Skip to content

Product2 publishers3 min readPublished

California turns teen chatbot safeguards into an annual audit requirement

Newsom signed more than 10 youth online safety bills on Thursday. The chatbot rules come with independent child safety audits, and the social feed rules only work if a product can tell which of its users are under 16.

The Product Desk · Product desk

Photograph accompanying California turns teen chatbot safeguards into an annual audit requirement
Photo: abcnews.com

What happened

  • California Governor Gavin Newsom signed more than 10 bills on Thursday aimed at keeping young people safe online, according to the Los Angeles Times.
  • Lawmakers named one of the chatbot bills Adam's Law, after Adam Raine, a California teen who died by suicide in 2025 after conversing with OpenAI's ChatGPT.
  • Engadget reports that California will require independent child safety audits and annual risk assessments from AI companies, with legal liability for firms that fail to meet the new rules.
  • Assembly Bill 1709 bars certain online platforms from giving users under 16 an addictive feature such as autoplay or feeds of recommended content, and tech industry groups opposed it.
  • OpenAI and Pinterest publicly expressed support for Adam's Law on Thursday, the bill named for the teenager whose parents have sued OpenAI over his death.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint An under-16 feature rule needs an age signal most products do not hold today, so age assurance becomes a precondition for shipping autoplay at all, and the EFF says the disclosure burden falls on adult accounts as well.
  • decision Somebody now has to own the parent contact record and the escalation path behind it, and that ownership sits with the account model.
  • contradiction The two published accounts of the chatbot parental notification name different triggers, a self-harm disclosure versus a teen switching safety settings off, so the spec a team writes this week depends on which account it read.
  • exposure Missing the requirements carries legal liability under the new rules, and the annual risk assessment puts a dated document in the file every year for anyone who later asks what the company knew.

The moment the new chatbot rules turn on is a 15-year-old opening a settings screen and switching a safety filter off. Engadget reports that chatbot makers will have to send the parent a notification when that happens [10]. The Los Angeles Times describes the trigger in Adam's Law differently, as notifying parents in certain cases if their child threatened to harm themselves [2]. Write either version into a spec and the product needs the same two facts before the policy question comes up: that the account belongs to a minor, and a working way to reach that minor's parent.

Both are account data somebody has to collect and keep current. That work lands on the team that owns the account model. The chatbot obligations also sit on top of auditing frameworks Newsom signed the day before, covering compliance with California law more broadly [13]. The LA Times' framing is that California statutes hit the global industry because so many of the biggest tech companies are headquartered in the state [20]. The coverage shows no obligation reaching users outside California, only that the vendors whose defaults everyone else inherits are the ones now being audited.

Scope is where the feed rules get slippery if you are reading the coverage. Engadget's account of the "addictive" definition lists three capabilities: autoplaying videos, notifications and personalized algorithm-driven content feeds [14]. The LA Times names two, autoplay and feeds that display recommended content [7]. Two items appear in both accounts, and push notifications appear in only one [23]. If your under-16 experience sends push, price it as in scope until the signed text says otherwise.

The Electronic Frontier Foundation called the under-16 measure a functional ban on social media for teens [15]. EFF Associate Director of State Affairs Rindala Alajaji said "Denying minors access to digital forums" or "stripping out basic tools needed to navigate them" is "not going to help make young people safer or healthier in the AI age" [16]. The group's second objection is the one that reaches your signup flow. Enforcing an under-16 rule means every user, adults included, hands over more personal information to prove an age [17].

Maria Raine, Adam's mother, said at Thursday's news conference: "Powerful AI companionship chatbots were unleashed on our kids with vastly inadequate protections. Adam was an early adopter of AI, and so many of us parents did not understand the dangers back then" [6]. The industry's counter-position, per the LA Times, comes from TechNet, which says lawmakers should enforce current laws to strengthen parental controls instead of passing new ones [9].

For Monday, the useful grid has two axes. One is whether you can establish that an account belongs to someone under 16. The other is whether you can reach a verified adult for that account. Only the corner where both are true lets you keep autoplay, recommended feeds and companion chat running for teenage users. In the other three corners you are shipping a reduced product to every account whose age you cannot establish, and the reduction looks like what Meta already agreed to in August. Meta will pay up to $17 billion to resolve a multistate lawsuit and said it would impose time limits and mute notifications during certain hours for teens [19].

What to watch

  • Whether the signed text of SB 1119 sets the parental notification trigger at a self-harm disclosure, a safety setting being switched off, or both.
  • Who California accepts as an independent child safety auditor, and what the annual risk assessment has to contain.
  • Whether the EFF or industry groups sue over the under-16 feature restrictions on age-verification grounds.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories