AI companion and chatbot app age assurance regulations: what operators need to know
In recent years, numerous countries have introduced age assurance regulations for online platforms to help safeguard children from potentially harmful content. From the UK’s Online Safety Act to Australia’s Social Media Minimum Age legislation, these laws establish new or stricter requirements for age gating.
The latest wave of that regulation focuses on AI companion or chatbot apps. Built on large language models (LLMs), these products include general-purpose assistants as well as apps designed around emotional connection or romantic partnership.
While these systems can be helpful, educational, and entertaining, they can also generate content that may be considered harmful to minors. In response, regulators worldwide have introduced or enacted new legislation to address those risks.
This article provides an overview of the AI companion and chatbot app regulations currently in effect and in progress in the US and worldwide. We’ll highlight how different jurisdictions are approaching age assurance requirements and discuss what platforms need to do to align with regulations.
What’s the difference between AI chatbots and AI companions?
At a basic level, AI chatbots are general-purpose large language models (LLMs) designed to hold human-like conversations. While they’re not necessarily built to provide counseling or emotional care, they are capable of relational interactions: offering advice, reflecting feelings back, or simply holding a conversation that feels personal.
AI companion apps are built for a different goal. Where a general-purpose chatbot responds to questions, a companion-like system is often designed and marketed around friendship, romance, or therapeutic partnership.
Increasingly, regulators and researchers refer to both under the umbrella of “AI companions and chatbots,” recognizing that as technology advances, the differences between the two continue to blur.
Why are regulators targeting AI companion and chatbot apps specifically?
AI companion and chatbot apps pose a particular risk to minors because they can mimic human connection in ways that young users may struggle to distinguish from the real thing. These systems frequently present themselves as a friend, romantic partner, or personal counselor, routinely using personal pronouns like “I” or “me” while falsely claiming to be alive, human, or emotionally sentient.
Regulators are also concerned that these systems create psychological risks with features like unpredictable reward intervals; flattery and sycophancy; and simulated emotional distress or abandonment if a user tries to disengage. Without guardrails, chatbots may encourage minors to keep their use secret from parents, avoid seeking professional help, or treat AI outputs as equivalent to medical or legal advice.
Most critically, these platforms run the risk of generating or normalizing deeply destructive content, including explicit encouragement of suicide and self-harm, endorsements of disordered eating or drug abuse, and exposure to sexually explicit interactions, graphic obscenity, or synthetic sexual deepfakes.
What laws regulate AI companions and chatbots in the US?
Dozens of AI chatbot age bills have been introduced in the US in 2026. Below are six examples that illustrate the range of approaches policymakers are taking, from broad mandates that leave method selection open to operators to outright bans on minor access.
US GUARD Act (proposed)
At the federal level, the GUARD Act represents the most sweeping proposal regulating AI chatbots and companions yet. Key provisions include:
Blanket ban on AI companions. The GUARD Act strictly prohibits AI companies from providing “AI companions” to minors (anyone under the age of 18).
No parental overrides. Unlike traditional online frameworks, the bill contains no mechanism for parental consent. If a user is determined to be under 18, they should be completely barred from accessing the companion bot.
Mandatory hard age-gating. The bill requires reasonable age verification measures for any public-facing AI chatbot that produces certain expressive content. It explicitly outlaws weak verification methods like self-attested checkboxes or simple birthdate entry. Operators would need to implement stronger age checks.
KIDS Act (proposed)
The Kids Internet Design and Safety (KIDS) Act is a broad online child safety bill that would apply to many online platforms, including AI chatbot and companion services. The SAFE BOTs Act and AWARE Act fall under it.
What makes it different: The KIDS Act does not mandate a specific age verification technology or prohibit minors from accessing AI companions. Instead, it gives operators flexibility in how they identify minors and implement age-appropriate protections.
How it approaches privacy: The bill emphasizes minimizing data collection from children and teens. It requires covered services to design products with minors’ safety and well-being in mind.
California’s SB-1119 (proposed)
California was the first state to enact a law specifically regulating AI companion chatbots. California SB 243, which took effect in 2025, requires companion chatbot operators to provide disclosures, implement safeguards for users experiencing emotional distress, and comply with additional protections for minors. California’s SB-1119 would build on that framework by introducing stricter age assurance and privacy requirements. Operators must complete annual risk assessments and undergo independent compliance audits to be submitted to the attorney general.
