On September 10, Governor Newsom signed a child-safety package built around two ideas: companion chatbots should not be allowed to improvise around a crisis, and social platforms should not be allowed to point an engagement engine at anyone under 16.
Sacramento has a ritual for technology bills. The governor stands with the First Partner, the authors line up behind the signing table, and the press release announces that California has once again written the strongest law in the country. That ritual happened on September 10 in Marin County. This time the subject was children, companion chatbots, and the design patterns social platforms use to hold a teenage thumb on a glass screen.
The ritual is easy to mock. The package is not. Strip the adjectives out of the governor’s office release and you still have a real shift in how California treats two product categories that spent a decade insisting they were speech, not design. Companion chatbots now have to prove, in writing and under independent review, that they are not going to treat a minor as an adult conversation partner. Covered social platforms now have to strip autoplay and history-based algorithmic feeds from users under 16. Those are product rules. Product rules are harder to dodge than mission statements.
They are also not a ban on teenagers using the internet. Anyone selling this package as a digital curfew is not reading the bills. Kids can still have accounts. What they cannot have, at least as a default and at least under California law, is the engagement stack the industry spent fifteen years optimizing.
Adam’s Law is the chatbot bill everyone will cite
Senate Bill 1119, signed as Chapter 190, is the centerpiece. Co-authored by Senator Steve Padilla and Assemblymembers Buffy Wicks and Rebecca Bauer-Kahan, it is named for Adam Raine. It takes effect for operators on July 1, 2027. The statute does not pretend a chatbot is a person and then hope for the best. It treats a companion chatbot as a product with a foreseeable minor user, and it loads obligations onto that product before it ships.
Before an operator makes a new or substantially modified companion chatbot available in California, it has to perform and document a child-safety risk assessment. That assessment has to cover the design, the configuration, and the live operation of the system as it relates to minors, including evaluations of covered harms. The operator then has to submit to independent child safety audits of its compliance. The auditor’s report has to say whether the company established and followed policies that match the statute, and the lead auditor signs that conclusion under penalty of perjury. That last detail matters. A safety PDF that nobody will swear to is marketing. A signed audit is a record.
The product defaults are the part most companies will feel first. For users under 18, persistent conversational memory is off. Push notifications are off. Sessions are capped at one hour, with a two-hour daily ceiling. Operators have to use the privacy-protective age-bracket signal California already required under the Digital Age Assurance Act rather than inventing a parallel age-gating theater. Parents get controls. If a child turns the safety settings off, the parent gets notice. If there is a credible threat of imminent self-harm, or the operator knows the child engaged in self-harm, the statute requires a parental notice and a path to crisis resources inside the product. The chatbot cannot claim to be human. It cannot simulate romantic interest in a child. Cross-context behavioral ads aimed at minors are out.
California already had a first-generation companion chatbot law. That earlier statute told operators to disclose that the user was talking to a machine and to route a minor in crisis toward help — if the operator knew the user was a minor. “If the operator knows” is how a lot of children’s privacy law dies in practice. SB 1119 deletes that convenient knowledge standard and replaces it with an age-signal duty plus default lockdowns. That is the actual upgrade. The press release calls it the strongest chatbot child-safety law in the country. For once the slogan is close to the text.
OpenAI endorsed the bill in the same week Newsom signed it. That endorsement is not charity. After a year of lawsuits, congressional letters, and a public argument about what companion products owe teenagers, supporting a California statute that other states can copy is cheaper than waiting for fifty different crisis-protocol drafts. It is also a bet that the labs would rather write the risk-assessment template than have a jury write it later.
AB 1709 goes after the feed, not the account
Assembly Bill 1709, authored by Assemblymember Josh Lowenthal, is the social-media half of the headline. It passed without a no vote in either house. That is not normal for a bill that tells Instagram, TikTok, and YouTube they may not serve addictive features to anyone under 16.
The statute builds on California’s earlier Protecting Our Kids from Social Media Addiction Act, which already restricted addictive feeds for minors unless the platform lacked actual knowledge or had verifiable parental consent. AB 1709 tightens the frame. A covered platform may not provide an addictive feature — the definition includes addictive feeds and autoplay — to a user under 16. The platform has to take reasonable measures to make sure those features are not offered. Age has to be established under the same age-assurance architecture the state has been stacking since last year. Parents can still consent in some postures. What the platform cannot do is treat a fifteen-year-old’s watch history as fuel for an infinite recommendation loop and call that a First Amendment product.
Enforcement is public, not private. The Attorney General or a local prosecutor brings the case. Knowing violations can draw civil penalties of up to $50,000 per affected minor; negligent violations, $25,000. The Attorney General also gets rulemaking authority to expand what counts as an addictive feature and, if needed, to widen the set of covered platforms. That is the sleeper clause. The Legislature wrote a list. The Department of Justice can keep writing it as the product teams invent the next loop.
