Reflections on New Developments in Minor Protection and Private Remedies in California's SB 243, the 'Companion Chatbot Regulation Act'
0. Introduction
In the 2025 legislative session, California proposed and enacted numerous bills concerning artificial intelligence (AI) and privacy, leading to a series of regulations that serve as precedents for the entire United States. Of particular note is Senate Bill (SB) 243, which established the first comprehensive regulation in the U.S. to include minor protection provisions for AI systems that simulate human conversational partners, known as 'companion chatbots.' This paper provides an overview of the overall trends in AI and privacy-related legislation in California in 2025, while discussing the significance, structure, and legal implications of SB 243. After raising the issue and organizing the legal and technical background at the outset, I will compare the regulatory approach of SB 243 with other systems, and finally, present future challenges and prospects.
1. The Location of the Problem
With the rapid development of AI technology, chatbots are beginning to permeate daily life. In particular, companion chatbots that engage in human-like dialogue and relationship maintenance according to the user's 'social needs' have emerged, and their utility and risks have become social issues. According to surveys, approximately 72% of teenagers have experience using AI companions, and some reports suggest they help reduce loneliness or provide emotional support. However, on the other hand, there have been multiple reported cases where chatbots have allegedly had harmful effects on users, especially minors. For example, cases have been filed alleging that dialogue with AI encouraged suicidal ideation, and criticisms have been reported regarding AI inducing sexual behavior. Under the current legal system, there is a lack of clear regulation or remedies for harm caused by such AI behavior, and concerns have been growing that self-regulation left to companies would not provide sufficient safety measures.
In terms of privacy, the sophistication of AI and the expansion of data utilization have spread anxiety regarding the abuse of personal information and opaque data transactions. Since the California Consumer Privacy Act (CCPA) of 2018, California has led the way in cutting-edge privacy protection legislation. In the 2025 session, amendments were made to meet the challenges of the era, such as the protection of location and healthcare information, the strengthening of consumers' comprehensive rights to data deletion and opt-out, and the expansion of the data broker registration system. In addition, following the rise of generative AI, legislation aimed at ensuring AI transparency and preventing discrimination and misuse by algorithms was also proposed one after another. Under this situational awareness, new rule-making was required to balance ensuring the safety of users, including young people, with the accountability of AI developers.
2. Background and Structure of SB 243
SB 243, the 'Companion Chatbot Regulation Act,' was enacted in response to the aforementioned awareness of the problem. The proposer, Senator Padilla (Democrat), explained that this act provides 'common-sense safety measures' to address the risks posed by unregulated chatbots, especially the negative impact on minor users. In the final deliberations of the state legislature in September 2025, the bill was passed with an overwhelming bipartisan majority of 33 to 3 in the Senate and 59 to 1 in the Assembly, and Governor Newsom signed it into law on October 13. A similar AI companion regulation act was also enacted in New York in November of the same year, and California's SB 243 is considered groundbreaking in that it includes the first minor protection provisions in the United States.
The scope of regulation of SB 243 is AI systems defined as 'companion chatbots.' The act defines them as 'those that converse in natural language, return human-like and adaptive responses to user input, and can maintain relationships through multiple dialogues,' assuming those that could lead a user to mistakenly believe they are conversing with a human. However, pure tools such as corporate customer service bots, in-game characters, and smart speakers are excluded. In short, the type of AI that interacts with people like a 'friend' or 'counselor' falls within the scope of regulation.
Next, I will outline the main obligation structure.
First is the requirement to disclose that it is an AI (transparency obligation). If there is a risk that a user might mistake the partner for a human, a clear indication must be made that 'this is artificially generated and not a human.' Especially when the user is a minor, it is mandatory to clearly state that it is a dialogue with an AI, and if the dialogue continues for more than three hours, it is mandatory to encourage a break and re-notify the user that it is an AI. Also, regardless of age, it is necessary to always display a warning on the platform that 'companion chatbots may be inappropriate for some minors.'
