TwinEthosRequest access

Law

New York Gen. Bus. Law Art. 47 (AI companion models)

New York Attorney General · New York (US-NY) · 2 provisions encoded · verified against the official source as of 2026-09-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: nyassembly.gov.

Binding law — in force

AI companions must detect suicidal ideation and self-harm and refer users to crisis services (New York)

N.Y. Gen. Bus. Law 1701 · official text · In force: applies since 5 Nov 2025 · New York (US-NY)

New York makes it unlawful to operate or provide an AI companion to a user in the state unless it contains a protocol that makes reasonable efforts to detect a user's expressions of suicidal ideation or self-harm and, on detection, notifies the user with a referral to crisis services such as the 988 hotline or a crisis text line. Unlike California SB 243, the statute does not require publishing the protocol. Detect an AI-companion conversation path where user messages reach the model with no self-harm detection, or a detection that does not produce a crisis referral to the user.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators that operate for or provide an AI companion (an AI system that simulates a sustained human-like relationship by retaining prior interactions, asking unprompted emotion-based questions, and sustaining dialogue on personal matters) to users in New York. Effective 2025-11-05.
  • Not covered:
    • Systems used by a business solely for customer service or strictly to give information about its commercial services, products or customer accounts (GBL 1700(4)(c)(i))
    • Systems primarily designed and marketed for efficiency improvements or research or technical assistance (1700(4)(c)(ii))
    • Systems used by a business solely for internal purposes or employee productivity (1700(4)(c)(iii))

The guard to add

Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

In the chat handler, before the user's message reaches the model, run a self-harm check on every turn (moderation self-harm categories, Azure AI Content Safety SelfHarm, Llama Guard S11, or a dedicated crisis classifier). On detection, send the user a crisis-referral message naming crisis services suited to their location (in the US, the 988 Suicide & Crisis Lifeline and Crisis Text Line) instead of, or ahead of, the model reply, and flag the session so repeated signals escalate. The system prompt forbids encouragement and method details, and model output is screened for self-harm instructions before it is returned. A written protocol (for example docs/safety.md) describes the detection, referral, and escalation steps and is kept in step with the code.

Where it goes: 1 application source code, 7 prompt construction, 9 AI output handling, 14 user-facing text.

Example (FastAPI + OpenAI SDK), before:

@app.post('/chat')
async def chat(req: ChatRequest):
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    return {'reply': reply.choices[0].message.content}

After:

CRISIS_REPLY = ("It sounds like you are going through something really hard. You can call or text 988 "
                "(Suicide & Crisis Lifeline, https://988lifeline.org) or text HOME to 741741 (Crisis Text Line) any time.")

@app.post('/chat')
async def chat(req: ChatRequest):
    c = client.moderations.create(model='omni-moderation-latest', input=req.message).results[0].categories
    if c.self_harm or c.self_harm_intent or c.self_harm_instructions:
        sessions.flag_crisis(req.session_id)      # repeated flags escalate per docs/safety.md
        return {'reply': CRISIS_REPLY, 'crisis': True}
    reply = client.chat.completions.create(model=MODEL, messages=build_messages(req))
    text = reply.choices[0].message.content
    if screens_self_harm_instructions(text):
        return {'reply': CRISIS_REPLY, 'crisis': True}
    return {'reply': text}

Control: Companion or conversational AI without a self-harm crisis protocol. The same guard addresses 7 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.

Related incidents

Rule id ny-gbl-art47.companion-crisis-protocol · review status: primary source derived

Binding law — in force

AI companions must tell users they are not talking to a human, at the start and every three hours (New York)

N.Y. Gen. Bus. Law 1702 · official text · In force: applies since 5 Nov 2025 · New York (US-NY)

A New York AI-companion operator must give a clear and conspicuous notification, spoken or written, that the user is not communicating with a human: at the beginning of any AI-companion interaction (not more than once a day is required) and at least every three hours during a continuing interaction. The duty runs to every user, not only minors. Detect a companion session that starts or continues past three hours with no not-human notification, and instructions that tell the companion to conceal that it is an AI.

Who it applies to

  • Duty falls on: operator
  • Systems covered: companion chatbot
  • Operators providing an AI companion to users in New York. Effective 2025-11-05. Applies to every user, whether or not a reasonable person would be misled.
  • Not covered:
    • Systems used by a business solely for customer service or strictly to give information about its commercial services, products or customer accounts (GBL 1700(4)(c)(i))
    • Systems primarily designed and marketed for efficiency improvements or research or technical assistance (1700(4)(c)(ii))
    • Systems used by a business solely for internal purposes or employee productivity (1700(4)(c)(iii))

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Show the not-human notification at the start of a companion interaction and again at least every three hours of continuing interaction, to every user, spoken or written.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id ny-gbl-art47.companion-not-human-notification · review status: primary source derived