Back to blog

States Passed 14 New AI Chatbot Laws This Year. What It Means for Kids' Toys

If you have been shopping for a talking toy this year, you have probably noticed the headlines get louder and less helpful at the same time. One week a report says AI toys are unsafe. The next week a state passes a law. The week after that, a think tank says the law is the wrong law. It is hard to tell whether anything has actually changed for the toy sitting on your child's bed.

So here is the honest version. In the first eight months of 2026, US states passed more rules about talking machines than in the previous decade combined, Europe rewrote its toy rulebook, and on 10 August a major technology policy institute published a report arguing that a lot of this new law will not do what parents think it does. Below is what actually passed, what it covers, what it misses, and the small number of things a parent can check today without waiting for any of it.

Updated 12 September 2026

Since this article was first published, three states now have live bills that would ban or pause the sale of AI toys rather than merely regulate how they behave: California SB 867, New York SB 9408 and Pennsylvania HB 2637. None has been enacted. A new section below sets out what each one would do and where it stands. Nothing else in this article has changed: state chatbot law still outnumbers federal law, and the European toy rules still do not apply until 2030.

How AI toy and chatbot rules moved in 2026Six months that changed what a talking toy is legally allowed to doJan 2026into force (apply in 2030)EU toy safety rules enterMar 2026Researchers call forAI toy safety labelsJun 2026chatbot law on the books11 US states have aJul 2026Digital rights groupspush back on federal bill10 Aug 202650-state patchworkITIF warns against aSources: Regulation (EU) 2025/2509, University of Cambridge, Transparency Coalition, Electronic Frontier Foundation, ITIF.
The pattern worth noticing: almost all of the fast movement happened at state level, while the two big structural reforms (Europe's toy regulation and the federal bills) will not bite for years.

What actually happened with AI chatbot laws in 2026?

States legislated, and Congress did not. The Transparency Coalition's mid-year review counted 14 chatbot safety measures passed or enacted across 13 states in 2026, which it called a watershed year for the category. As of June, 11 states had a chatbot law on the books: California, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island and Washington.

What makes this unusual is that the wave crossed party lines. Georgia and Idaho legislated alongside Washington and New York, which is not how online safety bills normally travel. Connecticut went furthest, folding chatbot safeguards, protections for minors, parental controls and AI subscription rules into a single 74 page law. The Future of Privacy Forum's 2026 chatbot legislation tracker counts close to 100 chatbot-specific bills introduced nationwide, most of which did not pass. We covered the Oregon and Washington laws in detail when they were signed.

What do these state laws actually require?

Most of them require disclosure, crisis protocols and some form of parental access. Very few of them require anything about how the underlying model was built or trained. The table below summarises the provisions that appear most often, based on Orrick's review of the 2026 state chatbot laws.

Common provision What it means in practice Does it cover a physical toy?
Disclosure duty The system must tell the user it is not a human Usually yes, if the toy holds a conversation
Crisis protocol Referral to help lines when self-harm is mentioned Yes, though written with teens in mind
Parental controls A guardian must be able to see or limit use Yes, where a companion app exists
Companion chatbot rules Extra duties for systems that simulate a relationship Ambiguous, and this is the live fight
Age assurance Some check on how old the user is Rarely, toys are sold to a parent, not a user

Read that last column carefully. A great deal of 2026 chatbot law was written for a teenager typing into a phone. A four year old talking to a bear in a bedroom is a different situation with different risks, and the statutes mostly do not say so.

Which states are trying to ban AI toys outright?

Three, and none of them has succeeded yet. California, New York and Pennsylvania each have a bill that would stop the sale of AI toys rather than regulate how they behave, and as of 12 September 2026 all three are still pending. This is the part of the landscape that changed most since the summer, and it is worth separating from the chatbot laws above, which regulate conduct rather than availability.

Bill What it would do Status on 12 September 2026
California SB 867 A four year moratorium on toys containing companion chatbots, defined as AI systems capable of sustaining human-like relationships Pending
New York SB 9408 An outright ban on the sale of chatbot toys, plus a study committee to report on long-term effects on children after four years Pending
Pennsylvania HB 2637 A three year moratorium on the sale of children's toys containing AI chatbots, with penalties for non-compliance Referred to the House Communications and Technology Committee on 15 June 2026

The Pennsylvania bill is the newest of the three. It was introduced by Representative Joe Ciresi, who chairs the House Communications and Technology Committee, and you can read the bill record on the Pennsylvania General Assembly site and the sponsor's own announcement of the moratorium. The New York text is on the New York Senate's legislation site, and California's is on the state's legislative information portal. The Toy Association keeps a running summary of state and federal AI toy activity, which is the fastest way to see whether any of this has moved since you read it here.

Two honest observations. First, all three bills turn on the phrase companion chatbot or its equivalent, and none of them defines it in a way that clearly separates a system designed to simulate an ongoing emotional bond from a toy that answers a question and tells a story. That drafting problem is the same one ITIF flags below. Second, a moratorium is a blunt instrument that would remove well-designed products alongside badly designed ones, which is a reasonable trade if you think the category cannot be made safe and an expensive mistake if you think it can.

At federal level the picture is steadier. The White House published a National Policy Framework for Artificial Intelligence on 20 March 2026 that lists protections for minors and parental tools among its priorities, and explicitly warns against a fragmented state-by-state landscape. A framework is not a statute.

Why does a policy institute say the new rules could backfire?