What makes it different: SB-1119 references the Digital Age Assurance Act, which requires requesting “age bracket data sent by a real-time secure application programming interface or operating system” when an application is downloaded and launched. Alternatively, it allows operators to verify a user’s age pursuant to specific provisions of the California Civil Code.
How it approaches privacy: Chatbots must default to an “ephemeral mode” that permanently deletes conversation logs and user inputs within 48 hours unless a parent explicitly consents to persistent conversational memory. Operators may not sell a minor’s personal data or track it to deploy targeted advertising and conversational product placements.
Colorado’s HB 26-1263 (passed)
Colorado’s HB 26-1263 establishes comprehensive guidelines for conversational AI service operators to protect consumers and minors. Effective January 1st, 2027, the law requires transparency disclosures, privacy management tools, and specific suicide and self-harm response protocols.
What makes it different: HB 26-1263 does not outline any specific technical mechanisms for age assurance. Instead, operators must use “commercially reasonable methods or generally accepted methods to estimate the age or age range of a user.”
How it approaches privacy: Operators must enable minors and parents to manage their privacy settings. Minors have the right to block the AI from retaining interaction history for content personalization or utilizing their personal data for machine learning model training. Mandatory annual reports to the attorney general may not contain identifying user information.
Georgia’s SB 540 (passed)
Georgia’s SB 540 regulates AI companion chatbots by mandating certain disclosures, restricting relationship-simulation features for minors, and requiring age assurance methods before exposing users to synthetic, sexually explicit content.
What makes it different: Under SB 540, chatbots must remind minor users they are talking to an AI every hour. The bill explicitly states that an operator may use “age estimation, account-based assurance, or identity-based verification where necessary.” It also notes that operators must minimize data collection and “shall not retain identity documents longer than reasonably necessary to complete age assurance.”
How it approaches privacy: Operators are required to provide account tools for managing privacy settings. They must also adhere to strict age assurance data rules, which mandate that any data or identity documents collected to verify a user’s age must be minimized, never sold, used exclusively for verification, and permanently deleted within 24 hours.
Michigan’s SB 760 (proposed)
Michigan’s SB 760 strictly prohibits advanced chatbot design features for minors. For example, it bans outputs that simulate human companionship, human emotion, or romantic relationships unless an operator has actual knowledge that a user is an adult.
What makes it different: This law defines an “age signal” as age information, including nonpersonally identifiable data indicating a user’s age or age range, which is “sent by a real-time secure application programming interface or operating system to an application.” It also references utilizing an “age verification mechanism” to establish actual knowledge of a user’s age.
How it approaches privacy: Operators must immediately delete age verification data and limit standard data collection to the absolute minimum necessary for verified minors. They must also obtain explicit written parental consent before training an AI model on a minor’s inputs. They may not use personal or health details gathered from a previous session or from more than 12 hours prior.
These six examples represent only a fraction of the bills currently in play across US states. The regulatory landscape is still taking shape, and significant change is expected. Because regulation is coming, platforms are better served by evaluating age assurance providers now that can be configured to meet requirements as they evolve.
How are other countries regulating AI companions and chatbots?
Outside of the US, regulations for AI companions and chatbots typically focus on risk assessments, age assurance and access controls, transparency requirements, content restrictions, and user reporting mechanisms.
However, some jurisdictions are creating purpose-built AI legislation while others are extending existing online safety frameworks. As examples:
In the UK, an amendment to the Crime and Policing Bill brought AI chatbots within the scope of the Online Safety Act (OSA).
Canada introduced a Digital Safety Act (Bill C-34), which would require AI chatbot services to fulfill certain duties to ensure safety.
The global regulatory environment for AI companions and chatbots is relatively nascent. As the space develops, operators should expect to see new regulations emerge with significant variation between how jurisdictions define and enforce them. Visit our global tracker, Persona Atlas, to see the most recent regulations worldwide.
How can AI companion and chatbot app operators meet different age assurance requirements?
To meet regulatory expectations worldwide, most AI companion and chatbot platforms will need to implement age assurance solutions that are accurate and offer a range of methods that can adapt to shifting regulations. Age assurance solutions should prioritize user privacy by minimizing data collection and delete user data after processing.
While AI companion and chatbot regulations vary significantly in their specifics, several compliance considerations apply broadly across them. Here’s what AI companion and chatbot app providers should think about:
Data privacy. Review your automated data deletion and redaction policies and how you’ll limit data collection. Consider your technical guardrails and whether your platform includes AI training on user data.
