On September 1, 2026, Tech Policy Press published an analysis by DLA Piper's Danny Tobey, Ashley Carr and Michael Atleson mapping all twelve state "companion bot" laws now on the books — the first consolidated read on what AI companion providers actually have to build. Three are already in force: New York, California and Hawaii. Nine more take effect in 2027: Colorado, Connecticut, Georgia, Iowa, Idaho, Nebraska, Oregon, Rhode Island and Washington.
Why It Matters
For anyone building or investing in AI companions — a category where romantic and sexual roleplay is the core retention driver, not an edge case — the compliance surface just became concrete. The four common principles are close enough across states that a single product spec can satisfy most of them, which is the good news. The bad news is in the definitional gaps: a product that's compliant in New York can be out of scope in Georgia and squarely non-compliant in Connecticut, because the states disagree on what a companion bot even is. Colorado's rulemaking is the piece to actually track. Because no other state has issued interpretive guidance on the "reasonable measures" and "technically feasible measures" language, whatever Colorado finalizes will likely become the reference point regulators and courts elsewhere reach for. The factors the AG has proposed — testing, monitoring, remediation, documentation — map almost exactly onto standard AI governance program design, which means companies with real model-evaluation infrastructure will clear the bar and companies shipping a wrapper around someone else's API will not. Note also what these laws do and don't touch. They regulate minors' access, disclosure, and crisis handling. Not one of them meaningfully restricts adult sexual companion content, which remains legal and largely unregulated at the state level. The regulatory pressure on adult AI intimacy continues to come from payment processors and app stores rather than legislatures — a distinction the industry should not confuse with safety.The scope definitions are where the divergence starts. Most of the laws restrict coverage to bots that exhibit anthropomorphic features and sustain relationships across multiple interactions — the classic AI-girlfriend product. But Colorado, Connecticut, Idaho, Iowa and Nebraska wrote broader language covering any bot that "simulates human conversation and interaction" via text, audio or video, which sweeps in a great deal of software that nobody would call a companion. All except Hawaii carve out chatbots used for business purposes or narrow functions like a video game feature.
The analysis identifies four requirements that now function as a de facto national baseline. First, transparency: all twelve require clear disclosure that the user is talking to an AI, though states differ on whether that's a one-time notice or persistent. Washington goes furthest, barring bots from representing themselves as human to any user, not just minors. Second, heightened minor protections (all but New York and Rhode Island): reasonable measures to block sexually explicit content, prevent engagement-maximizing mechanics like points and rewards, prevent emotional manipulation and dependency including discouraging users from seeking help from adults, and provide parental controls. Most trigger on actual or constructive knowledge that a user is a minor; Colorado and Georgia impose an affirmative duty to use "commercially reasonable" age-estimation methods, with Georgia limiting that duty to features that may generate sexually explicit content.
Third, crisis protocols: all twelve require detection of suicidal ideation or self-harm expressions and referral to crisis resources. Colorado, Georgia and Oregon require escalation procedures for repeated or severe indicators; Oregon specifies "clinical best practices and expertise" for additional intervention when a user keeps expressing ideation after receiving resources. Fourth, professional-representation limits: several prohibit bots from claiming to be mental health professionals — a restriction echoed in at least eight additional state laws aimed specifically at mental-health bots (Nevada, Utah, Illinois, Delaware, Maine, Tennessee, Rhode Island and Vermont). Colorado extends the concept to health care providers, dietitians and attorneys.
Connecticut is the outlier worth watching. Rather than requiring reasonable measures to prevent certain outputs, it forbids offering a companion bot to minors where it is "reasonably foreseeable" that the bot "is capable of" a broad list of harmful interactions — a capability standard rather than a conduct standard, which is a much harder thing to engineer around.
The near-term action is in Colorado. On August 11, the state Attorney General released proposed rules under what is now called the Chatbot Safety Act, addressing the statutory standards requiring "technically feasible measures" to prevent explicit sexual content to minors and "reasonable measures" to prevent responses that simulate emotional dependence or isolation from real-world supports. Sections 11.3 and 11.4 list the factors the AG would weigh: availability and effectiveness of safeguards, and the extent of testing, monitoring, remediation and documentation. Public comments are due October 26.
Sources
- What 12 State 'Companion Bot' Laws Demand of AI Providers — Tech Policy Press
- Big Long List Of AI Laws – Notable Updates — Mondaq / Taft
Update — 2026-09-02
Initial entry — story first created.