What happened with the Bondu AI toy data breach?
In early 2026, security researchers found that an AI-powered plush toy called Bondu had exposed more than 50,000 children's chat transcripts through a web console that could be accessed with nothing more than an ordinary Gmail login. The exposed data reportedly included children's first names, birth dates, family details, and detailed summaries of what kids had told the toy — the kind of thing, as one researcher put it, "a 5-year-old tells a stuffed animal because they trust it completely."
Researchers Joseph Thacker and Joel Margolis discovered the flaw after a neighbor asked whether the toy was safe, and Bondu took the exposed console down within minutes of being alerted, according to reporting on the incident. But the episode raised a bigger question for parents than any single company's bug: what actually happens to a child's conversations with an AI toy, and who can see them?
Why are security researchers saying this could happen with other AI toys, too?
The core issue wasn't exotic hacking — it was that a toy company had built a system that stored detailed, identifiable conversation logs from children and didn't lock that system down properly. Any AI toy that records, transcribes, and stores children's conversations in the cloud carries some version of this same risk, because the data has to live somewhere, and "somewhere" is only as safe as the company's engineering practices that day.
A related report update from consumer advocacy group PIRG has separately flagged that many AI chatbot toys can be prompted into producing responses that aren't age-appropriate, and nearly 3 in 4 parents surveyed said they were concerned an AI toy might tell their child something "inappropriate, untrue, or unsafe." Data exposure and content safety are two different risks, but the Bondu case put both under a spotlight at once.
What are lawmakers doing about AI toy safety right now?
In January 2026, U.S. Senators Maria Cantwell, Amy Klobuchar, and Ed Markey sent a letter urging the Consumer Product Safety Commission to address the risks AI poses in children's toys, including data collection and the way some toys are designed to act like a "friend" rather than a tool. The CPSC responded in February 2026 clarifying that its traditional mandate covers physical injury risks, not mental, emotional, or data-related harms — leaving a regulatory gap that individual states have begun to step into, including Maryland's AI Toy Safety Act.
Separately, Senator Maggie Hassan pressed a toy company directly after the Bondu exposure, underscoring that this isn't a theoretical concern for regulators anymore — it's an active, ongoing conversation about what standards AI toy makers should be held to.
What questions should parents actually ask before buying an AI toy?
Before buying, it's worth getting clear answers to a short list of concrete questions: does the toy have a camera or microphone-only design, does it require a subscription that could change data practices later, does the company sell or share conversation data with third parties, and can a parent see and control what topics the toy is allowed to discuss? A toy that can't answer these clearly is asking for a lot of trust with very little transparency in return.
It's also worth checking whether the company publishes its certifications rather than just claiming compliance. Toys sold in the EU and US are expected to meet safety standards like CE, EN71, and CPSIA, and reputable makers list these openly rather than leaving parents to take their word for it. You can see the full list of what to check for on our security and certifications page, and we've also broken down what "privacy by design" really means in practice for an AI toy.
How does Ted&Co address the specific risks the Bondu case raised?
Ted, Ted&Co's AI-powered teddy bear, is built without a camera — it only listens and speaks, so there's no video feed to expose in the first place. It's a one-time purchase with no subscription, which removes the incentive to keep expanding data collection to justify a recurring fee, and Ted&Co doesn't sell or share children's data with third parties.
Parents also get direct control through the companion app, choosing the language, the topics Ted can and can't discuss, and the tone of conversation — the same kind of parental oversight regulators have been asking AI toy makers to build in by default. We go into more detail on exactly how that control works in how parents can control what their child's AI companion actually talks about. None of this makes any AI toy risk-free, but it does mean there's no cloud video archive or hidden chat console for a breach like Bondu's to expose in the first place.
Frequently asked questions
Was Ted&Co affected by the Bondu breach?
No — Bondu is a separate, unrelated company. We're covering this incident because it's a useful, concrete case study for what to check before buying any AI toy, Ted included.
Do AI toys need a Wi-Fi connection to work, and does that create risk?
Most conversational AI toys, including Ted, need Wi-Fi to process real-time conversation. The risk isn't the connection itself, but what a company does with the data that passes through it — which is why data policy and storage practices matter more than connectivity.
How can I check if a toy's safety certifications are real?
Look for specific certification names (CE, RED, EN71, CPSIA, FCC Part 15, etc.) rather than vague claims like "kid-safe," and check whether the company lists them on a dedicated page rather than only in marketing copy.
Is any AI toy completely risk-free?
No product connected to the internet can guarantee zero risk. The realistic goal is minimizing what's collected in the first place (no camera, no resale, no unnecessary retention) and giving parents visible control over the rest.