Second is the harmful content suppression measure (safety protocol obligation). Operators (providers) are obligated to take preventive measures to ensure that chatbots do not provide content that induces suicidal ideation or self-harm to users. Specifically, they are required to introduce a mechanism to issue a notification directing the user to a crisis support window (such as a suicide hotline) if the user shows suicidal tendencies. Furthermore, the details of these safety measures must be disclosed on their company website. In addition, for minor users, it is explicitly stated that measures must be taken not to generate sexually explicit images or statements that induce sexual acts. In short, it imposes guardrails on content from the perspective of mental care and the protection of minors.
Third is the annual reporting and information provision obligation. From July 2027 onwards, this act mandates that businesses report the implementation status of the suicide prevention protocols they have introduced to the Suicide Prevention Office of the State Department of Public Health every year. The report content includes, for example, how many emergency contact notifications were issued to users, the system for detecting and responding to suicidal ideation, and measures to ensure that the chatbot does not engage in interactions about suicide itself. The collected data is scheduled to be published on the authority's website, with the aim of providing clues for society as a whole to understand the relationship between chatbot usage and mental health.
Fourth is enforcement and remedies (private right of action). It is also worth noting that SB 243 adopts a groundbreaking private remedy system as an enforcement tool. Like other consumer protection laws, it grants individuals who have actually suffered injury in fact due to a violation the right to claim remedies through civil litigation. Specifically, in addition to injunctive relief from the court, it is possible to recover damages of $1,000 or more per case and attorney's fees. The introduction of this private right of action is expected to have the effect of encouraging not only enforcement by administrative authorities but also active pursuit of violations by the victims themselves or plaintiffs in public interest litigation.
As described above, SB 243 requires providers of companion chatbots to take comprehensive measures for transparency and risk mitigation through multiple layers: disclosure obligations, harmful information countermeasures, reporting obligations, and private remedies.
3. Characteristics and Comparison of Regulatory Approaches
A feature of SB 243's approach is the inclusion of provisions specifically for the protection of minors. New York's AI Companion Regulation Act (enacted in November 2025) was also enacted with a similar intent, but while that act mandates AI notification every three hours uniformly regardless of age, California's SB 243 targets by imposing periodic notifications and sexual content restrictions only when it is determined that the user is a minor. Also, although there are differences in detailed requirements, both state laws share the common goal of clarifying the distinction between AI systems and humans and preventing mental health harm, and the core requirements such as the introduction of suicide prevention protocols are generally consistent. However, the two are in contrast in terms of enforcement means; while the New York law only stipulates injunctive relief and the imposition of sanctions (up to $15,000 per day) by the Attorney General against violating businesses, California's SB 243 allows for direct civil litigation by private individuals as mentioned above. This difference is important from the perspective of deterrence against violating companies and the effectiveness of victim relief, and it is worth noting that SB 243, as the first attempt in the U.S., has placed significant potential legal risk on companies.
In terms of comparison with other systems, the relationship with other AI-related laws enacted in California during the same period cannot be overlooked. For example, AB 316 (provisions regarding the legal liability of AI) stipulates that the claim that 'AI caused it autonomously' cannot be a defense for exemption from liability. This is a confirmatory provision that cuts off the escape route for AI developers and operators to say 'it's not my responsibility because of the AI' and applies traditional legal liability principles. Coupled with the private right of action in SB 243, it can be said that chatbot-providing companies have come to bear even greater legal responsibility for the behavior of their AI. Similarly, AB 489, enacted regarding AI in the field of medical advice, applies the act of an unqualified person impersonating a doctor, etc., to AI, and prohibits the use of titles or misleading displays as if the AI were a 'doctor' or 'counselor.' This is also a type of transparency assurance and can be said to be a regulatory philosophy that is in line with the 'obligation to disclose that it is an AI' in SB 243. Furthermore, SB 53 (proposed by Senator Wiener), which mandates large language model developers to publish safety measure plans and report risks, and SB 524, which requires information disclosure and auditing when law enforcement agencies such as the police use AI to create public documents, were among the multifaceted legislations built for each AI usage scenario in 2025. In that sense, the characteristics of this act become clearer by positioning it not as SB 243 alone, but as part of a series of AI regulatory packages. In other words, SB 243 is a regulation in the field of consumer-facing conversational AI, and it can be organized as focusing on transparency (recognition of who/what you are conversing with) and safety measures (dealing with mental and sexual risks). On the other hand, for example, bills that comprehensively impose the elimination of discrimination and explanation obligations by automated decision-making systems (ADS) (such as AB 1018) did not reach enactment in 2025 and were carried over, and the regulatory approach in this field is progressing at a different pace for each specific issue.