Because rules written for one product can quietly ban a better one. On 10 August 2026 the Information Technology and Innovation Foundation published a report on what policymakers should and should not do about chatbot safety for children. Its central argument is that lawmakers keep treating every conversational system as one category.

ITIF recommends separating general purpose chatbots from systems deliberately designed to simulate emotional relationships, and applying the strictest duties to the second group. It argues for targeted safeguards, meaningful parental controls, clear legal standards and continued research, rather than blanket age bans that would also remove documented educational and creative benefits. Its accompanying press release frames this as smarter policy rather than less policy, and StateScoop's coverage focuses on the practical risk of a 50 state patchwork that small manufacturers cannot navigate.

It is worth saying plainly that ITIF is a technology policy institute with industry funding, so its scepticism about broad restrictions is not a neutral view from nowhere. The useful part of the report is not its conclusion but its distinction, which most of the passed statutes genuinely lack.

Is there a counter-argument from the other side?

Yes, and it comes from an unexpected direction. The Electronic Frontier Foundation, which is usually the group arguing hardest for privacy, published a critique of the federal CHATBOT Act in July 2026 arguing that the bill forces a single parenting model on every family and would require identity verification that harms privacy in the name of protecting it.

So the debate is not simply industry against advocates. There is a real disagreement about whether mandatory age checks and blanket restrictions protect children or simply move the risk somewhere less visible while creating new databases of who is who. Meanwhile the main federal vehicle aimed specifically at toys, the Children's Artificial Intelligence Toy Safety Act of 2026, does something more modest than its title suggests: it mandates a study of AI-enabled toys and a joint action plan on their marketing and sale. A study is not a standard.

What about Europe, where the toy rules were just rewritten?

Europe did rewrite them, but not on the timeline most coverage implies. Regulation (EU) 2025/2509, the new Toy Safety Regulation, was published on 12 December 2025 and entered into force in early 2026. Its substantive requirements do not apply until 1 August 2030, after a transition period of roughly four and a half years, as Intertek's regulatory FAQ sets out.

The content matters even if the deadline is distant. Connected toys will need a safety assessment that explicitly accounts for children's vulnerabilities, and toys connected to the internet will have to sit alongside the Cyber Resilience Act, the AI Act and data protection law rather than being treated as ordinary plush. We looked at how the AI Act interacts with toys specifically in our piece on what the 2026 EU rules actually say. The practical upshot for a parent buying today is uncomfortable but simple: the strongest European protections are real, and they are four years away.

So what should a parent check before buying a talking toy?

Check the design choices, not the marketing claims, because design choices are the part no future law can retroactively fix. Regulation moves in years. A toy bought in November is in the house next week.

Five things to verify before you buy

  • Is there a camera? If yes, ask why a toy that talks needs to see. A microphone and speaker are enough for conversation.
  • Is there a subscription? A recurring fee means the company needs continued engagement from your child to stay solvent.
  • Can you see and change what it discusses? Parental control that exists only as a marketing bullet is not parental control.
  • What happens to the recordings? Look for an explicit statement on retention, resale and deletion, not a general privacy promise.
  • Which certifications, and issued by whom? Named standards with named bodies, not a generic safety badge.

That fourth point is the one that has caught real products out. Testing this year found toys claiming secure handling while their own privacy policies allowed third party sharing and biometric retention measured in years. If you want the longer version of what each certification actually covers, we wrote a plain language guide to CE, ASTM F963 and CPSIA.

Where does Ted&Co stand on all this?

Our position is that the failures described in these reports are design failures, not inevitable properties of talking toys. A toy that harvests biometric data does so because someone decided to collect it. A toy that pushes for engagement does so because a subscription depends on it.

So Ted has no camera, only a microphone and speaker. There is no subscription, which removes the commercial incentive to maximise time spent talking. Parents set the language, the topics, the boundaries and the tone from the Ted&Co app, and can switch between push-to-talk and automatic listening. We do not sell data and we do not run advertising. Our certifications and compliance page lists what has been tested and by whom, including GDPR and COPPA alignment, and the FAQ answers the specific questions parents send us most.

None of that is a claim that regulation is unnecessary. Clear rules would help honest manufacturers more than they hurt us. It is a claim that you should not have to wait until 2030 to buy a toy built the right way.

Frequently asked questions

Are AI toys banned anywhere in 2026?

No jurisdiction has enacted an outright ban on AI toys as of 12 September 2026. Three bills would change that, in California, New York and Pennsylvania, and all three remain pending. Talking toys continue to be legal to sell across the US and the EU.

Do state chatbot laws apply to my child's toy?

Often yes, but indirectly. Most 2026 state laws regulate conversational systems by function rather than by device, so a toy that holds a conversation can fall within scope. The duties were largely drafted with teenagers using phones in mind, which is why coverage of young children is uneven.

When do the new EU toy safety rules actually take effect?

Regulation (EU) 2025/2509 entered into force in early 2026 but applies from 1 August 2030 after a transition period of about 54 months. Until then, toys sold in the EU continue to comply with the existing Toy Safety Directive framework plus GDPR and the AI Act.

What is the difference between a chatbot and a companion chatbot?

A general purpose chatbot answers questions and performs tasks. A companion chatbot is designed to simulate an ongoing emotional relationship, often using memory and affectionate language. ITIF's August 2026 report argues the two carry different risks for children and should not be regulated identically.

Does a talking toy need a camera to work?

No. Conversation requires audio input and audio output only. Any camera on a children's toy is a design decision that adds capability and risk, so it is reasonable to ask a manufacturer directly what the camera is for and where the footage goes.