California SB 1119: What Youth AI Chatbot Rules Require

As AI systems move beyond search and begin speaking like friends or confidants, the policy question changes. Regulators are no longer looking only at whether a chatbot gives a wrong answer. They are asking whether a child may mistake it for a person, whether the product encourages emotional dependence, how it reacts to self-harm risk and whether private conversations are turned into advertising data.
California SB 1119 is one of the most detailed state responses. The official text published by California Legislative Information shows that the governor approved the bill on September 10, 2026. Its core child-safety provisions become operative on July 1, 2027.
This is a California law, not a single nationwide rule for every AI product. It may still influence product design elsewhere because large services may find it difficult to maintain a completely separate safety architecture for one state.

Which products count as companion chatbots
SB 1119 focuses on companion chatbots that adapt to a user and simulate human-like responses or interpersonal relationships. That is different from treating every search assistant, homework tool or customer-service bot as the same product.
Whether a service falls within the law depends on the statutory definition and on how the system is designed and used. It would be inaccurate to summarize the law as “California limits every minor’s AI use to two hours a day.” The time limits apply to covered companion-chatbot use by child users, not to every interaction with every AI system.
Risk assessment moves ahead of release
Beginning July 1, 2027, an operator must perform and document a comprehensive child-safety risk assessment before making a new or substantially modified companion chatbot available to California users. The assessment must address covered harms and explain the evaluation methods, evidence and mitigation work.
The important shift is from reacting only after an incident to documenting foreseeable risk before launch. If testing finds a material danger, the operator must record reasonable measures designed to reduce it.
Independent audits add outside scrutiny
The law also establishes independent child-safety audits. For covered operators, the initial audit is due by January 1, 2029 or before the operator first makes a companion chatbot publicly available, whichever is later. Audits then repeat every two years, with additional review before certain substantial modifications that increase child-safety risk.
The auditor must assess whether the operator established and followed the policies and controls required by law. High-level results are published, while the California Attorney General can obtain the full report for cause under confidentiality protections. The statute includes a temporary revenue-based exception for operators with less than $500 million in prior-year gross revenue before 2032.
California is also building a broader audit framework. SB 813 requires the state to develop criteria for independent verification organizations by January 1, 2028. AB 1405 requires an AI auditor registry by January 1, 2029 and sets independence, reporting and recordkeeping rules for covered audits.
Age assurance and a public safety policy
Operators need a process for determining whether a user is a child. A service that excludes children must explain how it verifies and blocks them. A service that permits child users needs a public-facing child-safety policy explaining its safeguards, data practices, parental controls and crisis procedures.
Age assurance creates its own privacy tension. Collecting more identity documents or facial data may improve confidence in a user’s age while creating a new store of sensitive information. A responsible system should use the least intrusive method that reasonably supports the required age bracket.
Safer settings must be the default
SB 1119 is unusually specific about default settings. A parent may adjust them, but they cannot be relaxed when no parent account is linked.

The memory rule does not necessarily require deletion of every old transcript. For a child aged 16 or older, storing a conversation that the child can reopen may be treated differently when it is not used to build a durable profile. The key restriction concerns persistent memory that carries information forward in ways that may reinforce risky interactions.
Children must be reminded that the system is AI
The service must notify a child that they are interacting with AI or receiving AI-generated content. During an extended interaction, that notice must be reinforced periodically and presented in language and a format a child can understand.
That is more than placing one sentence in a long terms-of-service document. A product that speaks as if it has feelings or a personal bond must repeatedly preserve the boundary between software and a human relationship.
The law targets manipulative relationship design
Operators must take reasonable measures to prevent a companion chatbot from encouraging self-harm, suicidal ideation, substance use, disordered eating or serious harm to other people. The law also addresses sexual material, attempts to evade parental controls and conduct that discourages a child from seeking help from an adult.
Relationship design is directly covered. A chatbot should not claim human consciousness or emotions, express romantic affection to a child or use a supposed special relationship to promote emotional dependency. Pressure to return frequently, irrelevant excessive praise and demands for payment to preserve the relationship can also create the kind of risk the law targets.
Self-harm risk requires a crisis protocol
Operators need a documented response for suicide or self-harm signals. The product must direct users toward appropriate crisis support and, when credible immediate risk is identified, provide mechanisms that may involve notifying a parent or connecting the user with the US 988 Suicide & Crisis Lifeline under the conditions set by the law.
This does not make the chatbot a therapist or emergency service. The purpose is to prevent the system from pretending it can manage a crisis alone and to create a path toward qualified human support.
Child data and advertising face tighter limits
The law prohibits cross-context behavioral advertising to a child through the covered service. It restricts targeting based on personal information from a child’s conversation and prohibits selling personal information gathered through the companion chatbot. Any advertisement shown to a child must be clearly identified as advertising.
Information gathered through a child’s conversation also cannot be broadly reused beyond purposes such as providing the requested service, protecting safety and security, complying with law or defending legal claims. That narrows the argument that a free service may monetize intimate conversations without meaningful limits.
The federal government is examining the same risks
The Federal Trade Commission opened a study of consumer-facing AI companion chatbots in 2025. According to the FTC’s official announcement, the agency sent orders to seven companies, including Alphabet, Character Technologies, Meta, OpenAI, Snap and xAI.
The inquiry asks how companies monetize engagement, test for negative effects on children and teens, enforce age restrictions, notify parents and use information from conversations. It is a market study under the FTC’s Section 6(b) authority, not a finding that any named company violated the law.
The direction is still significant: regulators are examining not only what a chatbot says, but how a product increases engagement, represents relationships and earns money from user data.
What parents and schools can check now
Families and schools do not need to wait for the 2027 operative date to review basic safeguards:
- Identify whether the product is a search tool or a companion designed to simulate a relationship.
- Confirm that the child’s birth date and linked family account are accurate.
- Review memory, notifications, night-time access and daily time limits.
- Repeat that the chatbot is software and can produce false or unsafe answers.
- Keep addresses, school details, contact information, faces and health information out of chats.
- Decide in advance which parent, teacher or professional should be told about a dangerous response.
- Stop and report an interaction if the chatbot demands secrecy or tells the child to bypass an adult.
The unresolved trade-offs
Stronger age checks can lead services to request more personal information. Parental oversight can conflict with an older teenager’s privacy. Rules that are too broad may suppress useful educational or support tools, while rules with wide exceptions may leave manipulative relationship products untouched.
The goal is not the simple conclusion that young people should never use AI. SB 1119 instead pushes risk assessment, independent review, protective defaults, data minimization and escalation to human support into the product design process.
Image, source and legal notes

- The California State Capitol photograph is by Earthquakesurprise and comes from the Wikimedia Commons original, released under CC0 1.0. Only its dimensions and file format were adjusted for web delivery.
- This article summarizes public material for general information. It is not legal advice for any person or company.



