AI Chatbot Compliance: What Your Business Needs to Know

Read Time: 9 minutes

At least twelve states have enacted laws regulating consumer-facing AI chatbots, and more are expected to follow. Core obligations generally fall into three categories: AI-identity disclosure, suicide and self-harm prevention protocols, and protections for minors. With a handful of such laws containing a private right of action and the ability to recover statutory damages, businesses that deploy AI chatbots should evaluate their public-facing AI deployment.

An increasing number of states are enacting legislation regulating the use and deployment of artificial intelligence (“AI”) in a variety of contexts. Like the rest of the United States’ privacy compliance regime, there is no single, comprehensive statute governing AI. Instead, businesses face a patchwork of overlapping state laws targeted as certain industries and use cases. Among these are statutes governing the use and deployment of AI systems in critical infrastructure, generation of deepfakes, delivery of healthcare services, real estate advertising, and other contexts. Still other states are incorporating AI data processing provisions into their comprehensive consumer privacy frameworks.

Perhaps the most common category of state AI legislation at this time is the regulation of AI chatbots made available to the general public. Although some states have laws that restrict the use of AI chatbots in specific contexts (such as providing professional mental or behavioral health care, like in Nevada, or offering therapy or psychotherapy services, like in Illinois), these statutes are narrower and do not apply to AI chatbot applications and systems that are accessed by the public for general purposes. This article focuses on the increasing wave of consumer AI chatbot laws as opposed to narrower AI chatbot restrictions or regulations affecting AI systems generally.

As of August 2026, at least twelve states have enacted laws regulating consumer-facing AI chatbots:

  1. California SB 243 (Companion Chatbot Law): Effective Date: January 1, 2026
  2. Colorado HB 26-1263: Effective Date: January 1, 2027
  3. Connecticut SB 5: Effective Date: October 1, 2026
  4. Georgia SB 540: Effective Date: July 1, 2027
  5. Hawaii SB 3001 (Act 248): Effective Date: July 14, 2026
  6. Idaho S 1297: Effective Date: July 1, 2027
  7. Iowa SF 2417: Effective Date: July 1, 2027
  8. Nebraska LB 525 (Conversational Artificial Intelligence Safety Act): Effective Date: July 1, 2027
  9. New York General Business Law Article 47 (Artificial Intelligence Companion Models Law): Effective Date: November 5, 2025 with protections for minors set effective January 1, 2027
  10. Oregon SB 1546: Effective Date: January 1, 2027
  11. Rhode Island S2195: Effective Date: January 1, 2027
  12. Washington ESHB 2225 (The Chatbot Disclosure Act): Effective Date: January 1, 2027

Although these statutes share a similar structure, each contains state-specific nuances. They apply based on where a company's users are located, not where the company is incorporated. Businesses offering chatbot services nationwide should therefore expect to comply with the disclosure, minor-protection, and crisis-protocol requirements in every state that has enacted such a law.

Even if a state has not yet enacted chatbot legislation, it may do so soon. Preparing now can help reduce future liability.

Consumer-facing AI chatbot laws generally impose three core obligations: AI-identity disclosure, suicide and self-harm prevention protocols, and protections for minors. The sections below summarize those obligations and the practical steps businesses can take to prepare.

Core Obligations Under State AI Chatbot Laws

  1. Disclosure That the User Is Interacting with AI. All twelve laws require operators to tell users when they are interacting with artificial intelligence. A chatbot may not claim or imply that it is human. In addition to being regulated by state chatbot laws, the disclosure obligation also exists under the unfair and deceptive acts or practices provision in Section 5 of the Federal Trade Commission Act and state analogs. For example, if a chatbot uses a human name and persona without identifying itself as AI, it could mislead a consumer into believing they are speaking with a human and influence a purchasing decision. The FTC has a long history of pursuing enforcement actions against companies for alleged deceptive practices. The FTC has signaled that it may extend such enforcement authority to AI-facilitated acts and practices. This overlapping requirement demonstrates the complex and layered nature of privacy and AI regulation in the United States. Notably, the FTC evaluates the “net impression” of a user’s overall experience, meaning that even a technically compliant disclosure may not cure a chatbot interface that uses manipulative or deceptive design elements—sometimes referred to as “dark patterns”—to obscure user choices or subvert autonomy. The general chatbot disclosure requirement is distinct from a prohibition on chatbots representing that they provide professional mental or behavioral healthcare services—a feature contained in the chatbot statutes of Colorado, Georgia, Hawaii, Idaho, Iowa, and Nebraska.

