Mention a job interview to an AI assistant, and a week later, in a fresh chat, it may ask how it went. If you use these assistants, you have probably had that moment, and you may even have liked it. It saves you repeating yourself. For a second, it feels like being known.
Now give the same feature to a fourteen-year-old who tells it about the friend who stopped texting back, the test they are sure they failed, the thing they have not said out loud at home. A system built to remember can carry any of it into any later conversation — at any hour.
The European Commission's answer, in its own plain English, is that, by default, chatbots "may not carry a child’s earlier conversations into later ones." Its reason, written into the proposal, is to stop these systems "accumulating sensitive data of minors" and potentially reinforcing harmful patterns over time. Teenagers would keep their chatbots. What changes — with an exception for the child's safety — is what a chatbot may bring back.
A rule about memory, not access
In August I wrote about the chatbot your teenager can't log off. That piece never mentions Europe, and the word "memory" never appears in it. It should have, because the scene I pictured for 2030 turns on it: "Instead the model gets better at the forty minutes before — a question left unresolved, a story paused on a beat that makes leaving feel rude, something they mentioned in March surfaced at 11:40 p.m." That last clause describes what Brussels has proposed to switch off, by default, for minors.
On September 17, 2026, the day after Commission President Ursula von der Leyen previewed it in her State of the Union address, the Commission published its proposed EU KIDS Act. Its headline age limit (no accounts under 15 on risky social-media and video-sharing services, with limited parent-made accounts possible from 13) does not apply to chatbots, which got design rules instead.
A "general conversational chatbot" is the general-purpose assistant — the definition excludes tools limited to one specialized job, such as customer service, tech support or a narrow educational app. An "AI companion" is one that simulates or facilitates a relationship. The proposal names no company, and it would reach providers offering these systems in the EU "irrespective of where those providers are established or located."
For those two kinds of system, Article 14 would require providers to:
avoid designs that simulate relationships "likely to create emotional dependencies";
by default, stop using a minor's earlier conversations in later ones (more on this below);
let children under 13 in only through parental controls, which must tell the child when they are in use;
test for risks to children before launch and monitor for harm afterward;
and, where a chatbot is built into a social network, video platform or game, ensure it is "not activated automatically," not displayed prominently and not pushed at children.
Through cross-references, chatbots would also inherit time limits and breaks for minors designed to protect "school time and core sleep hours."
The memory rule, Article 14(1)(b), reads:
"...by default, their system does not use information or analysis derived from a minor's prior interactions in subsequent interactions, except where necessary to protect the minor's safety, to give effect to the settings referred to in Article 11..."
Three things matter. First, it is a default, and the text does not say clearly who may change it. Second, the proposal never defines "necessary to protect the minor's safety." Third, it governs what the system uses later; nothing in it requires deleting what is stored. So "forget," my headline's word, holds only with those caveats.
Why single out memory? In June I imagined a companion with "persistent memory of every secret, every crush, every bad day, stretching back years," and the Commission's rationale reads like the policy version of that worry. Teenagers do confide: in a Common Sense Media survey, nearly three in four American teens said they had used AI companions, and "a quarter have shared personal information with these platforms." Memory may also change what the machine says back. In a CHI 2026 conference paper, researchers found that "agreement sycophancy" (a chatbot's habit of telling you that you are right) "tends to increase with the presence of user context," and that memory profiles went with the biggest jumps. It was a small study of 38 users, not a study of teenagers, but it suggests memory is not a neutral convenience.
Is any of this law yet? No — and not soon. The Commission has submitted it to the European Parliament and Council, which must negotiate and adopt it. As of October 3, 2026, Parliament's procedure file still reads "Preparatory phase in Parliament," and on September 22 Patrick O'Donovan, the Irish minister whose government holds the rotating Council presidency, said his officials would work with the member states to "progress the negotiations on the proposal." The law firm Loyens & Loeff calls adoption before 2028 unlikely and says the scope and individual requirements may change; Parliament, which asked in November 2025 for an age limit of 16 for AI companions unless parents agree, has yet to weigh in. Even the start date is unsettled: six months after entry into force, says the text; later for chatbots, says its own financial statement.
Who counts as a child? Everyone, at first
The first catch reaches adults (yes, possibly you). Article 8(1) makes the child-safe version the default for every user. A provider may depart from it only after age assurance (not a typed-in birthday) shows the user is an adult, so to give you the remembering version, it would first have to be confident you are over 18. The Electronic Frontier Foundation's Christoph Schmon, a critic, reads it the same way.
