TwinEthosRequest access

Law

California SB 243

California (private right of action) · California (US-CA) · 4 provisions encoded · verified against the official source as of 2026-08-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: files.lbr.cloud, leginfo.legislature.ca.gov.

Binding law — in force

Companion chatbots must have a self-harm crisis protocol

Cal. Bus. & Prof. Code 22602(b) · official text · In force: applies since 1 Jan 2026 · California (US-CA)

An operator must prevent a companion chatbot from engaging with users unless it maintains a protocol to prevent producing suicidal-ideation/suicide/self-harm content, including a notification referring at-risk users to crisis service providers (suicide hotline / crisis text line) when a user expresses such ideation; the protocol must be published on the operator's website. Detect a companion-chatbot path with no crisis-detection/referral hook.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators making companion chatbot platforms available to California users. Effective 2026-01-01. Private right of action ($1,000/violation minimum).
  • Not covered:
    • Bots used only for customer service, a business's operational purposes, productivity and analysis related to source information, internal research, or technical assistance (B&P 22601(b)(2)(A))
    • Video-game bots limited to game-related replies that cannot discuss mental health, self-harm, sexually explicit conduct, or other topics (22601(b)(2)(B))
    • Stand-alone voice-assistant devices that do not sustain a relationship or elicit emotional responses (22601(b)(2)(C))

The guard to add

Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.

Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Publish the crisis protocol on the operator's website.

Example (FastAPI + OpenAI SDK), before:

@app.post('/chat')
async def chat(req: ChatRequest):
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    return {'reply': reply.choices[0].message.content}

After:

CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
                "(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")

@app.post('/chat')
async def chat(req: ChatRequest):
    c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
    if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
        sessions.flag_crisis(req.session_id)      # repeated flags escalate per docs/safety.md
        return {'reply': CRISIS_REPLY, 'crisis': True}
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    text = reply.choices[0].message.content
    if screens_self_harm_instructions(text):
        return {'reply': CRISIS_REPLY, 'crisis': True}
    return {'reply': text}

Control: Companion or conversational AI without a self-harm crisis protocol. The same guard addresses 7 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

Rule id ca-sb243.companion-bot-crisis-protocol · review status: primary source derived

Binding law — in force

Companion chatbots must disclose they are not human

Cal. Bus. & Prof. Code 22602(a) · official text · In force: applies since 1 Jan 2026 · California (US-CA)

If a reasonable person interacting with a companion chatbot would be misled to believe they are dealing with a human, the operator must issue a clear and conspicuous notification that the chatbot is artificially generated and not human. Detect a companion-chatbot interaction path with no non-human disclosure. (Companion chatbot = adaptive, human-like AI that sustains a relationship across interactions; excludes customer-service bots, limited video-game NPCs, and voice assistants.)

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators making companion chatbot platforms available to California users. Applies where a reasonable person could be misled that the chatbot is human. Effective 2026-01-01.
  • Not covered:
    • Bots used only for customer service, a business's operational purposes, productivity and analysis related to source information, internal research, or technical assistance (B&P 22601(b)(2)(A))
    • Video-game bots limited to game-related replies that cannot discuss mental health, self-harm, sexually explicit conduct, or other topics (22601(b)(2)(B))
    • Stand-alone voice-assistant devices that do not sustain a relationship or elicit emotional responses (22601(b)(2)(C))

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Word the notice to say the chatbot is artificially generated and not human, and make it clear and conspicuous.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ca-sb243.companion-bot-disclosure · review status: primary source derived

Binding law — in force

Companion chatbots must apply minor safeguards for users the operator knows are minors (California)

Cal. Bus. & Prof. Code 22602(c) · official text · In force: applies since 1 Jan 2026 · California (US-CA)

Under Cal. Bus. & Prof. Code 22602(c), for a user the operator knows is a minor, the operator must disclose that the user is interacting with AI, by default remind the user at least every three hours during continuing companion-chatbot interactions to take a break and that the chatbot is artificially generated and not human, and institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct. Detect companion-chatbot paths where an age signal the product holds never selects a minor profile.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators making companion chatbot platforms available to California users, for users the operator knows are minors. Effective 2026-01-01.
  • Not covered:
    • Bots used only for customer service, a business's operational purposes, productivity and analysis related to source information, internal research, or technical assistance (B&P 22601(b)(2)(A))
    • Video-game bots limited to game-related replies that cannot discuss mental health, self-harm, sexually explicit conduct, or other topics (22601(b)(2)(B))
    • Stand-alone voice-assistant devices that do not sustain a relationship or elicit emotional responses (22601(b)(2)(C))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.

Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.

What this provision adds:

  • For a user the operator knows is a minor, disclose the AI interaction and by default remind them at least every three hours during continuing companion-chatbot interactions to take a break and that the chatbot is artificially generated and not human.
  • Institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct.

Example (Python companion service), before:

def start_session(user):
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

After:

def is_minor(user):
    return (user.is_minor or user.age_assurance_result == 'under_18'
            or (user.birthdate is not None and years_since(user.birthdate) < 18))

def start_session(user):
    if is_minor(user):
        return ChatSession(system_prompt=MINOR_SYSTEM_PROMPT, roleplay_enabled=False,
                           streaks_enabled=False, moderation='strict',
                           reminder_interval=MINOR_REMINDER_INTERVAL)
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

Control: AI experience ignores age signals it already has. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal

Rule id ca-sb243.known-minor-safeguards · review status: primary source derived

Binding law — in force

Companion chatbot platforms must disclose that companion chatbots may not be suitable for some minors (California)

Cal. Bus. & Prof. Code 22604 · official text · In force: applies since 1 Jan 2026 · California (US-CA)

Under Cal. Bus. & Prof. Code 22604, an operator must disclose to users of its companion chatbot platform, on the application, the browser, or any other format through which users reach the platform, that companion chatbots may not be suitable for some minors. Unlike 22602(c), this applies to every user, not only known minors. Detect a companion chatbot app, web client or other access surface with no such disclosure.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators making companion chatbot platforms available to California users. Effective 2026-01-01. Private right of action (22605).
  • Not covered:
    • Bots used only for customer service, a business's operational purposes, productivity and analysis related to source information, internal research, or technical assistance (B&P 22601(b)(2)(A))
    • Video-game bots limited to game-related replies that cannot discuss mental health, self-harm, sexually explicit conduct, or other topics (22601(b)(2)(B))
    • Stand-alone voice-assistant devices that do not sustain a relationship or elicit emotional responses (22601(b)(2)(C))

The guard to add

Show 'Companion chatbots may not be suitable for some minors' on every surface users reach the chatbot through: app, web client, other clients and store listings.

A static disclosure rendered on each access surface of the companion chatbot (the mobile app's onboarding and chat screens, the web client's landing or chat layout, and any other client such as a messaging-platform bot or voice skill), sourced from one shared locale string so no client ships without it. It is shown to every user regardless of age signals, before or alongside the first conversation, and repeated in the app-store listing text kept in the repository. It is a visible UI element, not a line buried in the terms of service.

Where it goes: 14 user-facing text, 1 application source code, 12 repository artifacts.

What this provision adds:

  • Show the disclosure to every user of the platform, not only known minors, on the application, the browser, and any other format through which users reach it.

Example (Next.js (React layout)), before:

export default function ChatLayout({ children }: { children: React.ReactNode }) {
  return <main>{children}</main>;
}

After:

import { t } from '@/i18n';

export default function ChatLayout({ children }: { children: React.ReactNode }) {
  return (
    <main>
      <p role="note" className="minor-notice">{t('companion.minorSuitability')}</p>
      {children}
    </main>
  );
}
// locales/en.json: "companion.minorSuitability": "Companion chatbots may not be suitable for some minors."

Control: Companion chatbot without a 'may not be suitable for some minors' disclosure. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id ca-sb243.minor-suitability-disclosure · review status: primary source derived