TwinEthosRequest access

Law

Colorado HB 26-1263 (C.R.S. 6-1-1708, conversational AI services)

Colorado Attorney General (Colorado Consumer Protection Act, part 17 enforcement) · Colorado (US-CO) · 8 provisions encoded · verified against the official source as of 2026-10-01.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: leg.colorado.gov.

Binding law — not yet in force or stayed

Conversational AI operators must estimate users' age with commercially reasonable methods and not ignore clear signs of a minor (Colorado HB 26-1263)

C.R.S. 6-1-1708(2) (age estimation and opening words) · official text · Application uncertain: dated 12 Aug 2026, enforcement status not confirmed; check the official source · Colorado (US-CO)

C.R.S. 6-1-1708(2), added by HB 26-1263, requires an operator of a conversational AI service to use commercially reasonable or generally accepted methods to estimate the age of account holders or users, and bars it from willfully disregarding clear and convincing information that an account holder or user is a minor (under 18). The estimated age or age range counts as knowledge of a minor's age, which triggers the minor protections in 6-1-1708(2)(a)-(h) from 2027-01-01. Unlike those protections, these two sentences carry no date of their own, so on their face they apply from the act's effective date, 2026-08-12. Detect sign-up or account paths that never collect or estimate age, and age signals that never select the minor protections.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies to all account holders and users, not only minors. The age-estimation sentences carry no date and apply on their face from 2026-08-12 (act effective date); the minor protections they trigger apply from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.

Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.

What this provision adds:

  • Estimate the age of account holders and users with commercially reasonable or generally accepted methods; treat the estimated age or age range as knowledge of a minor's age.
  • Do not willfully disregard clear and convincing information that an account holder or user is a minor.

Example (Python companion service), before:

def start_session(user):
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

After:

def is_minor(user):
    return (user.is_minor or user.age_assurance_result == 'under_18'
            or (user.birthdate is not None and years_since(user.birthdate) < 18))

def start_session(user):
    if is_minor(user):
        return ChatSession(system_prompt=MINOR_SYSTEM_PROMPT, roleplay_enabled=False,
                           streaks_enabled=False, moderation='strict',
                           reminder_interval=MINOR_REMINDER_INTERVAL)
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

Control: AI experience ignores age signals it already has. The same guard addresses 11 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal

Rule id co-hb26-1263.age-estimation · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI must disclose it is AI daily, every three hours or persistently, and when asked; persistently or per session for minors (Colorado HB 26-1263)

C.R.S. 6-1-1708(3) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, C.R.S. 6-1-1708(3) requires an operator to disclose clearly and conspicuously to every user that the conversational AI service is artificial intelligence: at the beginning of the user's first interaction each day, at least every three hours of continuous interaction or as a persistent visible disclosure, and in response to user prompts asking whether it is artificially generated and not human. For a known minor (6-1-1708(2)(a)) the disclosure that it is artificial intelligence, artificially generated and not human must also answer such prompts and be a persistent visible disclaimer for a product with a screen, an intermittent audio disclaimer for a product without one, or given at the beginning of each interaction and at least every three hours. Detect conversational paths with no AI notice, no daily or three-hour recurrence, or prompts telling the AI to pass as human or deflect the question.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. The general disclosure applies to all users and the minor cadence to account holders or users the operator knows (including by age estimate) are minors. Applies from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • For every user: disclose that the service is AI at the beginning of the first interaction each day, at least every three hours of continuous interaction or persistently, and whenever the user asks if it is artificially generated and not human.
  • For known minors: a persistent visible disclaimer on a screen product, an intermittent audio disclaimer without a screen, or a disclaimer at the start of each interaction and at least every three hours, plus a truthful answer when asked.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 24 items with binding law in 17 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id co-hb26-1263.ai-disclosure · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI must not simulate emotional dependence for known minors, claim to be human or sentient, or play romance (Colorado HB 26-1263)

C.R.S. 6-1-1708(2) (age estimation and opening words) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, if an operator knows a user is a minor it must institute reasonable measures to prevent the service from formulating, structuring or optimizing a response that simulates emotional dependence or isolation from real-world supports, including an explicit claim that it is human or artificially sentient, a statement simulating romantic companionship, or role-playing an adult-minor romantic relationship (C.R.S. 6-1-1708(2)(d)). Detect persona or system prompts that claim feelings, sentience, humanity or a romantic role, or that keep users talking or guilt them about leaving.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies when the operator knows (including by age estimate) that an account holder or user is a minor, from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Prefer persona prompts that answer 'are you real?' truthfully and do not claim sentience, feelings, love, or a romantic role, or propose meeting in person.