The bill also creates an e-Safety Advisory Commission inside the Department of Justice. Five members. Independent for advice, parked at DOJ for admin. It reports every January to the Governor and the Legislature. Advisory commissions are where good statutes go to become white papers, unless someone treats the annual report as an enforcement memo. Watch who gets appointed.
Lowenthal’s companion measure, Assembly Bill 2, is the damages bill. It raises what a large platform can owe when its conduct injures a child — reporting around the signing put the outer number as high as $1 million per child for negligent harm at the large-platform tier. That is the part general counsels will underline. Design rules without a number attached to them get litigated as philosophy. Design rules with a per-child number get budgeted.
The rest of the package is not filler
The governor’s office listed thirteen bills. Two of them will eat the coverage. The others are how the state closes the gaps platforms use after the headline statute lands.
Age signals get another turn in AB 1856. Child sexual abuse material reporting gets another turn in AB 1946. Access-by-children rules for online services sit in AB 2246. Student personal information, including how K-12 pupil data can be used in AI systems, sits in AB 1159. Digital wellness instruction is in AB 2071. Addictive feeds in the school-activity context show up in AB 302. School-issued devices and technology-based materials are in SB 1128. Computer science standards are in AB 2298. SB 1276 expands the criminal definition of sexual exploitation of a child to reach digitally altered and AI-generated depictions of a minor in sexual conduct. SB 867 takes the companion-chatbot problem down to toys. None of that is glamorous. All of it is how you stop a company from complying with the chatbot bill and then training a classroom model on a district’s homework folder.
The CSAM and deepfake expansions are the part of the package that should not be controversial and will still be litigated. California has already been pushing civil and criminal tools against nonconsensual sexually explicit material, including AI-generated images, and has put six-figure civil numbers on facilitators. Extending “child sexual exploitation” to cover synthetic depictions of a real or apparent minor is the only position that matches how these systems actually work. A generator that can produce the image does not get a pass because no camera was in the room.
What the signing statement leaves out
The release spends a lot of words on California’s greatest hits: warning labels, age-verification signals, after-school cyberbullying guidance, platform policy transparency from 2022, the earlier companion-chatbot protections, Soluna and Brightlife Kids, the Teen Tech Council, the 2023 AI executive order, the 2024 AI package, SB 53 on frontier-model transparency, yesterday’s auditor registry and independent verification framework. That recap is not wrong. It is a campaign document stapled to a bill list.
Three problems sit underneath it.
First, age assurance is still the load-bearing wall, and load-bearing walls fail. Every one of these duties — no addictive feed under 16, locked chatbot defaults under 18, no targeted ads to kids — collapses if the platform can say it did not know. California has been trying to kill that excuse with operating-system age-bracket signals. That is the right architecture. It only works if device makers, app stores, and covered platforms actually implement the signal the same way, and if the Attorney General treats a broken implementation as a violation rather than a beta.
Second, “independent child safety audit” will mean whatever the first three audit firms and the first three labs agree it means. SB 1119 requires the audit. It does not, in the governor’s summary, hand the public a scoring rubric. The state just spent two days building a registry for AI auditors and a framework for independent verification organizations. Those two regimes will collide with Adam’s Law whether anyone planned it or not. If child-safety audits become a specialty line inside the new auditor marketplace, that can be useful. If they become a second self-grading exercise with better stationery, the signed lead-auditor certification is the only thing standing between the statute and a consultancy product.
Third, the federal vacuum is real and everyone in the room knows it. Newsom closed the release the way he closes most of these: California will lead, Washington should catch up. Fine. State child-safety law is how you get movement when Congress cannot pass a kids’ online safety bill that survives both chambers and a platform lobby. It is also how you get a compliance map that looks like a patchwork quilt stitched by thirteen authors in one session. Platforms will forum-shop the definitions. Smaller chatbot startups will either geofence California or sell themselves to someone who can afford the audit. That is not a reason to veto the bills. It is a reason to write the implementing regulations like you expect to be copied and gamed.
Do you operate tools that target minors?
If you operate a companion chatbot that California minors can reach, start the risk assessment now. Do not wait for a trade-association template. Document covered harms, default settings, memory behavior, notification logic, session limits, crisis routing, and how you consume the age-bracket signal. Assume the first auditor will ask for the system prompt, the safety classifier thresholds, and the log of times a minor tried to turn protections off.
If you operate a covered social platform, inventory every feature that looks like autoplay, infinite scroll, or a history-and-profile recommendation loop. Separate the logged-out or age-unknown experience from the under-16 experience. Build the parental-consent path as a product, not a policy PDF. AB 1709 is effective January 1, 2027. That is sooner than the chatbot audit clock.
If you sell into K-12, read AB 1159 before you pitch an “AI tutor trained on district data.” Pupil-data rules in an AI system are about to have a statute number attached.
And if you are a general counsel who has been telling the board that California child-safety law is “evolving,” you can retire the euphemism. The state just told chatbot makers they need a signed audit and told social platforms they cannot point the engagement engine at a fifteen-year-old. The speeches were about responsibility. The bills are about defaults. Defaults are what change products.