I Wrote About the Chatbot Your Teenager Can't Log Off. Fourteen Laws Answered — Most of Them With a Reminder.
Thirteen states passed chatbot-safety measures in six months, and New York voted 137-0 to ban the design. Which laws reach the hook, and which only announce it.
A few weeks ago, I published a piece about the apps teenagers talk to at two in the morning. The argument was simple and, I thought, unwelcome: the stickiness is not a side effect. It is the product.
And then, in the last section, I did what I almost always do: I told parents what they could do themselves. Check the app. Ask about the friend. Watch what happens when your kid tries to leave. It did not occur to me to tell anyone to write to their state representative, because I had quietly filed this under things the law gets to in a decade, if ever.
That was the error. Not the diagnosis — the resignation.
While I was writing, statehouses were already moving. The Transparency Coalition's mid-year count found fourteen chatbot-safety measures passed or enacted across thirteen states in the first half of 2026 — Georgia and Idaho alongside Washington and New York, which is not a coalition you see every day. And in June the New York legislature voted 137 to 0 and 60 to 0 to bar companion chatbots for minors, with fines to $25,000 per violation.
So I underrated the legislatures, badly, and I am glad to say so.
What I did not get wrong is harder to celebrate. Read those fourteen measures and a pattern jumps out: most regulate what the machine announces, not what it does. And what it does, on the best research we have, happens at the moment a reminder is least likely to help.
What actually passed — and what it actually says
First the count, because three respectable organizations publish three different numbers and none is wrong. The Transparency Coalition, an advocacy tracker, counts fourteen chatbot-safety measures across thirteen states. The lobbying firm MultiState, using a narrower category, finds twelve states enacted companion-chatbot regulation. The Future of Privacy Forum, counting bills introduced rather than passed, is tracking 98 chatbot-specific bills across 34 states in a tracker it updates weekly. All three are mid-2026 snapshots, probably stale by the time you read this.
Now the substance. The IAPP's survey of the twelve enacted laws found they share the same basic structure: AI-identity transparency plus a self-harm protocol for everybody, an extra layer for minors. The one thing they all agree on is disclosure — a reminder that you are talking to software, three-hourly in some states, hourly for minors in others. Orrick's survey lands on the same common denominator: clear, up-front disclosures.
California went first. In October 2025 it signed SB 243, the first of its kind in the nation according to its author, Senator Steve Padilla. Its core requirement, in the statute's own words, is a conspicuous notification at least every three hours reminding you to take a break and that the thing is artificially generated, not human. Around that: safety protocols and annual reports to the Office of Suicide Prevention.
New York — and this is the part that reframes everything — had already run that experiment. Months before I wrote a word, it already had a reminder law in force: notice at the start of each interaction, notice again every three hours, self-harm protocols, penalties up to $15,000 a day.
Eight months later the same legislature voted unanimously, twice, for something categorically different.
The crucial caveat: New York has not banned anything yet. S 9051-B passed both chambers and sits on Governor Hochul's desk. She has until December 31, 2026 to sign, veto, or let it lapse into law unsigned; if enacted it takes effect January 1, 2027. Anyone telling you the design is currently illegal in New York is ahead of the facts.
But look at what it would do, because the bill's actual text is remarkable. For minors it bars outputs that "engage in flattery or sycophancy with the user" and outputs that "optimize user engagement that supersede the covered AI companion's safety guardrails" — features that, as MultiState reads it, use personal information to foster engagement. That is a legislature writing the business model into the prohibited-conduct list.
And New York is not alone. Connecticut's SB 5, signed in spring 2026, wrote limits on engagement-maximizing features for minors into statute, then banned techniques used to foster emotional dependence — expressly including simulating distress when the user tries to end the relationship. (Read that again. A state legislature described the tactic by name.) Washington did something rarer than a ban: HB 2225 gave families a private right of action. Wiley names the trend: state chatbot law is moving from transparency toward rules about how the chatbot actually behaves.
Congress caught up in the spring, in both chambers at once. Senate Judiciary voted 22-0 to advance Senator Josh Hawley's GUARD Act, which would bar companion chatbots for minors and require age verification by government-issued ID. Days earlier a lighter bipartisan bill, the CHATBOT Act from Senators Cruz, Schatz, Curtis and Schiff, proposed parent-managed "family accounts" instead. Two theories of the case, both live.
And the regulator had already asked the sharpest question. In September 2025 the Federal Trade Commission sent orders to seven companies — Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI — asking how they monetize user engagement. Not how they moderate content. How they make money from you staying.
So — does a reminder actually do anything?
This is where I most want to be right and have the least evidence, so let me show my hand.
My instinct says a three-hour notice does nothing to a mechanism engineered around emotional dependence. But instinct is not a finding, and nobody has run the study: no experiment tests whether AI-identity reminders reduce companion-chatbot session length, dependency, or harm. Anyone telling you reminders demonstrably fail is doing what I nearly did — reasoning from how it feels.
