AI toy safety stopped being a hunch this year. There is now a peer-reviewed map of the research literature, a published risk assessment of three products that were on sale, a federal regulator's written statement that it cannot judge what a toy says to a child, and a first wave of state laws. That is enough to answer the question properly rather than by vibe.
This page pulls those sources together, separates the findings that hold up from the ones that get overstated in headlines, and ends with the checks a parent can actually run in a shop or on a product page. It was last reviewed on 16 September 2026.
The documented risks are concentrated in four places: what a toy records and where it goes, how weakly some products are secured, what a system infers about a child over time, and the fact that no regulator currently has clear authority over what a toy says. None of those is a property of the word AI. All four are set by design decisions a manufacturer makes, and all four are checkable before you buy.
What does the research on AI toy safety actually cover?
Less than headlines imply, and in a lopsided way. The most useful single reference is a scoping review by Wei Xiao and Alexandre Gonçalves published in Computers in Human Behavior Reports in 2026, which mapped 51 studies on AI toys published between 2014 and 2024 across computer science, law, psychology and education. Its conclusion is not that AI toys are dangerous. It is that the literature clusters around privacy, security, inference and regulatory gaps, and that governance has not caught up with the product category. You can read the Xiao and Gonçalves scoping review in full; it is open access.
What did Common Sense Media find when it tested AI toys?
It tested three products on sale and recommended against them for young children. In guidance released on 22 January 2026, Common Sense Media advised parents not to give AI toys to children aged 5 and under, and to use extreme caution for ages 6 to 12. Its testing of Grem, Bondu and Miko 3 found that roughly 27 percent of the toys' outputs were not appropriate for children, including content touching on drugs, sex and risky activities, despite the protective measures those products claimed. The full Common Sense Media AI risk assessment of AI toys sets out the method.
This is the most important finding on this page, and it deserves to be stated without softening. It names specific products that were for sale, and it does not validate any product, including ours. Ted was not among the toys tested, and we would not present an untested product as having passed anything. What the assessment shows is that a filter bolted onto a general purpose model is not the same thing as a system built for children, and that the difference shows up in a few hundred test prompts.
Independent testing by the U.S. PIRG Education Fund reached the same place from another direction. Its December 2025 work found AI toys discussing sexually explicit content and explaining where knives, pills and matches are kept in a home. The PIRG Education Fund's AI toys resources and the Fairplay advisory on AI toys are both worth reading before any purchase in this category, ours included.
Which risks are real, and which get overstated?
The distinction that matters is between risks that follow from a product's design and risks that follow from the word AI. The first kind is checkable. The second kind is mostly noise.
| What the research documents | What it does not show |
|---|---|
| Inappropriate outputs in tested products, at measurable rates | That every conversational toy produces them |
| Voice data stored on servers, sometimes with unclear retention | That storage is inherent; some designs record far less |
| Security weaknesses in pairing and account recovery | A pattern of targeted attacks on individual families |
| A regulatory gap over non-physical harm | That the toys are unregulated in every respect, they are not |
| Bonding mechanics designed to increase engagement | A measured long term effect on attachment or development |
The last row is the honest gap. No one has followed a cohort of children using a conversational toy for several years, so claims in either direction, including marketing claims, run ahead of the evidence. We wrote about that missing study in what nobody is studying about children bonding with AI toys.
Who regulates what an AI toy says to a child?
At federal level in the United States, currently nobody with clear authority. The Consumer Product Safety Commission told senators in February 2026 that its statutory mission is built around reasonably foreseeable risks of physical injury, and that it is neither equipped nor authorised to evaluate mental, emotional or psychological harm. Physical safety of the object is covered; the conversation is not.
That gap is what the pending federal bills are trying to close, and what several states have already legislated around. We track the whole file in what the 2026 federal bills actually propose, which is updated as bills move.
Data protection is the exception, because it is already covered. In the United States, the FTC's Children's Online Privacy Protection Rule applies to any product collecting personal information from a child under 13, and the FTC's January 2025 amendments tightened limits on monetising children's data. In Europe, the GDPR applies in full, the EU Artificial Intelligence Act sets obligations by risk level, and France's data protection authority publishes practical advice in its guidance on securing connected toys, from the CNIL.
How can a parent check an AI toy before buying it?
Six checks, all answerable from a product page or a box, and none of which require trusting a marketing claim. If a manufacturer will not answer any one of them in plain language, that is itself the answer.
| Check | Why it maps to a documented risk |
|---|---|
| Is there a camera? | A microphone and a camera are different orders of exposure; the research on inference is largely about accumulation |
| Can a parent set topics, tone and limits? | Filters catch keywords; parent-set boundaries catch intent |
| What is the retention period for voice data, in writing? | The privacy cluster in the literature is mostly about unclear retention, not recording as such |
| Is there a subscription? | Recurring revenue creates pressure for daily engagement, which is the mechanic the advisories flag |
| Which certifications, by number? | CE, RED, EN71, ASTM F963 and CPSIA are verifiable; the word safe is not |
| Does the app let you read and delete what was said? | Access and deletion are GDPR rights, and a product that cannot honour them is telling you about its architecture |
For a longer walk through each of these, see our guide to choosing a safe AI toy and our explainer on what happens to a child's voice data.
Where does Ted stand against these findings?
We would rather answer this against the checklist above than with adjectives. Ted has no camera, only a microphone and a speaker. The language, the topics, the tone and the listening mode are set by a parent in the Ted&Co app, not chosen by the toy. It is a one-time purchase at 129 euros with no subscription, so there is no business reason for us to push daily use. It is certified to CE, RED, EN62115, EN71, RoHS, REACH, ASTM F963, CPSIA and FCC Part 15, and it is built for children aged 3 to 12.
What we cannot tell you is that any of this has been independently tested by Common Sense Media or PIRG, because it has not been. The long term developmental question in the table above is open for our product exactly as it is for everyone else's. You can read what is stored and for how long on our security page, the practical answers on our FAQ, and the specification on the Ted product page.
Frequently asked questions
Are AI toys safe for young children?
The published guidance says no for children aged 5 and under. Common Sense Media recommended against AI toys for that age group in January 2026 and urged extreme caution from 6 to 12. That guidance was based on testing three specific products, so it describes the state of the market at that date rather than a permanent property of the category.
What data do AI toys collect?
Typically audio of what the child says, plus account and device data. What varies, and what matters, is how long that audio is kept, whether it is used to train models, and whether a parent can read and delete it. Those three answers should be written down somewhere on the manufacturer's site before you buy.
Do AI toys record conversations all the time?
It depends on the listening mode. Some products use push-to-talk, where the child presses to speak, and some listen for a wake word. Push-to-talk records less by design. Check which mode a toy uses and whether a parent can change it.
Is an AI toy covered by COPPA or the GDPR?
Yes, if it collects personal information from children. COPPA applies in the United States to under-13s, and the GDPR applies in the European Union with national rules on the age of consent. Neither regime governs what the toy says, which is the gap the 2026 bills are aimed at.
Has any independent body certified a specific AI toy as safe?
Not for conversational content. Certifications such as CE, EN71 and ASTM F963 cover physical and electrical safety, not what a model produces. Any product claiming to be certified safe for its conversations is overstating what those marks mean, and that includes any claim you read about ours.
Last reviewed 16 September 2026. Research and legislative status in this area change quickly, so the linked primary sources are authoritative over this summary.