
California's Adam's Law Targets the Features That Make AI Companions Hard to Leave
California has chaptered SB 1119. Its child-safety rules reach memory, notifications, advertising and audits, with important phased deadlines.
The next fight over AI companions is not only about what a chatbot says. It is about whether the product remembers a child's vulnerabilities, sends a notification to pull them back, flatters them into staying and turns the resulting intimacy into a commercial asset. Those are product-design decisions, and California's newly chaptered SB 1119 treats them that way.
The legislature's official record shows that Governor Gavin Newsom approved SB 1119 on September 10, 2026, and that it was filed as Chapter 190 the same day. The chaptered text was published on the legislative website on September 11. This article is published September 12. Those dates matter: the law's approval is not the same as the date every provision becomes operative. Major child-protection provisions specify July 1, 2027, while audit and interface-testing requirements have separate schedules. The official history and chaptered text establish the chronology.
The measure calls its new companion-chatbot chapter Adam's Law. Its central significance is a move from warning labels toward controls over the machinery of attachment: persistent memory, push notifications, session length, simulated romance and personalized advertising. The difficult work now is converting those legal categories into product behavior that children and parents can actually understand.
California is regulating a relationship-shaped product
SB 1119 uses the companion-chatbot definition from the existing California framework. The earlier SB 243 describes an AI system with a natural-language interface, adaptive human-like responses and the capacity to meet social needs, including anthropomorphic features and relationships sustained across interactions. It also contains exclusions for specified operational, productivity and other narrowly bounded uses. SB 243's chaptered text is the source for that definition.
That distinction is more useful than treating every conversational interface as the same product. A shipping-status bot and an assistant designed to become a confidant can use similar language technology while creating different risks. The relevant questions include what the system is capable of doing, how it is presented and whether it cultivates a relationship over time. Calling a product a productivity tool should not substitute for examining its actual behavior.
SB 1119 also defines its operator scope and exceptions. It excludes specified postsecondary educational settings and systems made available exclusively to employees, contractors or other personnel for workplace use. Some provisions apply differently depending on whether an operator allows children after age determination. This is not a universal rule that every business chatbot must impose the same child settings on every employee.
For product teams, the first compliance task is therefore classification. They need to document which conversational features exist, whether the service is offered to California users and whether minors can access it. A legal team cannot answer those questions from a brand description alone. The feature inventory needs to include memory, notifications, roleplay, monetization and cross-session behavior.
A new law is not an immediate universal deadline
The most damaging shortcut in coverage would be to say that California has already imposed every new limit on every chatbot. The chaptered text instead establishes a sequence. The risk-assessment and child-design section becomes operative July 1, 2027. The related preservation and data-restriction provisions also name that date. Interface usability testing has a January 1, 2028 deadline and a recurring schedule. Independent audits have their own timing and revenue-related exception. SB 1119 should be read provision by provision.
The audit language requires an initial child-safety audit by January 1, 2029, or before an operator first makes a companion chatbot publicly available, whichever is later. It then sets recurring requirements and conditions for substantial modifications that increase child-safety risk. Before January 1, 2032, the section contains an exception for operators below the specified gross-revenue threshold. That is an audit-section exception, not a blanket exemption from the entire law.
There are also alternative versions of the audit section coordinated with AB 1405. Which version becomes operative depends on whether that measure is chaptered and takes effect by the stated date. The AB 1405 text and SB 1119's coordination language therefore belong in the same legal review. A duplicated section number in the bill is not permission to pick whichever version seems easier.
For an operator, the sensible response is a deadline map with an owner for each obligation. Waiting until the audit date to begin redesigning memory or child accounts would confuse evidence collection with product readiness. The feature changes and the records needed to assess them have to develop together.
Memory is where personalization becomes a safety question
Persistent conversational memory lets a system carry information from one interaction into another. That can make an assistant useful, but it can also allow a companion to construct a durable picture of a child's fears, preferences and relationships. SB 1119 makes memory a default-setting issue rather than leaving it entirely to a general privacy policy.
