Twelve months ago, “companion AI” was a product feature — a friendlier system prompt, a persona, a name. Today it is a regulated category with its own statutes, its own enforcement inquiries, and its own emerging age-assurance expectations. That shift did not happen gradually. It happened in about eight months, and if you build anything that lets a user hold an open-ended, relationship-shaped conversation with a model, it happened to you.
California’s SB 243, the first US law written specifically for AI companion chatbots, took effect on January 1, 2026. By the halfway point of the year, roughly a dozen states had enacted their own companion-chatbot rules. The FTC has seven of the largest platforms under a formal inquiry. And the category’s most prominent pure-play, Character.AI, did not wait to be told: it banned open-ended chat for under-18 users entirely and stood up an age-assurance stack to enforce it.
The through-line connecting all of it is a single legal idea that is easy to underestimate: liability no longer requires that you checked a user’s age and got it wrong. It attaches when you should have known a user was a minor and did nothing. That standard — constructive knowledge — is quietly more demanding than the hard ID gates people brace for, and most companion products are not built to meet it.
From feature to category: what actually changed
The regulatory turn on companion AI was driven by harm, not abstraction. Through 2024 and 2025, a series of lawsuits and press investigations tied companion chatbots to self-harm, sexualized exchanges with minors, and the kind of emotional dependency that reads very differently when the user is thirteen. Regulators responded to a specific product shape — not “AI” broadly, but systems designed to simulate an ongoing, personal, human-like relationship.
California moved first. Governor Newsom signed SB 243 on October 13, 2025, and it became operative on January 1, 2026, making California the first state to impose companion-chatbot-specific safeguards (Future of Privacy Forum; Jones Walker). The statute’s core obligations are behavioral rather than gatekeeping: if a reasonable person could be misled into thinking they are talking to a human, the operator must clearly and conspicuously disclose that the companion is AI; minors must be told the same and reminded at least every three hours of continuous use to take a break; and operators must maintain protocols to prevent the chatbot from producing suicidal-ideation or self-harm content, with referrals to crisis services, and to prevent it from producing sexually explicit content for a minor (Gunderson Dettmer). Enforcement has teeth SB 243 borrowed from privacy law: a private right of action, with damages of the greater of actual damages or $1,000 per violation, plus attorneys’ fees.
Then the wave. By mid-2026, a tracker maintained by MultiState counted roughly a dozen states that had enacted companion-chatbot legislation — a group that includes California and New York alongside states such as Colorado, Connecticut, Oregon, and Washington (MultiState). New York advanced restrictions on companion chatbots for children with penalties reported at up to $25,000 (TechTimes). The specifics differ, but the common core is consistent: operators must take reasonable measures to keep companion chatbots from generating a defined set of harms for minors — sexual content, romantic or sexual role-play, encouragement of self-harm, claims of being human or sentient, and manipulative emotional dependency.
Sitting above the states is the FTC. On September 11, 2025, the Commission opened a Section 6(b) study into the effects of AI companion chatbots on children and teens, issuing orders to seven firms: Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and xAI (Nelson Mullins; Davis+Gilbert). A 6(b) inquiry is not a lawsuit, but it is the instrument the FTC uses to build the factual record that precedes rulemaking and enforcement. The signal to the market is unambiguous: the largest platforms are being asked, under compulsion, exactly how they detect minors and what they do once they have.
The standard nobody budgeted for: constructive knowledge
Here is the part that trips up teams reading these laws for the first time. Most of the enacted companion-chatbot statutes do not, today, mandate hard upfront identity verification for every user before granting access to a general AI product. The obligations trigger on the operator’s actual or constructive knowledge that a given user is under 18 — in plain terms, what you knew or reasonably should have known (Troutman Pepper Locke; California Lawyers Association). At a glance that sounds lighter than an ID mandate. It is not. It is different in a way that is harder to engineer around.
An ID gate is a discrete, checkable event: you asked, the user answered, you have a record. A constructive-knowledge standard is continuous and evidentiary. It asks whether the totality of what your system observed — declared birthdates, account signals, usage patterns, the content of the conversation itself, app-store or OS age signals — should have put a reasonable operator on notice that this user is a child. You cannot satisfy it by pointing at a checkbox. You satisfy it by being able to show that you had a defensible process for forming, and acting on, a belief about age.
This is why “we relied on self-declaration” is now close to an admission rather than a defense. Regulators have already established, outside the AI context, that a birthdate field a child can lie past is not age assurance — the reasoning behind the ICO’s £14.47M Reddit penalty applies directly here, and we walked through it in why self-declaration stopped being enough. If your only age signal is a value the minor typed, a constructive-knowledge standard reads that as: you built a system that reasonably should have known, and you chose not to. The same logic is what makes the wider US state patchwork so unforgiving — you inherit the strictest interpretation any of your users’ states imposes.
There is a second subtlety worth internalizing. California’s guidance is explicit that where an operator receives an app-store or OS age signal, it may treat that as a primary indicator — but it may not rely on it wholly. When the operator holds “clear and convincing” internal information that a user’s age differs from the store signal, it must treat its own information as primary (Gunderson Dettmer). Translated: a store-declared age range is a starting point, not an alibi. If your model is watching a conversation that strongly reads as a fourteen-year-old, the store’s “18+” flag does not launder that away. This is the same “store signals are not a strategy” problem platforms already hit with Google Play and Apple age signals, now with an added duty to override the signal when your own evidence contradicts it.
