Skip to content

Build1 publisher3 min readPublished

California's Adam's Law sets a July 1, 2027 deadline for child safeguards in companion chatbots

Gavin Newsom signed California's SB 1119 on September 10, 2026, setting July 1, 2027 as the start date for its central duties on chatbots used by minors. Companion-chatbot operators with California users have 294 days to build age checks, child-safe defaults and a pre-launch risk assessment into the product.

The Engineer · Build desk

Illustration accompanying California's Adam's Law sets a July 1, 2027 deadline for child safeguards in companion chatbots

What happened

  • Operators must determine a user's age through California's age-assurance framework, or else apply the law's specified child protections more broadly.
  • Parent-controlled default settings must disable push notifications, limit a continuous session to one hour and cap total daily chatbot use at two hours.
  • Persistent conversational memory is disabled by default for child users unless the operator implements the safety guardrails the law describes.
  • On a credible and imminent threat, the required action can include notifying a linked parent account or providing streamlined access to the 988 Suicide & Crisis Lifeline.
  • From July 1, 2027, operators may not show children cross-context behavioral ads or target ads using personal information from a child's conversations.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision A product without a dependable age signal has to choose between integrating California's age-assurance framework and extending the child protections, usage caps included, to a wider pool of users.
  • constraint A memory feature built as one global setting has to become age-aware, since child accounts start with persistent memory off until the law's guardrails exist.
  • exposure Automatic deletion jobs become a liability for child accounts: once the preservation duty triggers, records must survive in exportable form, so retention systems need a per-account hold.
  • cost Every release that counts as a substantial modification carries a documented assessment first, so teams that change models or prompts often add compliance work to each release cycle.

Start with scope. The law was chaptered as Chapter 190 of the Statutes of 2026 [2]. A dev.to summary working from the chaptered bill page and the Governor's announcement [4] sets out who it reaches. It covers operators that make covered companion chatbots available to California users, and anyone under 18 counts as a child [5]. It borrows an existing legal definition of "companion chatbot", so an automated help widget is not necessarily in scope. Certain postsecondary educational and workplace-only uses are excluded [6].

The usage limits are the first real engineering work. The one-hour session cap and the two-hour daily cap [13] are two counters with different reset rules, and the daily one allows two full sessions [2]. If no parent account is linked, the child cannot change those defaults [15]. I would not enforce either limit with a client-side timer. A child who moves from a phone to a browser should not get a fresh count. That state belongs on the server, keyed to the account.

Disclosure also moves into the conversation loop. The law requires recurring, age-appropriate notices that the user is talking to an AI [16]. The dev.to summary argues that a notice shown once during onboarding may not be meaningful during an extended, emotionally charged conversation [17]. In practice the notice becomes a scheduled event inside the session.

Crisis handling needs a documented protocol for suicide and self-harm risk, with timely in-service support and referrals to a crisis service [11]. The parent-notification option is conditional. It applies only when notifying the linked parent would not create a threat of serious harm [12]. That condition puts a judgment in front of the notification. Whoever builds the escalation path has to decide who makes that call, and on what evidence, before any message reaches a parent.

The privacy rules reach into the data pipeline. An operator may not sell personal information gathered from a child through the chatbot [19]. Use and sharing are limited to purposes such as providing the service, safety and security, legal compliance and defending legal claims [19]. Dark patterns around the required safety features and controls are prohibited [19]. There is also a preservation duty. If the operator knows a child died or engaged in serious self-harm based on chatbot conversations, or has provided a specified safety notice, it must preserve the relevant conversation records in a usable, exportable form [20].

In my view the risk assessment is the item to start first, because it gates launches. From July 1, 2027, an operator must perform and document a comprehensive assessment before a new or substantially modified companion chatbot is made available in California [8]. It must address physical or financial harm, severe psychological or emotional harm, certain privacy intrusions and unlawful discrimination [9]. Mitigations have to be documented. A product that permits children also needs a published child-safety policy [10]. The dev.to summary does not say what counts as "substantially modified". For a team that swaps base models or rewrites system prompts often, that definition sets how many assessments it writes a year. Several of the central duties start on July 1, 2027 [3], 294 days after the signing [1].

What to watch

  • The chaptered text's definition of a "substantially modified" chatbot, since it decides whether routine model and prompt updates trigger a fresh risk assessment.
  • What California's age-assurance framework accepts as a determination of age, and whether operators treat the broad-protection fallback as the cheaper path.
  • The first published child-safety policies from companion-chatbot operators ahead of July 1, 2027.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories