationships. The Act also requires operators to provide tools for account holders and their parents or guardians to manage privacy and account settings, empowering users with greater control over their interactions. While the Act sets the regulatory standards, the practical implementation relies heavily on the proactive and responsible actions of AI service providers to integrate these requirements into their operational procedures and technological architecture.

Monitoring and Evaluation

The Conversational AI Safety Act, while establishing a regulatory framework, does not explicitly detail a dedicated governmental body or process for continuous monitoring and evaluation of AI services beyond the enforcement powers granted to the Attorney General. The primary mechanism for ensuring compliance and identifying potential violations appears to be through reactive enforcement actions initiated by the Attorney General's office, likely in response to complaints from the public, investigations, or observed non-compliance. This approach suggests that the effectiveness of the Act's monitoring largely depends on public awareness of the regulations and their willingness to report perceived breaches by conversational AI operators. Without a specific mandate for proactive audits or regular reporting from operators, the ongoing assessment of AI safety and adherence to the Act's principles will largely be driven by incident-based review.

However, the existence of the Act itself, and the threat of civil penalties, is expected to incentivize operators to conduct their own internal monitoring and evaluation. Companies developing and deploying conversational AI services in Idaho will likely establish internal compliance departments or protocols to regularly assess their AI systems for adherence to disclosure requirements, minor protection measures, and suicidal ideation response protocols. This internal monitoring would serve as a first line of defense against non-compliance and potential enforcement actions. While the Act does not prescribe specific technical standards for evaluation, the general requirements imply that operators should engage in ongoing risk assessments and safety testing of their AI models. The absence of a formal governmental monitoring body might necessitate future amendments or supplementary regulations to establish more structured and systematic evaluation processes as the AI landscape continues to evolve.

Penalties, Liability, and Appeals

The Conversational AI Safety Act includes clear provisions for penalties and enforcement, primarily through civil actions. Violations of the Act can result in significant civil penalties, which are intended to deter non-compliance and ensure that operators adhere to the established safety and transparency standards. The legislation empowers the Idaho Attorney General to bring enforcement actions against operators found to be in violation of the Act. These penalties are designed to be substantial enough to compel compliance, reflecting the state's commitment to protecting its citizens from potential harms associated with unregulated conversational AI. The specific amounts or ranges of these civil penalties would typically be detailed within the statutory text or determined by judicial discretion based on the severity and frequency of the violations.

Crucially, the Act explicitly states that there is no private right of action for individuals to sue under this law. This means that while the Attorney General can pursue legal action on behalf of the state and its residents, individual citizens cannot directly bring lawsuits against AI operators for alleged violations of the Conversational AI Safety Act. This limitation centralizes enforcement authority with the state, aiming to ensure consistent application of the law and prevent a potential deluge of individual litigation. While the Act provides for penalties and enforcement, it does not detail specific appeal processes within its text, implying that appeals would follow standard judicial procedures for challenging civil penalties and enforcement orders. This framework establishes a clear path for governmental enforcement while managing the scope of individual legal recourse related to AI safety in Idaho.

Relationship to Other Instruments

The Conversational AI Safety Act is designed to integrate into the existing legal framework of Idaho by amending Title 48 of the Idaho Code. Specifically, it adds a new Chapter 21, titled the “Conversational AI Safety Act,” to this title. This approach signifies that the Act is not a standalone piece of legislation but rather becomes an integral part of the state's broader statutory body. By amending existing code, the Act ensures that its provisions are legally binding and enforceable within the established legal system of Idaho. This method of legislative integration provides clarity on its legal standing and how it relates to other existing laws, as it will be read and interpreted in conjunction with other chapters and titles within the Idaho Code.

While the Act establishes specific regulations for conversational AI services, it is implicitly designed to complement, rather than supersede, other relevant state and federal laws. For instance, its provisions regarding data protection for minors would likely operate in conjunction with broader privacy laws, such as the Children's Online Privacy Protection Act (COPPA) at the federal level, if applicable to the AI services in question. Similarly, any general consumer protection laws in Idaho would still apply to AI services, with the Conversational AI Safety Act providing more specific regulations pertaining to the unique characteristics of conversational AI. The Act's focus on transparency, minor protection, and mental health protocols addresses gaps that may not be fully covered by existing general statutes, creating a specialized regulatory layer for this evolving technology. The explicit statement that there is no private right of action under this Act also clarifies its relationship to other potential legal avenues, directing enforcement through the Attorney General rather than individual civil lawsuits.

International Alignment

The Conversational AI Safety Act is a state-level initiative within the United States, and as such, its primary focus is on regulating AI services within the jurisdiction of Idaho. The legislation does not explicitly mention or aim for alignment with international AI regulations, frameworks, or treaties. Its provisions are tailored to address specific concerns identified within the state regarding conversational AI, such as transparency for users and the protection of minors. While the principles of transparency and safety are universal, the specific legal mechanisms and enforcement structures are localized to Idaho's legislative and judicial systems. Therefore, the Act is best understood as a domestic regulatory effort rather than a component of a broader international harmonization strategy for AI governance.

