One missed companion-chatbot safeguard can produce a private civil claim for the greater of actual damages or $1,000 per violation.
The claimant can also seek an injunction and reasonable attorney's fees and costs. If the same product failure affects many conversations or users, the words "per violation" are the part a founder cannot afford to leave undefined.
California Senate Bill 243 has been in force since 1 January 2026. Its first state reporting deadline arrives on 1 July 2027.
You do not need a California company, office, or employee. The law defines an operator as a person who makes a companion-chatbot platform available to a user in California. A Delaware C-Corporation serving one California user can be inside the rule.
What California SB 243 requires
SB 243 covers an AI system with a natural-language interface that gives adaptive, human-like responses, can meet a user's social needs, exhibits human traits, and can sustain a relationship across multiple interactions.
That definition matters more than the label on your landing page. Calling a product a coach, character, confidant, wellness guide, study buddy, or social assistant does not decide the issue. What the product does during repeated conversations does.
The law excludes bots used only for customer service, business operations, productivity, source-based analysis, internal research, or technical assistance. It also excludes certain limited video-game bots and stand-alone voice assistants that do not sustain relationships or generate emotionally charged responses.
For products inside the definition, the duties split into three groups.
First, if a reasonable person could be misled into thinking the chatbot is human, the operator must give a clear and conspicuous notice that it is artificially generated and not human.
Second, the platform cannot let a companion chatbot engage with users unless it maintains a suicide and self-harm protocol. That protocol must include a referral notice to a crisis service provider, such as a suicide hotline or crisis text line, when a user expresses suicidal ideation, suicide, or self-harm. The operator must publish details of the protocol on its website.
Third, when the operator knows a user is a minor, it must disclose that the user is interacting with AI. During a continuing interaction, the product must show a default break reminder at least every three hours and repeat that the chatbot is artificially generated and not human. The operator must also use reasonable measures to stop the chatbot from producing sexually explicit visual material or directly telling the minor to engage in sexually explicit conduct.
Every platform must also disclose that companion chatbots may not be suitable for some minors.
Beginning 1 July 2027, operators must report annually to California's Office of Suicide Prevention. The report covers the number of crisis referrals and the protocols used to detect, remove, and respond to suicidal ideation. The report cannot include user identifiers or personal information, and the operator must use evidence-based methods to measure suicidal ideation.
Why this lands inside the product
Building in one of these categories? Send me one message about what you're building and I'll name the laws you're inside — which documents they demand, and what covers you. Free, usually within a day or two. Start here.
— Santosh
SB 243 is not satisfied by adding one sentence to the Terms of Use.
The human-or-AI disclosure belongs in the conversation interface. The three-hour minor reminder needs a timer and a reliable age signal. The self-harm protocol needs detection criteria, a crisis-referral response, escalation ownership, testing records, and a public explanation that matches the system in production.
The reporting duty also changes what must be logged. A company cannot produce an annual count of crisis referrals in 2027 if it did not define the event and collect the count in 2026. At the same time, the statutory report must exclude identifiers and personal information. Your safety metrics and privacy design now depend on each other.
Enterprise buyers will ask for this evidence before they let a companion product reach employees, students, patients, or customers. The useful file is not a promise that the bot is safe. It is a product map showing the trigger, the response, the person responsible, the test result, and the retained record.
In September 2025, the Federal Trade Commission issued compulsory information orders to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and X.AI. The agency asked how their companion chatbots are tested, monitored, marketed, monetised, and restricted for children and teens. This was a Section 6(b) study, not a finding that any recipient broke the law. It still shows the evidence federal regulators expect a chatbot operator to possess.
In August 2025, the Texas Attorney General issued civil investigative demands to Meta AI Studio and Character.AI. The inquiry concerned possible deceptive marketing of chatbot personas as mental-health tools, privacy statements, and data use. The investigation was not a final violation finding. It is a warning that the product persona, the therapy-like claim, and the privacy notice can all become enforcement evidence.
The national rule is being built in layers
California's private claim sits beside federal and state duties rather than replacing them. SB 243 says its duties and remedies are cumulative.
The FTC is examining companion-chatbot safety and data practices at the federal level. Connecticut SB 5 adds its own companion and minor protections on a later timetable. If a chatbot can create or share intimate images, the federal TAKE IT DOWN Act can add a separate 48-hour removal duty.
One product can therefore need a companion-chatbot safety protocol, child-facing notices, privacy controls, and a content-removal workflow at the same time. StartEase maps those documents by product on its AI document services page.
Where you incorporate does not protect you
A Wyoming LLC or Delaware C-Corporation does not avoid SB 243 by keeping its team outside California. The statute follows product availability to a user in the state.
Geo-blocking California is a business choice, not a paperwork cure. If the product is available there, classify the chatbot against the statutory definition and build the required controls before launch.
Three things to fix before you scale
1. Write a product-classification memo. Record why the chatbot is or is not a companion chatbot. Test the real conversation design, memory, persona, emotional language, and relationship features against the definition. Do not rely on the product name.
2. Separate the minor experience in code. Decide what gives the operator knowledge that a user is a minor. Connect that signal to the AI disclosure, the three-hour break notice, the suitability warning, and sexual-content controls. Keep test evidence for each trigger.
3. Build the crisis protocol and reporting ledger now. Define detection, crisis referral, escalation, human review, testing, and ownership. Log reportable events without putting user identities into the annual state dataset. Publish a protocol summary that matches the live system.
The one-line summary for each founder
AI companions and character apps: a human-like persona now carries a California disclosure and safety file.
Wellness and mental-health chatbots: a disclaimer cannot rescue a product that acts like an unlicensed therapist or lacks a crisis protocol.
Kids and teen products: the three-hour reminder, AI disclosure, and sexual-content controls belong in the interface by default.
General-purpose chatbots: document why the product falls inside or outside the companion definition before a complaint makes that decision for you.
The core duties are already live. The reporting date is later, but the data needed for that report is being created now. The founders who connect the legal rule to product events today will have a defensible record when users, buyers, or regulators ask how the system works.
Building a companion chatbot? Send me one message about what you're building, and I'll name the rules you're inside.