Wednesday, 16 September 2026 PDT | 03:16 PM
The 1 News Alt Logo Text Smart News for Global Indians

A Governor's Dozen: 13+ Bills Addressing Artificial Intelligence, Online Youth Safety, and Privacy Signed in California

AI News September 17, 2026 02:30 AM
A Governor's Dozen: 13+ Bills Addressing Artificial Intelligence, Online Youth Safety, and Privacy Signed in California

In a substantial expansion of regulations in the Golden State, California Governor Gavin Newsom recently signed 15 bills addressing artificial intelligence, online youth safety, and privacy, expanding the legal framework we analyzed previously. Within this legislative package, several bills (including SB 1119, AB 1946, AB 2246, and AB 1856) directly amend or expand upon existing California statutes.

These laws, grouped by subject matter and summarized below, are the most recent and significant expansion yet of California’s fast-moving regulatory patchwork in these fields. Together, they reflect a trend of growing regulatory interest in companies operating AI chatbots, social platforms, or services likely to be accessed by minors in California.

SB 1119 (“Adam's Law”): AI Chatbot Guardrails

SB 1119 expands upon California's existing AI companion chatbot law (SB 243), imposing immediate obligations on operators of AI chatbots. Under the existing SB 243, operators are required to notify users that they are engaging with artificial intelligence if the user could reasonably be misled into believing that they are interacting with a human, and operators also must maintain protocols to prevent and appropriately respond to suicide and self-harm content (including crisis service referrals).

Beginning July 1, 2027, a far more comprehensive framework will take effect with new expansions under SB 1119. Operators of AI chatbots must determine a user’s age under the Digital Age Assurance Act, or alternatively, apply child-protective safeguards to all users. Before launching or substantially modifying a chatbot, operators must conduct and document a child-user risk assessment regarding risks of physical or financial harm, severe psychological or emotional harm, highly offensive intrusions on privacy rights, or adverse discrimination, and implement reasonable mitigations of identified risks.

Operators that permit child access must also comply with an extensive set of requirements, including: publishing a child safety policy; maintaining documented crisis-response protocols with parental notification or facilitating access to crisis service helplines; providing parental notification and control mechanisms; disabling persistent conversational memory (with an exception for users over 15) and push notifications; implementing usage limits and reminders; prohibiting chatbots from depicting sexual content, claiming sentience, treating physical, behavioral, or mental health, or simulating romantic interest; maintaining a public incident-reporting mechanism; and ensuring child-accessible interface designs are provided and tested with children and parents every two years beginning January 1, 2028. In addition, chat logs relating to parental notifications or incidents involving child deaths or self-harm must be preserved for at least three years. Operators that do not allow child users to access their chatbot must publish on their website a description of how the operator complies with the law’s age-assurance requirements.

SB 1119 also imposes restrictions on advertising directed to child users. Advertisements must be clearly labeled and operators may not engage in cross-context behavioral advertising or include targeted advertising within conversational chats, sell children’s personal information, or use such information beyond specified purposes.

For operators with at least $500 million in gross revenue (and from January 1, 2032, for all other operators), operators must also commission an independent child safety audit by the later of January 1, 2029 or before the chatbot becomes publicly available, and every two years thereafter, as well as before any substantial modification that the risk assessment identifies as increasing risk to child users. Operators must submit a summary of each audit to the California Attorney General (who may request a copy of the full report for cause) and publish that summary on the operator’s own website. Notably, this audit requirement only becomes operative if a separate bill, AB 1405, does not take effect by January 2, 2027.

Public prosecutors can recover $5,000 per negligent violation and $15,000 per intentional violation, per affected child, in addition to injunctive relief when the action is brought by the California Attorney General. The legislation also creates a private right of action for harmed children or their parents to seek actual damages and injunctive relief.

SB 867: Temporary Moratorium on AI Companion Chatbot Toys for Children

SB 867 prohibits the manufacture, sale, exchange, offer for sale, or possession with intent to sell any toy that embeds an AI companion chatbot and is designed, marketed, or manufactured for children under 16. This prohibition is temporary and will remain in effect until January 1, 2031.

AB 1405: AI Auditor Registration and Standards

AB 1405 establishes registration requirements and standards for AI auditors who conduct audits of AI features necessary for compliance with state law. The law will establish an AI Auditor Registry and a misconduct complaint mechanism by January 1, 2029, will require that AI auditors be registered by January 1, 2029 and provide prescribed information to the state in their audit reports (including business contact information, the California laws or regulations under which they conduct audits, and their standard operating procedure), and require registered AI auditors to comply with certain standards.

SB 813: Designation of AI Risk Assessment Expertise

SB 813 regulates “independent verification organizations” (IVOs), defined as AI auditors designated by the California Government Operations Agency as having expertise in AI risk assessment. The law provides that designation requirements and criteria for IVOs will be developed by January 1, 2028, establishes criteria for assessing whether an AI auditor qualifies as an IVO, and requires a designated IVO to submit annual reports of their standards, methodologies, changes to governance or funding relevant to their conflicts of interest or independence, and changes to their application information.

AB 1709: Addictive Features and Mandatory Age Verification

Covered websites, online services, and applications may not provide “addictive features” to users under 16. To comply, operators must verify users’ ages pursuant to the Digital Age Assurance Act, and either withhold addictive features from users under 16 or delete the accounts of such users. The Attorney General or public prosecutors may bring civil actions against companies for violations, with penalties up to $25,000 for negligent violations and $50,000 for knowing violations, per affected minor.