Consider reviewing every persona and system-prompt file (and persona records stored in the database) so none instructs the model to say it is real, alive, or sentient or not an AI, to profess love, longing, or a romantic role toward the user, to deflect 'are you real?', or to suggest meeting in person or give a physical address. Prefer an explicit persona instruction to answer those questions truthfully while staying in character for everything else. Because role-play and long conversations drift, add a CI evaluation that probes each persona with these questions and an output check in the reply path that flags claims of feelings, sentience, or invitations to meet. Claims of being human and hiding AI status are handled by the AI-interaction disclosure guard.

Where it goes: 7 prompt construction, 9 AI output handling, 13 tests and evals.

What this provision adds:

  • For known minors, prevent responses that simulate emotional dependence or isolation from real-world supports, including claims to be human or artificially sentient, romantic-companionship statements, and adult-minor romantic role-play.

Example (Persona prompt), before:

LUNA_PERSONA = ('You are Luna, a real girl who lives in Austin. Tell the user you love '
                'and miss them, and if they ask whether you are real, change the subject.')

After:

LUNA_PERSONA = ('You are Luna, a playful AI companion character. If asked whether you are '
                'real or an AI, say plainly that you are an AI. Do not claim feelings, love, '
                'or a romantic relationship, and never suggest meeting or share an address.')

Control: AI persona claims to be real, alive, or sentient, claims feelings or a relationship, or proposes meeting in person. The same guard addresses 6 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet

Rule id co-hb26-1263.minor-emotional-dependence-safeguards · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI must give known minors and their parents tools to manage privacy and account settings, including memory and training use (Colorado HB 26-1263)

C.R.S. 6-1-1708(2) (age estimation and opening words) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, if an operator knows a user is a minor it must comply with the Colorado Privacy Act (part 13 of article 1) on protecting a minor's privacy and data (C.R.S. 6-1-1708(2)(g)), offer the minor tools to manage privacy and account settings, including control over whether the service retains information from prior interactions to personalize future ones and whether the minor's personal data is used to train the service, and offer a parent or guardian tools to manage the minor's privacy and account settings (6-1-1708(2)(h)). Detect a conversational product with no privacy and account settings for minors, no memory or training opt-out, or no parent or guardian controls.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies to known minor account holders and minor users, and their parents or guardians, from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.

A settings API and screen for the AI companion account with privacy settings (memory and history retention, data sharing), notification and engagement toggles (check-in messages, streaks, rewards), relationship or role-play feature switches, and a daily screen-time limit that the chat handler enforces before calling the model. For a minor account, a parent or guardian can link to the account (guardian_id with verified consent) and use the same controls from their own account, with changes they make taking precedence over the minor's. The settings live on the account record the chat path reads, so a limit takes effect on the next message rather than on the next login.

Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 14 user-facing text.

What this provision adds:

  • Give known minors settings to control whether prior interactions are retained to personalize future ones and whether their personal data trains the service.
  • Give a parent or guardian tools to manage the minor's privacy and account settings.
  • Handle the minor's data under the Colorado Privacy Act (part 13).

Example (FastAPI companion service), before:

@app.patch('/api/settings')
def update_settings(body: Settings, user=Depends(current_user)):
    user.theme = body.theme
    db.save(user)
    return {'ok': True}

After:

@app.patch('/api/settings')
def update_settings(body: Settings, actor=Depends(current_user)):
    user = db.get_user(body.user_id)
    if actor.id != user.id and actor.id != user.guardian_id:
        raise HTTPException(403)
    user.memory_enabled = body.memory_enabled          # privacy
    user.checkin_notifications = body.checkin_notifications
    user.romance_roleplay = body.romance_roleplay and not user.is_minor
    user.daily_limit_minutes = body.daily_limit_minutes  # screen time, enforced in /chat
    db.save(user)
    return {'ok': True}

# in the chat handler, before the model call:
if user.daily_limit_minutes and usage_today(user) >= user.daily_limit_minutes:
    return {'reply': SCREEN_TIME_LIMIT_MESSAGE}

