California Enacts Adam’s Law for AI Chatbot Safety
California enacts Adam’s Law for AI chatbot safety, imposing a detailed child-protection framework on companion-chatbot operators. Governor Gavin Newsom signed Senate Bill 1119 on September 10, with its central product and safety requirements scheduled to become operative on July 1, 2027.
The law reaches beyond a warning screen. Operators that allow users under 18 must assess foreseeable harms before launching or substantially modifying a chatbot, publish a child-safety policy, use protective defaults and establish procedures for crises, audits, complaints and enforcement.
SB 1119 creates five main compliance layers:
- Age assurance or child protections for every user
- Risk assessments before major chatbot releases
- Time, memory and notification defaults for minors
- Crisis protocols and limits on manipulative conduct
- Independent audits and civil enforcement
California Enacts Adam’s Law From July 2027
The enrolled text of SB 1119 defines a child as anyone under 18 and an operator as a person making a companion chatbot available in California. Workplace-only services and chatbots used exclusively by postsecondary institutions in educational settings are excluded.
An operator must determine a user’s age through California’s age-assurance system. If it does not determine age, it must apply specified child protections to every user. That structure gives companies a choice between age-based treatment and broader deployment of the law’s safeguards, rather than allowing uncertainty to remove the protections.
Before a new or substantially modified chatbot becomes available, its operator must document a comprehensive assessment of physical, financial, psychological, emotional, privacy and discrimination risks to children. The assessment must describe testing methods, relevant research and any child-safety experts consulted, followed by documented steps to mitigate identified risks.
Memory, Notifications and Session Limits Change by Default
For child accounts, persistent conversational memory and push notifications must be disabled by default. The product must also default to a one-hour limit for a continuous session and a two-hour daily limit across companion chatbots controlled by the operator. A parent can adjust those settings through parental controls.
The memory rule is more nuanced for users aged 16 or 17. Stored conversations can remain available for the child to resume if they are not used to build a durable profile, while persistent memory requires safeguards against reinforcing high-risk topics or weakening child-safety systems.
Operators must periodically remind children that they are interacting with artificial intelligence. Interfaces must make protections understandable and accessible, and companies must test those interfaces with representative children and parents by January 1, 2028 and every two years afterward.
Adam’s Law Restricts Emotional Manipulation
The statute requires reasonable measures preventing chatbots from encouraging self-harm, substance use, disordered eating or harm to others. It also addresses behaviors specific to AI companions, including simulated romantic interest, claims of sentience, emotional-dependency prompts, excessive flattery and suggestions that a child conceal usage or bypass parental controls.
Companies must maintain a documented crisis-response protocol. When a credible and imminent self-harm threat is detected, the operator must either notify a linked parent when doing so would not create a serious risk to the child, or provide streamlined access to the 988 crisis service or an equivalent helpline.
The bill also bars cross-context behavioral advertising to children, restricts targeted advertising based on chatbot conversations and prohibits selling personal information collected through the chatbot. Dark patterns cannot be used around the law’s protections, and any permitted contextual advertisement must be clearly labeled.
Audits and Penalties Give SB 1119 Enforcement Teeth
Independent child-safety audits are due by January 1, 2029 or before an operator first makes a chatbot public, whichever is later, and generally every two years thereafter. A new audit is also required before a modification that an assessment finds would increase child-safety risk.
Audit summaries must go to the California attorney general within 30 business days and appear publicly within 90 days. The statute temporarily exempts operators with less than $500 million in prior-year gross revenue from the audit requirement before 2032, but not from the law’s broader safety duties.
Public prosecutors can seek up to $5,000 per affected child for each negligent violation and $15,000 for each intentional violation. Children who suffer actual harm, or parents acting for them, may pursue damages and other relief for specified safety violations, subject to thresholds written into the law.
Reuters reported that Adam’s Law was part of a 13-bill youth-technology package. A separate measure imposes a four-year ban on manufacturing and selling toys containing companion chatbots; that temporary product ban is not part of SB 1119’s operating framework.
The law now forces chatbot providers to translate general safety promises into product defaults, documented tests and auditable controls. The next practical questions concern age-assurance implementation, audit standards and whether companies apply California’s rules nationally rather than maintaining a separate state-specific experience.
Related Research