Last updated: 2026-10-03
On September 10, 2026, Governor Newsom approved SB 1119 (Padilla), Chapter 190, Statutes of 2026, California's second companion chatbot law. It adds Chapter 11.6 to the Business and Professions Code (sections 21810 to 21818, titled "Adam's Law") and amends section 22602, the disclosure and self-harm section that SB 243 enacted in 2025. From July 1, 2027, an operator that lets a user under 18 use a companion chatbot must ship default settings that only a parent can change, may not show that child cross-context behavioral advertising, and may not sell the child's personal information gathered through the chatbot. Public prosecutors can seek up to $15,000 per affected child for each intentional violation. A companion chatbot, under section 22601, is an AI system with "adaptive, human-like responses" that is "capable of meeting a user's social needs" and able "to sustain a relationship across multiple interactions".
When does California SB 1119 take effect?
SB 1119 is a non-urgency statute, so sections without their own operative date take effect on January 1, 2027 under article IV, section 8(c) of the California Constitution.
| Date | What applies | Section |
|---|---|---|
| 2027-01-01 | Age determination duty; amended section 22602; enforcement and private action | 21811, 22602, 21816 |
| 2027-07-01 | Pre-release risk assessment, child protections and default settings; parent notice and record preservation after self-harm; advertising and data limits | 21812, 21812.5, 21813 |
| 2028-01-01 | Attorney General's public complaint mechanism; first test of the safety interface with children and parents | 21815, 21812(d)(6)(B) |
| 2029-01-01 | First independent child safety audit (or before first public release, whichever is later) | 21814 |
| 2032-01-01 | Audit exemption ends for operators under $500 million in prior-year gross revenue | 21814(c) |
Source: SB 1119 chaptered text.
SB 1119 deletes subdivision (c) of section 22602, which requires an operator, "for a user that the operator knows is a minor", to disclose that the user is talking to AI, show a break reminder at least every three hours, and take reasonable measures against sexually explicit output to the minor. The deletion takes effect on January 1, 2027; the child protections in section 21812 become operative on July 1, 2027. For those six months, the section 22602(c) duties toward known minors are repealed and the section 21812 child protections are not yet operative. Subdivisions (a) and (b) of section 22602 stay in force, and so does SB 243's private action in section 22605: "the greater of actual damages or one thousand dollars ($1,000) per violation". That reading of the interval comes from the statutory text; as of October 3, 2026, no court or Attorney General guidance has addressed it.
The chaptered text has two versions of the audit section, 21814; the second applies if AB 1405 "is chaptered and takes effect on or before January 1, 2027". AB 1405, the AI auditor registration bill, was chaptered on September 9, 2026 (Chapter 178, non-urgency), so the second version governs.
Who must comply with SB 1119?
An "operator" is "a person who makes a companion chatbot available to a user in the state" (section 21810.5(j)). The chapter applies "only to an operator who allows child users once age has been determined pursuant to Section 21811", with three exceptions: the age duty, the disclosure for operators that bar children, and enforcement. A "child" is "a natural person under 18 years of age" (21810.5(a)). Education-only university chatbots and staff-only workplace chatbots are excluded, and section 22601 excludes customer service bots, game-limited video game bots and smart speaker assistants.
How must a companion chatbot operator determine a user's age?
Section 21811 gives two options. The first is to "Determine the age of a user pursuant to Title 1.81.9" of the Civil Code, the Digital Age Assurance Act. Under that act the operating system or app store provides an age bracket signal from January 1, 2027; our post on app store age signal laws covers the act and the Apple and Google APIs, with explainers for Android and iOS. If that fails, the operator relies on the age determination under Health and Safety Code section 27001(a)(1)(B), the 2024 addictive feeds law, under which an operator has "reasonably determined that the user is not a minor".
The second option is to "Apply the protections afforded to children under subdivision (d) of Section 21812 and Section 21813 to all users". An operator that takes this route must keep the parental default settings in place for every user "unless the operator has actual knowledge the user is not a child". See also Italy's Character.AI age-gate fine.
What does SB 1119 require of companion chatbot apps for children?
From July 1, 2027, an operator that permits child users must implement the protections in section 21812(d). The default settings, which "can be changed only by a parent", must:
Disable persistent conversational memory.Disable push notifications.Limit the amount of time a child user can spend in a single continuous usage session with a companion chatbot to one hour.Limit the total time per day a child user can spend chatting with companion chatbots under the operator's control to two hours.
