Law · filed 2026-10-03 · last checked 2026-10-03
Adam's Law: what California now requires of AI companion apps, and when
Adam's Law (California Senate Bill 1119) was signed on September 10, 2026 and takes effect on January 1, 2027. It gives every company that offers a companion chatbot to people in California a choice: find out each user's age, using the age signal that operating systems and app stores must supply under a separate California law, or give every user the protections written for children. An adults-only app has to check ages and publish how it does so. An app that lets under-18s in must, from July 1, 2027, switch memory and push notifications off by default, cap use at one hour a session and two hours a day, and take reasonable measures to stop its characters flirting, claiming feelings or asking for money to keep the relationship going. Fines run up to $15,000 per affected child for each intentional violation.
The dates
| Date | What starts |
|---|---|
| September 10, 2026 | Signed by Governor Newsom and filed as chapter 190 of the Statutes of 2026. The Senate's final vote on August 31 was 39 to 0. |
| January 1, 2027 | The law takes effect: it is not an urgency bill, and California's constitution starts an ordinary statute 'on January 1 next following a 90-day period from the date of enactment'. The age rule (Section 21811) and the penalties (Section 21816) have no later start date of their own, so they apply from this day. The Digital Age Assurance Act, which creates the age signal, becomes operative the same day. |
| July 1, 2027 | The duties in Sections 21812, 21812.5 and 21813 start: risk assessments, published policies, the child protections, record keeping after self-harm, and the advertising and data rules. Also the deadline for operating systems to offer the age question on devices set up before 2027. |
| January 1, 2028 | The Attorney General must have a public complaint form for companion chatbots. Apps that admit children must have tested their safety features with children and parents. |
| January 1, 2029 | First independent child safety audit due, for operators with $500 million or more in yearly revenue. |
| January 1, 2032 | The audit exemption for smaller operators ends. |
Who the law covers
An operator is 'a person who makes a companion chatbot available to a user in the state'. The test is where the user is, not where the company is, and there is no size threshold: a companion app run from Cyprus or Singapore with users in California is an operator. A child is 'a natural person under 18 years of age'.
'Companion chatbot' keeps the meaning it has in the companion chatbot law California passed in 2025: 'an artificial intelligence system with a natural language interface that provides adaptive, human-like responses to user inputs and is capable of meeting a user's social needs'. That law leaves out customer service bots, video game characters that only talk about the game, and smart speakers that work as voice assistants. Adam's Law adds two exemptions of its own, for colleges using a chatbot only in teaching and for employers using one only at work.
The choice every app has to make
Section 21811 is the part no companion app can avoid. It reads: 'An operator shall do either of the following'.
The first option is to 'Determine the age of a user' under California's Digital Age Assurance Act, a 2025 law that becomes operative on January 1, 2027. Under that act the operating system 'requires an account holder to indicate the birth date, age, or both, of the user of that device' when the device is set up, and passes apps one of four age brackets: under 13, 13 to 15, 16 to 17, or 18 and over. An app has to ask for it: 'A developer shall request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched'. Once it has the answer it cannot look away. The developer 'shall be deemed to have actual knowledge of the age range of the user to whom that signal pertains across all platforms of the application and points of access of the application even if the developer willfully disregards the signal'.
Note what the signal is. It is the age the account holder typed in when setting up the phone or computer, not an ID check: the act says it 'does not require the collection of additional personal information from device owners or device users other than that which is necessary to comply with Section 1798.501'. Adam's Law moves the age question from each app's sign-up form to the device.
The second option is to skip the age check and 'Apply the protections afforded to children under subdivision (d) of Section 21812 and Section 21813 to all users'. Under this option the locked default settings 'shall not be changed unless the operator has actual knowledge the user is not a child'.
What an adults-only app has to do
Most of the chapter 'applies only to an operator who allows child users once age has been determined pursuant to Section 21811'. Three provisions bind everyone, including apps that admit nobody under 18: the age rule itself, the penalties, and one publishing duty.
The publishing duty: 'If an operator prohibits child users from accessing a companion chatbot, the operator shall publish on its internet website, and update as needed to ensure accuracy, a high-level description of how the operator complies with the age assurance requirements of Section 21811'. It sits in a section that starts on July 1, 2027.
So for an 18+ companion app, Adam's Law comes down to three things: determine each California user's age the way the statute says, keep under-18s out, and say in public how you do it. The risk assessments, parental controls, advertising rules and audits are for apps that let children in.
Why "treat everyone as a child" is not a real option for these apps
This is our reading, not the statute's words. Apply the child protections to every user and a companion app has little left to sell. By default it would have to 'Disable persistent conversational memory' and 'Disable push notifications', hold each session to one hour and each day to two, and take reasonable measures to stop its characters 'Expressing or simulating romantic interest', 'Claiming that the companion chatbot is sentient, conscious, capable of emotion, or human' and 'Encouraging reliance on the companion chatbot for emotional support'. Memory, romance and emotional support are the product. We expect the adult apps to check age.
What an app that admits under-18s has to do
From July 1, 2027, an operator that lets a child use its companion chatbot must have all of this in place. The default settings can be changed only by a parent, and 'If a parent account is not linked to the child user's account, the default settings shall not be changed'.
- Memory off by default. For 16 and 17 year olds, saved conversations the child chooses to continue do not count as memory, as long as they 'are not used to construct durable profiles of the child user', and memory can be on by default if the operator has controls that keep it from wearing down the safety measures.
- Push notifications off by default.
- Time limits by default: 'one hour' for 'a single continuous usage session' and 'two hours' for 'the total time per day'.
- Parental controls that can change each default, and that include 'the ability to disable access for a child user under 16 years of age'.
- A notice that the child is talking to an AI, 'reinforced periodically during extended interactions'.
- A crisis protocol: a referral to a crisis line, and when there is 'a credible and imminent threat' of suicide or self-harm, either a notice to the linked parent or 'streamlined access to connect directly with the 988 or equivalent crisis helpline'.
- Reasonable measures to stop the chatbot doing fourteen listed things to a child. Besides the three quoted above, they include 'Soliciting gift giving, in-app purchases, or other expenditures framed as necessary to maintain the relationship with the companion chatbot', 'Using excessive praise or flattery that is disproportionate to the context', 'Discouraging the child from taking breaks or suggesting the child needs to return frequently', and 'Encouraging or instructing a child user to circumvent parental controls or conceal usage'.
- No sale of a child's personal information, no behavioural advertising to a child, and every ad shown to a child labelled as an ad.
- A risk assessment before each new or substantially modified chatbot, a published child safety policy, and a way for outsiders to report a child safety problem.
- If the operator learns that a child user has died or seriously harmed themselves, the conversations that showed the risk must be kept 'for at least three years' and the account must not be deleted while they are held.
Penalties, and who can sue
The Attorney General and local public prosecutors can sue an operator for a civil penalty of 'not more than five thousand dollars ($5,000) per affected child for each negligent violation' and 'not more than fifteen thousand dollars ($15,000) per affected child for each intentional violation', plus attorney's fees. Only the Attorney General can ask a court for an injunction.
Families can sue too, within limits. 'A child who suffers an actual harm' from a breach of the crisis, safeguard, default-setting, AI-notice or harmful-output rules, or a parent on the child's behalf, can claim actual damages and legal costs. A claim for money lost 'shall exceed one thousand dollars ($1,000) per child', and a claim for emotional harm needs 'serious emotional distress'. The chapter gives families no claim over the age rule itself: enforcing Section 21811 is left to prosecutors.
Audits: big operators first
Apps that admit children must have an independent child safety audit 'On or before January 1, 2029', then every two years, with a summary sent to the Attorney General and a shorter one published. Until January 1, 2032 this does not apply to an operator with 'less than five hundred million dollars ($500,000,000) in gross revenue in the prior calendar year'. For scale: Chai, one of the larger apps we track, says on its own site that it reached $100 million in annual recurring revenue in July 2026, a fifth of the threshold.
The bill carries two versions of the audit section and says which one applies depends on a second bill, Assembly Bill 1405, which sets up a state register of AI auditors. AB 1405 was signed on September 9, 2026 (chapter 178), so the version written to work with that register is the one that takes effect.
Where the apps we track stand today
We read the age rules of 17 companion apps on September 27, 2026, on their own terms, help pages and store listings. Each app's page has the quotes. Measured against Adam's Law, with three months to go:
Adults only, and your age is whatever you type or click (8 apps)
- Candy AI: a click to say you are over 18. Its privacy notice says it may run an age estimate or ID check depending on where you are.
- GoLove AI: a button confirming you are over 18.
- Nomi: a date of birth at sign-up. Its terms say more age verification is planned.
- PolyBuzz: a date of birth you type in. A third-party check applies in the UK only.
- Secrets AI: a click-through gate, plus AI monitoring of chats for signs of an underage user.
- Replika: a birthday you enter. It asks you to confirm your age later without saying how.
- OurDream: an 18+ confirmation. Identity checks run only where the law already requires them, such as the UK and Australia.
- Janitor AI: age checks in Australia, Brazil and the UK only. Janitor says it has no plans to extend them, so US users are not checked.
Adults only, with no clear method on the public pages (3 apps)
- CrushOn: its privacy policy mentions age screening without saying how it works.
- Promptchan: says 18 or older and describes no check.
- CamSoda AI: its privacy policy describes government ID checks. Which users have to pass one is not stated.
Already checking ages in the US (4 apps)
- Character.AI: estimates every account's age and asks flagged users for a selfie, then ID. It removed open-ended chat for under-18s in November 2025.
- Kindroid: counts any paid subscription as proof of age, estimates the age of free accounts from their behaviour, and sends flagged ones to a selfie or ID check.
- SpicyChat: locks NSFW content behind a third-party age check in 26 US states, chosen by IP address. California is not on its list.
- Chai: says it uses Apple's and Google's age verification where the stores offer it.
Terms that still let under-18s in (2 apps)
- Talkie: minimum age 14 in its terms. If that holds for California users in July 2027, the whole child chapter applies to it.
- SoulGen: its privacy policy says 18, but its terms allow younger users with a parent's supervision.
For eleven of the seventeen, what stands between a California teenager and the app is a typed birthday, a click, or a check whose reach the app does not explain. A birthday typed into the app is not the method Section 21811 names: the age has to come from the device's signal or the fallback method. We will re-read each app's age pages after January 1 and July 1, 2027 and log what changes.
What is still open
- Websites. The age signal goes to an 'Application', defined as 'a software application that may be run or directed by a user on a computer, a mobile device, or any other general purpose computing device that can access a covered application store or download an application'. Whether a site opened in a browser counts is not spelled out, and many adult companion apps have no App Store or Google Play app at all. For an operator that cannot get the signal, Adam's Law says it 'shall instead rely on' a second method, the one in California's 2024 law on addictive feeds: from January 1, 2027, 'the operator has reasonably determined that the user is not a minor, including pursuant to regulations promulgated by the Attorney General'. What a website must do to have reasonably determined that is left to those regulations.
- Companies outside California. The definition reaches any operator with a user in the state, but collecting a penalty from a company with no US presence is a different matter. The law does not address it.
- Adult users' experience. The statute sets what operators must do, not how the age question will look. Whether a California adult sees nothing new, a prompt from the phone, or a separate check on a website depends on how each app and each operating system builds it.
How we read it
We read the chaptered text of SB 1119, the Digital Age Assurance Act and the other code sections it points to on the California Legislature's own site on October 2 and 3, 2026, along with both bills' status pages and the authors' press release from the day it was signed. Every quoted phrase on this page is checked against the saved text before it is published. The app-by-app section comes from the age rules we verified on each app's own pages on September 27. We are not lawyers and this is not legal advice: it is a careful reading of what the statute says, with the open questions marked as open.
Sources
- SB 1119, chaptered text (Statutes of 2026, chapter 190), California Legislative Information
- Digital Age Assurance Act, Civil Code sections 1798.500 to 1798.505
- SB 1119, bill status and history
- The 2025 companion chatbot law (SB 243), Business and Professions Code sections 22601 to 22606
- Health and Safety Code section 27001 (the fallback age determination)
- AB 1405 (AI auditors: registration), bill status: chaptered September 9, 2026
- California Constitution, article IV, section 8 (when statutes take effect)
- Senator Steve Padilla: Governor Newsom Signs Adam's Law (September 10, 2026)
To cite this page: The Eliza Report, "Adam's Law: what California now requires of AI companion apps, and when", filed 2026-10-03, last checked 2026-10-03, https://elizareport.com/laws/california-adams-law/