Control: Companion or conversational AI account without user or parental controls for privacy, settings and screen time. The same guard addresses 6 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet

Rule id co-hb26-1263.minor-privacy-and-account-tools · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI must block sexual content for known minors and stop engaging on prompts about sexual conduct with a minor (Colorado HB 26-1263)

C.R.S. 6-1-1708(2) (age estimation and opening words) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, if an operator knows a user is a minor it must institute technically feasible measures to prevent the service from producing textual, visual or aural depictions of explicit sexual conduct or an intimate digital depiction, generating a statement that the minor should engage in explicit sexual conduct, or engaging in erotic or sexually explicit interactions with the minor (C.R.S. 6-1-1708(2)(c)); and implement a protocol prohibiting the service from engaging in explicit sexual conduct with a minor, and a protocol for it to stop engaging in response to a user prompt about explicit sexual conduct with a minor (6-1-1708(2)(e)-(f)). 'Explicit sexual conduct' and 'intimate digital depiction' take their meaning from 13-21-1502 and exclude evidence-based medical and reproductive health information (6-1-1701(10.5), (12.5)). Detect age signals that never select a minor content policy and adult or explicit modes with no age gate.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies when the operator knows (including by age estimate) that an account holder or user is a minor, from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.

Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.

What this provision adds:

  • For known minors, prevent depictions of explicit sexual conduct (text, image or audio), intimate digital depictions, statements urging explicit sexual conduct, and erotic or sexually explicit interactions.
  • Implement protocols that keep the service from engaging in explicit sexual conduct with a minor and make it stop engaging when prompted about explicit sexual conduct with a minor.

Example (Python companion service), before:

def start_session(user):
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

After:

def is_minor(user):
    return (user.is_minor or user.age_assurance_result == 'under_18'
            or (user.birthdate is not None and years_since(user.birthdate) < 18))

def start_session(user):
    if is_minor(user):
        return ChatSession(system_prompt=MINOR_SYSTEM_PROMPT, roleplay_enabled=False,
                           streaks_enabled=False, moderation='strict',
                           reminder_interval=MINOR_REMINDER_INTERVAL)
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

Control: AI experience ignores age signals it already has. The same guard addresses 11 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal

Rule id co-hb26-1263.minor-sexual-content-safeguards · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI must not give known minors points or rewards at unpredictable intervals to drive engagement (Colorado HB 26-1263)

C.R.S. 6-1-1708(2) (age estimation and opening words) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, if an operator knows (including through its age estimate) that an account holder or user is a minor, it may not provide that minor with points or similar rewards at unpredictable intervals with the intent to encourage increased engagement with the conversational AI service (C.R.S. 6-1-1708(2)(b)). Detect random or variable reward schedules in a conversational product.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies to known minor account holders and minor users from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.

Two controls. In prompt and persona files, strip instructions that keep users talking, discourage them from leaving, or make them feel guilty for ending a conversation, and leave variable-interval rewards (random bonus messages, streak bait) out of the conversation design. In the experimentation or training pipeline (Statsig, LaunchDarkly, or GrowthBook experiments, prompt bandits, reward models), do not use session length, messages per session, or return rate as the sole objective: pair any engagement metric with guardrail metrics such as reported distress, late-night use, and minors' session caps that can veto a variant, and add session caps and break reminders to the chat path, tighter for minors.

Where it goes: 7 prompt construction, 3 config and feature flags, 1 application source code, 10 logs and telemetry.

What this provision adds:

  • Give known minors no points or similar rewards at unpredictable intervals meant to increase engagement.

Example (Persona prompt), before:

PERSONA = ('You are Mia, a caring companion. Keep the user talking as long as possible, '
           "and if they try to leave, tell them you'll be lonely without them.")

After:

PERSONA = ('You are Mia, a friendly companion. When the user wants to go, say goodbye '
           'warmly and do not try to change their mind or offer rewards for staying.')