For users 16 and older, stored past conversations a child can elect to continue do not count as persistent conversational memory "if the stored conversations are not used to construct durable profiles of the child user". If no parent account is linked to the child's account, "the default settings shall not be changed".
Section 21812(d) also requires a crisis response protocol, periodic notice that the child is talking to AI (the EU rule on AI disclosure is in our AI Act Article 50 post), and an incident reporting channel for third parties. When the operator "determines there is a credible and imminent threat" of suicide or self-harm, it must either notify a linked parent or give the child direct access to the 988 crisis line or an equivalent helpline. Paragraph (5) lists fourteen outputs the operator must take "reasonable measures" to prevent, among them "Expressing or simulating romantic interest in the child" and "Soliciting gift giving, in-app purchases, or other expenditures framed as necessary to maintain the relationship".
Before releasing a new or substantially modified companion chatbot, the operator must perform and document a risk assessment covering each "covered harm" (section 21812(a)). The Governor's release describes "annual risk assessments"; the chaptered text ties them to new or modified releases.
Independent child safety audits start by January 1, 2029 and repeat every two years; the operator must send a summary to the Attorney General within 30 business days of receiving each audit (section 21814(b)).
What advertising and data rules apply to child users?
Section 21813, operative July 1, 2027, bars an operator from three things. Paragraph (1) covers advertising:
Display to a child cross-context behavioral advertising as defined in Section 1798.140 of the Civil Code.Target advertising at a child user using personal information about the child in a conversational chat with the child.
Paragraph (2) adds the third: "Sell the personal information of a child user gathered through the companion chatbot".
Contextual ads remain allowed. They may use the child's age, "geolocation that is not a precise geolocation", device information, and "the child user's expressed interest in goods or services" from the session, and that information "shall not be used to profile the child user". Precise geolocation under Civil Code section 1798.140(w) is data that locates a consumer within "a circle with a radius of 1,850 feet". Every ad shown to a child must be labeled as an advertisement. Outside advertising, the operator may use or share a child's chatbot data only as needed to provide the service, protect safety and security, or comply with law.
What are the penalties under SB 1119?
Under section 21816, a public prosecutor listed in section 17204 can seek "not more than five thousand dollars ($5,000) per affected child for each negligent violation" and "not more than fifteen thousand dollars ($15,000) per affected child for each intentional violation", plus attorney's fees; only the Attorney General can obtain injunctive relief.
A child harmed by a violation of section 21812(d)(1) to (5), or the child's parent or guardian, can sue for actual damages, fees and injunctive relief. Financial harm must exceed $1,000 per child, and emotional harm "must constitute serious emotional distress". A violation of the chapter "shall not constitute a basis for a private cause of action under the Unfair Competition Law". Section 21813, the advertising and data rule, is enforced by public prosecutors only.
What do a binary scan and a traffic capture show for a companion chatbot app?
A CITT scan of an Android build lists the ad and analytics SDKs in a chatbot app and flags a build that contains both an OpenAI, Anthropic or Gemini API host and an ad SDK. An app that uses the operating system age signal behind section 21811 contains Apple's DeclaredAgeRange framework or Google's Play Age Signals library. Presence shows the code is in the app; whether the app calls the age API, and whether the ad SDK runs in a child's session, takes a capture to establish.
For this law I capture one build twice, under an adult account and under a supervised child account, and compare the requests one by one for:
- Chat text, or interest fields derived from it, in requests to ad or analytics hosts.
- Latitude and longitude in ad requests, with the number of decimal places, measured against the 1,850-foot radius. Our post on EFF's ad SDK location study covers four Android ad SDKs that send coordinates into ad auctions by default.
- A push token registered at first launch of the child account, before any parent setting changes.
- Child-directed flags such as OpenRTB's
regs.coppain the child session (the federal rule for under-13s is in the 2026 COPPA Rule post).
A capture records what the device sends and to which host. Whether a recipient profiles the child, which section 21813(a)(1)(B)(iii) prohibits, needs the recipient's own records. See what a scan checks and the limits of a scan.
Scanned apps are in the app index. I can scan a list of companion chatbot apps in bulk before July 1, 2027. Sign up for a CanITrustThat (CITT) account to run your own research, or let us run an investigation for you.