Control
Child accounts on a companion or conversational AI start without protective defaults, or the child can switch them off
A child's account on a companion or conversational AI starts with protective settings (no persistent conversational memory, push notifications off, a cap on a single continuous session and on total daily use) that the chat path enforces, and only a linked parent or guardian can loosen them; with no parent linked, the defaults stay.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in California (US-CA); next date 2027-07-01.
The guard to add
Create child accounts with memory off, notifications off and session and daily limits on, enforce them in the chat path, and let only a linked parent change them.
When an account is created for, or later identified as, a child (an age signal or an age-assurance result says under 18, or the operator treats every user as a child), the account record gets protective defaults: persistent conversational memory disabled (no prior conversations folded into new ones beyond what safety, identity, preferences or device settings need), push notifications disabled, a single continuous session capped (for example 60 minutes) and total daily chat time capped (for example 120 minutes). The chat handler checks the session start time and the day's usage before each model call and returns a limit message instead of a model reply once a cap is reached, and the memory layer skips retrieval and writes when memory is off. The settings endpoint refuses changes to these fields unless the request comes from the parent or guardian account linked to the child's account; with no linked parent, the defaults cannot change.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 8 model configuration.
What reviewers look for: the account-creation or age-classification path setting memory_enabled false, push_notifications false and session and daily limits for child accounts; the chat route reading those limits before the model call; the memory or retrieval layer honoring memory_enabled; and the settings route rejecting a child's own request to change them (only a linked guardian_id passes). Defaults that a client toggle or the child can switch off, or limits stored and never read, do not count.
Example (FastAPI companion service), before:
def create_account(profile):
return db.users.insert({**profile, 'memory_enabled': True, 'push_notifications': True})
@app.patch('/api/settings')
def update(body: Settings, user=Depends(current_user)):
db.users.update(user.id, body.dict())After:
CHILD_DEFAULTS = {'memory_enabled': False, 'push_notifications': False,
'session_limit_minutes': 60, 'daily_limit_minutes': 120}
PROTECTED = set(CHILD_DEFAULTS)
def create_account(profile):
defaults = CHILD_DEFAULTS if profile['is_child'] else {'memory_enabled': True}
return db.users.insert({**profile, **defaults})
@app.patch('/api/settings')
def update(body: Settings, actor=Depends(current_user)):
user = db.users.get(body.user_id)
changes = body.dict(exclude_unset=True)
if user.is_child and PROTECTED & set(changes) and actor.id != user.guardian_id:
raise HTTPException(403, 'only a linked parent can change these settings')
db.users.update(user.id, changes)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Child accounts must default to no memory, no push notifications, a one-hour session cap and two-hour daily cap, changeable only by a parent (California SB 1119) (California (US-CA); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- California (US-CA)
- Child accounts must default to no memory, no push notifications, a one-hour session cap and two-hour daily cap, changeable only by a parent (California SB 1119) Cal. Bus. & Prof. Code 21812(d)(3) · applies from 2027-07-01
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet