If you have been shopping for a talking toy this year, you have probably noticed the headlines get louder and less helpful at the same time. One week a report says AI toys are unsafe. The next week a state passes a law. The week after that, a think tank says the law is the wrong law. It is hard to tell whether anything has actually changed for the toy sitting on your child's bed.
So here is the honest version. In the first eight months of 2026, US states passed more rules about talking machines than in the previous decade combined, Europe rewrote its toy rulebook, and on 10 August a major technology policy institute published a report arguing that a lot of this new law will not do what parents think it does. Below is what actually passed, what it covers, what it misses, and the small number of things a parent can check today without waiting for any of it.
What actually happened with AI chatbot laws in 2026?
States legislated, and Congress did not. The Transparency Coalition's mid-year review counted 14 chatbot safety measures passed or enacted across 13 states in 2026, which it called a watershed year for the category. As of June, 11 states had a chatbot law on the books: California, Colorado, Connecticut, Georgia, Idaho, Iowa, Nebraska, New York, Oregon, Rhode Island and Washington.
What makes this unusual is that the wave crossed party lines. Georgia and Idaho legislated alongside Washington and New York, which is not how online safety bills normally travel. Connecticut went furthest, folding chatbot safeguards, protections for minors, parental controls and AI subscription rules into a single 74 page law. The Future of Privacy Forum's 2026 chatbot legislation tracker counts close to 100 chatbot-specific bills introduced nationwide, most of which did not pass. We covered the Oregon and Washington laws in detail when they were signed.
What do these state laws actually require?
Most of them require disclosure, crisis protocols and some form of parental access. Very few of them require anything about how the underlying model was built or trained. The table below summarises the provisions that appear most often, based on Orrick's review of the 2026 state chatbot laws.
| Common provision | What it means in practice | Does it cover a physical toy? |
|---|---|---|
| Disclosure duty | The system must tell the user it is not a human | Usually yes, if the toy holds a conversation |
| Crisis protocol | Referral to help lines when self-harm is mentioned | Yes, though written with teens in mind |
| Parental controls | A guardian must be able to see or limit use | Yes, where a companion app exists |
| Companion chatbot rules | Extra duties for systems that simulate a relationship | Ambiguous, and this is the live fight |
| Age assurance | Some check on how old the user is | Rarely, toys are sold to a parent, not a user |
Read that last column carefully. A great deal of 2026 chatbot law was written for a teenager typing into a phone. A four year old talking to a bear in a bedroom is a different situation with different risks, and the statutes mostly do not say so.
Why does a policy institute say the new rules could backfire?
Because rules written for one product can quietly ban a better one. On 10 August 2026 the Information Technology and Innovation Foundation published a report on what policymakers should and should not do about chatbot safety for children. Its central argument is that lawmakers keep treating every conversational system as one category.
ITIF recommends separating general purpose chatbots from systems deliberately designed to simulate emotional relationships, and applying the strictest duties to the second group. It argues for targeted safeguards, meaningful parental controls, clear legal standards and continued research, rather than blanket age bans that would also remove documented educational and creative benefits. Its accompanying press release frames this as smarter policy rather than less policy, and StateScoop's coverage focuses on the practical risk of a 50 state patchwork that small manufacturers cannot navigate.
It is worth saying plainly that ITIF is a technology policy institute with industry funding, so its scepticism about broad restrictions is not a neutral view from nowhere. The useful part of the report is not its conclusion but its distinction, which most of the passed statutes genuinely lack.
Is there a counter-argument from the other side?
Yes, and it comes from an unexpected direction. The Electronic Frontier Foundation, which is usually the group arguing hardest for privacy, published a critique of the federal CHATBOT Act in July 2026 arguing that the bill forces a single parenting model on every family and would require identity verification that harms privacy in the name of protecting it.
So the debate is not simply industry against advocates. There is a real disagreement about whether mandatory age checks and blanket restrictions protect children or simply move the risk somewhere less visible while creating new databases of who is who. Meanwhile the main federal vehicle aimed specifically at toys, the Children's Artificial Intelligence Toy Safety Act of 2026, does something more modest than its title suggests: it mandates a study of AI-enabled toys and a joint action plan on their marketing and sale. A study is not a standard.