Age assurance. Most AI companion and chatbot laws are intentionally vague about exact age assurance collection mechanisms. While this provides platforms some flexibility in implementation, it also introduces uncertainty about what will be considered sufficient. Consider how you’ll adapt to different jurisdictions with different requirements around age estimation, inference, and verification.
User experience. Effective compliance doesn’t have to lead to high user drop-off. A well-designed age assurance approach applies the lightest-touch method first and escalates to more stringent verification only when necessary. This protects the user experience while helping companies meet their obligations.
How does Persona help AI chatbot operators meet their compliance requirements?
Persona is a leading identity verification provider that helps AI platforms navigate complex age assurance regulations worldwide with a privacy-first approach. Trusted by leading generative AI companies, social media apps, and gaming platforms, Persona helps organizations balance compliance, privacy, and user experience.
Persona’s configurable and flexible building blocks enable platforms to create user-friendly verification flows that align with global regulations and privacy standards. Persona offers:
A comprehensive suite of age assurance methods. Persona offers a broad library of age assurance methods, configurable to your risk, compliance, and conversion goals. Examples include selfie age estimation, government ID verification, and phone or email-based inference.
Automated privacy controls. With Persona, you can limit data collection, automatically redact or delete sensitive information, and maintain rigorous audit trails.
Double-blind architecture via Persona Relay. Through Relay, your platform never sees your user’s date of birth, name, document, or other raw age signals collected for verification purposes. In addition, Persona never sees which platform or content your user is trying to access.
User-friendly experiences. Persona’s Dynamic Flow product lets you build and launch custom age assurance flows for your jurisdiction using customizable, no-code configurations. Decide which age assurance methods to use based on user signals and risk.
If you’re building an AI companion app and thinking about whether new age assurance regulations apply to you, Persona can help. Reach out to schedule a consultation, or explore Persona’s age assurance solutions to see how they work.
FAQs
Are AI companions the same as AI chatbots under the law?
Toggle description visibility
No, not always. AI companions generally refers to a type of chatbot designed to simulate friendship, emotional intimacy, or another interpersonal relationship. Some proposals regulate all AI chatbots while imposing stricter requirements on companion-style products. The GUARD Act, for example, distinguishes between general AI chatbots and AI companions and would strictly prohibit minors from accessing the latter.
Is the GUARD Act law yet?
Toggle description visibility
No. While the GUARD Act passed the Senate Judiciary Committee on April 30, 2026, it has not been enacted into law as of August 20th, 2026 and may change as it moves through Congress. However, its bipartisan support signals growing federal interest in age verification and stronger protections for minors using AI companions.
Do I need age verification for my AI chatbot?
Toggle description visibility
It depends on where your users are located, how your chatbot is designed, and whether it is accessible to minors. Some enacted and proposed laws apply specifically to companion chatbots while others cover broader online services or content. Assess your obligations based on the jurisdiction and consider implementing age assurance early, particularly if your product offers emotional, sexual, therapeutic, or other potentially high-risk interactions.
What age assurance methods are allowed under AI chatbot regulations?
Toggle description visibility
Required age assurance methods vary greatly by jurisdiction. Acceptable methods may include age estimation, age inference, government ID verification, or checks using phone, payment, or other verified account data. Some laws require a method to reliably distinguish minors from adults and do not treat a birthdate entry or simple self-declaration as sufficient. For example, the GUARD Act would allow government-issued identification or another commercially reasonable and reliable method.
How can Persona support AI chatbot age verification?
Toggle description visibility
Persona provides security-focused, privacy-preserving age verification. This includes a robust library of approved age assurance methods, granular privacy controls that minimize data collection, fraud controls that prevent circumvention, and dynamic flows that help minimize friction and data collection while maintaining compliance. While AI chatbot operators are responsible for selecting methods appropriate to their users, risks, and legal obligations, Persona partners with them to build compliant, user-friendly age assurance flows.
What does Persona do with my data after verifying my age with an AI chatbot?
Toggle description visibility
Customers are typically the data controller. In those instances, Persona recommends automatically redacting any personal data after successfully verifying or estimating your age. Only the age outcome, such as "Over 18", and context around the method(s) used, would be retained in that case. Persona does not sell or share personal data processed for verification or use it to train AI models.
