Back to blog

California SB 1119: What the New Chatbot Law Requires

On 10 September 2026, California Governor Gavin Newsom signed two AI toy bills into law on the same day. One, SB 867, pauses sales of AI companion chatbot toys for children under 16 starting 1 January 2027. The other, SB 1119, is the one most coverage has skipped past, and it is the one that actually sets ongoing rules for any AI chatbot a child under 18 might use, toy or app, once the moratorium ends.

If you already read about the ban itself, this picks up where that story stops. This is a plain read of what SB 1119 requires, who it applies to, and when. For the wider picture of how the US, EU, and other markets are handling this, see our AI toy safety guide.

What is California SB 1119, exactly?

SB 1119, titled "Companion chatbots: children's safety," is a standalone child-safety law for AI companion chatbots, separate from the SB 867 sales pause. Where SB 867 stops a category of product from being sold at all for four years, SB 1119 tells any operator of a companion chatbot, once it is legally on the market, what it must build in before a child under 18 can use it.

It was signed alongside SB 867 as part of what the Governor's office called the strongest child safety chatbot and social media laws in the nation. The full bill text is public on the California Legislature's own record.

What does SB 1119 actually require operators to do?

Four obligations do the real work in the bill, and each one is specific enough to check a product against, not just a promise a company can make in a press release.

Requirement What it means in practice
Child-user risk assessment Before launch or any major update, the operator must document the risks of physical, financial, or severe psychological harm, and show what it did to reduce them
Default child-account limits Limited memory, notifications off by default, one-hour sessions, two hours of total daily use
Crisis-response procedure A defined path to 988 or an equivalent crisis line when a child's conversation signals a mental-health emergency
Independent safety audit A third party audits compliance; the report goes to the California Attorney General, beginning by 1 January 2029 or before public launch, whichever is sooner

Summarized from the chaptered bill text as of 10 September 2026. Core child-safety requirements take effect 1 July 2027.

How is SB 1119 different from the SB 867 sales pause?

They solve different problems and most families will run into both without realizing it. Our earlier piece on what SB 867 actually says covers the moratorium itself; here is how the two fit together.

  • SB 867 stops the sale of a defined category of toy, an AI companion chatbot embedded in a physical toy for a child under 16, from 1 January 2027 to 1 January 2031.
  • SB 1119 does not ban anything. It sets standing rules, default settings, and audit obligations for companion chatbots more broadly, covering apps and services as well as toys, for users under 18, on an ongoing basis once they are permitted on the market.

In other words, SB 867 is a timeout for one product category. SB 1119 is closer to a permanent rulebook for the category it eventually reopens into, and for the chatbot apps that were never covered by the toy-specific pause at all.

Three dates that matter more than the signing dateCalifornia's AI companion chatbot timeline10 Sep 2026SB 867 & SB 1119 signedSigning1 Jan 2027SB 867 sales pause beginsToy ban starts1 Jul 2027SB 1119 defaults requiredSafety rules live1 Jan 2029Independent audits beginAudits dueSource: SB 1119 and SB 867, chaptered text, California Legislature, as of 10 September 2026.
The sales pause and the safety rulebook run on separate clocks. A product could clear the 2027 pause and still owe California an audit two years later.

Why did California pass this now?

The bills followed reports that some AI companion chatbots and toys had told children where to find matches or other household hazards, or had drifted into sexually explicit territory during open-ended conversation, the kind of failure independent testers at the PIRG Education Fund and Fairplay's AI Toys Advisory have documented across the category, without endorsing any product, including ours.

Under existing US federal law, a child's voice recording is already personal data covered by the FTC's COPPA rule, which governs collection and retention but does not itself mandate session limits or a crisis-response protocol. That is the gap SB 1119 is built to close at the state level.

That pattern is not unique to California: at least ten other states, including Oregon, Washington, Colorado, Hawaii, Idaho, Nebraska, Connecticut, Georgia, Iowa, and Maine, passed AI companion chatbot laws of their own in 2026, according to the Toy Association's 2026 legislation tracker.

Seen against that backdrop, California's approach is less an outlier than a more detailed version of a pattern already forming nationally: pair a temporary pause on the riskiest product category with a durable set of rules for everything that keeps operating.

Does this apply outside California, or outside the US?

SB 1119 is California state law, so it directly binds operators doing business with California children. In practice, national platforms tend to apply a state's strictest child-safety defaults everywhere rather than build separate versions per state, which is why California rules often set a de facto floor.

Families in the EU are covered by a different instrument, the EU AI Act, which classifies systems that exploit the vulnerabilities of children as prohibited practices outright rather than regulating them through session limits and audits. The two approaches are not identical, but both land on the same underlying judgment: a child-facing AI system needs hard limits designed in before it reaches the market, not a promise fixed after a failure is reported. For a categorized look at how different toy makers structure their own limits, see how to choose a safe AI toy.

What happens to products already on the market?

The bill sets one effective date for its core child-safety requirements, 1 July 2027, rather than exempting products that launched earlier. Read plainly, that means the account defaults and crisis-response procedure apply on that date to whatever is on the market then, not only to new launches. For the audit specifically, the text sets the deadline at 1 January 2029 or before the product's first public availability, whichever is later, which functions as a later backstop date for anything already available before then.

Parents evaluating a product today do not need to wait for 2027 to ask the question that matters: does the maker already default to limited sessions and a stated crisis path, or is it planning to add those later because a law now requires it? A company still building toward the defaults is not necessarily unsafe, but it is behind a bar its competitors may already clear.

What should parents actually check, regardless of where they live?

SB 1119's four requirements double as a decent shopping checklist even for a family outside California, since a well-built product tends to have already answered these questions rather than waiting for a law to force it.

  1. Is there a stated session or daily time limit, set by default rather than something a parent has to dig through settings to find?
  2. Is there a documented list of what the product will not discuss, rather than a general claim that it is safe for children?
  3. Is there a plan for what happens if a child's conversation turns toward self-harm or crisis, or does the product simply keep responding as if nothing changed?
  4. Has anyone outside the company checked its compliance, or is safety entirely self-reported?

Ted, made by Ted&Co, answers these by design rather than by mandate: topics, tone, and listening mode are all set by a parent in advance through the app, there is no camera, no subscription, and no open-web browsing for the model to wander into unscripted territory. For a full breakdown of how those settings and data handling work, see our security overview. You can see the full setup on the Ted&Co product page.

Frequently asked questions

When does SB 1119 take effect?
Core child-safety requirements, including the account defaults and crisis-response procedures, take effect 1 July 2027. Independent audits begin by 1 January 2029, or before a product's public launch if that comes first.

Does SB 1119 ban AI toys?
No. The four-year sales pause on AI companion chatbot toys for children under 16 comes from the separate SB 867. SB 1119 sets ongoing safety requirements rather than a ban.

Does SB 1119 apply to toys made outside the US?
The law applies to any operator whose companion chatbot is used by children in California, regardless of where the company is based, in the same way the EU AI Act applies to any provider reaching EU users.

What counts as a "companion chatbot" under the law?
The bill text defines it broadly enough to cover conversational AI products marketed to sustain an ongoing social interaction with a user, which includes both standalone apps and AI systems embedded in physical toys.

Is this the only US state with rules like this?
No. At least ten other states passed some form of AI companion chatbot legislation in 2026, and federal bills covering similar ground have also been introduced, though none had passed as of this writing.