    Some state laws also require periodic reminders to be given to consumers. Washington requires operators to remind adults every three hours and minors under the age of eighteen every hour that they are communicating with a bot. California requires operators to provide “take a break” reminders at least every three hours to users known to be minors.
  2. Scope of Regulated Chatbots. Businesses must understand how each state defines the chatbots it regulates. States have adopted three approaches:
    1. Conversational: The broadest approach covers any chatbot with a natural-language interface that simulates human conversation and is accessible to users. This framework may regulate any conversational AI chatbot available to the general public, regardless of whether it is designed to build a relationship, including customer-service bots, tutoring bots, and general-assistant bots that answer questions or complete tasks. Nebraska, Iowa, Idaho, and Colorado have adopted this approach in their chatbot statutes.
    2. Functional Companion: A functional companion chatbot can provide human-like responses and sustain a relationship across multiple interactions. This definition may capture general-purpose chatbots even when they are not intended as companion services. California, Washington, and Connecticut use this approach and provide carve-outs for purely transactional customer-service bots and standalone voice-assistant devices. Washington, however, brings customer-service bots back into scope if they sustain relationships across multiple interactions or elicit emotional responses.
    3. Designed Companion: The narrowest approach applies in Georgia, Hawaii, New York, Oregon, and Rhode Island. A designed companion chatbot asks emotion-based questions, sustains ongoing dialogue on personal matters, and retains prior interactions to create personalized engagement. Systems that do not ask emotion-based questions, such as customer-service bots, may fall outside the scope of these laws.

      It is important for businesses to review the applicable state's definition of "chatbot" to determine which category governs.
  3. Crisis Response Protocols. All twelve enacted laws require operators to maintain protocols to detect suicidal ideation and refer affected users to appropriate resources. Some also prohibit chatbots from generating content that describes self-harm. Detection methods range from simple keyword filtering to evidence-based screening tools.
  4. Protections for Minors. Protecting children and teenagers who use AI chatbots is a top priority for legislators and regulators alike. Most state statutes prohibit chatbots from manipulating minors or fostering emotional dependence. New York requires its disclosure and self-harm protocols to apply to all users, not just minors—an approach other states may adopt.

    For users under the age of majority, many state AI chatbot laws include age-verification requirements and content restrictions. Those restrictions typically prohibit sexually explicit content, suggestive dialogue, and manipulative engagement techniques, such as prompting a user to return affection or mimicking a romantic relationship. These manipulative techniques overlap with the concept of “dark patterns” under state comprehensive privacy laws. At least thirteen states have enacted laws providing that consent obtained through a dark pattern—defined as a user interface designed to subvert or impair user autonomy, decision-making, or choice—does not constitute valid consent, which may independently expose chatbot operators to liability if their conversational design manipulates users into sharing personal information or maintaining engagement. In addition, for users under the age of thirteen, the federal Children’s Online Privacy Protection Act (“COPPA”) imposes distinct requirements—including verifiable parental consent and data retention limits—that businesses must satisfy alongside state chatbot obligations.
  5. Private Right of Action. Most state AI chatbot laws, like comprehensive consumer privacy statutes, authorize only the state attorney general to enforce them. California, Oregon, and Washington, however, permit individuals to sue businesses for violations. Statutory damages may reach up to $1,000 per violation, and each chatbot output could constitute a separate actionable violation.

Practical Steps for Compliance

Whether your business is evaluating an AI chatbot or already operates one, investing in compliance now can help avoid costly disputes. Consider the following steps:

  1. Understand your data practices—and disclose them appropriately. Identify what information your chatbot collects, uses, and shares to determine which scope definition applies. Depending on your industry, additional privacy and confidentiality requirements may apply. Prepare clear terms of use and disclaimers before users begin a conversation, and disclose the categories of information the chatbot collects on your website or in your application privacy policy. Businesses should also consider whether chatbot conversation data is used to train AI models and, if so, ensure this practice is disclosed in their privacy notices, as some states now require AI training disclosures.
  2. Identify applicable state law. Determine which state’s law governs your chatbot use case and which definitional category applies. Then configure your bot to limit what it promises or discusses in accordance with applicable requirements.
  3. Test, monitor, and review. After implementing changes, test the chatbot to confirm that it operates as intended. Verify that required disclosures appear at the right times and that age-verification mechanisms function properly. Maintain conversation logs for audits and potential dispute defense. Review these operational frameworks periodically and after material changes to the technology or use case.
  4. Review vendor agreements. If your business licenses an underlying AI model, review vendor agreements to ensure they address applicable compliance obligations. Pay particular attention to liability allocation and indemnification provisions. A strong vendor indemnity can provide important protection in litigation. As the FTC’s recent settlement with OkCupid demonstrates, sharing user data with third-party AI companies in ways not disclosed in a privacy policy can constitute a deceptive trade practice under Section 5, regardless of the purpose of the data sharing.

Conclusion

Overall, new AI chatbot bills are being introduced and enacted regularly. A one-time compliance effort will not be sufficient to keep pace with evolving state requirements. Congress and the White House continue to debate federal action that could preempt this state patchwork. In the meantime, businesses should take a proactive approach to compliance, as federal legislation will likely incorporate successful elements from existing state frameworks.

If you have questions about AI chatbot compliance obligations, please contact a member of Koley Jessen's Data Privacy and Security Practice Area.

Special thanks to Summer Associate Sidney Linder for her contributions to this article.


This content is made available for educational purposes only and to give you general information and a general understanding of the law, not to provide specific legal advice. By using this content, you understand there is no attorney-client relationship between you and the publisher. The content should not be used as a substitute for competent legal advice from a licensed professional attorney in your state.

Explore Our

Newsroom


Learn about the latest legal news, firm announcements, and upcoming events on the topics important to you and your business.

A close-up view of a modern bridge against a clear sky. The bridge features a sleek, curved design with an underside illuminated by warm sunlight, creating a contrast of light and shadow. The railing and cables are visible, adding to the architectural det
Jump to Page

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.