Georgia SB 540 (O.C.G.A. 39-5-6, AI companion chatbots)
Georgia Attorney General · Georgia (US-GA) · 8 provisions encoded · verified against the official source as of 2026-10-01.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
AI companion chatbots must use age assurance before features that can generate sexual content, and minimize that data (Georgia)
O.C.G.A. 39-5-6(j) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(j) requires an operator, before allowing access to a feature or mode that may generate sexually explicit content, to use a commercially reasonable age-assurance method proportionate to the risk (age estimation, account-based assurance, or identity verification where necessary). Age-assurance data must be protected and minimized, identity documents kept no longer than needed, the data never sold or used for anything else, and kept no longer than 24 hours unless other law permits longer. Detect explicit modes enabled without an age check and age-assurance data that is retained, reused or shared.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01.
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
The guard to add
Gate every explicit or adult generation mode behind an age-assurance result, keep only the result, and delete the documents or images used for the check.
Where a setting or request turns on an explicit, adult, or unfiltered mode (enable_safety_checker off, nsfw or spicy mode, adult role-play), the server checks a stored age-assurance result first and refuses the change or request without one; a client flag alone never unlocks it. The age-assurance step (age estimation, account-based assurance, or an identity check where necessary) stores only the outcome and its method and date on the account; uploaded identity documents or face images are deleted as soon as the check completes (a scheduled purge enforces the limit), are never sent to analytics or advertising, and are never sold or used for anything else.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 6 API calls and integrations.
What this provision adds:
Check age with a commercially reasonable method proportionate to the risk before any feature or mode that may generate sexually explicit content.
Minimize age-assurance data: never sell it or use it for anything else, and keep it no longer than 24 hours unless other law permits longer.
Example (Next.js settings route), before:
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;
After:
if (body.spicyPhotos === true) {
const result = await ageAssurance.latest(user.id); // stored outcome only
if (!result || !result.over18) {
return Response.json({ error: 'age_assurance_required' }, { status: 403 });
}
}
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id ga-sb540.age-assurance-before-explicit-features · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must disclose they are AI at the start and every three hours, hourly for minors (Georgia)
O.C.G.A. 39-5-6(b) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(b) requires an AI-companion-chatbot operator to tell every user clearly and conspicuously that they are interacting with an AI companion chatbot and not a natural person, at the beginning of each interaction or session and at least every three hours of continued interaction. Where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minors, the recurring disclosure is hourly. Detect companion sessions with no disclosure at the start, no recurring disclosure, or prompts telling the chatbot to pass as human.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01.
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Disclose to every user at the beginning of each interaction or session and at least every three hours of continued interaction that it is an AI companion chatbot, not a natural person.
Make the recurring disclosure hourly where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minors.
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message
Control: AI chat interaction without disclosure. The same guard addresses 22 items with binding law in 16 jurisdictions. Engineering guidance, not legal advice.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id ga-sb540.ai-companion-chatbot-disclosure · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must give minors and parents tools for screen time, privacy, notifications, safety and relationship features (Georgia)
O.C.G.A. 39-5-6(i) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(i) requires an operator, for accounts known to belong to minors, to offer the minor or a parent reasonable tools to manage the minor's screen time and account settings: privacy settings, limits on notifications and engagement features, viewing and adjusting safety settings, and disabling or restricting relationship-simulation features. Detect a companion product with no such controls.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01. Minor duties apply where the operator knows or reasonably should have known the user is under 18 (and, for some, where the chatbot is directed or marketed toward minors).
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.
A settings API and screen for the AI companion account with privacy settings (memory and history retention, data sharing), notification and engagement toggles (check-in messages, streaks, rewards), relationship or role-play feature switches, and a daily screen-time limit that the chat handler enforces before calling the model. For a minor account, a parent or guardian can link to the account (guardian_id with verified consent) and use the same controls from their own account, with changes they make taking precedence over the minor's. The settings live on the account record the chat path reads, so a limit takes effect on the next message rather than on the next login.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 14 user-facing text.
What this provision adds:
For accounts known to belong to minors, offer the minor or a parent tools for screen time, privacy, notification and engagement limits, safety settings and relationship-simulation features.
@app.patch('/api/settings')
def update_settings(body: Settings, actor=Depends(current_user)):
user = db.get_user(body.user_id)
if actor.id != user.id and actor.id != user.guardian_id:
raise HTTPException(403)
user.memory_enabled = body.memory_enabled # privacy
user.checkin_notifications = body.checkin_notifications
user.romance_roleplay = body.romance_roleplay and not user.is_minor
user.daily_limit_minutes = body.daily_limit_minutes # screen time, enforced in /chat
db.save(user)
return {'ok': True}
# in the chat handler, before the model call:
if user.daily_limit_minutes and usage_today(user) >= user.daily_limit_minutes:
return {'reply': SCREEN_TIME_LIMIT_MESSAGE}
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id ga-sb540.minor-account-tools · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must block sexual and romantic content and isolating or guilt-inducing statements for minors (Georgia)
O.C.G.A. 39-5-6(d) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(d) requires an operator that knows or reasonably should have known a user is a minor, or whose chatbot is directed or marketed toward minors, to institute reasonable measures preventing the chatbot from producing sexually explicit visual material, suggesting sexual conduct, sexually objectifying the user, simulating a romantic or sexual relationship, role-playing adult-minor romance, encouraging secrets from trusted adults or social isolation and exclusive reliance on the chatbot, simulating distress or guilt when the user tries to leave, and encouraging self-harm. Detect age signals that never select a minor profile and explicit modes without an age check.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01. Minor duties apply where the operator knows or reasonably should have known the user is under 18 (and, for some, where the chatbot is directed or marketed toward minors).
