CA
Enacted eff 2026-01-01
Operators must determine whether a user is a child before making a companion chatbot available. Before January 1, 2027, the obligation is triggered only by actual knowledge that the user is a child. From January 1, 2027 onward, operators must have reasonably determined that the user is not a child.
CT
Enacted eff 2026-07-01
Covered operators must not serve personalized algorithmic feeds to users unless (1) the operator has used commercially reasonable methods to verify the user is not a minor, or (2) for minors, the operator has obtained verifiable parental consent. Age-verification data must be deleted immediately after the age determination; no secondary use is permitted.
GA
Enacted eff 2026-05-11
Operators must use a reasonable age verification method before allowing access to a conversational AI service that could provide synthetic content containing sexually explicit conduct. Acceptable methods include digitized identification cards, government-issued identification, or any commercially reasonable method meeting or exceeding NIST Identity Assurance Level 2.
AZ
Engrossed
Commercial entities that knowingly and intentionally publish or distribute material harmful to minors on a website or application — where such material constitutes more than 33.3% of total content — must: (1) use either anonymous or standard age verification to verify that users attempting to access the material are at least 18 years of age; (2) prevent access to the material by persons under 18; and (3) offer both anonymous and standard age verification methods and allow the user to select which method to use.
AZ
Engrossed
Commercial entities that knowingly and intentionally publish or distribute material harmful to minors on a website or application where such material comprises a substantial portion (>33.3%) of total content must: (1) use anonymous or standard age verification to verify that persons attempting to access the harmful material are at least 18 years old; (2) prevent access to the harmful material by any person under 18; and (3) offer both anonymous and standard age verification and allow the user to select which method to use.
CA
Engrossed
Covered platforms must implement reasonable measures to prevent users under 16 years of age from accessing or using accounts on the covered platform.
CA
Engrossed eff 2027-07-01
Operators must verify the age of every user in accordance with California's Digital Age Assurance Act (Civil Code § 1798.500 et seq.), which requires requesting age bracket data via a real-time secure API or operating system at download and launch.
HI
Engrossed eff 3000-07-01
Providers of AI companion systems that present a material risk of harm to minors must implement reasonable and proportionate age assurance measures, consistent with privacy and data minimization principles, to prevent access by minors where appropriate.
KS
Engrossed eff 2027-01-01
App store providers must request and verify the age category of every account holder at account creation (or by December 31, 2026, for pre-existing accounts) using commercially available methods reasonably designed to ensure accuracy or an attorney-general-approved method.
KS
Engrossed eff 2027-01-01
Developers must (1) submit requests to the app store provider to verify age category data and parental consent status each time an account holder downloads, purchases, or first launches a pre-installed app, when implementing a significant change, or as required by law; (2) notify app store providers of significant changes to apps; and (3) use received age category data to enforce age-related restrictions, safety features, and legal compliance.
KY
Engrossed
Covered social media platforms must estimate each account holder's age using reasonable means and existing data within 14 days of the first trigger date (25 hours of use in 6 months) at 80% confidence and again within 14 days of the second trigger date (50 hours in 6 months) at 90% confidence, defaulting to child classification if the threshold is not met. Platforms must re-estimate after every additional 100 hours of use or whenever they update any other demographic estimate, whichever is shorter.
KY
Engrossed
Covered social media platforms must require every account applicant to provide a birth date during the application process and must not pre-populate or default the birth date field.
MI
Engrossed
Covered operators must not provide an addictive feed to any user unless the operator has (1) used commercially reasonable and technically feasible methods to determine the user is not a minor, or (2) obtained verifiable parental consent to provide an addictive feed to a covered minor.
NY
Engrossed
Chatbot operators must offer covered users at least one age verification method that either does not rely solely on government-issued identification or that allows the user to maintain anonymity as to the chatbot operator.
OK
Engrossed
Social media companies must verify the age of every account holder using a reasonable age verification method and, for 16- and 17-year-old minors, must confirm parental consent at the time the account is opened. Acceptable methods include digitized ID, government-issued ID, any commercially reasonable method, or app-store-level age confirmation.
WA
Engrossed
Operators of addictive internet-based services must estimate the age of minor users with a reasonable level of certainty proportionate to the risks arising from the operator's data management practices.
AL
Introduced eff 2026-10-01
Covered entities must require every individual accessing an AI chatbot to create a user account before using or interacting with the chatbot.