AB 2: A Statutory Duty of Care for Large Social Media Platforms

AB 2 imposes an affirmative duty of care on social media platforms with over $100 million in annual revenue, exposing them to liability where a failure to exercise ordinary care results in injury to a child. Damages are capped at the greater of $5,000 per violation (up to $1 million per child) or three times actual damages.

AB 2246: A New Age-Appropriate Design Code

AB 2246 repeals and replaces the California Age-Appropriate Design Code Act, establishing a new framework governing online services, products, and features “likely to be accessed by children” under 18. Covered platforms must estimate users’ ages, apply default maximum privacy settings, implement specified safety features, limit the collection, sale, sharing, and retention of personal information to what is necessary, and take reasonable steps to prevent harm to child users. The legislation grants children a right to void contracts entered into as a result of a covered service’s design features. Enforcement sits with the Attorney General and public prosecutors, with penalties of up to $5,000 for negligent violations and up to $15,000 for intentional violations, per affected child.

AB 1856: Technical Amendments to the Digital Age Assurance Act

AB 1856 amends California’s Digital Age Assurance Act, the age-verification framework incorporated into several of the state’s newly enacted online safety laws, including SB 1119 and AB 1709. The bill clarifies and refines the Act’s age-signal regime by revising key definitions, specifying when operators must collect age information, narrows the Digital Age Assurance Act’s scope by redefining “operator system provider” to exempt open-source operating systems and applications from the age-verification and age-signal requirements altogether (while commercial platforms such as Windows, macOS, iOS, and standard Android remain fully covered), and restricts requests for such signals to circumstances authorized by law. As a result, its practical significance lies in shaping how the broader Digital Age Assurance Act will operate in practice and, by extension, how other California laws that depend on that framework will be implemented.

AB 1946 strengthens California’s existing framework for reporting child sexual abuse material (CSAM) on social media platforms. Covered platforms must provide a user-reporting mechanism, ensure human review of reports (unless the content matches a known CSAM hash or has already been blocked), contact reporting users in writing by a method chosen by the reporting user (including, but not limited to, a telephone number for purposes of sending text messages or an email address), permanently block qualifying reported material within 48 hours, confirm actions taken within 72 hours, and issue a final written determination within seven days. The bill allows enforcement of civil actions by the California Attorney General and local government counsel, with penalties up to $250,000 per day of violation and injunctive relief, and creates a private right of action for reporting users depicted in the material, who may recover actual damages or statutory damages up to $250,000 per violation.

SB 1276: Sexual Exploitation and Digital Media

SB 1276 amends California's sexual exploitation of a child statute to criminalize knowingly developing, downloading, streaming, accessing, or exchanging sexual conduct material depicting a minor under 18 via electronic or digital media, and extends this to digitally altered or AI-generated depictions. It also broadens the mandated-reporting definition of “sexual exploitation” under the Child Abuse and Neglect Reporting Act to capture AI-generated material.

Student Personal Data, Education, and Wellness Legislation

AB 1159: Student Data Cannot Be Used to Train AI

AB 1159 strengthens privacy protections for student personal data, including by prohibiting operators of websites, online services, or applications designed or marketed for K-12 school purposes, or known to be used for such purposes, from using protected student personal data to train or develop AI systems. Harmed students or their parents can bring individual or class actions to recover the greater of actual damages or $500 per plaintiff per violation in addition to injunctive relief, subject to a 60-day cure period for the alleged violation.

AB 2071: Student Instruction and Digital Wellness

AB 2071 requires the California Department of Education to develop a plan to expand digital wellness and media literacy instruction across elementary, middle, and high schools, and address how excessive or inappropriate use of digital technology and AI affects youth mental health by January 1, 2028.

AB 302: Extracurricular Activities and Addictive Feeds

AB 302 prohibits local educational agencies from excluding students from extracurricular activities based on non-use or non-ownership of “addictive feeds,” and from using such mediums as the only means of communication with pupils or parents, beginning in the 2027-28 school year.

SB 1128 bars local educational agencies, starting in the 2027-28 school year, from requiring kindergarten students to take school-issued electronic devices home, except in limited cases such as an Individualized Education Program, a declared emergency, or independent study enrollment.

AB 2298: Digital Literacy Implementations to Education Curriculum

AB 2298 amends the Education Code to require the relevant curriculum commission to consider incorporating media literacy, AI literacy, and cybersecurity skills into California's curriculum frameworks, instructional materials, and computer science content standards in their next scheduled revisions or adoptions throughout 2024-27.

Taken together, the Governor’s signing of these bills confirms what many observers have suspected for some time: California is not waiting for federal action on AI and youth safety. Instead, it is building out a detailed, sector-specific compliance architecture with phased deadlines stretching from immediate effect through 2032. As the impacts of the newly signed bills remain to be seen, companies operating AI chatbots, social media platforms, or any online service likely to be accessed by minors in California should be mapping their current practices against each of these regimes now, particularly given the private rights of action embedded in several of the bills (e.g., SB 1119, AB 1159, and AB 1946) and the steep per-violation, per-child penalty structures that recur throughout the legislative package.

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.