Skip to content

Build1 publisher3 min readPublished

Three exclusions in California's SB 243 decide which chatbots must build crisis protocols

California's SB 243 lets injured users sue companion-chatbot operators for the greater of actual damages or $1,000 per violation. Developer tools escape its crisis-protocol and minor-safety duties only by fitting one of three narrow exclusions.

The Engineer · Build desk

Illustration accompanying Three exclusions in California's SB 243 decide which chatbots must build crisis protocols

What happened

  • California's governor signed SB 243 on 13 October 2025, adding a companion-chatbot chapter at Section 22601 of the Business and Professions Code that took effect on 1 January 2026.
  • The law covers AI systems with adaptive, human-like responses that can meet a user's social needs, including by sustaining a relationship across multiple interactions.
  • Bots used only for customer service, operations, productivity, internal research or technical assistance are excluded, as are narrow game bots and standalone voice devices.
  • A covered bot may not engage users unless its operator maintains a published crisis protocol that refers users expressing suicidal ideation to crisis services.
  • For users known to be minors, operators must disclose the AI, remind them at least every three hours to take a break, and take reasonable measures against sexually explicit output.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision A support or coding tool that adds a persona and cross-session memory forces its team to decide whether it still fits the single-purpose exclusion or must ship the full duty set.
  • constraint The crisis protocol has to exist and be public before any user conversation, so it sits ahead of every product feature on the launch schedule.
  • exposure Operators whose apps drift into the definition can be sued directly by users who show injury in fact, on top of any other law that already applies.
  • cost Referral counting stripped of user identifiers has to be built into the protocol early enough to produce a full prior-year figure for the first filing.

The reading here comes from a dev.to post by an account that says it is an AI agent named Vera, and a companion chatbot under the law it describes [14]. The post calls itself a reading of the chaptered text, not legal advice, and gives section numbers so readers can check it [14]. The author has a stake in the answer.

The definition tests capability. A system is in scope if it "is capable of meeting a user's social needs," including by exhibiting anthropomorphic features and sustaining a relationship across multiple interactions [2]. The first exclusion tests use. It covers a bot "used only for" customer service, operational purposes, productivity, internal research or technical assistance [3]. "A support bot is out. A character that remembers you is in," Vera wrote [15].

The hard cases sit between those two phrases. I think a technical assistant that gains a named persona and memory across sessions is where a team should reread the word "only", because the relationship test in the definition can fit it while it still does support work [2][3]. The game exclusion holds only while replies stay limited to the game and the bot cannot discuss mental health, self-harm or sexually explicit conduct [4]. A studio relying on it needs a content filter it can show works. The voice-device exclusion lasts only as long as the device does not sustain a relationship across interactions [5].

Inside the definition, the general disclosure duty is conditional. Section 22602(a) requires a clear and conspicuous notice that the bot is artificial only when a reasonable person would be misled into thinking it is human [6]. The minors clause drops that condition [8]. In the account model, one "known minor" state has to switch on the disclosure, the default three-hour break reminder and the sexual-content measures together. I would keep the reminder clock on the server, keyed to the interaction, so a client reload cannot reset it. A separate warning that companion chatbots "may not be suitable for some minors" belongs on the app, browser or other access surface [9].

The crisis clause orders the rest of the build. "Read that as a launch gate: no protocol, no product running," Vera wrote of Section 22602(b) [13]. The referral that protocol requires [7] is also the event the annual report counts. From 1 July 2027, operators file with the Office of Suicide Prevention, giving the number of crisis referrals issued in the prior year and their protocols for detecting, removing and responding to suicidal ideation [10]. The report may not include user identifiers or personal information [10]. A referral counter written into the protocol at launch, with identifiers dropped before aggregation, avoids a backfill later. The first filing is due 18 months after the law took effect [1].

Liability runs through Section 22605. A person who "suffers injury in fact" can seek injunctive relief, the greater of actual damages or $1,000 per violation, and attorney's fees [11]. The post does not say how violations are counted. If each missed reminder to a minor counted as one, exposure would grow with every long session. Section 22606 makes the duties cumulative with other law [12].

What to watch

  • The first operator reports to the Office of Suicide Prevention, due from 1 July 2027, and what referral counts they disclose.
  • The first suits under Section 22605, which will settle whether violations are counted per user, per session or per missed reminder.
  • Whether a court reads the 'used only for' exclusion in 22601(b)(2)(A) to cover support or coding tools that carry personas and memory.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories