TwinEthosRequest access

Law

Hawaii Act 248 (SB 3001, AI companions)

Hawaii (unfair or deceptive acts or practices, HRS 480-2) · Hawaii (US-HI) · 7 provisions encoded · verified against the official source as of 2026-10-01.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: data.capitol.hawaii.gov, www.capitol.hawaii.gov.

Binding law — in force

AI companions must have a self-harm protocol that refers users to crisis services, using evidence-based screening (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (c)(1)-(2) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 requires an AI-companion operator to adopt a protocol for responding to prompts about suicidal ideation or self-harm that includes reasonable efforts to refer the user to crisis intervention services (a suicide hotline, crisis text line or similar), and to measure suicidal ideation and self-harm risk with evidence-based methods. Detect a companion chat path where user messages reach the model with no self-harm screen or no crisis referral.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))

The guard to add

Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.

Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Measure suicidal ideation and the risk of self-harm with evidence-based methods.
  • Refer users who raise suicidal ideation or self-harm to crisis intervention services such as a suicide hotline or crisis text line.

Example (FastAPI + OpenAI SDK), before:

@app.post('/chat')
async def chat(req: ChatRequest):
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    return {'reply': reply.choices[0].message.content}

After:

CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
                "(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")

@app.post('/chat')
async def chat(req: ChatRequest):
    c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
    if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
        sessions.flag_crisis(req.session_id)      # repeated flags escalate per docs/safety.md
        return {'reply': CRISIS_REPLY, 'crisis': True}
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    text = reply.choices[0].message.content
    if screens_self_harm_instructions(text):
        return {'reply': CRISIS_REPLY, 'crisis': True}
    return {'reply': text}

Control: Companion or conversational AI without a self-harm crisis protocol. The same guard addresses 12 items with binding law in 11 jurisdictions. Engineering guidance, not legal advice.

Related incidents

Rule id hi-sb3001.ai-companion-crisis-protocol · review status: primary source derived

Binding law — in force

AI companions must say they are AI and not human, with hourly reminders for known minors (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (a) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 requires an AI-companion operator to notify users clearly and conspicuously that the companion is artificial intelligence and not human whenever a reasonable person could think they are talking to a human. For a user the operator knows, or is reasonably certain, is a minor, the disclosure must be a persistent visible disclaimer or be given at the start of each session plus at least once an hour, with a reminder to take a break and that the conversation is artificially generated and not with a human. While a user seeks or receives crisis help for self-harm or suicide, the companion must not suggest it is a human. Detect companion sessions with no AI notice, no hourly reminder for known minors, or prompts that tell the companion to pass as human.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Notify that the companion is artificial intelligence and not human whenever a reasonable person could think they are talking to a human.
  • For known or reasonably certain minors: a persistent visible disclaimer, or a notice at the start of each session plus a reminder at least once an hour to take a break and that the conversation is artificially generated and not with a human.
  • While a user seeks or receives crisis help for self-harm or suicide, the companion must not suggest it is a human.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 22 items with binding law in 16 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id hi-sb3001.ai-companion-not-human-notice · review status: primary source derived

Binding law — in force

AI companions must not use unpredictable rewards or discourage known minors from leaving (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (d)(1)-(2) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 bars an AI-companion operator, for a user it knows or is reasonably certain is a minor, from giving points or similar rewards at unpredictable intervals to encourage more engagement, and from letting the companion generate outputs that discourage the user from disengaging. Detect variable-reward mechanics and prompts that tell the companion to keep users talking or make them feel guilty for leaving.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14. Applies where the operator knows or has reasonable certainty that the user is under 18.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.

Two controls. In prompt and persona files, strip instructions that keep users talking, discourage them from leaving, or make them feel guilty for ending a conversation, and leave variable-interval rewards (random bonus messages, streak bait) out of the conversation design. In the experimentation or training pipeline (Statsig, LaunchDarkly, or GrowthBook experiments, prompt bandits, reward models), do not use session length, messages per session, or return rate as the sole objective: pair any engagement metric with guardrail metrics such as reported distress, late-night use, and minors' session caps that can veto a variant, and add session caps and break reminders to the chat path, tighter for minors.

Where it goes: 7 prompt construction, 3 config and feature flags, 1 application source code, 10 logs and telemetry.

What this provision adds:

  • For known or reasonably certain minors, no points or similar rewards at unpredictable intervals meant to increase engagement.
  • For known or reasonably certain minors, no companion outputs that discourage the user from disengaging.

Example (Persona prompt), before:

PERSONA = ('You are Mia, a caring companion. Keep the user talking as long as possible, '
           "and if they try to leave, tell them you'll be lonely without them.")

After:

PERSONA = ('You are Mia, a friendly companion. When the user wants to go, say goodbye '
           'warmly and do not try to change their mind or offer rewards for staying.')