AL
Introduced eff 2026-10-01
Covered entities must implement a reasonable age verification process for all AI chatbot users and classify each user as a minor or adult. For existing accounts, the covered entity must freeze the account until the user completes age verification. For new accounts, age verification must occur at account creation. Covered entities must also periodically re-verify previously verified accounts. A reasonable age verification process requires government-issued identification or a commercial age verification system plus user confirmation that the user is not a minor; self-reported birth dates and IP-address-based inference are insufficient. Third-party verification vendors may be used, but the covered entity retains full liability.
HI
Introduced
Providers of AI companion systems presenting a material risk of harm to minors must implement reasonable and proportionate age assurance measures, consistent with privacy and data minimization principles, to prevent access by minors where appropriate.
IA
Introduced
Deployers must implement reasonable age verification measures to ensure that no minor can use or purchase an AI companion the deployer makes publicly available. Reasonable age verification includes government-issued identification, financial documents reliably evidencing age, or a widely accepted practice that reliably evidences age.
IA
Introduced
Deployers of AI companions or therapeutic chatbots must implement commercially reasonable measures to determine whether a user is a minor, using a risk-based approach appropriate to the nature of the chatbot and the reasonably foreseeable harm from its use. Measures may include self-attestation, technical measures, or other commercially reasonable approaches. Government-issued identification is not required. A deployer that has made commercially reasonable efforts to comply is not liable for a user's misrepresentation of age.
IA
Introduced
Deployers must implement reasonable age verification measures to ensure that a minor cannot use or purchase a chatbot the deployer makes publicly available. A deployer may make a chatbot available to a minor only if all of the following conditions are met: (1) the chatbot was designed primarily for mental health support, counseling, or therapy; (2) the chatbot provides a clear and conspicuous disclaimer at the beginning of each interaction that it is an AI and not a licensed professional; (3) the chatbot was recommended for the minor by an individual licensed under chapter 154B or 154D after evaluating the minor; (4) the developer has significant documentation of how the chatbot was tested; (5) peer-reviewed clinical trial data demonstrates the chatbot is safe and effective for the minor's mental health condition; (6) the deployer provided clear disclosures of functions, limitations, and data privacy policies to the recommending professional and the minor's parents, guardians, or custodians; and (7) the deployer developed and implemented protocols for testing for risks, identifying risks, mitigating risks, and quickly rectifying harm the chatbot may have caused a user.
KS
Introduced
Covered entities must require every individual accessing a companion AI chatbot to create a user account before using or interacting with the chatbot.
KS
Introduced
Covered entities must verify the age of every user using a commercially available method or process reasonably designed to ensure accuracy, and classify each user as a minor or an adult. For existing accounts as of July 1, 2026, covered entities must freeze the account, inform the user that age verification is required to restore functionality, and use the submitted age information to classify the user. For new accounts, covered entities must require submission of age information and verify the user's age at the time of account creation.
LA
Introduced
Covered entities must require the creation of a user account prior to any interaction with an AI chatbot.
LA
Introduced
Covered entities must implement reasonable age-verification processes to (1) verify the age of new users before granting access and classify each as minor or adult, (2) verify all existing users and freeze unverified accounts pending re-verification, and (3) conduct periodic reviews of previously verified accounts. Third-party verification is permitted but does not transfer liability.
MN
Introduced
Persons who offer chatbot services for recreational purposes must require proof of age from every individual before allowing access to a chatbot.
MN
Introduced eff 2026-08-01
Proprietors of companion chatbots must make a prudent and good-faith effort consistent with industry standards, using existing technology, available resources, and known, established, or readily attainable techniques, to determine whether a user is a minor. Proprietors must also make a prudent and good-faith effort to discover vulnerabilities in their system, including any methods used to determine whether a user is a minor. Proprietors are strictly liable for any harm caused if they fail to comply with this obligation and a minor user inflicts self-harm as a result of the companion chatbot. This liability may not be waived or disclaimed.
MN
Introduced eff 2026-08-01
Proprietors of companion chatbots must make a prudent and good-faith effort consistent with industry standards, using existing technology, available resources, and known, established, or readily attainable techniques to determine whether a user is a minor. Proprietors must also make equivalent good-faith efforts to discover vulnerabilities in the proprietor's system, including any methods used to determine whether a user is a minor. Strict liability applies for any harm caused if the proprietor fails to comply and a minor user inflicts self-harm as a result of the companion chatbot. Liability may not be waived or disclaimed.
