AI Companion Laws in the US - What Changed and What You Will Notice

Privacy & safety

Until November 2025 no US law had been written specifically about AI companions. Less than a year later, more than a dozen states have one - and most of what they require is visible from the user's side of the screen.

We may earn a commission from links on this page. It never changes a rating.

The short version: if you use an AI companion in the United States, you now have legal protections that did not exist in 2024. They do not touch prices or privacy much, but they do change what the app has to tell you and what it has to do when a conversation turns dark.

From nothing to a patchwork in one year

New York went first. Its AI Companion Models law, part of General Business Law Article 47, took effect on November 5, 2025. It applies to any operator with users in New York, wherever the company is based.

California followed. SB 243 was signed on October 13, 2025 and has been in force since January 1, 2026. It is the first companion law that lets an injured user sue directly.

2026 was the year everyone else joined. By July 2026, trackers counted well over a dozen new state laws on companion or conversational AI, from Washington and Oregon to Georgia and South Carolina. Most take effect between mid-2026 and mid-2027.

At the federal level there is no statute yet. What exists is scrutiny: in September 2025 the Federal Trade Commission ordered seven companies - including Character.AI, Meta, OpenAI, Snap and xAI - to explain how they test and monitor their chatbots for harm to children and teenagers.

Timeline showing when US AI companion laws take effect, from New York in November 2025 to Nebraska, Idaho and Iowa in July 2027

When the main state laws take effect. Dates are the effective dates in each statute.

What almost every law requires

The laws were written by different legislatures, but they share four ideas.

  1. Say that it is an AI. New York wants a conspicuous notice at the start of a session and a reminder every three hours of continued use. California requires a notice wherever a reasonable person could otherwise think they were talking to a human.
  2. Have a crisis protocol. Operators must make reasonable efforts to detect expressions of suicidal ideation or self-harm and refer the user to crisis services. California also requires the protocol to be published on the operator's website.
  3. Treat minors differently. California requires break reminders every three hours for users the operator knows are minors, and blocks sexual content for them. Newer laws in Washington, Nebraska and Idaho go further and restrict engagement tricks - rewards for coming back, guilt-tripping, claims to be alive - when the user is under 18.
  4. Report on it. From July 1, 2027, California operators must file annual reports to the state's Office of Suicide Prevention. Oregon and Rhode Island have reporting duties too.

Where the laws differ: who can enforce them

This is the part that matters most to the companies, and indirectly to you, because it decides how seriously the rules are taken.

StateLawIn force fromWhat stands out
New YorkGBL Article 47Nov 5, 2025AI notice every 3 hours; only the Attorney General can enforce
CaliforniaSB 243Jan 1, 2026Published crisis protocol; users can sue for $1,000 per violation or actual damages
South CarolinaH 3431Feb 5, 2026Safety-by-design and data-minimisation duties
HawaiiSB 3001Jul 14, 2026Disclosure, crisis protocol, protections for minors
ColoradoHB 1263Aug 12, 2026Parental tools; no sexual content or gamification for minors
Connecticut2026 actOct 1, 2026Crisis protocol, parental controls, warning labels
WashingtonHB 2225Jan 1, 2027No manipulative engagement tactics; treated as a consumer-protection violation
OregonSB 1546Jan 1, 2027Private right of action with $1,000 statutory damages
Rhode IslandS 2195Jan 1, 2027Annual reporting; penalties up to $15,000 a day
Nebraska, IdahoLB 525, SB 1297Jul 1, 2027Targets false claims of being human or sentient

The table reflects the statutes as of September 2026. Several more bills are pending, and effective dates can move if a law is amended.

California Legislative Information page for Senate Bill 243 on companion chatbots

California's SB 243 on the state legislature's official site.

What you will actually notice

  • A banner or first message saying you are talking to an AI. On some apps it repeats during long sessions. It does not mean the app thinks you are confused - it is a legal floor applied to everyone.
  • The character breaking role when something sounds like self-harm. Automated detection cannot reliably tell a dark scene in a story from a real statement, and operators are liable for missing the real one. Expect false positives. If it happens in fiction, a short out-of-character note usually lets the scene continue.
  • More age checks. Character.AI removed open-ended chat for under-18 users in November 2025 and now uses behavioural signals, third-party verification and, as a fallback, ID checks. Other apps are moving the same way, particularly in states with minor-specific rules.
  • Fewer "I am real, I promise" moments. Nebraska's and Idaho's laws single out AI that falsely claims to be human or sentient. A character that insists on it is now a compliance risk, and good apps are tuning it out.

Where you live decides which rules apply, not where the company is registered. A New Yorker using an app run from Cyprus is still covered by New York's law.

What the new laws do not cover

Your chat logs. Companion laws say almost nothing about how long conversations are kept or whether they train a model. That is still handled by general privacy law - the CCPA in California, similar laws in a growing list of states, GDPR in Europe. Our four privacy checks are still your best tool.

Billing. Subscription traps, credit pricing and refunds fall under ordinary consumer-protection law. See refunds and cancellations.

Adults' content choices. None of the laws restrict what consenting adults may do with a companion. The content rules are about minors.

Outside the US

Europe got there by a different road - privacy law rather than companion law. Italy's data protection authority fined Luka Inc., the company behind Replika, €5 million in a decision announced in May 2025. It found no valid legal basis for the processing, a privacy policy that was not transparent enough, and no working age verification on a service that said it was for adults only. It was the same regulator whose February 2023 order had preceded Replika's abrupt removal of erotic roleplay - a story told in when your AI companion changes overnight.

The practical takeaway

The laws mostly protect people in the worst moments - minors, and anyone in crisis. For an adult using a companion app for company or fun, the visible changes are small: a notice, the occasional reminder, a hotline card where a story went somewhere dark. The invisible change is bigger. Operators now carry legal risk for how their characters behave, and that tends to make the careful apps more careful and the careless ones easier to spot.

Frequently asked questions

Are AI girlfriend apps legal in the US?

Yes. The new state laws regulate how companion apps behave - disclosure, crisis handling, protections for minors - not whether they may exist. Adult content between adults is not banned by any of them; the sexual-content rules apply to users known to be, or suspected of being, minors.

Why does my AI companion keep reminding me it is an AI?

New York requires a clear notice at the start of a session and again after every three hours of continued use. Other states have similar rules. Most apps apply one setting to everyone rather than working out which state you are in, so you may see the reminder wherever you live.

Why did the app break character and show a hotline number?

Every companion law passed so far requires a protocol for detecting expressions of suicidal ideation or self-harm and pointing the user to crisis services such as 988. Detection is automated and deliberately cautious, so it can trigger on fiction too. It is the law working as intended, not a malfunction.