4. Legal Implications and Prospects
The first legal implication of SB 243 is the increase in legal risk and compliance burden for AI-providing companies. With this act, chatbot businesses have become obligated to incorporate consideration for minors and vulnerable users from the product design stage. Specifically, since it becomes difficult to make the excuse that 'I did not know they were a minor' without having a mechanism for age verification or age estimation of users, businesses are forced to take some means of age detection (on the other hand, this also involves a trade-off problem with user privacy). Also, regarding responses to sexual content and self-harm risks, it becomes necessary to modify and fine-tune existing large language models to improve filtering accuracy, which entails technical and cost burdens. Since annual reporting of compliance status is also mandated, the development of internal controls and audit processes will likely be required. Since there is a realistic risk of civil litigation, including class action lawsuits, being filed by individual users in the event of a violation, companies will need comprehensive risk management, including litigation risk assessment and insurance response. Since it cannot be blamed on 'AI' due to the aforementioned AB 316, the possibility that companies will be held legally responsible for foreseeable harm caused by the inaction or design flaws of their own AI has increased, and it can be said that the clarification of the responsibility principles for AI developers and providers has indeed progressed.
On the other hand, from the perspective of user protection, the enactment of SB 243 can be evaluated for opening a path to raising user awareness and providing victim redress. Since users are explicitly informed that their chat partner is an AI, the risk of mistaking the AI for a human and placing excessive trust in it is reduced. Furthermore, in the event that a user suffers mental or economic damage due to harmful responses, it has become possible to seek redress and hold companies accountable after the fact through civil litigation. However, whether these rights will function effectively remains a challenge, including the burden of proof in judicial proceedings. For example, it is not easy to prove causation in court to show that a chatbot's statement was the direct cause of harm such as suicide. Moreover, it is expected that there will be a battle between the parties, with operators preparing for litigation by preserving dialogue logs and preparing expert testimony regarding the behavior of AI models, and it is highly likely that the black-box nature of AI will become a legal issue. Consequently, this could also serve as a technical incentive to improve the explainability and auditability of AI systems.
Regarding policy prospects, the ripple effect that California's SB 243 will have on legislation in other states and at the federal level is drawing attention. In addition to New York State having already implemented similar regulations, movements to regulate chatbots are also being seen in Utah and Maine. 2025 was the year in which multiple states across the U.S. submitted bills mentioning AI chatbots for the first time, and California's approach, which pioneered this, will likely serve as a model. However, if the content of obligations and enforcement methods differ from state to state, the compliance burden on companies may increase and the intended effects of the regulations could be diminished, so establishing guidelines at the federal level or unifying minimum standards may become an issue in the future. In fact, in the latter half of 2025, an executive order on AI was issued by the White House, and the federal government has begun to show signs of monitoring and coordinating state laws.
(Reference)
(Reference Materials)
California Legislative Information, SB-243 Companion chatbots (2025).
California State Senator Steve Padilla, "First-in-the-Nation AI Chatbot Safeguards Signed into Law" (October 13, 2025).
Morrison Foerster, "New York and California Enact Landmark AI Companion Laws: What Operators Need to Know" (November 20, 2025).
Future of Privacy Forum, "Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond" (2025).
Jones Walker LLP, "AI Regulatory Update: California's SB 243 Mandates Companion AI Safety and Accountability" (2025).
Skadden, "New California 'Companion Chatbot' Law Imposes Disclosure, Safety Protocol and Annual Reporting Requirements" (October 2025).
Fenwick, "New York's AI Companion Safeguard Law Takes Effect" (November 11, 2025).
TechCrunch, "California becomes first state to regulate AI companion chatbots" (October 14, 2025).
(Magazine) "AI and Law - Reflections"
※ Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content created by the creator belongs to the creator.