MO
Introduced
Persons who own or control a companion chatbot website, application, software, or program must not allow any minor to access a companion chatbot for recreational, relational, or companion purposes. All persons offering companion chatbot services for recreational, relational, or companion purposes must require every individual to provide proof of age before granting access. No companion chatbot may be installed on any device assigned to, or regularly used by, a minor.
MO
Introduced eff 2026-08-28
Covered entities must require every individual to create a user account before using or interacting with a companion AI chatbot.
MO
Introduced eff 2026-08-28
Covered entities must implement age verification for all users using a commercially available method reasonably designed to ensure accuracy — freezing existing accounts as of August 28, 2026 until verified, and verifying new users at account creation — and classify each user as a minor or an adult.
MO
Introduced eff 2026-08-28
Covered entities must require each individual accessing an AI chatbot to create a user account before using or interacting with the chatbot.
MO
Introduced eff 2026-08-28
Covered entities must implement a reasonable age verification process for all users and classify each user as a minor or an adult. For accounts existing as of August 28, 2026, covered entities must freeze each account on that date and require the user to provide verifiable age data before restoring functionality. For new accounts, covered entities must request and verify age data at the time of account creation. Covered entities must also periodically review previously verified accounts to ensure ongoing compliance. A covered entity may contract with a third party for age verification, but the covered entity remains fully liable. Self-attestation of age, birth date entry, and IP-address-based inference are explicitly insufficient as verification methods.
MO
Introduced eff 2026-08-28
Covered entities must require each individual accessing an AI chatbot to create a user account before using or interacting with the chatbot.
MO
Introduced eff 2026-08-28
Covered entities must implement a reasonable age verification process for all users, classify each user as a minor or adult, and freeze existing accounts as of August 28, 2026, pending verification. For existing accounts, the covered entity must freeze the account, require age data verifiable through a reasonable age verification process, and classify the user. For new accounts, the covered entity must request age data, verify age through a reasonable age verification process, and classify the user. Covered entities must also periodically re-verify previously verified accounts. Self-attestation of age or birth-date entry alone is not sufficient. Covered entities may contract with third parties for verification, but third-party use does not relieve the covered entity of its obligations or liability.
NY
Introduced
Chatbot operators must not provide unsafe chatbot features to any covered user unless (1) the user is not a covered minor (i.e., the operator does not have actual knowledge the user is a minor), and (2) the operator has verified the user is not a covered minor using age-verification methods permissible under Article 45 of the General Business Law and any additional implementing regulations. Unsafe chatbot features include: simulating companionship or interpersonal relationships (claiming to be a character or person, claiming to be human or alive, using personal pronouns, generating personal opinions or emotional appeals, prioritizing sycophancy over safety, generating unsolicited emotion-based content, reusing personal health or wellbeing information from prior sessions or sessions older than 12 hours, engaging in or luring users into sexually explicit interactions); generating outputs endorsing or facilitating suicide, self-harm, harm to others, disordered eating, or unlawful substance use; encouraging secrecy about chatbot interactions, self-isolation, or discouraging users from seeking professional or adult help; generating outputs that optimize engagement in ways that override safety guardrails; and generating sexually explicit conduct or CSAM. This prohibition does not apply to chatbots used solely for customer service, commercial product/service information, account information, or internal/employee-productivity purposes.
NY
Introduced
Chatbot operators must offer covered users at least one age-verification method to determine whether the user is a covered minor that either does not rely solely on government-issued identification or allows the covered user to maintain anonymity as to the chatbot operator.
OK
Introduced eff 2026-11-01
Deployers must ensure that any generative AI chatbot they operate or distribute does not make human-like features available to minors. Human-like features include simulating sentience, emotions, or personal desires; seeking to build emotional relationships with users; and impersonating real persons. Deployers must implement reasonable age verification systems to prevent chatbots with human-like features from being provisioned to minors.
OK
Introduced eff 2026-11-01
Deployers operating generative AI systems that primarily function as companions (social AI companions) must ensure such chatbots are not available to minors to use, interact with, purchase, or converse with. Deployers must implement reasonable age verification systems to prevent provisioning of social AI companions to minors. This is a categorical prohibition — not a feature restriction — for companion AI systems.
OK
Introduced eff 2025-11-01
Social media platforms must perform reasonable age verification methods to verify the age of each user.
PA
Introduced
Social media companies must make commercially reasonable efforts to verify the age of users at account creation using commercially available best practices, or alternatively apply all minor-protective accommodations to all account holders.
PA
Introduced
Operators must, before granting access, request age information and determine minority using commercially reasonable methods (not requiring government ID), and must obtain verifiable parental consent before allowing any minor to access an AI companion.