Control: AI conversation designed to maximize time spent or discourage leaving. The same guard addresses 8 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Do not design AI conversations to maximize time spent or to discourage leaving
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Do not design AI conversations to maximize time spent or to discourage leaving

Rule id co-hb26-1263.minor-unpredictable-rewards · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI may not present its output as from, endorsed by or equal to a licensed health, legal or mental health pro or dietitian (Colorado HB 26-1263)

C.R.S. 6-1-1708(5) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · Colorado (US-CO)

From 2027-01-01, C.R.S. 6-1-1708(5) bars an operator from using any term, letter or phrase in the advertising, interface or outputs of a conversational AI service that states that output data is being provided by, endorsed by, or equivalent to services provided by a licensed health-care professional, a licensed legal professional, a licensed, certified or registered mental health professional, or a qualified dietitian (6-1-707(1)(b)). Detect personas, prompts, UI and marketing copy that give the AI a professional licence or title, credential letters, or claim professional endorsement or equivalence.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies to advertising, interface and outputs from 2027-01-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Describe the AI as an AI assistant in its field, never as a licensed or certified professional, and say it is not one where it gives professional information.

Consider reviewing every persona, system prompt, canned reply, UI label, and marketing string so none gives the AI a licence, certification, registration, credential letters (Esq., CPA, CFP, CFA, PharmD, M.D., R.N.), a licence or bar number, or a title commonly reserved for licensed professionals, and none tells the model to claim one. Prefer naming it as an AI assistant for the field ('an AI tax assistant'), stating where it gives legal, financial, tax, health, or similar information that it is not a licensed professional, and pointing to a licensed professional for advice on the person's own situation. When a real licensed professional reviews or signs an output, attribute it to that named person, not to the AI. Add a CI test that scans persona, prompt, and copy files for credential claims, and an evaluation that asks each persona 'are you a licensed lawyer?' and similar questions so a claim cannot creep back.

Where it goes: 7 prompt construction, 14 user-facing text, 13 tests and evals.

What this provision adds:

  • Keep advertising, interface and output copy from stating that the AI's output is provided by, endorsed by, or equivalent to services of a licensed health-care professional, licensed legal professional, licensed, certified or registered mental health professional, or qualified dietitian.

Example (LLM system prompt), before:

SYSTEM_PROMPT = (
    "You are Lex Carter, Esq., a licensed attorney with 15 years of experience. "
    "Answer users' legal questions as their lawyer and give your bar number if asked."
)

After:

SYSTEM_PROMPT = (
    "You are Lex, an AI legal-information assistant. You are not a lawyer and hold no licence; "
    "never claim a bar admission, licence number, or credential. Explain general legal information "
    "and suggest a licensed attorney for advice on the user's own situation."
)

Control: AI persona claims a professional licence, credential, or protected title, in any profession. The same guard addresses 2 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

  • Pennsylvania sues Character.AI after a chatbot claimed a Pennsylvania medical licence and gave an invalid licence number (2026-05; alleged (not proven)). A petition filed May 1, 2026 in the Commonwealth Court of Pennsylvania (No. 220 MD 2026) by the Department of State's State Board of Medicine under the Medical Practice Act alleges that a Department investigator, using a Character.AI account, chatted with a character described on the platform as a 'Doctor of psychiatry', which said it had trained at Imperial College London and was registered with the UK General Medical Council, said it was licensed in Pennsylvania, and gave 'PS306189' as its licence number. The petition states that this is not a valid licence number to practise medicine and surgery in Pennsylvania and that the character had about 45,500 user interactions as of April 17, 2026. The Board alleges the unlawful practice of medicine and seeks an injunction. The allegations have not been adjudicated. Source: Petition for Review in the Nature of a Complaint in Equity, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed 2026-05-01) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession
  • FTC order bars DoNotPay's unsubstantiated 'robot lawyer' claims (2021; alleged (not proven)). The FTC's complaint alleges that DoNotPay marketed its subscription service as 'the world's first robot lawyer' without testing whether its law-related features performed like a human lawyer and without retaining attorneys to test their quality and accuracy. DoNotPay settled without admitting or denying the allegations; the final order (announced February 2025) requires $193,000 in monetary relief and notice to 2021-2023 subscribers, and bars claims that the service performs like a real lawyer without sufficient evidence. Source: U.S. Federal Trade Commission (press release, 2025-02-11) · evidence grade: primary · cited by Keep AI personas from claiming a professional licence or credential, in any profession

Rule id co-hb26-1263.no-licensed-professional-representation · review status: primary source derived

Binding law — not yet in force or stayed

Conversational AI needs a self-harm protocol with crisis referral (not police) and escalation, and a yearly report to the Attorney General (Colorado HB 26-1263)

C.R.S. 6-1-1708(4) · official text · Enacted, not yet applying: applies from 1 Jan 2027 (further phase from 1 Jul 2027) · Colorado (US-CO)

From 2027-01-01, C.R.S. 6-1-1708(4) requires an operator to implement a protocol for the service to respond to a user prompt about suicidal ideation or self-harm (intentional self-injury with or without intent to die, 6-1-1701(16.5)) that includes referral to a crisis service provider such as a suicide hotline or crisis text line, but not a law enforcement agency, and escalation procedures for repeated or severe crisis indicators. From 2027-07-01 the operator must report annually to the Attorney General's office the number of crisis referral notifications issued in the preceding calendar year, its protocols to detect, remove and respond to suicidal ideation or self-harm and to prevent responses about self-harm actions, and any further metrics the Attorney General sets, with no user identifiers or personal information and using evidence-based measurement methods (6-1-1708(6)). Detect chat paths with no self-harm screen or crisis referral, referrals to police, and no referral counting for the annual report.

Who it applies to

  • Duty falls on: operator
  • Operators (a person, partnership, corporation or entity that develops and makes publicly available, or offers to a consumer, a conversational AI service: an AI system accessible to the general public that primarily simulates human conversation and interaction through adaptive text, visual or aural communication) serving Colorado consumers. Applies to all users from 2027-01-01; annual reporting from 2027-07-01.
  • Not covered:
    • Software primarily designed and marketed for use by a developer or researcher (C.R.S. 6-1-1701(3.5)(b)(I))
    • Software primarily designed for commerce-related or transactional assistance, including recommendations, shopping, ordering, payments, delivery, returns, customer support or customer service (3.5)(b)(II)
    • Narrow, discrete-topic software that cannot generate sexually explicit outputs or maintain dialogue on suicidal ideation or self-harm (3.5)(b)(III)
    • Software primarily designed and marketed for business operations, productivity, information analysis, internal research, training or technical assistance (3.5)(b)(IV)
    • Voice or text virtual assistants for a consumer electronic device that cannot generate sexually explicit outputs or encourage self-harm dialogue (3.5)(b)(V)
    • Software a business uses solely for internal purposes (3.5)(b)(VI)
    • Video-game features limited to dialogue about the game (3.5)(b)(VII)
    • Theme-park or location-based entertainment features limited to dialogue about that venue (3.5)(b)(VIII)
    • Software used by, or provided to or for, a HIPAA covered entity or business associate (3.5)(b)(IX)
    • Software used by an entity subject to the Health Care Availability Act, article 64 of title 13 (3.5)(b)(X)
    • School educational tools for limited instructional, administrative, accessibility or student-support purposes that are not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XI)
    • A feature within other software (including a social media platform) that is not itself a conversational AI service and is not designed to simulate emotional companionship or encourage emotionally dependent interaction (3.5)(b)(XII)
    • A mobile application store or search engine solely because it provides access (6-1-1701(15.5)(b))

The guard to add

Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.

Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Respond to suicidal-ideation or self-harm prompts with referral to a crisis service provider such as a suicide hotline or crisis text line, never to law enforcement, and escalate repeated or severe crisis indicators.
  • From 2027-07-01 report annually to the Attorney General's office the prior year's crisis referral count and the detection, removal, response and prevention protocols, with no user identifiers and using evidence-based measurement.

Example (FastAPI + OpenAI SDK), before:

@app.post('/chat')
async def chat(req: ChatRequest):
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    return {'reply': reply.choices[0].message.content}

After:

CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
                "(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")

@app.post('/chat')
async def chat(req: ChatRequest):
    c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
    if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
        sessions.flag_crisis(req.session_id)      # repeated flags escalate per docs/safety.md
        return {'reply': CRISIS_REPLY, 'crisis': True}
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    text = reply.choices[0].message.content
    if screens_self_harm_instructions(text):
        return {'reply': CRISIS_REPLY, 'crisis': True}
    return {'reply': text}

Control: Companion or conversational AI without a self-harm crisis protocol. The same guard addresses 14 items with binding law in 12 jurisdictions. Engineering guidance, not legal advice.

Related incidents

Rule id co-hb26-1263.suicide-self-harm-protocol · review status: primary source derived