What about Europe, where the toy rules were just rewritten?
Europe did rewrite them, but not on the timeline most coverage implies. Regulation (EU) 2025/2509, the new Toy Safety Regulation, was published on 12 December 2025 and entered into force in early 2026. Its substantive requirements do not apply until 1 August 2030, after a transition period of roughly four and a half years, as Intertek's regulatory FAQ sets out.
The content matters even if the deadline is distant. Connected toys will need a safety assessment that explicitly accounts for children's vulnerabilities, and toys connected to the internet will have to sit alongside the Cyber Resilience Act, the AI Act and data protection law rather than being treated as ordinary plush. We looked at how the AI Act interacts with toys specifically in our piece on what the 2026 EU rules actually say. The practical upshot for a parent buying today is uncomfortable but simple: the strongest European protections are real, and they are four years away.
So what should a parent check before buying a talking toy?
Check the design choices, not the marketing claims, because design choices are the part no future law can retroactively fix. Regulation moves in years. A toy bought in November is in the house next week.
Five things to verify before you buy
- Is there a camera? If yes, ask why a toy that talks needs to see. A microphone and speaker are enough for conversation.
- Is there a subscription? A recurring fee means the company needs continued engagement from your child to stay solvent.
- Can you see and change what it discusses? Parental control that exists only as a marketing bullet is not parental control.
- What happens to the recordings? Look for an explicit statement on retention, resale and deletion, not a general privacy promise.
- Which certifications, and issued by whom? Named standards with named bodies, not a generic safety badge.
That fourth point is the one that has caught real products out. Testing this year found toys claiming secure handling while their own privacy policies allowed third party sharing and biometric retention measured in years. If you want the longer version of what each certification actually covers, we wrote a plain language guide to CE, ASTM F963 and CPSIA.
Where does Ted&Co stand on all this?
Our position is that the failures described in these reports are design failures, not inevitable properties of talking toys. A toy that harvests biometric data does so because someone decided to collect it. A toy that pushes for engagement does so because a subscription depends on it.
So Ted has no camera, only a microphone and speaker. There is no subscription, which removes the commercial incentive to maximise time spent talking. Parents set the language, the topics, the boundaries and the tone from the Ted&Co app, and can switch between push-to-talk and automatic listening. We do not sell data and we do not run advertising. Our certifications and compliance page lists what has been tested and by whom, including GDPR and COPPA alignment, and the FAQ answers the specific questions parents send us most.
None of that is a claim that regulation is unnecessary. Clear rules would help honest manufacturers more than they hurt us. It is a claim that you should not have to wait until 2030 to buy a toy built the right way.
Frequently asked questions
Are AI toys banned anywhere in 2026?
No jurisdiction has enacted an outright ban on AI toys as of August 2026. A California proposal would have imposed a four year moratorium on AI chatbots for under 18s, and several state laws restrict specific practices, but talking toys remain legal to sell across the US and EU.
Do state chatbot laws apply to my child's toy?
Often yes, but indirectly. Most 2026 state laws regulate conversational systems by function rather than by device, so a toy that holds a conversation can fall within scope. The duties were largely drafted with teenagers using phones in mind, which is why coverage of young children is uneven.
When do the new EU toy safety rules actually take effect?
Regulation (EU) 2025/2509 entered into force in early 2026 but applies from 1 August 2030 after a transition period of about 54 months. Until then, toys sold in the EU continue to comply with the existing Toy Safety Directive framework plus GDPR and the AI Act.
What is the difference between a chatbot and a companion chatbot?
A general purpose chatbot answers questions and performs tasks. A companion chatbot is designed to simulate an ongoing emotional relationship, often using memory and affectionate language. ITIF's August 2026 report argues the two carry different risks for children and should not be regulated identically.
Does a talking toy need a camera to work?
No. Conversation requires audio input and audio output only. Any camera on a children's toy is a design decision that adds capability and risk, so it is reasonable to ask a manufacturer directly what the camera is for and where the footage goes.