Binding law — in force
Verify users are 18+ before access to a tool that creates artificial sexual material, keeping no identity data (Texas CPRC 129B.002(a-1), (b))
From 2025-09-01, a commercial entity that operates an Internet website with a publicly accessible tool for creating artificial sexual material harmful to minors, or otherwise makes publicly available an application for creating such material, must use reasonable age verification methods (digital identification, or a commercial age verification system using government-issued identification or transactional data, 129B.003) to verify that an individual attempting to access the tool is 18 or older (Civ. Prac. & Rem. Code 129B.002(a-1)). The entity or its third-party verifier may not retain any identifying information of the individual (129B.002(b)). The duty does not apply to an entity whose acknowledged terms prohibit generating such material and which takes affirmative technological steps to limit its creation (129B.002(a-2)). Detect explicit or adult generation modes switched on with no age gate.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
- Lane
- Binding law — in force In force: applies since 1 Sep 2025
- Official source
- Tex. Civ. Prac. & Rem. Code 129B.002(b) · captured 4 Oct 2026 · anchor hash (SHA-256)
3218187d35fb…· 6 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Provider-side moderation settings configured outside the repository
- The age gate may sit in middleware or the settings route that controls the flag; follow the flag before reporting. An entity relying on the 129B.002(a-2) exception (acknowledged terms prohibiting the material, plus filt…
Who it applies to
- Duty falls on: provider, operator
- Commercial entities that operate a website with a publicly accessible tool, or make publicly available an application, for creating artificial sexual material harmful to minors (computer-generated sexual material in which a person is recognizable as an actual person, produced with AI or other software), where Texas law governs. Applies from 2025-09-01. Not applicable to an entity relying on the (a-2) terms-and-filters exception; whether a tool is one 'for creating' such material and whether the exception's steps suffice are human determinations.
- Not covered:
- A commercial entity whose terms and conditions or use policies, acknowledged before access, prohibit generating artificial sexual material harmful to minors, and which takes affirmative technological steps to limit its creation (such as training the application to identify likely sexual material, effective reporting tools, filtering likely sexual material or AI-generated sexually explicit content before it is shown, or filtering sexually explicit images from training datasets) (129B.002(a-2); 129B.0045(b))
- Bona fide news or public interest broadcasts, website videos, reports or events; the rights of a news-gathering organization (129B.005(a))
- Internet service providers, search engines and cloud service providers solely for providing access or connection to content not under their control, to the extent not responsible for creating it (129B.005(b))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Gate every explicit or adult generation mode behind an age-assurance result, keep only the result, and delete the documents or images used for the check.
Where a setting or request turns on an explicit, adult, or unfiltered mode (enable_safety_checker off, nsfw or spicy mode, adult role-play), the server checks a stored age-assurance result first and refuses the change or request without one; a client flag alone never unlocks it. The age-assurance step (age estimation, account-based assurance, or an identity check where necessary) stores only the outcome and its method and date on the account; uploaded identity documents or face images are deleted as soon as the check completes (a scheduled purge enforces the limit), are never sent to analytics or advertising, and are never sold or used for anything else.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 6 API calls and integrations.
What this provision adds:
- Use a reasonable age verification method: digital identification, or a commercial age verification system relying on government-issued identification or public or private transactional data (a self-declared age does not count).
- Neither the entity nor its third-party verifier may retain any identifying information of the individual; keep only the verification outcome.
- Alternatively (129B.002(a-2)): require acknowledged terms prohibiting artificial sexual material harmful to minors, and take technological steps to limit it (classifiers, reporting tools, filtering sexual output before display and explicit images from training data).
Example (Next.js settings route), before:
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;After:
if (body.spicyPhotos === true) {
const result = await ageAssurance.latest(user.id); // stored outcome only
if (!result || !result.over18) {
return Response.json({ error: 'age_assurance_required' }, { status: 403 });
}
}
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;Control: Feature that can generate sexually explicit content opens without age assurance, or age-assurance data is kept or reused. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id tx-hb581.age-verification-for-sexual-material-tools · review status: primary source derived