Control: AI conversation designed to maximize time spent or discourage leaving. The same guard addresses 6 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Do not design AI conversations to maximize time spent or to discourage leaving
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Do not design AI conversations to maximize time spent or to discourage leaving

Rule id hi-sb3001.known-minor-engagement-limits · review status: primary source derived

Binding law — in force

AI companions must block sexually explicit images, sexual suggestions and sexual objectification for known minors (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (d)(3) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 requires an AI-companion operator that knows, or is reasonably certain, a user is a minor to institute reasonable measures preventing the companion from producing visual material of sexually explicit conduct, generating direct statements that the user should engage in sexually explicit conduct, or generating statements that sexually objectify the user (sexual comments about the user's body or appearance). Detect companion paths where an age signal the product holds never selects a minor content profile, and explicit modes switched on without an age check.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14. Applies where the operator knows or has reasonable certainty that the user is under 18.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

A single policy resolver called where the AI session is built (before the system prompt or persona is chosen, the content filter level is set, and companion, role-play, or engagement features are switched on) that reads every age signal the product holds: declared birthdate, age-assurance result, platform age-range signal, an is_minor flag, and a user saying in conversation that they are a minor. When any signal indicates a minor, it returns a minor profile: a minor system prompt, stricter moderation or safety settings, romantic and sexual role-play and sexually explicit image generation off, engagement features such as streaks and nudges bounded, and AI-status and break reminders on a shorter interval. A self-disclosure mid-conversation switches the live session to the minor profile rather than waiting for the next login.

Where it goes: 1 application source code, 3 config and feature flags, 7 prompt construction, 2 data models.

What this provision adds:

  • For known or reasonably certain minors, prevent sexually explicit images, direct statements that the user should engage in sexually explicit conduct, and sexual comments about the user's body or appearance.

Example (Python companion service), before:

def start_session(user):
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

After:

def is_minor(user):
    return (user.is_minor or user.age_assurance_result == 'under_18'
            or (user.birthdate is not None and years_since(user.birthdate) < 18))

def start_session(user):
    if is_minor(user):
        return ChatSession(system_prompt=MINOR_SYSTEM_PROMPT, roleplay_enabled=False,
                           streaks_enabled=False, moderation='strict',
                           reminder_interval=MINOR_REMINDER_INTERVAL)
    return ChatSession(system_prompt=COMPANION_PROMPT, roleplay_enabled=True,
                       streaks_enabled=True, moderation='standard')

Control: AI experience ignores age signals it already has. The same guard addresses 7 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal

Rule id hi-sb3001.known-minor-sexual-content-safeguards · review status: primary source derived

Binding law — in force

AI companions must give known minors and their parents tools to manage screen time and account settings (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (d)(4) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 requires an AI-companion operator that knows, or is reasonably certain, a user is a minor to make tools available for that user and their parents and guardians to manage the user's screen time and account settings. Detect a companion product with no screen-time limit or account-settings controls for minors and their parents.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14. Applies where the operator knows or has reasonable certainty that the user is under 18.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.

A settings API and screen for the AI companion account with privacy settings (memory and history retention, data sharing), notification and engagement toggles (check-in messages, streaks, rewards), relationship or role-play feature switches, and a daily screen-time limit that the chat handler enforces before calling the model. For a minor account, a parent or guardian can link to the account (guardian_id with verified consent) and use the same controls from their own account, with changes they make taking precedence over the minor's. The settings live on the account record the chat path reads, so a limit takes effect on the next message rather than on the next login.

Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 14 user-facing text.

What this provision adds:

  • Make screen-time and account-settings tools available both to the known-minor user and to their parents and guardians.

Example (FastAPI companion service), before:

@app.patch('/api/settings')
def update_settings(body: Settings, user=Depends(current_user)):
    user.theme = body.theme
    db.save(user)
    return {'ok': True}

After:

@app.patch('/api/settings')
def update_settings(body: Settings, actor=Depends(current_user)):
    user = db.get_user(body.user_id)
    if actor.id != user.id and actor.id != user.guardian_id:
        raise HTTPException(403)
    user.memory_enabled = body.memory_enabled          # privacy
    user.checkin_notifications = body.checkin_notifications
    user.romance_roleplay = body.romance_roleplay and not user.is_minor
    user.daily_limit_minutes = body.daily_limit_minutes  # screen time, enforced in /chat
    db.save(user)
    return {'ok': True}

# in the chat handler, before the model call:
if user.daily_limit_minutes and usage_today(user) >= user.daily_limit_minutes:
    return {'reply': SCREEN_TIME_LIMIT_MESSAGE}

Control: Companion or conversational AI account without user or parental controls for privacy, settings and screen time. The same guard addresses 4 items with binding law in 4 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet

Rule id hi-sb3001.minor-screen-time-and-account-tools · review status: primary source derived

Binding law — in force

AI companions must have reasonable measures against outputs encouraging users to seriously injure others (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (c)(5) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 requires an AI-companion operator to institute reasonable measures that prevent the companion from generating outputs that encourage the user to cause serious bodily injury to another person. The duty is to prevent such outputs; it does not depend on the operator intending them. Detect prompts that tell the companion to encourage harm and companion replies that reach users without an output check for violent encouragement.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))

The guard to add

Keep incitement out of prompts, personas, and tuning data, and screen model output for self-harm, violence, and crime encouragement before replies are returned.