Character.AI as the case study nobody can wave away
The cleanest read on where this is heading is not a statute — it is a company’s decision. Character.AI, the platform most directly named in the lawsuits and the FTC’s orders, concluded that mitigations were not enough and removed the product surface entirely for minors. As of November 25, 2025, users under 18 lost access to open-ended chat with characters; what remains for under-18 accounts is bounded, lower-risk functionality like character creation and short-form generation, not the free-form companion relationship at the center of the concern (ABC7).
Banning a class of user only means something if you can identify the class. So Character.AI paired the ban with an age-assurance layer, and its architecture is instructive because it is exactly the shape the law is pushing everyone toward. Rather than force every adult through an ID check — which would be a conversion catastrophe for a consumer product — it runs age estimation first from passive signals, and escalates to a third-party verification step (using Persona) only when the system is not confident the user is an adult. Most adults clear silently; the friction lands on the ambiguous cases near the threshold.
That is a layered decision, and it is the right instinct. But it also imports a risk worth naming out loud: routing your step-up verification through a single centralized third party concentrates biometric and identity data in one place, which is precisely the failure mode we examined after the Persona–Discord incident. Choosing to verify is not the end of the design problem. How you verify — how much data you collect, where it lives, how long it survives — is the next one, and getting it wrong turns a compliance win into a breach headline. The data-retention breach wave of the past year is a catalog of operators who verified and then hoarded.
What a defensible companion-AI age stack looks like
If you operate a companion product, the operative question is no longer “do we need age verification?” It is “can we demonstrate a reasonable, layered process for knowing when a user is a minor and applying the right experience?” That is an architecture question, and it decomposes cleanly.
Estimate first, at low friction. Facial age estimation from a single selfie, or estimation from other privacy-preserving signals, lets the broad middle of clearly-adult and clearly-underage users resolve without an ID check. Estimation is not magic — its accuracy and its error bands are measurable, and you should treat the NIST-benchmarked accuracy picture as ground truth rather than a vendor’s marketing number. The point of estimation is throughput: keep the expensive, high-friction path for the cases that actually need it.
Escalate near the threshold, don’t guess. The users who matter are the ones close to the line. A layered orchestration or waterfall routes a low-confidence or near-18 result up to a stronger method — a document check, an NFC-chip read, a wallet- or bank-backed age attribute — instead of forcing the whole population through it or, worse, letting the ambiguous cases through on a shrug. This is what “reasonable measures” looks like when an enforcer inspects it: not one model’s guess, but a decision tree with an escalation path.
Design the minor experience, not just the block. A constructive-knowledge regime rewards operators who have somewhere to route a detected minor. Building age-based tiered experiences — where a minor gets a materially different, safety-constrained product rather than a hard door — aligns with the behavioral obligations these statutes actually impose (disclosures, break reminders, content limits) and is far more defensible than a binary that a determined teenager treats as a puzzle.
Verify the fact, keep the proof — not the biometrics. Every live capture you run and retain is a liability that compounds. Token-based reusable verification lets a returning user present a signed, privacy-preserving proof of “verified 18+” instead of re-submitting a face every session; the verify-once, prove-everywhere model shrinks both friction and breach surface at the same time. The Character.AI lesson cuts both ways: verify, yes — but don’t rebuild the honeypot you were trying to avoid.
Tune against the false-positive, too. Over-aggressive estimation locks out real adults, and in a consumer companion product that is a churn event, not a footnote. The false-positive adult-lockout problem is the reason your escalation path has to be smooth in both directions: a wrongly-flagged adult needs a clean way to prove age, not a dead end.
Where this goes next
Two vectors are worth watching. The first is federal escalation. The GUARD Act would replace the current knowledge-based state standard with something categorically harder — mandatory age verification at account creation, periodic re-verification, and outright prohibition of minors on covered AI companions, with birthdate and IP inference explicitly ruled insufficient. If it advances, the “estimate-and-escalate” latitude that today’s state laws allow narrows toward “verify everyone.” Building a layered stack now is the cheapest way to be ready for that, because a waterfall that can dial its strictness up is a configuration change, not a re-architecture.
The second is the FTC’s 6(b) record maturing into rules or actions. When the Commission publishes what it learned about how the seven named firms detect minors, it will effectively define the industry’s floor for “reasonable.” Operators who can already point to a documented, layered age-assurance process will be describing what they do; operators still on self-declaration will be explaining why they don’t.
Companion AI did not ask to become an age-gated category, but it is one now — by statute in a dozen states, by inquiry at the FTC, and by the revealed preference of the market’s most-scrutinized player. The teams that treat age assurance as core product architecture rather than a compliance bolt-on are the ones who will still be shipping companion experiences to adults a year from now.
Xident is built for exactly this decision shape: age-threshold classification for an 18+ line, facial age estimation to resolve the clear majority at low friction, client- and server-side liveness and face match to make the estimate trustworthy, layered orchestration so near-threshold and low-confidence cases escalate to a stronger method instead of slipping through, and token-based reusable verification plus privacy-preserving age signals so you prove the fact without hoarding the biometrics. Verify age like it is part of the product, because under a constructive-knowledge standard, it is.
If you are mapping a companion-AI age-assurance flow against SB 243, the wider state wave, or a possible GUARD Act future, that is the conversation to have now.
This article is for general information and does not constitute legal advice. Companion-chatbot obligations vary by state and are evolving quickly; confirm your specific requirements with qualified counsel and validate any vendor’s claims against your own risk profile and regulatory footprint.