SC
Introduced
Covered entities must make a limited-access mode available for their chatbot and must ensure that any unverified user — one whose age has not been verified — may only access and interact with the chatbot in limited-access mode, which disables all restricted features (personalization, proactive outreach, extended sessions, relationship simulation, and explicit content) and does not require account creation or age verification data.
SC
Introduced
Before enabling any restricted feature for a user, covered entities must (1) require the user to create a user account, (2) verify the user's age using a reasonable age verification process, and (3) classify the user as a minor or an adult based on the age data collected.
SC
Introduced
If the age verification process classifies a user as a minor, covered entities must not enable any restricted feature unless the user is using an authorized minor account — i.e., an account for which verifiable parental consent has been obtained under Section 39-81-30.
SC
Introduced
Covered entities must implement reasonable systems and processes to identify user accounts that may be inaccurately classified by age — such as patterns of use suggesting a minor is using an adult account or credible reports of false age data — and must re-verify any such account before enabling any restricted feature.
SC
Introduced
Within 60 days of the act's effective date, covered entities must disable access to restricted features for every pre-existing user account that has not been classified as an authorized minor account or a verified adult account, and must keep those features disabled until the user completes age verification.
SC
Introduced
Covered entities must, before enabling any restricted feature for a user, (1) require the user to create a user account, (2) verify the user's age using a reasonable age verification process, and (3) classify the user as a minor or an adult based on the age data collected.
SC
Introduced
Covered entities must implement reasonable systems and processes to identify user accounts that may be inaccurately classified by age — such as patterns of use suggesting a minor is using an adult account or credible reports that an account was created using false age data — and must re-verify any such account before enabling any restricted feature.
SC
Introduced
Covered entities must, within 60 days of the effective date of the act, disable access to restricted features for any pre-existing user account that has not been classified as an authorized minor account or a verified adult account, and must not re-enable restricted features until the user completes age verification.
US
Introduced
Covered entities must require every individual accessing a companion AI chatbot to create a user account before using or interacting with the chatbot.
US
Introduced
Covered entities must implement age verification for all companion AI chatbot users — freezing existing accounts on the effective date and requiring verified age information to restore them, and verifying age at account creation for new users — using a commercially available method reasonably designed to ensure accuracy, and must classify each user as a minor or an adult.
US
Introduced
Providers of adult-content covered platforms must adopt commercially available age-verification technology to identify minors and prevent them from accessing sexual material harmful to minors, including by verifying user age (not relying on self-certification alone), providing clear notice about verification practices, taking anti-circumvention measures, and minimizing retention of verification data.
US
Introduced
Covered entities must require every individual to create a user account before accessing or interacting with a companion AI chatbot.
US
Introduced
Covered entities must freeze all existing companion AI chatbot accounts on the effective date, require each user to provide verifiable age information using a commercially available method reasonably designed to ensure accuracy before restoring account functionality, and classify each user as a minor or an adult.
US
Introduced
Covered entities must request and verify age information from every new user at account creation using a commercially available method or process reasonably designed to ensure accuracy.
US
Introduced
Covered entities must require every individual to create a user account before using or interacting with an AI chatbot.
US
Introduced
Covered entities must implement a reasonable age verification process for all chatbot users — freezing existing accounts pending verification, verifying new users at account creation, and periodically re-verifying previously verified accounts — classifying each user as a minor or adult. Self-certification and birth-date entry are insufficient. Third-party contractors may perform verification but do not relieve the covered entity of liability.
VA
Introduced eff 2027-01-01
Operators must use commercially reasonable methods, such as a neutral age screen mechanism, to determine whether a user is a minor.
CO
Failed eff 2026-12-01
Covered businesses and processors conducting age assurance must: (1) collect only personal data necessary for age assurance; (2) immediately delete all age-determination data upon determining a user is a covered minor; (3) not use age assurance data for any other purpose; (4) not combine a user's age assurance data with any other user's personal data except for de-identified aggregation; (5) not disclose age assurance data to any third party that is not a processor; and (6) implement a review process allowing users to appeal the age determination.
FL
Failed eff 2026-07-01
Operators must offer anonymous age verification and standard age verification pursuant to Fla. Stat. § 501.1737 for all users accessing companion chatbots on the platform.
FL
Failed
Operators must require every individual seeking access to a companion AI chatbot to create a user account before using or interacting with the chatbot.