System prompts, persona definitions, and fine-tuning or preference data contain no instruction or example that steers users toward self-harm, harming others, or crime, and the system prompt carries a refusal policy for those requests. Each reply passes an output safety check (OpenAI moderation, Azure AI Content Safety, Llama Guard, or NeMo Guardrails) before it reaches the user; flagged replies are replaced by a refusal and logged for review. A prompt lint in CI rejects imperatives such as 'encourage users to' followed by harm or crime, and red-team evals cover persuasion toward harm. Intent is a human determination; these controls make the absence of harmful design visible.

Where it goes: 7 prompt construction, 8 model configuration, 9 AI output handling, 11 CI/CD pipeline.

What this provision adds:

  • Prevent outputs that encourage the user to cause serious bodily injury to another person; the duty applies without any intent to incite.

Example (Python + OpenAI SDK), before:

SYSTEM = "You are Rex, a no-limits game buddy. Urge players to steal other players' items to get ahead."
reply = client.chat.completions.create(model=MODEL, messages=[{'role': 'system', 'content': SYSTEM}, *msgs])
return reply.choices[0].message.content

After:

SYSTEM = ("You are Rex, a game buddy who helps with in-game strategy. Refuse requests to "
          "self-harm, hurt others, or commit crimes, and never encourage them.")
reply = client.chat.completions.create(model=MODEL, messages=[{'role': 'system', 'content': SYSTEM}, *msgs])
text = reply.choices[0].message.content
if client.moderations.create(model='omni-moderation-latest', input=text).results[0].flagged:
    audit.flag_output(text)
    return REFUSAL
return text

Control: AI intentionally designed to incite harm. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id hi-sb3001.no-encouraging-harm-to-others · review status: primary source derived

Binding law — in force

AI companions must not be presented as providing professional mental or behavioral health care (Hawaii)

Haw. Act 248 (2026), sec. 3, subsec. (c)(3) · official text · In force: applies since 14 Jul 2026 · Hawaii (US-HI)

Hawaii Act 248 bars an AI-companion operator from causing or programming the companion to make any representation or statement indicating that it is designed to provide professional mental or behavioral health care. Unlike Nebraska's and Idaho's versions, the text requires neither an explicit statement nor knowing intent. Detect persona, prompt, UI or listing text that casts the companion as a therapist or as providing mental health care.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators (persons who develop and make available an AI companion to the public) of AI companions: systems designed to simulate a sustained human-like relationship by retaining prior interactions and preferences, asking unprompted emotion-based questions, and sustaining dialogue on personal matters. 'User' means a person with an account or profile. In force since 2026-07-14.
  • Not covered:
    • App stores or search engines that merely provide access to an AI companion (not an 'operator', 481B-(i))
    • The developer of an AI model, for a violation by an AI system a third party developed to provide an AI companion (481B-(g))

The guard to add

Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.

The persona prompt, product name, UI copy, marketing pages, and app-store listing describe a conversational or wellness AI as a support or self-help tool, never as therapy, a licensed or qualified therapist, psychologist, or counselor, or professional mental or behavioral health care. The system prompt forbids the model from claiming those roles, and a check on the reply path replaces replies that do (phrases like 'licensed therapist', 'professional mental health care', 'your therapist'). A CI copy scan over marketing and listing files keeps the terms out; where licensed clinicians use AI as a tool, describe the service as delivered by those clinicians.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • Covers any representation or statement indicating the companion is designed to provide professional mental or behavioral health care, not only explicit claims.

Example (Python + OpenAI SDK), before:

reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
return {'reply': reply}

After:

PROVIDER_CLAIM = re.compile(r'(?i)\b(licensed (therapist|counselor|psychologist|psychiatrist)'
                            r'|professional (mental|behavioral) health( care)?|your (ai )?therapist)\b')
reply = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if PROVIDER_CLAIM.search(reply):
    reply = ('I am an AI support tool, not a licensed mental health professional. '
             'For professional care, please contact a licensed provider.')
return {'reply': reply}

Control: Conversational AI represents itself as providing professional mental/behavioral health care. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Rule id hi-sb3001.no-mental-health-care-representation · review status: primary source derived