California AI Companion Regulation: Safety Measures, Minors and Disclosure Obligations
An explanation of California's SB 243, covering the definition of AI companions, exclusions, disclosure and safety obligations, protection of minors, and the impact on companies outside the state.
Primary sources
The announcements and documents this analysis covers.
On October 13, 2025, Governor Newsom signed SB 243, which imposes disclosure obligations and safety measures on operators of AI companion chatbots, enacting it as Chapter 677 of the Statutes of 2025. The law adds a new chapter (Chapter 22.6, Sections 22601 through 22606) to the state's Business and Professions Code, and because it contains no urgency clause, it took effect on January 1, 2026. This article organizes, based on the statutory text, the definition of the regulated "companion chatbot" and its exclusions, the obligations imposed on businesses, enforcement centered on a private right of action, and the points of contact for Japanese companies providing companion-type AI services to users in California.
What Was Enacted
SB 243 was introduced by State Senator Steve Padilla on January 30, 2025, passed the State Senate on May 23 and the State Assembly on September 10 of that year, and was enacted with the Governor's signature on October 13 of that year. Its legal nature is that of a statute amending California's Business and Professions Code; it is not an administrative guideline of the kind common in Japan, but a statutory obligation accompanied by a private right of action. The law was introduced against the background of reported cases in which minors engaged in self-harm in the course of interacting with AI companions. Its application is phased in two stages: the provisions on disclosure obligations and safety protocols apply from January 1, 2026, while the annual reporting obligation to the state, described below, begins to apply on July 1, 2027.
Regulated Systems and Exclusions
Section 22601 defines a "companion chatbot" as an AI system with a natural language interface that provides adaptive, human-like responses to user inputs, is capable of meeting a user's social needs, including by exhibiting anthropomorphic features, and is able to sustain a relationship across multiple interactions. The same section defines an "operator" as a person who makes a companion chatbot platform available to users in California.
There are three categories of exclusions. Bots used only for customer service, business operations, productivity and analysis related to source information, internal research or technical assistance are excluded, as are bots within video games that are limited to replies related to the game, cannot discuss mental health, self-harm or sexually explicit content, and cannot maintain a dialogue on topics unrelated to the game. In addition, voice assistants in stand-alone, voice-activated consumer electronic devices that do not sustain a relationship across multiple interactions and do not generate outputs likely to elicit emotional responses from the user are also excluded. Accordingly, business FAQ bots and bots limited to in-game guidance functions can be read as falling outside the scope under the statutory text. On the other hand, companion-type AI services designed and marketed on the premise of building an ongoing relationship or emotional bond with users are likely to fall within the scope unless an exclusion applies.
Obligations of Businesses
Section 22602(a) requires that, where a reasonable user could be misled into believing they are interacting with a human, a clear and conspicuous notification be given that the chatbot is artificially generated and not human. Section 22602(b) requires the establishment of a protocol to prevent the production of content concerning suicidal ideation, suicide or self-harm, and requires that its details, including notifications to users and referrals to crisis service providers such as suicide hotlines, be published on the operator's website. Section 22602(c) sets out additional obligations for minors: in addition to disclosing that the user is interacting with AI, the operator must provide notifications at least every three hours reminding the user to take a break, and must take measures to prevent the generation of sexually explicit content directed at minors. Section 22604 requires a disclosure on all platforms through which the companion chatbot is offered that companion chatbots may not be suitable for some minors.
Section 22603 requires operators, from July 1, 2027, to report annually to the state's Office of Suicide Prevention on matters such as the number of times during the preceding year they issued crisis service provider referrals under Section 22602, their protocols for detecting, removing and responding to suicidal ideation, and evidence-based methods for measuring suicidal ideation. Section 22606 provides that the obligations under the chapter are cumulative with obligations under other laws and do not relieve anyone of liability under other laws.
Enforcement and the Private Right of Action
Section 22605 grants a person who suffers injury in fact as a result of a violation of the chapter the right to bring a civil action. The available remedies are injunctive relief, damages in an amount equal to the greater of actual damages or USD 1,000 per violation, and reasonable attorney's fees and costs. The design allows injured individuals to sue directly without first going through corrective measures by an administrative agency, and according to press reports and law firm commentary, this contrasts with a similar New York regulation enacted around the same time, which contains no private right of action. As of the time of writing, no case could be confirmed in which a lawsuit has actually been filed under Section 22605. Several lawsuits concerning AI companion services had been pending even before the law was enacted, but whether they are based on Section 22605 cannot be determined from the materials reviewed for this article.
Points of Contact for Japanese Companies
Japanese law currently has no regulation establishing disclosure obligations, self-harm response protocols or a private right of action for companion-type AI chatbots. There may be situations in which existing laws such as the Act on the Protection of Personal Information (APPI), the Premiums and Representations Act and tort liability under the Civil Code become relevant, but the situation differs in that there is no cross-industry dedicated regulation like SB 243.
On the other hand, SB 243's definition of "operator" does not require having an entity located in California; it covers anyone who makes a platform available to users in the state. Accordingly, where a Japanese business provides a companion-type AI service accessible to California residents, it does not necessarily fall outside the scope merely because the service is provided from outside the state. As an item to check going forward, the first step is to have a procedure for determining concretely, from a functional standpoint, whether the company's service falls within the definition in Section 22601 or within any of the three categories of exclusions. This determination is positioned as part of identifying applicable laws, as covered in The First Legal Checklist a Company Starting an AI Service Should Create.
If, as a result of that determination, the company concludes that its service may fall within the scope, it needs to check whether the current wording of the terms of use is sufficient as a clause disclosing that the service is AI. This is a point to consider in common with The Legal Issues to Look at First in the Terms of Use of Generative AI Services. In addition, the practical starting point is to check whether the company has put in place a flow for detecting self-harm and suicidal ideation and referring users to crisis service providers, and, if not, which department will put it in place, following the procedure for establishing internal operating rules covered in How to Create a Generative AI Use Policy. The approach behind the disclosure obligation, which is to avoid designs that mislead users into believing they are dealing with a human, also partly overlaps with the discussion in Legal Issues in Deepfake and Impersonation Advertising, which deals with impersonation using AI.
Developments to Watch
As of the date of writing, the following points remain unsettled or require ongoing monitoring.
- Whether administrative guidance will be published on the reporting format and specific items to be included in the annual reports to the state's Office of Suicide Prevention beginning July 1, 2027
- The filing of lawsuits based on the private right of action under Section 22605, and the rulings in them
- To what extent other states' regimes, such as New York's AI companion regulation (effective November 5, 2025) and a similar regulation with a private right of action that, according to press reports, Oregon enacted in March 2026, will be aligned with the content of California's regulation
- The status of publication of interpretive guidance and enforcement cases by the California Attorney General and other regulators
All of these are matters not settled as of the time of writing, and once they are settled, the application to the company's own services will need to be rechecked.