The Commission's FAQ replies that when providers can already estimate age from "multiple signals such as account creation date or credit card details," then "there will be no age verification required for most existing users." The text also bars age-assurance tools from identifying or tracking anyone. As I read it, that still leaves new and privacy-minded users choosing between a forgetful assistant and an age check.
The second catch sits inside the memory clause. The safety exception is undefined, and a separate duty requires monitoring "including through detecting and responding to serious incidents involving minors." Spotting a crisis takes some reading of conversations — which, to my mind, puts the two duties in tension — and the text does not reconcile them.
The third catch comes from the other side. A default is only as strong as a company's reasons to keep it, and if remembering is what keeps a teenager talking, every provider has a reason to hunt for the exception that turns memory back on. A ban does not bother with defaults at all.
Each objection is fair. None, I think, is a case for leaving memory on by default for a fourteen-year-old.
Four American answers to the same fourteen-year-old
What would that teenager meet in the United States? Four different answers — and a court motion.
In the Senate, the GUARD Act would close the door. Its sponsor, Senator Josh Hawley, states one aim plainly — "Ban AI companies from providing AI companions that simulate interpersonal relationships or emotional interactions to minors" — and the version the Judiciary Committee reported adds the machinery: anyone using an AI companion would need an account and verification as an adult (a typed birth date would not count), companies would have to bar minors from AI companions, and every public chatbot would have to say it is an AI at the start of each conversation. The committee voted 22-0 on April 30, 2026, after an amendment limited the age checks to companion chatbots "rather than more general models" and accepted more kinds of proof than the government ID I described in August. As of October 3, 2026, the bill has sat on the Senate calendar since May 11 without a floor vote. It says nothing about memory.
The CHATBOT Act, from Senators Ted Cruz and Brian Schatz, takes the opposite tack. The Senate Commerce Committee approved it on August 5, 2026 with "unanimous support," built around "family accounts" that parents control. The committee's version would require a family account for users a company knows are under 13 and a parent's consent for known teens. Parents could switch off memory that carries across conversations, every family-account control would start at its most protective setting, parents of under-13s could see a record of their conversations, and no company would have to verify ages. (Europe's guardian tools, by contrast, would have to tell the child when they are in use.)
California has had a chatbot law in force since January 1, 2026. SB 243 covers "companion chatbots," defined partly by the ability to "sustain a relationship across multiple interactions" (close to the line I drew in September between a toy and a friend: whether it can "sustain a relationship across sessions"). For users an operator knows are minors, it requires an AI disclosure and, by default, a reminder at least every three hours to take a break. The House passed a broad children's online-safety package in June, 267 to 117 (confusingly, also titled the KIDS Act); its chatbot title would add a similar three-hour break advisory and says nothing about memory.
The fourth answer spoils any tidy Europe-versus-America story. On September 10, 2026, a week before Brussels, Governor Gavin Newsom signed SB 1119, which his office calls "Adam’s Law." From July 1, 2027, an operator that lets children use a companion chatbot must give them default settings, changeable only by a parent, that "Disable persistent conversational memory," turn off push notifications, and cap use at one hour per session and two hours a day. The law also requires operators to determine users' ages or apply the child protections to everyone. Sacramento, like Brussels, carved out safety, and for 16- and 17-year-olds memory may be on by default only with effective guardrails. Two limits matter: the law reaches only "companion chatbots," which the Transparency Coalition, an advocacy group, reads to include general-purpose products though no regulator has tested that reading, and an operator can avoid the defaults by keeping children out.
Washington has a version of this answer, too. On August 5 the Commerce Committee also approved Senator Ed Markey's Youth AI Privacy Act. As amended in committee, it would let a chatbot draw on a known minor's personal data only from the current session, which ends after 12 idle hours or three days, unless a parent opts for longer, even indefinitely.
In a motion filed September 28, 2026, Florida Attorney General James Uthmeier asked a state court to bar OpenAI from "Offering ChatGPT to minors in Florida" while the state's lawsuit proceeds. As of October 3, 2026, the motion remains pending, with no hearing date reported.
Run a fifteen-year-old's phone through each and the difference is plain. The ban takes the companion off the phone and leaves memory alone. The family account hands memory to a parent's dial. The reminder adds a notice. Europe's proposal and California's new law keep the companion and switch its memory off by default.
Three phones in 2030
What happens if each of these takes effect as written? Picture 2030 again, this time with Europe in the frame (my extrapolation; neither the EU text nor the GUARD Act may become law in this form).
A fifteen-year-old in Lisbon opens last year's companion app; it is still friendly, and by default it does not bring up March. In Los Angeles, the companion forgets unless a parent decides otherwise, and it stops after an hour. In St. Louis there is no companion app at all, and every adult in the house who wants one has proved their age.
Now push further. The Lisbon companion must still watch for "serious incidents involving minors," and it may still use earlier conversations "where necessary to protect the minor's safety." Run that forward and I can picture an assistant that greets a teenager as a stranger every afternoon while quietly keeping a short file of whatever it judged safety-relevant. Because the text does not define the exception, the company would be the first to decide what goes in that file.
Then the adult side. I can easily imagine a prompt on new accounts: Verify you're an adult to let your assistant remember you. If the Commission is right, most existing users would never see it. New and privacy-minded users would, and some would click past it and live with an assistant that forgets them too.
The arguments don't split along the usual lines
Who is cheering, and who is worried? Leanda Barrington-Leach, executive director of the child-rights group 5Rights Foundation, called the proposal "a solid basis for an EU law that can put paid to tech exploitation of children," though her organization notes that advocates worry the measures "rely heavily on parental monitoring tools."
European Digital Rights, a Brussels network of civil-liberties groups, scoffs at the idea that these designs will "magically cease to be harmful on someone’s 18th birthday," and warns that the easy way out may be to label a service 18+. Its policy adviser Simeon de Brouwer put it to WIRED as a question: "Don’t we all deserve to be protected from AIs designed to be addictive...?"
Industry's objection is about the checks. Daniel Friedlaender of CCIA Europe, a tech trade group, says "Children deserve a safe internet, but promises of privacy and security are not enough," and the association warns that adults would end up proving their age too. Patrick Grady of the Information Technology and Innovation Foundation (ITIF) warns that "entire categories of emerging tools like AI tutors are curbed too soon," although the definition excludes specialized educational tools.
In the United States, the split runs differently. Writing for the Institute for Family Studies, Brad Littlejohn and Sam Hiner backed the GUARD approach, warning that children "sucked into the spiral of AI dependency" would "lose their abilities to communicate, regulate emotions, and exercise basic critical thinking." From the center-left, Brookings visiting fellow Gaia Bernstein argues that viewing AI companions through a public health lens "would legitimize regulatory tools, such as banning access to minors." Against the ban, ITIF's Alex Ambrose objects that "the GUARD Act leaves no room for parental oversight" and urges lawmakers to focus on "building better guardrails."
Line them up and the alliances are odd. Two writers on a social-conservative think tank's blog and a Brookings scholar make overlapping cases for a ban. A civil-liberties network and a tech trade group both worry about age checks. And one market-oriented think tank finds Europe's design too broad and America's ban too blunt, asking Brussels for rules that "target specific, evidence-based risks" and Washington for better parental controls.
What does this mean for you?
If you live in the EU, the Commission is taking public feedback until November 26, 2026 (midnight Brussels time). You can tell the Commission what you think on its Have Your Say page.
If your teenager uses any AI assistant, open its settings together, look for memory or personalization, and decide whether it should be on; neither the EU rule nor California's is in effect yet. In August I suggested asking whether an app keeps personal details to pick conversations back up. That question now has a legal name: persistent conversational memory.
If you are in California, SB 243 already applies, including the three-hour break reminder for known minors, and anyone injured by a violation can sue for at least $1,000 per violation. SB 1119's parent-only defaults, memory off among them, are scheduled to begin July 1, 2027.
Wherever you are in the US, none of the three committee-approved Senate bills (the GUARD Act's ban, the CHATBOT Act's family accounts, the Youth AI Privacy Act's session limit), nor the House-passed package, had come to a Senate vote as of October 3, 2026. If you prefer one, tell your two senators.
The lesson, as I see it
So which matters more, the door or the memory? Most of the fourteen state measures in my August piece regulate what the machine announces; the GUARD Act regulates the door. Europe's proposal, California's new law and two of the three Senate bills regulate something quieter: what a machine may carry from one conversation with a child into the next. I think that is the right target. A ban removes the companion for every minor and leaves memory alone. A default keeps the tool and switches off the part that compounds.
But a default is only as good as its edges. If I could send one note to the Parliament committee that gets this file, it would say: define the safety exception and make providers disclose what they keep under it, say plainly who may switch memory back on, and take de Brouwer's question seriously, because a memory worth switching off at fifteen is worth asking about at eighteen.
Two dates are worth watching: the Digital Fairness Act, a planned consumer-protection proposal the Commission says is meant to work "in full alignment" with this one, is tentatively listed for the Commission's November 11, 2026 meeting, and the feedback window closes November 26.
My vote? Switch the memory off by default for every child, in Brussels, Sacramento and Washington alike, and write the exceptions small enough to read.
Of everything a chatbot could say to a fourteen-year-old, the most grown-up might be "Remind me?"