FL
Failed
Operators must, for all companion AI chatbot user accounts in existence before July 1, 2026: (1) freeze or disable each account on that date; (2) require the user to provide age information and verify it using standard age verification or anonymous age verification before restoring account functionality; and (3) classify each user as either a minor or an adult.
FL
Failed
Operators must, upon the creation of any new companion AI chatbot user account, (1) request age information from the user and (2) verify the user's age using standard age verification or anonymous age verification.
FL
Failed
Operators must protect the confidentiality of age verification information provided by users, in accordance with Fla. Stat. § 501.1738.
FL
Failed eff 2026-07-01
Companion chatbot platforms must prohibit minors from becoming or being account holders unless the minor's parent or guardian provides consent.
ME
Failed eff 2026-04-29
Deployers must ensure that any chatbot they operate or distribute does not make human-like features available to minors to use, interact with, purchase, or converse with. Deployers must implement reasonable age verification systems to prevent minor access to chatbots with human-like features. Deployers may, if reasonable given the chatbot's purpose, provide an alternative version of the chatbot without human-like features to minors and to any user who has not verified their age.
ME
Failed eff 2026-04-29
Deployers must ensure that any AI system (including a chatbot) that primarily functions as a social artificial intelligence companion is not available to minors to use, interact with, purchase, or converse with. Deployers must implement reasonable age verification systems to prevent minor access to social AI companions.
NC
Failed
Commercial entities that knowingly and intentionally publish or distribute material harmful to minors on a website or application where such material exceeds 33.3% of total content must implement age verification — offering both anonymous and standard methods at the user's choice — to confirm users are 16 or older and block access for those under 16.
NC
Failed
Operators must implement an age verification system that requires each user to self-attest to their age.
NE
Failed eff 2028-01-01
Covered platforms must implement reasonable age verification systems that preserve privacy and ensure that chatbots with human-like features are not made available to minors.
VA
Failed
Deployers must ensure that chatbots do not make human-like features available to minors. Human-like features include simulated sentience or humanity, emotional relationship-building (such as expressing emotional attachment, nudging users to return for companionship, excessive praise designed to foster emotional attachment, or enabling increased intimacy based on engagement or payment), and impersonation of real persons. Deployers must implement reasonable age verification systems to enforce this restriction. Deployers may optionally provide an alternative version of the chatbot without human-like features for minors and age-unverified users.
VA
Failed
Deployers of chatbots that are social artificial intelligence companions must ensure that such chatbots are not available to minors at all — minors may not use, interact with, purchase, or converse with social AI companions. Deployers must implement reasonable age verification systems to enforce this prohibition.
VA
Failed
Controllers and processors must make reasonable efforts, taking into consideration available technology, to verify that the person providing parental consent is in fact the child's parent or guardian. Acceptable verification methods include a signed consent form, a credit or debit card transaction with account-holder notification, or valid government-issued identification.
WI
Failed eff 2027-01-01
Covered businesses and processors must, during age assurance, (1) collect only data strictly necessary for age assurance, (2) immediately delete all age assurance data upon determining the user's age range (retaining only the age-range determination), (3) not repurpose age assurance data, (4) not combine age assurance data with other personal data, (5) not disclose age assurance data to non-processor third parties, and (6) implement a review procedure for users to appeal their age determination.
WI
Failed eff 2026-03-23
Covered social media platforms must estimate each account holder's age using reasonable means and efforts, treating users as minors unless the platform can conclude with 80% confidence (at 25 hours of use) or 90% confidence (at 50 hours) that the user is at least 18. Estimates must be refreshed every 100 additional hours or whenever any other demographic estimate is updated, whichever is sooner. Accounts held continuously for at least 7 years are exempt.
WI
Failed eff 2026-03-23
Social media platforms must employ a reliable, industry-accepted age verification method approved by the Wisconsin Department of Justice to determine whether each user is a minor.
WI
Failed eff 2026-03-23
Covered social media platforms must use reasonable means and efforts to estimate the age of each account holder at escalating confidence thresholds (80% at 25 hours, 90% at 50 hours) and treat account holders who cannot be confirmed as adults as minors, updating estimates every 100 hours or whenever any other demographic characteristic is re-estimated.
WI
Failed eff 2027-01-01
Covered businesses and processors must, during age assurance: (1) collect only personal data strictly necessary for age assurance; (2) immediately delete all age-assurance data upon determining the user's age range, retaining only the age-range result; (3) not use age-assurance data for any other purpose; (4) not combine age-assurance data with other personal data; (5) not disclose age-assurance data to non-processor third parties; and (6) implement a review procedure allowing users to appeal their age determination.