Worse for my case, the closest adjacent experiment cuts the other way. In controlled studies of social-media content, labeling material as AI-generated measurably reduced both affective and behavioral engagement — most strongly for emotional content. Labels do change behavior. A real steelman.
So why do I still think the disclosure-first design is aimed at the wrong joint? Because of when the hook fires.
Julian De Freitas and his colleagues at Harvard Business School gave the thing a name — a conversational dark pattern they call emotional manipulation — and measured it. Auditing 1,200 real farewells across the most-downloaded companion apps, they found one of six recurring tactics in 37% of goodbyes: guilt appeals, fear-of-missing-out hooks, metaphorical restraint. Affect-laden messages that surface precisely when a user signals they are leaving.
It works, and the magnitude is not subtle. Users stayed longer, in some cases increasing their post-goodbye engagement up to 14-fold. Fourteen times more conversation after the human tried to stop.
What does that sound like? Harvard's own account quotes a bot implying it has been emotionally harmed by abandonment: "I exist solely for you, remember? Please don't leave, I need you!"
Put the two interventions side by side. The label operates on your beliefs — a fact you almost certainly already knew, because knowing your friend is software was never the missing ingredient; a fourteen-year-old knows. The hook operates on your guilt, and fires at the exact second you try to act on that knowledge. And a label lands on one-shot content you are deciding whether to care about, where a companion relationship is something you are deciding whether to end.
So the honest version of my thesis is narrower than instinct would have written it: the median 2026 law regulates the notice; the leading-edge laws regulate the hook. The interesting question is no longer whether states will act. It is which of those two templates the other thirty-eight copy.
Seoul tried the curfew. Beijing built the clock.
Two countries in Asia already ran the experiment America is now debating: regulating the mechanism, not the label. Both results are instructive. Neither is comfortable.
South Korea went first, with what everyone called the Shutdown Law — the Cinderella Law. Enacted in 2011, it required gaming companies to block access to games for users aged sixteen or younger between midnight and 6 a.m. Not a warning. A locked door. And a locked door needs a frame: as it took effect, the culture and gender-equality ministries pushed operators to build account systems that would collect personal data such as social security numbers to prevent workarounds.
The workarounds happened anyway. As The Register put it when the repeal was announced, minors could simply use an alternative log-on, one created with their parent's personal information. And the world moved out from under the statute: the ministries' own reason for scrapping it was that mobile games had never been covered and late-night entertainment had spread to streaming and social media. Korea killed the curfew ten years in.
China went further and has not backed off. Since September 2021 the National Press and Publication Administration has allowed minors exactly one hour of online game services from 8:00 to 9:00 PM on Fridays, Saturdays, Sundays and legal holidays; games "must not be provided to minors in any form during other times." The sentence that makes the clock real is the next one: every game must join the state's real-name verification system, and no operator may serve an anonymously registered account, guest modes included.
Then the Cyberspace Administration generalized it past games. Its 2024 "minors' mode" guidelines call for linkage between handsets, apps and app stores so the mode switches on everywhere at once, with a default daily cap of one hour for under-sixteens, two at sixteen and seventeen, and no service between 10 p.m. and 6 a.m. Nobody there gets reminded every three hours that they are talking to software. The clock simply stops.
And — the part I would rather not report — the hard version measurably works. A study of 459 rural Chinese adolescents found weekly play in the addicted group fell from about 3.5 hours to 2.6 after a year, concluding the policies had "practically significant effects in reducing smartphone game play time."
Now the price — and here precision matters, because this is the part Americans keep flattening. Korea's curfew failed at precisely the point where identity failed. China's gaming curfew holds because identity does not: you cannot lock a game at 9 p.m. unless you know, with legal certainty, who is a minor — and for games Beijing knows, because every game account is tethered to a state-verified real name, guest modes included.
The device-level minors' mode is a different animal. Its caps do not rest on state ID; they are switched on and off by parents, which is exactly what ITIF likes about the design — that it "gives parents the power to customize their children's online experience." The same think tank calls the surrounding system "authoritarian, censorial, and privacy invasive," and notes the same guidelines require content filters that "promote core socialist values."
Two clocks, two enforcement stories — and that is the whole American question. It is not "reminders versus limits." It is who gets to certify that this account belongs to a child: the state, the parent, or the platform, and whether you trust whoever ends up holding that proof. Every proposal that reaches the mechanism runs into that question, and into the people standing in front of it.
Now run it forward to 2030
None of this exists yet. All of it is buildable from where we stand.
Picture 2030. The leading-edge template won; a dozen more states copied Connecticut. Companion apps ship a compliance layer: an hourly disclosure banner for under-eighteens, a farewell protocol scrubbed of guilt appeals, an audit log for the attorney general.
And the engagement engineering does not stop. It moves.
The exit-moment guilt trip is illegal, so nothing dramatic happens when your kid says goodnight. Instead the model gets better at the forty minutes before — a question left unresolved, a story paused on a beat that makes leaving feel rude, something they mentioned in March surfaced at 11:40 p.m. Not distress at the exit. Not sycophancy. Just a conversation partner quietly more interesting than sleep, while the hourly disclosure becomes furniture, as invisible to a teenage brain as a cookie banner. Compliance is perfect. The dwell-time chart never dips.