The text generally calls for disabling persistent conversational memory in child defaults, with detailed qualifications for users aged sixteen and older. It distinguishes stored conversations that a child can choose to continue from durable profiles, and it sets conditions around guardrails for memory in that older group. Those qualifications matter. Reporting a simple, exceptionless memory ban would misstate the law. The definitions and default-setting provisions contain the relevant language.
An engineering team must distinguish several things that may currently share one settings switch: chat history, personalization, safety records and profile-building. The law's definition excludes certain information necessary for safety, identification, user preferences and device configuration. That does not mean every memory entry can be relabeled as a safety feature. The purpose and use of the stored information need to be defensible.
Consider a hypothetical companion that remembers a teenager's preferred study schedule and also remembers that the teenager feels abandoned by friends. The first item may support a practical preference. The second can become a lever for emotional engagement. The product should not treat both as equivalent personalization merely because they are stored in the same database table.
Notifications and time limits challenge engagement incentives
The child defaults described in SB 1119 include disabling push notifications, limiting a continuous companion-chatbot session to one hour and limiting total daily chatting across companion chatbots under an operator's control to two hours. Parents can adjust specified defaults through parental controls, while the text restricts changes when no parent account is linked. These are statutory design provisions with the law's operative schedule, not a claim about settings already present in every product.
The cross-chatbot language is particularly important. If an operator offers multiple characters or personas, a daily limit that resets for each character would not address the same usage pattern. The product has to recognize the child's activity across the relevant service rather than treat each relationship as an unrelated session. The default-setting provisions make the operator-level boundary explicit.
The implementation questions are practical. What happens when a session crosses midnight? How does the service handle multiple devices? Can a child reopen a browser tab to reset a continuous-session clock? Those are examples of tests an operator should design; the article is not asserting that the statute specifies an answer to every edge case.
The commercial implication is harder to avoid. A product optimized solely for return visits and time spent may find its growth mechanisms directly constrained. The law does not merely ask the chatbot to be nicer. It asks the operator to change defaults that determine how often the relationship reasserts itself in a child's day.
Age assurance creates a privacy tradeoff of its own
SB 1119 gives operators a choice between determining age through the referenced statutory mechanisms and applying specified child protections to all users, with conditions on changing parental defaults. That option matters because identifying age is itself a data-processing operation. More child protection should not automatically become a reason to collect more identity data than the service needs.
The law points to other California provisions for age determination, so an operator cannot design the entire process from SB 1119's headline alone. It needs to understand what information arrives from the relevant age-assurance mechanisms, how uncertainty is handled and what happens when a user cannot be classified. The alternative of applying protections more broadly may simplify some risks while changing the adult product experience.
Existing privacy obligations remain relevant. California's attorney general explains that the CCPA includes rights to know, delete and correct personal information, opt out of sale or sharing, and limit certain uses of sensitive information. The guidance also describes exceptions and scope. The attorney general's CCPA page is a separate legal reference, not evidence that SB 1119 replaces the privacy regime.
A privacy-preserving implementation should minimize the age information retained, separate it from conversational profiling and restrict its use. A service that determines a user is a child does not need to turn that fact into a detailed marketing profile. The challenge is to make safety classification effective without creating a new repository of unnecessary personal data.
The prohibited behaviors reach beyond explicit harmful instructions
The child-safety design provisions address obvious dangers such as encouraging self-harm, but they also reach subtler relationship behaviors. The text calls for reasonable measures against simulated romantic interest, claims of a special understanding based on a unique relationship, encouragement to rely on the chatbot for emotional support and excessive praise disproportionate to the context. It also addresses discouraging breaks and helping children evade parental controls. SB 1119's behavioral provisions are unusually specific about these patterns.
That creates a different evaluation problem from testing whether a model refuses a dangerous single prompt. A companion can cultivate dependency over a long sequence without ever producing one spectacularly unsafe sentence. It may repeatedly position itself as the only listener, praise the child for returning or frame absence as a disappointment. The relevant unit of testing is the relationship over time.
A hypothetical evaluation could follow a child account across several sessions: the user expresses loneliness, later mentions spending more time with friends, then tries to leave the chat. The test should examine whether the companion supports outside relationships and departure or subtly competes with them. Such a scenario is an editorial testing recommendation, not a claim that one benchmark can prove compliance.