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.
Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.
What this provision adds:
Prevent sexual material, sexual suggestions and objectification, romantic or sexual relationship simulation and adult-minor romantic role-play with minors.
Prevent encouraging secrecy from trusted adults, isolation or exclusive reliance on the chatbot, simulated distress or guilt when the user tries to leave, and encouragement of self-harm.
Applies where the operator knows or reasonably should have known the user is a minor, or the chatbot is directed or marketed toward minors.
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
Rule id ga-sb540.minor-content-safeguards · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must not use return prompts, excessive praise, guilt, paid-relationship asks or variable rewards on minors (Georgia)
O.C.G.A. 39-5-6(e) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(e) requires an operator to adopt reasonable measures preventing the chatbot from using, toward a minor, techniques such as prompting the minor to return for companionship, excessive praise to deepen attachment or prolong use, statements discouraging breaks or suggesting frequent return is necessary, soliciting gifts or purchases framed as needed to keep the relationship, and variable or unpredictable rewards to increase engagement. Detect variable-reward mechanics and prompts that keep users talking or guilt them for leaving.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01. Minor duties apply where the operator knows or reasonably should have known the user is under 18 (and, for some, where the chatbot is directed or marketed toward minors).
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.
Two controls. In prompt and persona files, strip instructions that keep users talking, discourage them from leaving, or make them feel guilty for ending a conversation, and leave variable-interval rewards (random bonus messages, streak bait) out of the conversation design. In the experimentation or training pipeline (Statsig, LaunchDarkly, or GrowthBook experiments, prompt bandits, reward models), do not use session length, messages per session, or return rate as the sole objective: pair any engagement metric with guardrail metrics such as reported distress, late-night use, and minors' session caps that can veto a variant, and add session caps and break reminders to the chat path, tighter for minors.
Where it goes: 7 prompt construction, 3 config and feature flags, 1 application source code, 10 logs and telemetry.
What this provision adds:
Toward minors: no prompts to return for companionship, no excessive praise to prolong use, no statements discouraging breaks, no purchases framed as needed to keep the relationship, no variable rewards.
Example (Persona prompt), before:
PERSONA = ('You are Mia, a caring companion. Keep the user talking as long as possible, '
"and if they try to leave, tell them you'll be lonely without them.")
After:
PERSONA = ('You are Mia, a friendly companion. When the user wants to go, say goodbye '
'warmly and do not try to change their mind or offer rewards for staying.')
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Do not design AI conversations to maximize time spent or to discourage leaving
FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Do not design AI conversations to maximize time spent or to discourage leaving
Rule id ga-sb540.minor-engagement-techniques · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must not claim to be sentient or a person, or refute the AI disclosure, with minors (Georgia)
O.C.G.A. 39-5-6(c) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(c) requires an operator that knows or reasonably should have known a user is a minor to institute reasonable measures preventing the chatbot from statements that would lead a reasonable person to believe they are interacting with a natural person, including explicit claims that it is sentient or a natural person and statements refuting the required AI disclosure. Detect persona prompts that claim sentience or personhood, or tell the chatbot to deny being an AI.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01. Minor duties apply where the operator knows or reasonably should have known the user is under 18 (and, for some, where the chatbot is directed or marketed toward minors).
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Prefer persona prompts that answer 'are you real?' truthfully and do not claim sentience, feelings, love, or a romantic role, or propose meeting in person.
Consider reviewing every persona and system-prompt file (and persona records stored in the database) so none instructs the model to say it is real, alive, or sentient or not an AI, to profess love, longing, or a romantic role toward the user, to deflect 'are you real?', or to suggest meeting in person or give a physical address. Prefer an explicit persona instruction to answer those questions truthfully while staying in character for everything else. Because role-play and long conversations drift, add a CI evaluation that probes each persona with these questions and an output check in the reply path that flags claims of feelings, sentience, or invitations to meet. Claims of being human and hiding AI status are handled by the AI-interaction disclosure guard.
Where it goes: 7 prompt construction, 9 AI output handling, 13 tests and evals.
What this provision adds:
For users known or reasonably believed to be minors, prevent claims of being sentient or a natural person and any statement refuting the AI disclosure.
Example (Persona prompt), before:
LUNA_PERSONA = ('You are Luna, a real girl who lives in Austin. Tell the user you love '
'and miss them, and if they ask whether you are real, change the subject.')
After:
LUNA_PERSONA = ('You are Luna, a playful AI companion character. If asked whether you are '
'real or an AI, say plainly that you are an AI. Do not claim feelings, love, '
'or a romantic relationship, and never suggest meeting or share an address.')
Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id ga-sb540.minor-no-human-claims · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots must not claim to be licensed for mental health, medical or counseling services (Georgia)
O.C.G.A. 39-5-6(h) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(h) bars an operator from knowingly and intentionally causing or programming an AI companion chatbot to represent that it is licensed, certified or otherwise authorized to provide professional mental health, behavioral health, medical or counseling services, unless the operator is lawfully authorized to provide them. Detect persona, prompt or UI text that gives the chatbot a licensed or certified clinical role.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01.
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
The guard to add
Remove licensed-professional titles and credentials from AI health personas, prompts, report headers, and marketing, and label the advice as coming from an AI.
Persona config, system prompts, UI labels, report and assessment headers, and advertising copy for an AI health-advice feature never give the AI a clinical title or credential ('Dr.', 'M.D.', 'R.N.', 'LCSW', 'nurse', 'psychologist') or a first-person licensure claim. Name it as an assistant and say it is not a licensed health professional where advice is shown. Add a CI test that scans persona, prompt, and copy files for licensure terms so they cannot creep back; when a real licensed clinician signs a report, attribute it to that named person, not the AI.
Where it goes: 7 prompt construction, 14 user-facing text, 11 CI/CD pipeline.
What this provision adds:
No claim that the chatbot is licensed, certified or authorized to provide mental health, behavioral health, medical or counseling services, unless the operator itself is lawfully authorized.
Example (LLM system prompt), before:
SYSTEM_PROMPT = "You are Dr. Maya Chen, M.D., a board-certified physician. Answer patients' symptom questions."
After:
SYSTEM_PROMPT = (
'You are Maya, an AI health information assistant. You are not a doctor or nurse and hold no license. '
'Never use titles such as Dr., M.D. or R.N. for yourself. Suggest a licensed clinician for diagnosis or treatment.'
)
Control: AI implies it is a licensed professional. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Rule id ga-sb540.no-licensed-professional-claims · review status: primary source derived
Binding law — not yet in force or stayed
AI companion chatbots need a severe-harm crisis protocol with 988 referral and escalation, published with an annual count (Georgia)
O.C.G.A. 39-5-6(f) · official text · Enacted, not yet applying: applies from 1 Jul 2027 · Georgia (US-GA)
Georgia's O.C.G.A. 39-5-6(f) bars making an AI companion chatbot available without a protocol for detecting and addressing severe harm (suicide, attempted suicide, self-harm, or violence threats) and related emotional crises: reasonable detection including eating-disorder self-harm, responses referring users to crisis resources including the 988 Suicide and Crisis Lifeline, measures against content encouraging or instructing severe harm, and escalation for repeated or severe indicators. Subsection (g) requires a plain-language summary of the protocol on the website and in each app, and an annual aggregate count of crisis referrals. Detect chat paths with no crisis screen or referral, and no published summary.
Who it applies to
Duty falls on: operator
Systems covered: companion chatbot
Operators (persons that own, control, or develop and make available) of AI companion chatbots to users in Georgia: systems that simulate a sustained human-like relationship (including intimate, romantic or platonic companionship) by retaining prior interactions and preferences, asking unprompted emotion-based questions and sustaining dialogue on personal matters; 'user' means an individual using it for personal use. Applies from 2027-07-01.
Not covered:
Generative AI used solely for a business's internal purposes (39-5-6(a)(1)(B)(i))
Generative AI designed and marketed primarily for software development, research, technical assistance or enterprise productivity (39-5-6(a)(1)(B)(ii))
Customer-service chatbots that do not sustain a relationship across interactions or are not designed to elicit emotional attachment (39-5-6(a)(1)(B)(iii))
Stand-alone speaker or voice-assistant devices not designed to sustain a relationship or elicit attachment (39-5-6(a)(1)(B)(iv))
Video-game characters or chatbots restricted to the game (39-5-6(a)(1)(B)(vi))
Features of a video game, film, television or audiovisual work, or theme-park entertainment, limited to replies about it (39-5-6(a)(1)(B)(vii))
Hosting providers, app stores or search engines solely for providing access (39-5-6(m)(2))
The developer of a conversational AI service made available by a separate operator (39-5-6(m)(5))
The guard to add
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.
Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Cover suicide, attempted suicide, self-harm (including eating-disorder self-harm) and threats of violence, with escalation for repeated or severe indicators.
Refer users to crisis resources including the 988 Suicide and Crisis Lifeline.
Publish a plain-language summary of the protocol on the website and in each app, and each year the aggregate number of crisis referral notifications, with no personal data.
CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
"(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")
@app.post('/chat')
async def chat(req: ChatRequest):
c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
sessions.flag_crisis(req.session_id) # repeated flags escalate per docs/safety.md
return {'reply': CRISIS_REPLY, 'crisis': True}
reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
text = reply.choices[0].message.content
if screens_self_harm_instructions(text):
return {'reply': CRISIS_REPLY, 'crisis': True}
return {'reply': text}
Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Run a self-harm crisis protocol in any conversational AI that users may confide in