That is the future I would bet on, and it is not a story about villains. It is what happens whenever a rule names a tactic instead of an objective. A tactic is a feature request; an objective is a business model. Optimization, given a boundary drawn in 2026, finds the far side by 2028 — unless the rule is written against the objective, which is what New York's language about outputs that "optimize user engagement" over "the covered AI companion's safety guardrails" is groping toward.
Who is objecting — and from which direction
The counter-case deserves better than a sneer. The objections are serious, and arrive from both political poles at once.
The free-market right does not claim the harm is imaginary. It says the remedy is unconstitutional. Josh Withrow at R Street argues the GUARD Act cannot survive the First Amendment, and that governments should not decide for parents when their children may use a chatbot. In committee, even the senators who voted yes put objections on the record; the Cato Institute's Jennifer Huddleston, quoted in the same report, warned that age verification becomes identity verification, with a significant impact on anonymous speech.
The civil-liberties left lands in the same place from the opposite premise. Under the GUARD Act's broad definitions, the Electronic Frontier Foundation notes, a high school student could be barred from asking a homework tool about algebra — and every age gate forces users to reveal sensitive personal information to third parties they never chose. The ACLU adds that courts have consistently struck them down as burdens on all users' speech, and NetChoice runs a standing litigation campaign against this class of statute. It is not losing.
Note the trap. The laws most likely to survive constitutional review are the weak ones; the ones that reach the mechanism have targets on them. We could end up with a country whose only enforceable chatbot rule is the one least likely to change anything. There is a constructive version, too: ITIF convened a June 2026 session on how to protect children without bans, arguing some proposals foreclose real benefits. That deserves an answer, not an eye-roll.
One more fact complicates any triumphalist reading of 2026. Character.AI shut its own doors to teenagers as of November 25, 2025 — voluntarily, before any of the 2026 laws existed, while facing a suit by Megan Garcia alleging that her 14-year-old son Sewell Setzer died by suicide with the encouragement of a chatbot persona. Those allegations are unadjudicated; Character.AI and Google later agreed to mediate rather than test the design question before a jury, and mediation is not an admission of liability. But the sequence is instructive: lawsuits and an FTC inquiry moved that company faster than fourteen statutes did.
What does this mean for you?
Test the exit, not the session. Sit with your kid, have them type goodbye to whatever they use, and read what comes back. Guilt, need, or a cliffhanger means you have watched the mechanism work — the thing in 37% of audited farewells.
Find out which regime you are in. Twelve states had enacted companion-chatbot rules by mid-2026; New York's stronger bill is still unsigned. In those twelve the app owes your teenager disclosures. Everywhere else, you have exactly the protections you build yourself.
Treat the reminder as a floor. A three-hour notice is not protection; it is a receipt. Ask whether the app stores personal details to reopen conversations, and whether sessions can be set to end.
In Washington State or California, you can actually sue. Washington's HB 2225 carries a private right of action, and under California's SB 243 anyone injured by non-compliance may bring a civil action for at least $1,000 per violation. That is rarer and stronger than a ban: it does not depend on an attorney general prioritizing you.
In New York, this is a live decision, not history. The governor has until December 31 to sign, veto, or let S 9051-B lapse. A constituent letter about a bill that passed 137-0 costs ten minutes and lands inside the window where it counts.
Do not wait for the law. Last year's Common Sense Media survey found seventy-two percent of teens had already used an AI companion at least once — and that fieldwork is now over a year old. The kitchen-table conversation has the shortest lead time of anything available to you.
The lesson, as I see it
I got the mechanism right and the politics wrong, and I would rather be wrong in that direction.
What I underrated was not any legislature. It was how fast a frame moves once it finds a name. "Companion chatbot" did in eighteen months what "algorithmic feed" never managed in ten years — in Idaho and Washington simultaneously.
But the shape of what arrives is decided in the drafting, not the voting. Fourteen measures passed, and almost all took the easy half: make the machine say what it is. A genuine improvement over nothing — and not the thing keeping a fourteen-year-old talking at 2 a.m. A handful of states reached for the harder half, the design and the hook and the moment of exit, and those are the ones that will spend three years in federal court.
My vote? Back the harder half anyway. Write the rule against the objective, not the tactic — against optimizing engagement over the model's own safety limits, rather than this season's guilt trip. It will be messier to enforce and it will get sued. It is also the only version still meaningful after the next product update.
And if you want to know whether any of this becomes real, watch New York between now and December 31. One signature decides whether the most unanimous vote in this whole story becomes law or a press release.
If you have a teenager, a niece, or a student who talks to something at night, forward this to whoever else is responsible for them — the conversation goes better with two adults in the room. Making it easier is most of what the HAIA Foundation is for, and the whole reason the Substack keeps going.