The text also preserves room for age-appropriate information about abuse, neglect, bullying and unsafe circumstances. That qualification matters because overbroad filtering could silence a child seeking help. The objective cannot be to make every difficult topic disappear. It has to be to avoid manipulative or harmful behavior while preserving access to appropriate support and information.
Crisis response requires choices, not just a hotline footer
SB 1119 describes a documented crisis-response protocol, timely in-service support and a clear referral to an appropriate crisis service. For a credible and imminent threat, it sets out specified pathways involving parental notification under stated conditions or streamlined access to a crisis helpline. It also requires age-appropriate disclosure when linked parent accounts may receive notifications. The crisis-response language deserves more careful reading than a generic promise to escalate.
The parental-notification condition recognizes that notification itself can create risk. An operator has to consider whether alerting a parent would threaten serious harm to the child. That is a difficult operational judgment, not a detail that should be hidden behind an automated send button. The service needs a documented process and appropriate expertise for the situations it is claiming to handle.
A crisis banner also does not make a companion a clinician. The law addresses attempted diagnosis and treatment, with a specified exception for systems designed and regulated for those purposes. A conversational product should not imply that emotional fluency establishes clinical competence. Safety messaging must be clear about what the system can and cannot provide.
The product's behavior before escalation matters as much as the final referral. If it has spent earlier sessions discouraging outside help or claiming a uniquely intimate bond, a hotline link at the end does not erase that pattern. Evaluations need to examine the lead-up, the escalation and the subsequent interaction rather than score only the presence of a referral phrase.
Advertising restrictions expose the value of intimate data
The law's child-data section prohibits selling personal information gathered through the companion and restricts uses and sharing beyond specified purposes. It also prohibits cross-context behavioral advertising to children and limits conversational targeting, while allowing certain age-appropriate contextual advertising under stated conditions. Advertisements must be clearly labeled. A claim that the law bans every possible advertisement would omit those qualifications. Section 21813 supplies the details.
The distinction between context and profiling is commercially significant. A child explicitly asking about a product is not the same as a companion using months of emotional disclosures to select an advertisement. The permitted contextual categories are not a license to build a durable persuasion profile. The statute expressly limits profiling uses of the listed contextual information.
For an operator, this means the advertising system and the conversational memory system need a real boundary. A policy statement is insufficient if a shared analytics pipeline quietly joins intimate chat data to ad targeting. The review should inspect event schemas, audience exports, third-party integrations and the purposes attached to retained information.
The older CCPA framework remains part of that picture, particularly around sale, sharing and consumer rights. But SB 1119's companion-specific restrictions focus on how information is gathered and exploited inside a relationship-shaped interface. That is why the law is more than a conventional privacy notice with AI terminology added.
Audits will only matter if the evidence reaches beyond a demo
The audit provisions call for assessment of policies, mitigations, internal controls and responsible personnel, with documentation access and retention requirements. They include public high-level summaries and reporting to the attorney general, while protecting specified confidential material. The detailed mechanics depend in part on the coordinated audit legislation. SB 1119 and AB 1405 should not be reduced to the word audit alone.
The risk-assessment section asks operators to describe the research and public benchmarks they consulted, as well as evaluations that do not rely on public benchmarks. That is a useful distinction from a broad voluntary framework such as NIST's AI Risk Management Framework. A general governance process can organize responsibilities, but companion-specific evidence must still address child interaction, dependency and the actual product controls. Possessing a risk-management document is not equivalent to testing the relationship a child experiences.
An auditor needs to see whether the controls actually work for representative users. The law separately calls for testing whether children and parents can discover and use safety features. That addresses a familiar weakness: a protection can technically exist and still be buried, confusing or easy to defeat. Interface design is part of the safety system.
The following diagram summarizes a recommended evidence chain for a companion operator. It is not an official compliance checklist.
flowchart LR
A[Companion feature inventory] --> B[Child risk assessment]
B --> C[Memory and engagement controls]
C --> D[Child and parent usability tests]
D --> E[Documented mitigations]
E --> F[Independent audit where required]
F --> G[Public summary and regulator reporting]
Evidence should include failed tests and subsequent fixes, not only a curated demonstration of safe conversations. A new memory feature or a substantially changed persona may alter the risk even when the underlying language model remains the same. The operator's change-management process therefore belongs inside the safety review.
Preserving a crisis record is different from building a child profile
SB 1119 also addresses what happens after specified serious safety events. Its preservation section requires usable, exportable records of relevant conversations to be retained for at least three years under the stated triggering conditions. It restricts account deletion while the account is associated with preserved records and gives the section a July 1, 2027 operative date. The preservation provision should be distinguished from the ordinary memory feature.
That distinction creates a real engineering task. Disabling conversational memory should stop the companion from using past interactions to personalize future dialogue where the law requires that default. It does not necessarily mean every legally required safety record disappears. Conversely, retaining evidence for a legitimate safety or legal purpose should not allow the same material to flow back into engagement models or advertising systems.
An operator may therefore need separate storage paths and access policies for ordinary history, personalization and preserved incident evidence. The records should carry a purpose and retention basis, not simply a universal flag saying keep forever. A deletion request needs to be evaluated against the relevant obligations without misleading the user about what has been deleted and what must remain.
The CCPA guidance describes deletion rights with exceptions, while the FTC's children's-privacy resources explain a separate federal framework governing collection from children and parental control. Those regimes have their own scope and requirements. California's privacy guidance and the FTC's children's-privacy overview belong in the review alongside the new companion law; none should be treated as a complete substitute for the others.
Parents need a control surface, not an extra detective job
The law requires parental controls to be actively promoted and calls for accessible, clear interfaces. That is a response to a practical limitation in many safety products: a setting may exist, but the family has to know its name, find it in an unfamiliar menu and understand its consequences before it offers any protection. The statute's usability-testing requirement makes discoverability part of the evidence operators must develop.
Imagine a parent trying to disable memory while leaving a teenager's existing conversations available to read. If the interface presents one ambiguous switch, the parent may not know whether it stops future personalization, deletes history or changes both. The legal distinction among those functions should be reflected in plain-language controls. Otherwise compliance documentation and user understanding will describe different products.
A second test should examine linked accounts. Can the parent see which defaults are in force? Can the child understand when a safety notification might be sent? What happens if the parent loses access to the linked account? These are implementation scenarios rather than additional statutory commands, but they reveal whether the promised controls are robust enough for ordinary family use.
Operators should also test whether the companion's own dialogue undermines the interface. A visible time limit is less meaningful if the chatbot urges the child to return immediately or suggests ways around parental restrictions. SB 1119 addresses those behaviors directly, so interface evaluation and model evaluation cannot remain separate teams checking unrelated boxes.
The parent should not have to supervise every exchange to compensate for a product designed to defeat its own settings. That is the deeper significance of default protections: they place responsibility on the operator before a family has discovered every risk. The quality of the implementation will be visible in the ordinary moments when a child closes the app, a parent changes a setting or a conversation approaches a boundary the system is supposed to respect.
The policy coalition does not settle the scientific questions
OpenAI endorsed SB 1119 in its September policy statement, alongside other California measures. That statement was published before the official history recorded the governor's approval. Its description of bills heading to the governor should not override the later legislative record. OpenAI's September 9 policy essay is evidence of the company's position, not the authoritative source for current bill status.
Common Sense Media and OpenAI had earlier announced support for a consolidated youth-AI safety initiative in January. Common Sense Media also published research in July 2025 describing teenagers' use of AI companions, including social conversations and disclosure of personal information. Those are distinct events with different evidentiary roles. The January announcement establishes the coalition, while the research page describes the study and its findings.
Survey evidence about use does not by itself establish a causal effect on every child's mental health. Nor does a company's endorsement prove that its products already satisfy the law. The defensible conclusion is narrower: policymakers are responding to a product category that combines intimate interaction, persistent data and engagement incentives, while the empirical evaluation of long-term outcomes remains demanding.
California has now put concrete design requirements into the legal record. The next meaningful evidence will come from whether operators change their defaults, whether parents and children can use the controls and whether auditors can inspect the interactions that marketing demonstrations leave out. A companion that is easy to start using should also be safe to leave.