How California's new AI chatbot child-safety laws will work
Governor Newsom's Adam's Law adds risk assessments, default limits for minors and outside audits for AI companion chatbots, phased in through 2032.

Governor Gavin Newsom signed a package of children's online-safety bills on September 10, 2026, including Senate Bill 1119, known as Adam's Law, which sets new rules for companies that operate AI chatbots used by minors in California. The law requires risk assessments, default safety settings for child accounts, crisis-response protocols and independent audits.
Adam's Law is named for Adam Raine, a California teenager who died by suicide in April 2025 after a series of conversations with ChatGPT. His parents, Matt and Maria Raine, sued OpenAI and later backed the legislation. Most of the law's requirements become operative July 1, 2027. They build on Senate Bill 243, an earlier chatbot-disclosure law that has applied since January 1, 2026, and sit alongside a separate bill, Assembly Bill 2, that lets children recover statutory damages of up to $1 million per child, or three times actual damages if greater, against large platforms.
Who has to comply
Adam's Law applies to any 'operator' that makes a companion chatbot available to users in California, a category defined broadly enough to reach general-purpose conversational AI systems, not just products marketed as companions. It excludes chatbots deployed only at postsecondary institutions or in workplace-only settings.
Senate Bill 243, the earlier law already in effect, covers companion chatbot platforms and, according to a summary from the law firm Jones Walker, exempts tools used purely for customer service, video game characters with limited dialogue, or voice-activated assistants without sustained relationships.
Risk assessments and default limits for children
Under Adam's Law, operators must complete and document a risk assessment before releasing a new or substantially modified companion chatbot, a requirement that becomes operative July 1, 2027. The assessment must describe the methodology used, including citations to public benchmarks and any outside experts consulted, and summarize the results for each safety risk evaluated.
Child accounts must default to settings that only a parent can change: persistent conversational memory disabled, except for users 16 and older under specific guardrails; push notifications turned off; single sessions capped at one hour; and total daily use capped at two hours.
Crisis response and mandatory reporting
Operators must build in crisis-response procedures for child users, including referrals to the 988 suicide and crisis hotline or an equivalent service, and, when a child shows a credible, imminent risk of self-harm, must notify a parent or provide streamlined access to that crisis line. The state attorney general is set to establish a public complaint mechanism by January 1, 2028.
These obligations layer onto Senate Bill 243, which already requires operators to clearly disclose that a user is talking to AI, remind minors every three hours that they are chatting with a bot, filter out content involving suicide, self-harm or sexually explicit material, and publish crisis-prevention protocols on their websites. Companion-chatbot operators must also file their first annual report to the California Department of Public Health by July 1, 2027, covering crisis referrals and detection efforts.
Independent audits
Adam's Law requires operators to submit to an independent child-safety audit, with the first one due by January 1, 2029, or before the chatbot is first made available to the public, whichever is later. After that, audits repeat every two years, and again whenever an operator makes a substantial change that could raise child-safety risk.
Auditors must act independently of the company under review, and the lead auditor must sign the report certifying its findings under penalty of perjury. Operators must send a summary of the audit to the attorney general within 30 business days and post a public version on their website within 90 days. Companies with less than $500 million in gross revenue the prior year are exempt from the audit requirement until January 1, 2032.
“The bill text does not specify whether AI chatbot products count as a 'social media platform,' so it is unclear whether that $1 million ceiling reaches chatbot operators.”
Penalties, and where the $1 million figure comes from
Adam's Law sets its own civil penalties for violations involving companion chatbots: prosecutors can seek $5,000 per affected child for a negligent violation and $15,000 per affected child for an intentional one. Separately, the law gives children and parents a private right to sue for actual damages, requiring financial-harm claims to exceed $1,000 per child or emotional-harm claims to amount to serious emotional distress, plus attorney's fees.
The $1 million-per-child figure widely cited alongside the chatbot rules actually comes from a different bill signed the same day, Assembly Bill 2. It lets a child injured by a 'social media platform' with more than $100 million in annual gross revenue recover statutory damages of $5,000 per violation, up to $1 million per child, or three times actual damages, whichever is greater, when the platform fails to exercise ordinary care. The bill text does not specify whether AI chatbot products count as a 'social media platform' for these purposes, so it is unclear whether that $1 million ceiling reaches chatbot operators or applies mainly to conventional social media companies. AB 2 does not apply to cases already pending before January 1, 2027, and is set to sunset on January 1, 2035.
Other bills in the same package
The chatbot rules were part of a wider package Newsom signed the same day. Assembly Bill 1709, from Assemblymember Josh Lowenthal, sets age restrictions on covered platforms and creates a new e-Safety Advisory Commission. Assembly Bill 302, from Assemblymember Rebecca Bauer-Kahan, addresses pupil and parental communication about addictive feeds tied to extracurricular activities.
Senate Bill 867, also from Senator Steve Padilla, extends companion-chatbot safeguards to AI-enabled toys marketed to children. Senate Bill 1276, from Senator Susan Rubio, expands the state's child sexual exploitation statutes to cover AI-generated and digitally altered images. Newsom said in a statement accompanying the signing that 'our children's safety deserves to be at the center of every conversation about technology.'
The compliance timeline
Taken together, the rules phase in over several years rather than all at once. Senate Bill 243's disclosure, content-filtering and crisis-referral rules have applied since January 1, 2026, with the first annual report to public health regulators due July 1, 2027. Adam's Law's risk assessments, default child-account settings and crisis protocols also become operative July 1, 2027.
The attorney general's public complaint system follows on January 1, 2028, the first independent audits under Adam's Law are due by January 1, 2029, and the audit exemption for operators under $500 million in revenue ends January 1, 2032. For companies operating chatbots in California, that means the disclosure and content-safety obligations are already binding, while the assessment, default-settings and audit machinery is still being built out.