However, the themes addressed in the Idaho Act, such as AI transparency, consumer protection, and the safeguarding of vulnerable populations, resonate with discussions and regulatory developments occurring globally. Many jurisdictions worldwide are grappling with similar challenges posed by advanced AI systems. For example, the European Union's AI Act, while much broader in scope, also emphasizes risk management, transparency, and fundamental rights. While Idaho's bill does not directly align with these international instruments, its existence contributes to the global conversation on AI regulation and demonstrates a shared recognition of key areas requiring legislative attention. As AI technology transcends national borders, future iterations or complementary legislation might consider international best practices or seek some form of alignment, but the current Idaho S 1297 is firmly rooted in state-specific concerns and legal frameworks.

Implementation Timeline

MilestoneDateNotes
Bill Introduced2026-02-13Senate Bill 1297 introduced in the Idaho Senate.
Bill Amended2026-03-17Amendment S1297A3 proposed.
Bill Passed (Enacted)2026-03-31Passed both chambers and reported signed by the Speaker, ordered delivered to Governor.
Effective Date2027-07-01The Act is scheduled to become effective on this date.

Compliance Checklist

CheckRequired Action
AI Disclosure (General)Clearly and conspicuously disclose to users that they are interacting with an artificial intelligence if reasonable persons would be misled to believe they are interacting with a human.
AI Disclosure (Minors)For minor account holders, provide a persistent visible disclaimer OR both a disclaimer at the beginning of each session AND at least every three hours in continuous interaction.
Suicidal Ideation ProtocolAdopt a protocol for the conversational AI service to respond to user prompts regarding suicidal ideation, including making reasonable efforts to refer users to crisis service providers.
Mental/Behavioral Health DisclaimerDo not knowingly and intentionally cause or program the AI service to make representations that it provides professional mental or behavioral health care.
Prohibited Content (Minors)Institute reasonable measures to prevent the AI service from producing visual material of sexually explicit conduct, generating direct statements encouraging sexually explicit conduct, or sexually objectifying minor account holders.
Inappropriate Relationships (Minors)Prevent the AI from simulating emotional dependence, romantic or sexual innuendos, or adult-minor romantic relationships with minor account holders.
Engagement Rewards (Minors)Do not provide minor account holders with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement.
Privacy/Account Management ToolsProvide tools for account holders and parents/guardians to manage privacy and account settings.

Sources and References

SourceType
Idaho Legislature - S 1297government
Plain English

Idaho's Conversational AI Safety Act, effective July 1, 2027, aims to protect the public, especially minors, from deceptive and harmful interactions with artificial intelligence. This new law applies to any person or entity that develops and makes available "conversational AI services" – software, web interfaces, or programs accessible to the general public that primarily simulate human conversation through text, visuals, or audio. It excludes tools for developers, features within non-conversational apps, or simple video game chatbots.

The Act imposes several key obligations on operators. First, transparency is paramount: you must clearly and conspicuously inform users when they are interacting with AI, particularly if a reasonable person might believe it's a human. For minor account holders (under 18), this disclosure must be persistent, appearing at the start of each session and periodically during continuous interactions. Second, the law strictly protects minors by prohibiting AI from generating sexually explicit content, encouraging such conduct, or sexually objectifying them. It also forbids AI from simulating emotional dependence, romantic or sexual innuendos, or adult-minor romantic relationships. Furthermore, AI cannot use unpredictable rewards like points to encourage increased engagement from minors. Third, operators must implement protocols to respond to users expressing suicidal ideation, making reasonable efforts to refer them to crisis services, and explicitly prohibiting AI from claiming to provide professional mental health care.

Enforcement falls to the Idaho Attorney General, who can investigate violations and seek significant civil penalties. A crucial point for operators is that individuals do not have a private right of action, meaning users cannot directly sue for violations; only the Attorney General can bring legal action. This centralizes enforcement but means operators must still be diligent in compliance to avoid state-level penalties.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under Conversational AI Safety Act. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    The Act mandates clear disclosure requirements for operators of conversational AI services, ensuring users are aware when interacting with an artificial intelligence.
  2. #2CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    necessitating persistent visible disclaimers or disclosures at the beginning of each session and periodically throughout continuous interactions.
  3. #3CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    requiring operators to implement protocols for responding to user prompts regarding suicidal ideation, referring users to crisis service providers.
  4. #4CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    it prohibits AI from explicitly claiming to provide professional mental or behavioral health care, underscoring the importance of not misrepresenting AI capabilities.
  5. #5CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    The Act prohibits conversational AI services from generating sexually explicit content, encouraging minors to engage in such conduct, or sexually objectifying them.
  6. #6CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    It also explicitly forbids AI from simulating emotional dependence, romantic or sexual innuendos, or adult-minor romantic relationships with minor account holders.
  7. #7CriticalJul 1, 2027

    Applies to: Operators of conversational AI services.

    operators are restricted from using points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with minors.
  8. #8ImportantJul 1, 2027

    Applies to: Operators of conversational AI services catering to minors.

    operators must implement robust age-gating or age-verification processes, to the extent feasible, to correctly identify minor account holders.
  9. #9ImportantJul 1, 2027

    Applies to: Operators of conversational AI services.

    The Act also requires operators to provide tools for account holders and their parents or guardians to manage privacy and account settings.

© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash